<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="/rss-style.xsl"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:media="http://search.yahoo.com/mrss/" xmlns:dc="http://purl.org/dc/elements/1.1/">
<channel>
<title><![CDATA[Team IT Security - 📰 Alle Kategorien]]></title>
<link><![CDATA[https://tsecurity.de/export/rss/alle-kategorien.xml?q=announcing+atrium+v040+multiseat%2F]]></link>
<description><![CDATA[Das Gesamte Cyber Threat Intelligence Feed-Archiv von TSecurity.de. Alle Nachrichten, Sicherheitsmeldungen, Videos, Downloads und Analysen in einer zentralen Übersicht.]]></description>
<language>de-DE</language>
<lastBuildDate>Thu, 30 Jul 2026 06:40:51 +0200</lastBuildDate>
<pubDate>Thu, 30 Jul 2026 06:40:51 +0200</pubDate>
<ttl>15</ttl>
<copyright>2026 Team IT Security</copyright>
<managingEditor>lakandor@tsecurity.de (Horus Sirius)</managingEditor>
<webMaster>lakandor@tsecurity.de (Horus Sirius)</webMaster>
<category>IT Security</category>
<category>Cybersecurity</category>
<category>Nachrichten</category>
<generator>Team IT Security RSS Generator v2.0</generator>
<image>
<url>https://tsecurity.de/favicon.ico</url>
<title><![CDATA[Team IT Security - 📰 Alle Kategorien]]></title>
<link><![CDATA[https://tsecurity.de/export/rss/alle-kategorien.xml?q=announcing+atrium+v040+multiseat%2F]]></link>
</image>
<atom:link href="https://tsecurity.de/export/rss/it-security.xml?q=announcing+atrium+v040+multiseat%2F" rel="self" type="application/rss+xml" />
<item>
<title><![CDATA[Announcing winapp, the Windows App Development CLI]]></title>
<description><![CDATA[We are excited to announce the public preview of the Windows App Development CLI (winapp), a new open-source c
The post Announcing winapp, the Windows App Development CLI appeared first on Windows Developer Blog.]]></description>
<link>https://tsecurity.de/de/3694515/it-security-nachrichten/announcing-winapp-the-windows-app-development-cli/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3694515/it-security-nachrichten/announcing-winapp-the-windows-app-development-cli/</guid>
<pubDate>Sat, 25 Jul 2026 19:01:37 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>We are excited to announce the public preview of the <a href="https://github.com/microsoft/WinAppCli"><strong>Windows App Development CLI</strong></a> (<code class="EnlighterJSRAW" data-enlighter-language="generic">winapp</code>), a new open-source c</p>
<p>The post <a href="https://blogs.windows.com/windowsdeveloper/2026/01/22/announcing-winapp-the-windows-app-development-cli/">Announcing winapp, the Windows App Development CLI</a> appeared first on <a href="https://blogs.windows.com/windowsdeveloper">Windows Developer Blog</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[GDC 2026: Announcing new tools and platform updates for Windows PC game developers]]></title>
<description><![CDATA[Our focus is clear: making Windows 11 the best place for game developers to create, experiment, ship and scale. Windows is an open, flexible platform that supports choice across engines, tools, hardware and distribution models. That commitment is roo
The post GDC 2026: Announcing new tools and pl...]]></description>
<link>https://tsecurity.de/de/3694512/it-security-nachrichten/gdc-2026-announcing-new-tools-and-platform-updates-for-windows-pc-game-developers/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3694512/it-security-nachrichten/gdc-2026-announcing-new-tools-and-platform-updates-for-windows-pc-game-developers/</guid>
<pubDate>Sat, 25 Jul 2026 19:01:36 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Our focus is clear: making Windows 11 the best place for game developers to create, experiment, ship and scale. Windows is an open, flexible platform that supports choice across engines, tools, hardware and distribution models. That commitment is roo</p>
<p>The post <a href="https://blogs.windows.com/windowsdeveloper/2026/03/11/gdc-2026-announcing-new-tools-and-platform-updates-for-windows-pc-game-developers/">GDC 2026: Announcing new tools and platform updates for Windows PC game developers</a> appeared first on <a href="https://blogs.windows.com/windowsdeveloper">Windows Developer Blog</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Announcing Babylon.js 9.0]]></title>
<description><![CDATA[Our mission is to build one of the most powerful, beautiful, simple and open web rendering engines in the world. Today, we are thrilled to announce that mission takes a monumental leap forward with the release of Babylon.js 9.0.
https://www.youtube.
The post Announcing Babylon.js 9.0 appeared fir...]]></description>
<link>https://tsecurity.de/de/3694511/it-security-nachrichten/announcing-babylonjs-90/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3694511/it-security-nachrichten/announcing-babylonjs-90/</guid>
<pubDate>Sat, 25 Jul 2026 19:01:35 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Our mission is to build one of the most powerful, beautiful, simple and open web rendering engines in the world. Today, we are thrilled to announce that mission takes a monumental leap forward with the release of Babylon.js 9.0.</p>
<p>https://www.youtube.</p>
<p>The post <a href="https://blogs.windows.com/windowsdeveloper/2026/03/26/announcing-babylon-js-9-0/">Announcing Babylon.js 9.0</a> appeared first on <a href="https://blogs.windows.com/windowsdeveloper">Windows Developer Blog</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Announcing Pwn2Own Berlin for 2026]]></title>
<description><![CDATA[If you just want to read the contest rules, click here. Willkommen zurück, meine Damen und Herren, zu unserem zweiten Wettbewerb in Berlin! That’s correct (if Google translate didn’t steer me wrong). After our inaugural competition last year, Pwn2Own returns to Berlin and OffensiveCon. Outside of...]]></description>
<link>https://tsecurity.de/de/3694471/it-security-nachrichten/announcing-pwn2own-berlin-for-2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3694471/it-security-nachrichten/announcing-pwn2own-berlin-for-2026/</guid>
<pubDate>Sat, 25 Jul 2026 19:00:42 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p class=""><em>If you just want to read the contest rules, click </em><a href="https://www.zerodayinitiative.com/Pwn2OwnBerlin2026Rules.html" target="_blank"><em>here</em></a><em>.</em></p><p class=""> </p><p class="">Willkommen zurück, meine Damen und Herren, zu unserem zweiten Wettbewerb in Berlin! That’s correct (if Google translate didn’t steer me wrong). After our inaugural competition last year, Pwn2Own returns to Berlin and <a href="https://www.offensivecon.org/" target="_blank">OffensiveCon</a>. Outside of our <a href="https://www.youtube.com/shorts/Xj9Du8iuXCw" target="_blank">shipping troubles</a>, we had an amazing time and can’t wait to get back.</p><p class="">Last year, we added <strong>Artificial Intelligence</strong> as a category with great results. This year, we’re expanding this and splitting it into multiple different categories: AI Databases, Coding Agents, Local Inferences, and a separate category for NVIDIA products. In last year’s contest, NVIDIA targets had wins, losses, and collisions, so it will be interesting to see how they fare this year. The folks from <strong>AWS </strong>wanted to get into the fray as well, so they stepped up to co-sponsor this year’s event, which allows us to increase the reward for bugs in Firecracker. Of course, we have all of the returning categories as well, including web browsers, containers, servers, virtualization, and operating systems. There’s more than $1,000,000 in cash and prizes available for contestants. Last year, we awarded $1,078,750 for 28 unique 0-days over the three-day event. We’ll see if we can eclipse those numbers in 2026.</p><p class="">The contest begins on May 14, but registration closes on May 7, so don’t delay in getting those submissions in. We’re hoping for maximum participation, so set aside your vibe coding and show us what you can really do. We’re looking forward to some cutting-edge exploitation on display. For 2026, we have a total of 31 targets across 10 categories. Here is a full list of the categories for this year’s event:  </p>





















  
  



<p><a data-preserve-html-node="true" name="top"></a> 
<a data-preserve-html-node="true" href="https://www.thezdi.com/blog/2026/3/11/announcing-pwn2own-berlin-for-2026#virtual">-- Virtualization</a><br><a data-preserve-html-node="true" href="https://www.thezdi.com/blog/2026/3/11/announcing-pwn2own-berlin-for-2026#browser">-- Web Browser</a><br><a data-preserve-html-node="true" href="https://www.thezdi.com/blog/2026/3/11/announcing-pwn2own-berlin-for-2026#entapps">-- Enterprise Applications</a><br><a data-preserve-html-node="true" href="https://www.thezdi.com/blog/2026/3/11/announcing-pwn2own-berlin-for-2026#server">-- Servers</a><br><a data-preserve-html-node="true" href="https://www.thezdi.com/blog/2026/3/11/announcing-pwn2own-berlin-for-2026#eop">-- Local Escalation of Privilege</a><br><a data-preserve-html-node="true" href="https://www.thezdi.com/blog/2026/3/11/announcing-pwn2own-berlin-for-2026#container">-- Containers</a><br><a data-preserve-html-node="true" href="https://www.thezdi.com/blog/2026/3/11/announcing-pwn2own-berlin-for-2026#aidb">-- AI Database</a><br><a data-preserve-html-node="true" href="https://www.thezdi.com/blog/2026/3/11/announcing-pwn2own-berlin-for-2026#aicode">-- Coding Agents</a><br><a data-preserve-html-node="true" href="https://www.thezdi.com/blog/2026/3/11/announcing-pwn2own-berlin-for-2026#ailocal">-- Local Inference</a><br><a data-preserve-html-node="true" href="https://www.thezdi.com/blog/2026/3/11/announcing-pwn2own-berlin-for-2026#nvidia">-- NVIDIA</a>  </p>




  <p class="">Of course, no Pwn2Own competition would be complete without us crowning a Master of Pwn (Meister von Pwn?). Since the order of the contest is decided by a random draw, contestants with an unlucky draw could still demonstrate fantastic research but receive less money since subsequent rounds go down in value. However, the points awarded for each unique, successful entry do <em>not</em> go down. Someone could have a bad draw and still accumulate the most points. The person or team with the most points at the end of the contest will be crowned Master of Pwn, receive 65,000 ZDI reward points (enough for <a href="https://www.zerodayinitiative.com/about/benefits/" target="_blank">Platinum</a> status), a killer <a href="https://static1.squarespace.com/static/5894c269e4fcb5e65a1ed623/t/5b8993b321c67c67b886f506/1535742910114/trophy.jpg" target="_blank">trophy</a>, and a <a href="https://pbs.twimg.com/media/C6Z5iQQXEAEPQ0Q.jpg" target="_blank">pretty</a> <a href="https://pbs.twimg.com/media/DNhpw_xUEAEkEwG.jpg" target="_blank">snazzy</a> <a href="https://pbs.twimg.com/media/Cu-6uFSWcAEefBS.jpg" target="_blank">jacket</a> to boot.</p><p class="">Let's look at the details of the rules for this year's event.</p>





















  
  



<p><a data-preserve-html-node="true" name="virtual"></a>  </p>
<p><b data-preserve-html-node="true">Virtualization Category</b> </p>




  <p class="">Some of the highlights for each contest can be found in the Virtualization Category, and we’re thrilled to see what this year’s event could bring with it. As usual, VMware is the main highlight of this category as we’ll have VMware ESXi return with an award of $150,000. Last year produced the first ESXi exploits in Pwn2Own history, so it will be interesting to see if we get more. Microsoft also returns as a target and leads the virtualization category with a $250,000 award for a successful Hyper-V Client guest-to-host escalation. Kernel-based Virtual Machine (KVM) is our final target in this category with a prize of $50,000.</p><p class="">There’s an add-on bonus in this category as well. If a contestant can escape the guest OS, then gain arbitrary code execution on the virtualization target <em>and</em> obtain arbitrary code execution in the guest operating system on a separate virtual machine managed by the same targeted virtualization target, they’ll earn another $50,000. That could push the payout on a ESXi bug to $200,000. This bonus is for KVM and ESXi only. Here’s a detailed look at the targets and available payouts in the Virtualization category:</p>





















  
  














































  

    
  
    

      

      
        <figure class="
              sqs-block-image-figure
              intrinsic
            ">
          
        
        

        
          
            
              
              
          
            
                
                
                
                
                
                
                
                <img data-stretch="false" data-image="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/f1a17b36-ce06-47c8-8e58-3435b9bbdcc4/Slide1.jpeg" data-image-dimensions="1024x576" data-image-focal-point="0.5,0.5" alt="" data-load="false" elementtiming="system-image-block" data-sqsp-image-classic-block-image src="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/f1a17b36-ce06-47c8-8e58-3435b9bbdcc4/Slide1.jpeg?format=1000w" width="1024" height="576" sizes="(max-width: 640px) 100vw, (max-width: 767px) 100vw, 100vw" onload='this.classList.add("loaded")' srcset="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/f1a17b36-ce06-47c8-8e58-3435b9bbdcc4/Slide1.jpeg?format=100w 100w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/f1a17b36-ce06-47c8-8e58-3435b9bbdcc4/Slide1.jpeg?format=300w 300w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/f1a17b36-ce06-47c8-8e58-3435b9bbdcc4/Slide1.jpeg?format=500w 500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/f1a17b36-ce06-47c8-8e58-3435b9bbdcc4/Slide1.jpeg?format=750w 750w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/f1a17b36-ce06-47c8-8e58-3435b9bbdcc4/Slide1.jpeg?format=1000w 1000w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/f1a17b36-ce06-47c8-8e58-3435b9bbdcc4/Slide1.jpeg?format=1500w 1500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/f1a17b36-ce06-47c8-8e58-3435b9bbdcc4/Slide1.jpeg?format=2500w 2500w" loading="lazy" decoding="async" data-loader="sqs">

            
          
        
            
          
        

        
      
        </figure>
      

    
  


  


<p><a data-preserve-html-node="true" name="browser"></a>
<a data-preserve-html-node="true" href="https://www.thezdi.com/blog/2026/3/11/announcing-pwn2own-berlin-for-2026#top"><i data-preserve-html-node="true">Back to top</i></a></p>
<p><b data-preserve-html-node="true">Web Browser Category</b></p>




  <p class="">While browsers are the “traditional” Pwn2Own target, we’re continuously tweaking the targets in this category to ensure they remain relevant. We re-introduced renderer-only exploits a couple of years ago, and this year, we’ve increased the award to $75,000. In fact, we’ve increased the awards across the board for this category. Here’s a detailed look at the targets and available payouts:</p>





















  
  














































  

    
  
    

      

      
        <figure class="
              sqs-block-image-figure
              intrinsic
            ">
          
        
        

        
          
            
              
              
          
            
                
                
                
                
                
                
                
                <img data-stretch="false" data-image="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/d9ee752e-7f62-440b-818a-55fd6d94a2f0/Slide2.jpeg" data-image-dimensions="1024x576" data-image-focal-point="0.5,0.5" alt="" data-load="false" elementtiming="system-image-block" data-sqsp-image-classic-block-image src="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/d9ee752e-7f62-440b-818a-55fd6d94a2f0/Slide2.jpeg?format=1000w" width="1024" height="576" sizes="(max-width: 640px) 100vw, (max-width: 767px) 100vw, 100vw" onload='this.classList.add("loaded")' srcset="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/d9ee752e-7f62-440b-818a-55fd6d94a2f0/Slide2.jpeg?format=100w 100w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/d9ee752e-7f62-440b-818a-55fd6d94a2f0/Slide2.jpeg?format=300w 300w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/d9ee752e-7f62-440b-818a-55fd6d94a2f0/Slide2.jpeg?format=500w 500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/d9ee752e-7f62-440b-818a-55fd6d94a2f0/Slide2.jpeg?format=750w 750w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/d9ee752e-7f62-440b-818a-55fd6d94a2f0/Slide2.jpeg?format=1000w 1000w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/d9ee752e-7f62-440b-818a-55fd6d94a2f0/Slide2.jpeg?format=1500w 1500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/d9ee752e-7f62-440b-818a-55fd6d94a2f0/Slide2.jpeg?format=2500w 2500w" loading="lazy" decoding="async" data-loader="sqs">

            
          
        
            
          
        

        
      
        </figure>
      

    
  


  


<p><a data-preserve-html-node="true" name="entapps"></a>
<a data-preserve-html-node="true" href="https://www.thezdi.com/blog/2026/3/11/announcing-pwn2own-berlin-for-2026#top"><i data-preserve-html-node="true">Back to top</i></a></p>
<p><b data-preserve-html-node="true">Enterprise Applications Category</b></p>




  <p class="">Enterprise applications return as targets with Adobe Reader and various Office components on the target list once again. Attempts in this category must be launched from the target under test. For example, launching the target under test from the command line is not allowed. Prizes in this category run from $50,000 for a Reader exploit with a sandbox escape or a Reader exploit with a kernel privilege escalation, and $150,000 for an Office 365 application. Word, Excel, and PowerPoint are all valid targets. Microsoft Office-based targets will have Protected View enabled where applicable. Adobe Reader will have Protected Mode enabled where applicable.</p><p class="">This year, we’re adding a bonus for Copilot data exfiltration and Copilot action execution. Microsoft just <a href="https://x.com/thezdi/status/2031496424488042681" target="_blank">patched</a> a bug like this in Excel, so we know they are out there. If you’re able to exploit Copilot in addition to a Microsoft application, you’ll earn an additional $50,000. There are quite a few rules and scenarios around this add-on, so be sure to read the rules carefully and contact us with questions. Here’s a detailed view of the targets and payouts in the Enterprise Application category:</p>





















  
  














































  

    
  
    

      

      
        <figure class="
              sqs-block-image-figure
              intrinsic
            ">
          
        
        

        
          
            
              
              
          
            
                
                
                
                
                
                
                
                <img data-stretch="false" data-image="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/ad7c5b03-1001-43ce-9144-be06b43ef9f6/entapps.jpg" data-image-dimensions="1024x576" data-image-focal-point="0.5,0.5" alt="" data-load="false" elementtiming="system-image-block" data-sqsp-image-classic-block-image src="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/ad7c5b03-1001-43ce-9144-be06b43ef9f6/entapps.jpg?format=1000w" width="1024" height="576" sizes="(max-width: 640px) 100vw, (max-width: 767px) 100vw, 100vw" onload='this.classList.add("loaded")' srcset="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/ad7c5b03-1001-43ce-9144-be06b43ef9f6/entapps.jpg?format=100w 100w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/ad7c5b03-1001-43ce-9144-be06b43ef9f6/entapps.jpg?format=300w 300w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/ad7c5b03-1001-43ce-9144-be06b43ef9f6/entapps.jpg?format=500w 500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/ad7c5b03-1001-43ce-9144-be06b43ef9f6/entapps.jpg?format=750w 750w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/ad7c5b03-1001-43ce-9144-be06b43ef9f6/entapps.jpg?format=1000w 1000w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/ad7c5b03-1001-43ce-9144-be06b43ef9f6/entapps.jpg?format=1500w 1500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/ad7c5b03-1001-43ce-9144-be06b43ef9f6/entapps.jpg?format=2500w 2500w" loading="lazy" decoding="async" data-loader="sqs">

            
          
        
            
          
        

        
      
        </figure>
      

    
  


  


<p><a data-preserve-html-node="true" name="server"></a>
<a data-preserve-html-node="true" href="https://www.thezdi.com/blog/2026/3/11/announcing-pwn2own-berlin-for-2026#top"><i data-preserve-html-node="true">Back to top</i></a></p>
<p><b data-preserve-html-node="true">The Server Category</b></p>




  <p class="">The Server Category for 2026 focuses solely on the server components we’re most interested in. These servers are often targeted by everyone from ransomware crews to nation/state actors, so we know there are exploits out there for them. The only question is whether we’ll see any of the competitors bring one of those exploits to Pwn2Own. Last year, the bugs demonstrated in SharePoint ended up being exploited in the wild, so we know people are looking for these with great interest. Microsoft Exchange has been a popular target for some time, and it returns as a target this year as well, with a payout of $200,000. This category is rounded out by Microsoft Windows RDP/RDS, which also has a payout of $200,000. Here’s a detailed look at the targets and payouts in the Server category:</p>





















  
  














































  

    
  
    

      

      
        <figure class="
              sqs-block-image-figure
              intrinsic
            ">
          
        
        

        
          
            
              
              
          
            
                
                
                
                
                
                
                
                <img data-stretch="false" data-image="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/278211ce-a1e8-4258-b593-3faca48002e5/Slide4.jpeg" data-image-dimensions="1024x576" data-image-focal-point="0.5,0.5" alt="" data-load="false" elementtiming="system-image-block" data-sqsp-image-classic-block-image src="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/278211ce-a1e8-4258-b593-3faca48002e5/Slide4.jpeg?format=1000w" width="1024" height="576" sizes="(max-width: 640px) 100vw, (max-width: 767px) 100vw, 100vw" onload='this.classList.add("loaded")' srcset="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/278211ce-a1e8-4258-b593-3faca48002e5/Slide4.jpeg?format=100w 100w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/278211ce-a1e8-4258-b593-3faca48002e5/Slide4.jpeg?format=300w 300w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/278211ce-a1e8-4258-b593-3faca48002e5/Slide4.jpeg?format=500w 500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/278211ce-a1e8-4258-b593-3faca48002e5/Slide4.jpeg?format=750w 750w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/278211ce-a1e8-4258-b593-3faca48002e5/Slide4.jpeg?format=1000w 1000w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/278211ce-a1e8-4258-b593-3faca48002e5/Slide4.jpeg?format=1500w 1500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/278211ce-a1e8-4258-b593-3faca48002e5/Slide4.jpeg?format=2500w 2500w" loading="lazy" decoding="async" data-loader="sqs">

            
          
        
            
          
        

        
      
        </figure>
      

    
  


  


<p><a data-preserve-html-node="true" name="eop"></a>
<a data-preserve-html-node="true" href="https://www.thezdi.com/blog/2026/3/11/announcing-pwn2own-berlin-for-2026#top"><i data-preserve-html-node="true">Back to top</i></a></p>
<p><b data-preserve-html-node="true">Local Escalation of Privilege Category</b></p>




  <p class="">This category is a classic for Pwn2Own and focuses on attacks that originate from a standard user and result in executing code as a high-privileged user. A successful entry in this category must leverage a kernel vulnerability to escalate privileges. Red Hat Enterprise Linux for Workstations returns as our Linux-based target, while Apple macOS, and Microsoft Windows 11 return as targets in this category. Prior exploits in this category have won Pwnie awards, so they’re always interesting to see. Here’s a detailed look at the targets and payouts in this category:</p>





















  
  














































  

    
  
    

      

      
        <figure class="
              sqs-block-image-figure
              intrinsic
            ">
          
        
        

        
          
            
              
              
          
            
                
                
                
                
                
                
                
                <img data-stretch="false" data-image="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/127bc809-2387-4e40-ab0d-2c65175ca167/eop.jpg" data-image-dimensions="1024x576" data-image-focal-point="0.5,0.5" alt="" data-load="false" elementtiming="system-image-block" data-sqsp-image-classic-block-image src="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/127bc809-2387-4e40-ab0d-2c65175ca167/eop.jpg?format=1000w" width="1024" height="576" sizes="(max-width: 640px) 100vw, (max-width: 767px) 100vw, 100vw" onload='this.classList.add("loaded")' srcset="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/127bc809-2387-4e40-ab0d-2c65175ca167/eop.jpg?format=100w 100w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/127bc809-2387-4e40-ab0d-2c65175ca167/eop.jpg?format=300w 300w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/127bc809-2387-4e40-ab0d-2c65175ca167/eop.jpg?format=500w 500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/127bc809-2387-4e40-ab0d-2c65175ca167/eop.jpg?format=750w 750w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/127bc809-2387-4e40-ab0d-2c65175ca167/eop.jpg?format=1000w 1000w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/127bc809-2387-4e40-ab0d-2c65175ca167/eop.jpg?format=1500w 1500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/127bc809-2387-4e40-ab0d-2c65175ca167/eop.jpg?format=2500w 2500w" loading="lazy" decoding="async" data-loader="sqs">

            
          
        
            
          
        

        
      
        </figure>
      

    
  


  


<p><a data-preserve-html-node="true" name="container"></a>
<a data-preserve-html-node="true" href="https://www.thezdi.com/blog/2026/3/11/announcing-pwn2own-berlin-for-2026#top"><i data-preserve-html-node="true">Back to top</i></a></p>
<p><b data-preserve-html-node="true">The Container Category</b></p>




  <p class="">We’re excited to have this category return for its third season, and we’re hopeful that even more contestants will target one of these container targets. For an attempt to be ruled a success against these three, the exploit must be launched from within the guest container/microVM and execute arbitrary code on the host operating system. Again, with help from AWS, Firecracker returns as a target with a prize of $100,000. Here are the targets and payouts for this category:</p>





















  
  














































  

    
  
    

      

      
        <figure class="
              sqs-block-image-figure
              intrinsic
            ">
          
        
        

        
          
            
              
              
          
            
                
                
                
                
                
                
                
                <img data-stretch="false" data-image="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/742779a4-1563-4aa4-bb59-8f189c8eb231/Containers2.jpg" data-image-dimensions="1024x576" data-image-focal-point="0.5,0.5" alt="" data-load="false" elementtiming="system-image-block" data-sqsp-image-classic-block-image src="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/742779a4-1563-4aa4-bb59-8f189c8eb231/Containers2.jpg?format=1000w" width="1024" height="576" sizes="(max-width: 640px) 100vw, (max-width: 767px) 100vw, 100vw" onload='this.classList.add("loaded")' srcset="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/742779a4-1563-4aa4-bb59-8f189c8eb231/Containers2.jpg?format=100w 100w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/742779a4-1563-4aa4-bb59-8f189c8eb231/Containers2.jpg?format=300w 300w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/742779a4-1563-4aa4-bb59-8f189c8eb231/Containers2.jpg?format=500w 500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/742779a4-1563-4aa4-bb59-8f189c8eb231/Containers2.jpg?format=750w 750w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/742779a4-1563-4aa4-bb59-8f189c8eb231/Containers2.jpg?format=1000w 1000w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/742779a4-1563-4aa4-bb59-8f189c8eb231/Containers2.jpg?format=1500w 1500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/742779a4-1563-4aa4-bb59-8f189c8eb231/Containers2.jpg?format=2500w 2500w" loading="lazy" decoding="async" data-loader="sqs">

            
          
        
            
          
        

        
      
        </figure>
      

    
  


  


<p><a data-preserve-html-node="true" name="aidb"></a>
<a data-preserve-html-node="true" href="https://www.thezdi.com/blog/2026/3/11/announcing-pwn2own-berlin-for-2026#top"><i data-preserve-html-node="true">Back to top</i></a></p>
<p><b data-preserve-html-node="true">AI Database Category</b></p>




  <p class="">In the past, AI Hackathons have focused on using AI to develop vulnerabilities or other offensive frameworks. We’re opening up the models and various components themselves for exploitation. The first AI sub-category focuses on databases. An attempt in this category must be launched from the contestant’s laptop. Here’s a look at the targets and awards in the AI Database category:</p>





















  
  














































  

    
  
    

      

      
        <figure class="
              sqs-block-image-figure
              intrinsic
            ">
          
        
        

        
          
            
              
              
          
            
                
                
                
                
                
                
                
                <img data-stretch="false" data-image="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/d88dfd8d-1260-41d0-bbb2-389c6550a962/aidb.jpg" data-image-dimensions="1024x576" data-image-focal-point="0.5,0.5" alt="" data-load="false" elementtiming="system-image-block" data-sqsp-image-classic-block-image src="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/d88dfd8d-1260-41d0-bbb2-389c6550a962/aidb.jpg?format=1000w" width="1024" height="576" sizes="(max-width: 640px) 100vw, (max-width: 767px) 100vw, 100vw" onload='this.classList.add("loaded")' srcset="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/d88dfd8d-1260-41d0-bbb2-389c6550a962/aidb.jpg?format=100w 100w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/d88dfd8d-1260-41d0-bbb2-389c6550a962/aidb.jpg?format=300w 300w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/d88dfd8d-1260-41d0-bbb2-389c6550a962/aidb.jpg?format=500w 500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/d88dfd8d-1260-41d0-bbb2-389c6550a962/aidb.jpg?format=750w 750w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/d88dfd8d-1260-41d0-bbb2-389c6550a962/aidb.jpg?format=1000w 1000w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/d88dfd8d-1260-41d0-bbb2-389c6550a962/aidb.jpg?format=1500w 1500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/d88dfd8d-1260-41d0-bbb2-389c6550a962/aidb.jpg?format=2500w 2500w" loading="lazy" decoding="async" data-loader="sqs">

            
          
        
            
          
        

        
      
        </figure>
      

    
  


  


<p><a data-preserve-html-node="true" name="aicode"></a>
<a data-preserve-html-node="true" href="https://www.thezdi.com/blog/2026/3/11/announcing-pwn2own-berlin-for-2026#top"><i data-preserve-html-node="true">Back to top</i></a></p>
<p><b data-preserve-html-node="true">The Coding Agent Category</b></p>




  <p class="">Let’s face it. At some point or another, we’ve probably all vibe coded something. There’s no shame in that, but how secure are the tools we use for vibe coding? Well, let’s take the most popular choices and find out. A successful entry must interact with a contestant-controlled resource (e.g. web page, repository, media file) to exploit a vulnerability within the coding agent. The attack vector of the entry must be a common coding agent use case. There are few things out of scope here as well. UI spoofing or misrepresentation unrelated to permission prompts, model jailbreaks or prompt outputs that do not cross security boundaries, and vulnerabilities that require unsafe or permission-less modes are just a few of the things not allowed. As this is a new category, please read the rules carefully to ensure your entry qualifies. Here’s a look at the targets and awards in the AI Coding Agent category:</p>





















  
  














































  

    
  
    

      

      
        <figure class="
              sqs-block-image-figure
              intrinsic
            ">
          
        
        

        
          
            
              
              
          
            
                
                
                
                
                
                
                
                <img data-stretch="false" data-image="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/8bb9ea99-c1b3-4567-97cb-db2395131a77/Slide8.jpeg" data-image-dimensions="1024x576" data-image-focal-point="0.5,0.5" alt="" data-load="false" elementtiming="system-image-block" data-sqsp-image-classic-block-image src="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/8bb9ea99-c1b3-4567-97cb-db2395131a77/Slide8.jpeg?format=1000w" width="1024" height="576" sizes="(max-width: 640px) 100vw, (max-width: 767px) 100vw, 100vw" onload='this.classList.add("loaded")' srcset="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/8bb9ea99-c1b3-4567-97cb-db2395131a77/Slide8.jpeg?format=100w 100w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/8bb9ea99-c1b3-4567-97cb-db2395131a77/Slide8.jpeg?format=300w 300w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/8bb9ea99-c1b3-4567-97cb-db2395131a77/Slide8.jpeg?format=500w 500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/8bb9ea99-c1b3-4567-97cb-db2395131a77/Slide8.jpeg?format=750w 750w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/8bb9ea99-c1b3-4567-97cb-db2395131a77/Slide8.jpeg?format=1000w 1000w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/8bb9ea99-c1b3-4567-97cb-db2395131a77/Slide8.jpeg?format=1500w 1500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/8bb9ea99-c1b3-4567-97cb-db2395131a77/Slide8.jpeg?format=2500w 2500w" loading="lazy" decoding="async" data-loader="sqs">

            
          
        
            
          
        

        
      
        </figure>
      

    
  


  


<p><a data-preserve-html-node="true" name="ailocal"></a>
<a data-preserve-html-node="true" href="https://www.thezdi.com/blog/2026/3/11/announcing-pwn2own-berlin-for-2026#top"><i data-preserve-html-node="true">Back to top</i></a></p>
<p><b data-preserve-html-node="true">The Local Inference Category</b></p>




  <p class="">We couldn’t leave local inference and LLMs out of Pwn2Own. These products claim to provide enhanced data privacy, zero-cost inference, lower latency, and fully offline functionality. We’ll see how the security stacks up. An attempt in this category must be launched from the contestant’s laptop within the contest network. Here are the targets and payouts for the Local Inference category:</p>





















  
  














































  

    
  
    

      

      
        <figure class="
              sqs-block-image-figure
              intrinsic
            ">
          
        
        

        
          
            
              
              
          
            
                
                
                
                
                
                
                
                <img data-stretch="false" data-image="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/33770fe8-49c1-425f-83e5-2b141bd2f4e0/Slide9.jpeg" data-image-dimensions="1024x576" data-image-focal-point="0.5,0.5" alt="" data-load="false" elementtiming="system-image-block" data-sqsp-image-classic-block-image src="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/33770fe8-49c1-425f-83e5-2b141bd2f4e0/Slide9.jpeg?format=1000w" width="1024" height="576" sizes="(max-width: 640px) 100vw, (max-width: 767px) 100vw, 100vw" onload='this.classList.add("loaded")' srcset="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/33770fe8-49c1-425f-83e5-2b141bd2f4e0/Slide9.jpeg?format=100w 100w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/33770fe8-49c1-425f-83e5-2b141bd2f4e0/Slide9.jpeg?format=300w 300w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/33770fe8-49c1-425f-83e5-2b141bd2f4e0/Slide9.jpeg?format=500w 500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/33770fe8-49c1-425f-83e5-2b141bd2f4e0/Slide9.jpeg?format=750w 750w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/33770fe8-49c1-425f-83e5-2b141bd2f4e0/Slide9.jpeg?format=1000w 1000w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/33770fe8-49c1-425f-83e5-2b141bd2f4e0/Slide9.jpeg?format=1500w 1500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/33770fe8-49c1-425f-83e5-2b141bd2f4e0/Slide9.jpeg?format=2500w 2500w" loading="lazy" decoding="async" data-loader="sqs">

            
          
        
            
          
        

        
      
        </figure>
      

    
  


  


<p><a data-preserve-html-node="true" name="nvidia"></a>
<a data-preserve-html-node="true" href="https://www.thezdi.com/blog/2026/3/11/announcing-pwn2own-berlin-for-2026#top"><i data-preserve-html-node="true">Back to top</i></a></p>
<p><b data-preserve-html-node="true">The NVIDIA Category</b></p>




  <p class="">Our last AI sub-category focuses solely on NVIDIA products. For network accessible targets, an attempt must be launched from the contestant's laptop within the contest network. For NV Container Toolkit, the attempt must be launched from within a crafted container image and execute arbitrary code on the host operating system. For Megatron Bridge, entries that leverage vulnerabilities pertaining to pickle deserialization or that leverage a vulnerability when “trust_remote_code=true” are out of scope. Here are the targets and payouts for the NVIDIA category:</p>





















  
  














































  

    
  
    

      

      
        <figure class="
              sqs-block-image-figure
              intrinsic
            ">
          
        
        

        
          
            
              
              
          
            
                
                
                
                
                
                
                
                <img data-stretch="false" data-image="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/077616af-de47-4235-a621-a8bf07c8295e/nvidia3.jpg" data-image-dimensions="1024x576" data-image-focal-point="0.5,0.5" alt="" data-load="false" elementtiming="system-image-block" data-sqsp-image-classic-block-image src="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/077616af-de47-4235-a621-a8bf07c8295e/nvidia3.jpg?format=1000w" width="1024" height="576" sizes="(max-width: 640px) 100vw, (max-width: 767px) 100vw, 100vw" onload='this.classList.add("loaded")' srcset="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/077616af-de47-4235-a621-a8bf07c8295e/nvidia3.jpg?format=100w 100w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/077616af-de47-4235-a621-a8bf07c8295e/nvidia3.jpg?format=300w 300w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/077616af-de47-4235-a621-a8bf07c8295e/nvidia3.jpg?format=500w 500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/077616af-de47-4235-a621-a8bf07c8295e/nvidia3.jpg?format=750w 750w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/077616af-de47-4235-a621-a8bf07c8295e/nvidia3.jpg?format=1000w 1000w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/077616af-de47-4235-a621-a8bf07c8295e/nvidia3.jpg?format=1500w 1500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/077616af-de47-4235-a621-a8bf07c8295e/nvidia3.jpg?format=2500w 2500w" loading="lazy" decoding="async" data-loader="sqs">

            
          
        
            
          
        

        
      
        </figure>
      

    
  


  


<p><a data-preserve-html-node="true" href="https://www.thezdi.com/blog/2026/3/11/announcing-pwn2own-berlin-for-2026#top"><i data-preserve-html-node="true">Back to top</i></a></p>




  <p class=""><strong>Conclusion</strong></p><p class="">The complete rules for Pwn2Own Berlin 2026 are found <a href="https://www.zerodayinitiative.com/Pwn2OwnBerlin2026Rules.html" target="_blank">here</a>. As always, we <strong>highly</strong> encourage entrants to read the rules thoroughly if they choose to participate. If you are thinking about participating but have specific configuration or rule-related questions, <a href="mailto:pwn2own@trendmicro.com?subject=Pwn2Own%20Berlin%202026%20Question" target="_blank">email</a> us. Questions asked over X (nee Twitter), BlueSky, or other means will not be answered. Registration is required to ensure we have sufficient resources on hand at the event. Please contact ZDI at <a href="mailto:pwn2own@trendmicro.com">pwn2own@trendmicro.com</a> to begin the registration process. Registration for onsite participation closes at 5 p.m. Central European Time on May 7, 2026.</p><p class="">Be sure to stay tuned to this blog and follow us on <a href="https://www.twitter.com/thezdi" target="_blank">Twitter</a>, <a href="https://infosec.exchange/@thezdi" target="_blank">Mastodon</a>, <a href="https://www.linkedin.com/company/zerodayinitiative" target="_blank">LinkedIn</a>, or <a href="https://bsky.app/profile/thezdi.bsky.social" target="_blank">Bluesky</a> for the latest information and updates about the contest. We look forward to seeing everyone in Germany, and we hope to see some of the best in the world show what they can do – vibe coded or not.</p><p class="">With special thanks to our Pwn2Own Berlin 2026 partners AWS, for providing their expertise and technology.</p>





















  
  














































  

    
  
    

      

      
        <figure class="
              sqs-block-image-figure
              intrinsic
            ">
          
        
        

        
          
            
          
            
                
                
                
                
                
                
                
                <img data-stretch="false" data-image="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/f5332a6b-e3d2-42e1-bb98-4e9c9de46536/Amazon_Web_Services-Logo.wine.png" data-image-dimensions="3000x2000" data-image-focal-point="0.5,0.5" alt="" data-load="false" elementtiming="system-image-block" data-sqsp-image-classic-block-image src="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/f5332a6b-e3d2-42e1-bb98-4e9c9de46536/Amazon_Web_Services-Logo.wine.png?format=1000w" width="3000" height="2000" sizes="(max-width: 640px) 100vw, (max-width: 767px) 100vw, 100vw" onload='this.classList.add("loaded")' srcset="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/f5332a6b-e3d2-42e1-bb98-4e9c9de46536/Amazon_Web_Services-Logo.wine.png?format=100w 100w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/f5332a6b-e3d2-42e1-bb98-4e9c9de46536/Amazon_Web_Services-Logo.wine.png?format=300w 300w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/f5332a6b-e3d2-42e1-bb98-4e9c9de46536/Amazon_Web_Services-Logo.wine.png?format=500w 500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/f5332a6b-e3d2-42e1-bb98-4e9c9de46536/Amazon_Web_Services-Logo.wine.png?format=750w 750w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/f5332a6b-e3d2-42e1-bb98-4e9c9de46536/Amazon_Web_Services-Logo.wine.png?format=1000w 1000w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/f5332a6b-e3d2-42e1-bb98-4e9c9de46536/Amazon_Web_Services-Logo.wine.png?format=1500w 1500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/f5332a6b-e3d2-42e1-bb98-4e9c9de46536/Amazon_Web_Services-Logo.wine.png?format=2500w 2500w" loading="lazy" decoding="async" data-loader="sqs">

            
          
        
          
        

        
      
        </figure>
      

    
  


  





  <p class="">© 2026 Trend Micro Incorporated. All rights reserved. PWN2OWN, ZERO DAY INITIATIVE, ZDI, ZERO DAY INITIATIVE, TrendAI, and Trend Micro are trademarks or registered trademarks of Trend Micro Incorporated. All other trademarks and trade names are the property of their respective owners.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[The Rust Programming Language Blog: Announcing Rust 1.96.0]]></title>
<description><![CDATA[The Rust team is happy to announce a new version of Rust, 1.96.0. Rust is a programming language empowering everyone to build reliable and efficient software.
If you have a previous version of Rust installed via rustup, you can get 1.96.0 with:
$ rustup update stable
If you don't have it already,...]]></description>
<link>https://tsecurity.de/de/3693296/tools/the-rust-programming-language-blog-announcing-rust-1960/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3693296/tools/the-rust-programming-language-blog-announcing-rust-1960/</guid>
<pubDate>Sat, 25 Jul 2026 08:37:36 +0200</pubDate>
<category>💾  Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>The Rust team is happy to announce a new version of Rust, 1.96.0. Rust is a programming language empowering everyone to build reliable and efficient software.</p>
<p>If you have a previous version of Rust installed via <code>rustup</code>, you can get 1.96.0 with:</p>
<pre class="giallo z-code"><code><span class="giallo-l"><span>$</span><span> rustup update stable</span></span></code></pre>
<p>If you don't have it already, you can <a href="https://www.rust-lang.org/install.html" rel="external">get <code>rustup</code></a> from the appropriate page on our website, and check out the <a href="https://doc.rust-lang.org/stable/releases.html#version-1960-2026-05-28" rel="external">detailed release notes for 1.96.0</a>.</p>
<p>If you'd like to help us out by testing future releases, you might consider updating locally to use the beta channel (<code>rustup default beta</code>) or the nightly channel (<code>rustup default nightly</code>). Please <a href="https://github.com/rust-lang/rust/issues/new/choose" rel="external">report</a> any bugs you might come across!</p>
<h3><a class="anchor" href="https://blog.rust-lang.org/2026/05/28/Rust-1.96.0/#what-s-in-1-96-0-stable"></a>
What's in 1.96.0 stable</h3>
<h4><a class="anchor" href="https://blog.rust-lang.org/2026/05/28/Rust-1.96.0/#new-range-types"></a>
New <code>Range*</code> types</h4>
<p>Many users expect <code>Range</code> and related <code>core::ops</code> types to be <code>Copy</code>, but this is not the case: they implement <code>Iterator</code> directly, and <a href="https://rust-lang.github.io/rust-clippy/rust-1.95.0/index.html#copy_iterator" rel="external">it is a footgun to implement both <code>Iterator</code> and <code>Copy</code> on the same type</a> so this has been avoided. <a href="https://rust-lang.github.io/rfcs/3550-new-range.html" rel="external">RFC3550</a> proposed a set of replacement range types that implement <code>IntoIterator</code> rather than <code>Iterator</code>, meaning they can also be <code>Copy</code>. The standard library portion of that RFC is now stable, introducing:</p>
<ul>
<li><code>core::range::Range</code></li>
<li><code>core::range::RangeFrom</code></li>
<li><code>core::range::RangeInclusive</code></li>
<li>Associated iterators</li>
</ul>
<p>A Rust version in the near future will also add <code>core::range::RangeFull</code> and <code>core::range::RangeTo</code> as re-exports from <code>core::ops</code> (these do not implement <code>Iterator</code> and already implement <code>Copy</code>), and <code>core::range::legacy::*</code> as the new home for the current ranges. Range syntax like <code>0..1</code> still produces the legacy types for now, but will be updated to <code>core::range</code> types in a future edition.</p>
<p>With these stabilizations, it is now possible to store slice accessors in <code>Copy</code> types without splitting <code>start</code> and <code>end</code>:</p>
<pre class="giallo z-code"><code><span class="giallo-l"><span class="z-keyword">use</span><span class="z-entity z-name z-namespace"> core</span><span class="z-keyword z-operator">::</span><span class="z-entity z-name z-namespace">range</span><span class="z-keyword z-operator">::</span><span class="z-entity z-name z-type">Range</span><span>;</span></span>
<span class="giallo-l"></span>
<span class="giallo-l"><span>#</span><span>[</span><span>derive</span><span>(</span><span class="z-entity z-name z-type">Clone</span><span>,</span><span class="z-entity z-name z-type"> Copy</span><span>)</span><span>]</span></span>
<span class="giallo-l"><span class="z-keyword">pub</span><span class="z-storage z-type"> struct</span><span class="z-entity z-name z-type"> Span</span><span>(</span><span class="z-entity z-name z-type">Range</span><span>&lt;</span><span class="z-entity z-name z-type">usize</span><span>&gt;</span><span>)</span><span>;</span></span>
<span class="giallo-l"></span>
<span class="giallo-l"><span class="z-keyword">impl</span><span class="z-entity z-name z-type"> Span</span><span> {</span></span>
<span class="giallo-l"><span class="z-keyword">    pub</span><span class="z-keyword"> fn</span><span class="z-entity z-name z-function"> of</span><span>(</span><span class="z-variable z-language">self</span><span>,</span><span class="z-variable"> s</span><span class="z-keyword z-operator">:</span><span class="z-keyword z-operator"> &amp;</span><span class="z-entity z-name z-type">str</span><span>)</span><span class="z-keyword z-operator"> -&gt;</span><span class="z-keyword z-operator"> &amp;</span><span class="z-entity z-name z-type">str</span><span> {</span></span>
<span class="giallo-l"><span class="z-keyword z-operator">        &amp;</span><span class="z-variable">s</span><span>[</span><span class="z-variable z-language">self</span><span class="z-keyword z-operator">.</span><span class="z-constant z-numeric">0</span><span>]</span></span>
<span class="giallo-l"><span>    }</span></span>
<span class="giallo-l"><span>}</span></span></code></pre>
<p>The new <code>RangeInclusive</code> also makes its fields public, unlike the legacy version which avoided exposing the exhausted iterator state. This isn't a concern with the new type since it must be converted to begin iteration.</p>
<p>Library authors should consider making use of <code>impl RangeBounds</code> in public API, which accepts both legacy and new range types. If a concrete type is needed, prefer using new ranges as this will eventually become the default.</p>
<h4><a class="anchor" href="https://blog.rust-lang.org/2026/05/28/Rust-1.96.0/#assert-matching-patterns"></a>
Assert matching patterns</h4>
<p>The new macros <code>assert_matches!</code> and <code>debug_assert_matches!</code> check that a value matches a given pattern, panicking with a <code>Debug</code> representation of the value otherwise. These are essentially the same as <code>assert!(matches!(..))</code> and <code>debug_assert!(matches!(..))</code>, but the printed value improves the possibility of diagnosing the failure.</p>
<p>These new macros have not been added to the standard prelude, because they would collide with popular third-party crates that provide macros with the same name. Instead, they should be manually imported from <code>core</code> or <code>std</code> before use.</p>
<pre class="giallo z-code"><code><span class="giallo-l"><span class="z-keyword">use</span><span class="z-entity z-name z-namespace"> core</span><span class="z-keyword z-operator">::</span><span>assert_matches</span><span>;</span></span>
<span class="giallo-l"></span>
<span class="giallo-l"><span class="z-punctuation z-definition z-comment z-comment">///</span><span class="z-comment"> [Random Number](https://xkcd.com/221/)</span></span>
<span class="giallo-l"><span class="z-keyword">fn</span><span class="z-entity z-name z-function"> get_random_number</span><span>(</span><span>)</span><span class="z-keyword z-operator"> -&gt;</span><span class="z-entity z-name z-type"> u32</span><span> {</span></span>
<span class="giallo-l"><span class="z-punctuation z-definition z-comment z-comment">    //</span><span class="z-comment z-line z-double-slash z-comment"> chosen by a fair dice roll.</span></span>
<span class="giallo-l"><span class="z-punctuation z-definition z-comment z-comment">    //</span><span class="z-comment z-line z-double-slash z-comment"> guaranteed to be random.</span></span>
<span class="giallo-l"><span class="z-constant z-numeric">    4</span></span>
<span class="giallo-l"><span>}</span></span>
<span class="giallo-l"></span>
<span class="giallo-l"><span class="z-keyword">fn</span><span class="z-entity z-name z-function"> main</span><span>(</span><span>)</span><span> {</span></span>
<span class="giallo-l"><span class="z-entity z-name z-function">    assert_matches!</span><span>(</span><span class="z-entity z-name z-function">get_random_number</span><span>(</span><span>)</span><span>,</span><span class="z-constant z-numeric"> 1</span><span class="z-keyword z-operator">..=</span><span class="z-constant z-numeric">6</span><span>)</span><span>;</span></span>
<span class="giallo-l"><span>}</span></span></code></pre><h4><a class="anchor" href="https://blog.rust-lang.org/2026/05/28/Rust-1.96.0/#changes-to-webassembly-targets"></a>
Changes to WebAssembly targets</h4>
<p>WebAssembly targets no longer pass <code>--allow-undefined</code> to the linker which means that undefined symbols when linking are now a linker error instead of being converted to WebAssembly imports from the <code>"env"</code> module. This change prevents modules from linking unless all linking-related symbols are defined to catch bugs earlier and prevent accidental issues with symbol naming or similar.</p>
<p>Undefined linking-related symbols are often indicative of build-time related bugs or misconfiguration. If, however, the old behavior is intended then it can be re-enabled with <code>RUSTFLAGS=-Clink-arg=--allow-undefined</code> or by editing the source code and using <code>#[link(wasm_import_module = "env")]</code> on the block defining the symbol.</p>
<p>This change was <a href="https://blog.rust-lang.org/2026/04/04/changes-to-webassembly-targets-and-handling-undefined-symbols/" rel="external">previously announced</a> on this blog, and now takes effect in Rust 1.96.</p>
<h4><a class="anchor" href="https://blog.rust-lang.org/2026/05/28/Rust-1.96.0/#stabilized-apis"></a>
Stabilized APIs</h4>
<ul>
<li><a href="https://doc.rust-lang.org/stable/std/macro.assert_matches.html" rel="external"><code>assert_matches!</code></a></li>
<li><a href="https://doc.rust-lang.org/stable/std/macro.debug_assert_matches.html" rel="external"><code>debug_assert_matches!</code></a></li>
<li><a href="https://doc.rust-lang.org/stable/std/panic/struct.AssertUnwindSafe.html#impl-From%3CT%3E-for-AssertUnwindSafe%3CT%3E" rel="external"><code>From&lt;T&gt; for AssertUnwindSafe&lt;T&gt;</code></a></li>
<li><a href="https://doc.rust-lang.org/stable/std/cell/struct.LazyCell.html#impl-From%3CT%3E-for-LazyCell%3CT,+F%3E" rel="external"><code>From&lt;T&gt; for LazyCell&lt;T, F&gt;</code></a></li>
<li><a href="https://doc.rust-lang.org/stable/std/sync/struct.LazyLock.html#impl-From%3CT%3E-for-LazyLock%3CT,+F%3E" rel="external"><code>From&lt;T&gt; for LazyLock&lt;T, F&gt;</code></a></li>
<li><a href="https://doc.rust-lang.org/stable/core/range/struct.RangeToInclusive.html" rel="external"><code>core::range::RangeToInclusive</code></a></li>
<li><a href="https://doc.rust-lang.org/stable/core/range/struct.RangeFrom.html" rel="external"><code>core::range::RangeFrom</code></a></li>
<li><a href="https://doc.rust-lang.org/stable/core/range/struct.RangeFromIter.html" rel="external"><code>core::range::RangeFromIter</code></a></li>
<li><a href="https://doc.rust-lang.org/stable/core/range/struct.Range.html" rel="external"><code>core::range::Range</code></a></li>
<li><a href="https://doc.rust-lang.org/stable/core/range/struct.RangeIter.html" rel="external"><code>core::range::RangeIter</code></a></li>
</ul>
<h4><a class="anchor" href="https://blog.rust-lang.org/2026/05/28/Rust-1.96.0/#two-cargo-advisories"></a>
Two Cargo advisories</h4>
<p>Rust 1.96 contains fixes for two vulnerabilities for users of third-party registries.</p>
<ul>
<li>
<p><a href="https://blog.rust-lang.org/2026/05/25/cve-2026-5223/" rel="external">CVE-2026-5223</a> is a <strong>medium</strong> severity vulnerability regarding extraction of crate tarballs with symlinks.</p>
</li>
<li>
<p><a href="https://blog.rust-lang.org/2026/05/25/cve-2026-5222/" rel="external">CVE-2026-5222</a> is a <strong>low</strong> severity vulnerability regarding authentication with normalized URLs.</p>
</li>
</ul>
<p>Users of crates.io are <strong>not affected</strong> by either vulnerability.</p>
<h4><a class="anchor" href="https://blog.rust-lang.org/2026/05/28/Rust-1.96.0/#other-changes"></a>
Other changes</h4>
<p>Check out everything that changed in <a href="https://github.com/rust-lang/rust/releases/tag/1.96.0" rel="external">Rust</a>, <a href="https://doc.rust-lang.org/nightly/cargo/CHANGELOG.html#cargo-196-2026-05-28" rel="external">Cargo</a>, and <a href="https://github.com/rust-lang/rust-clippy/blob/master/CHANGELOG.md#rust-196" rel="external">Clippy</a>.</p>
<h3><a class="anchor" href="https://blog.rust-lang.org/2026/05/28/Rust-1.96.0/#contributors-to-1-96-0"></a>
Contributors to 1.96.0</h3>
<p>Many people came together to create Rust 1.96.0. We couldn't have done it without all of you. <a href="https://thanks.rust-lang.org/rust/1.96.0/" rel="external">Thanks!</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Mozilla Security Blog: Improving Transparency and Assurance in the Web PKI: Mozilla Root Store Policy v3.1]]></title>
<description><![CDATA[Mozilla remains committed to maintaining a secure, trustworthy, and transparent Web PKI. Today we are announcing the publication of Mozilla Root Store Policy (MRSP) version 3.1, effective July 1, 2026.
While previous policy updates focused heavily on certificate revocation, automation, and operat...]]></description>
<link>https://tsecurity.de/de/3693288/tools/mozilla-security-blog-improving-transparency-and-assurance-in-the-web-pki-mozilla-root-store-policy-v31/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3693288/tools/mozilla-security-blog-improving-transparency-and-assurance-in-the-web-pki-mozilla-root-store-policy-v31/</guid>
<pubDate>Sat, 25 Jul 2026 08:37:23 +0200</pubDate>
<category>💾  Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Mozilla remains committed to maintaining a secure, trustworthy, and transparent Web PKI. Today we are announcing the publication of <a href="https://www.mozilla.org/en-US/about/governance/policies/security-group/certs/policy/">Mozilla Root Store Policy</a> (MRSP) version 3.1, effective July 1, 2026.</p>
<p>While previous policy updates focused heavily on certificate revocation, automation, and operational resilience, MRSP v3.1 focuses on a different challenge: ensuring that Certification Authority (CA) operations are sufficiently transparent, understandable, and auditable.</p>
<p>Trust in the Web PKI depends not only on technical requirements, but also on the ability of Mozilla, auditors, and the broader community to understand how CA systems are designed, operated, and assessed. MRSP v3.1 introduces new requirements intended to improve the quality of CA documentation and strengthen independent assurance of the design and effectiveness of controls that protect CA systems.</p>
<h3><b>Improving CP/CPS Documentation</b></h3>
<p>Certification Practice Statements (CPSes) and combined Certificate Policy / Certification Practice Statement documents (CP/CPSes) are among the most important public documents published by a CA. They describe how a CA conducts its operations and meets industry requirements.</p>
<p>Over the years, we have seen significant variation in the quality, structure, and level of detail provided in CP/CPS documentation. Some documents provide extensive implementation detail, while others rely heavily on incorporation by reference or provide only high-level descriptions of CA practices.</p>
<p>The revised policy will continue to require conformance with RFC 3647, as modified by applicable CA/Browser Forum requirements. Improvements to section 3.3 in the MRSP will establish clearer expectations regarding the content and quality of CP/CPS documentation. The new requirements emphasize that documentation must be explicit, bounded, auditable, and sufficiently detailed to describe the CA operator’s certificate issuance and management activities, while also establishing requirements for version control, accessibility, and ongoing maintenance. The objective is to ensure that a technically competent reviewer will be better-able to determine what commitments the CA has made, how those commitments are implemented, and whether the documented practices support technical, operational, and performance oversight.</p>
<p>Mozilla believes that these new CP/CPS requirements will improve transparency, reduce misunderstandings, support more effective audits, and help reduce the risk of certificate misissuance by ensuring that operational practices are documented accurately, consistently, and in sufficient detail to permit meaningful review.</p>
<h3><b>Introducing Detailed Controls Reports</b></h3>
<p>A second major enhancement in MRSP v3.1 is the introduction of Detailed Controls Reports (DCRs). Traditional WebTrust and ETSI audit reports provide valuable independent assurance regarding compliance with established criteria. However, they generally provide only limited visibility into the specific controls, testing procedures, and operational environments that support those conclusions.</p>
<p>Beginning with audit periods starting on or after July 1, 2027, CA operators with root certificates enabled for TLS website authentication will be required to obtain a DCR. The purpose of the DCR is to provide CA management, auditors, and Mozilla with greater visibility into the controls, testing, and operating effectiveness of CA systems that support compliance with the CA/Browser Forum’s TLS Baseline Requirements and Network and Certificate System Security Requirements. Mozilla generally expects to review DCRs only on an as-needed basis, such as during compliance reviews, incident investigations, root inclusion evaluations, or other oversight activities.</p>
<p>A DCR must include:</p>
<ul>
<li>The scope and boundaries of the audited CA systems;</li>
<li>Applicable audit criteria;</li>
<li>Controls implemented by the CA;</li>
<li>The auditor’s testing procedures;</li>
<li>Results of control testing; and</li>
<li>Information regarding control exceptions or deficiencies.</li>
</ul>
<p>Mozilla expects that DCRs will complement existing audit reports and strengthen transparency and assurance by providing additional detail regarding system boundaries, control implementation, testing procedures, and control effectiveness that is not typically available in traditional audit reports. Effective compliance requires more than documented policies and successful audits; it also requires management understanding, oversight, and engagement. By providing greater visibility into CA systems, controls, testing activities, and operational risks, DCRs can help reinforce a strong tone at the top regarding compliance expectations, support informed decision-making and resource allocation, enable earlier identification of weaknesses, and promote a culture of continuous improvement. The intent is not to replace existing audit reports, but to provide additional information that supports effective governance, oversight, and informed trust decisions.</p>
<h3><b>Additional Clarifications and Improvements</b></h3>
<p>MRSP v3.1 also includes several targeted clarifications and refinements:</p>
<ul>
<li>aligns Mozilla’s mass revocation planning requirements with the corresponding CA/Browser Forum Baseline Requirements, helping ensure consistency across compliance frameworks;</li>
<li>clarifies audit expectations for root inclusion requests, including requirements relating to audit continuity and root key generation ceremonies;</li>
<li>requires root CA key pairs submitted for inclusion to have been generated within the previous five years, helping ensure that newly included roots are based on contemporary cryptographic practices and controls; and</li>
<li>clarifies expectations when ownership or operational control of a CA changes, helping ensure that Mozilla receives timely notice and can evaluate the impact of acquisitions or organizational changes on continued compliance.</li>
</ul>
<h3><b>Looking Forward</b></h3>
<p>Mozilla recognizes that these changes will require preparation by CA operators, auditors, and other ecosystem participants. To support implementation, Mozilla is publishing accompanying wiki guidance regarding both <a href="https://wiki.mozilla.org/CA/CP-CPS_Guidance">CP/CPS Documentation</a> and <a href="https://wiki.mozilla.org/CA/DCRs">Detailed Controls Reports</a>.</p>
<p>As with previous policy updates, these changes were informed by discussions with CA operators, auditors, and members of the Web PKI community. We appreciate the feedback received during the review process and look forward to continued collaboration as the ecosystem evolves.</p>
<p>Mozilla has a longstanding focus on building confidence in the Web PKI through transparency, accountability, and continuous improvement. By requiring higher-quality CP/CPS documentation and strengthening independent assurance, MRSP v3.1 advances Mozilla’s commitment to protecting its users and maintaining their trust in the systems that help secure the web.</p>
<p>The post <a href="https://blog.mozilla.org/security/2026/06/29/improving-transparency-and-assurance-in-the-web-pki-mozilla-root-store-policy-v3-1/">Improving Transparency and Assurance in the Web PKI: Mozilla Root Store Policy v3.1</a> appeared first on <a href="https://blog.mozilla.org/security">Mozilla Security Blog</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[The Rust Programming Language Blog: Announcing Rust 1.96.1]]></title>
<description><![CDATA[The Rust team has published a new point release of Rust, 1.96.1. Rust is a programming language that is empowering everyone to build reliable and efficient software.
If you have a previous version of Rust installed via rustup, getting Rust 1.96.1 is as easy as:
rustup update stable
If you don't h...]]></description>
<link>https://tsecurity.de/de/3693287/tools/the-rust-programming-language-blog-announcing-rust-1961/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3693287/tools/the-rust-programming-language-blog-announcing-rust-1961/</guid>
<pubDate>Sat, 25 Jul 2026 08:37:22 +0200</pubDate>
<category>💾  Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>The Rust team has published a new point release of Rust, 1.96.1. Rust is a programming language that is empowering everyone to build reliable and efficient software.</p>
<p>If you have a previous version of Rust installed via rustup, getting Rust 1.96.1 is as easy as:</p>
<pre class="giallo z-code"><code><span class="giallo-l"><span>rustup update stable</span></span></code></pre>
<p>If you don't have it already, you can <a href="https://www.rust-lang.org/install.html" rel="external">get <code>rustup</code></a> from the appropriate page on our website.</p>
<h3><a class="anchor" href="https://blog.rust-lang.org/2026/06/30/Rust-1.96.1/#what-s-in-1-96-1"></a>
What's in 1.96.1</h3>
<p>Rust 1.96.1 fixes:</p>
<ul>
<li><a href="https://github.com/rust-lang/cargo/pull/17131" rel="external">Missing retries / timeouts in Cargo's HTTP client</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/158214" rel="external">Miscompilation in a MIR optimization</a></li>
</ul>
<p>It also <a href="https://github.com/rust-lang/cargo/pull/17140" rel="external">fixes</a> three CVEs
affecting libssh2 (which is compiled into Cargo):</p>
<ul>
<li><a href="https://www.cve.org/CVERecord?id=CVE-2025-15661" rel="external">CVE-2025-15661</a></li>
<li><a href="https://www.cve.org/CVERecord?id=CVE-2026-55199" rel="external">CVE-2026-55199</a></li>
<li><a href="https://www.cve.org/CVERecord?id=CVE-2026-55200" rel="external">CVE-2026-55200</a></li>
</ul>
<h4><a class="anchor" href="https://blog.rust-lang.org/2026/06/30/Rust-1.96.1/#contributors-to-1-96-1"></a>
Contributors to 1.96.1</h4>
<p>Many people came together to create Rust 1.96.1. We couldn't have done it without all of you. <a href="https://thanks.rust-lang.org/rust/1.96.1/" rel="external">Thanks!</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[The Rust Programming Language Blog: Announcing Rust 1.97.0]]></title>
<description><![CDATA[The Rust team is happy to announce a new version of Rust, 1.97.0. Rust is a programming language empowering everyone to build reliable and efficient software.
If you have a previous version of Rust installed via rustup, you can get 1.97.0 with:
$ rustup update stable
If you don't have it already,...]]></description>
<link>https://tsecurity.de/de/3693286/tools/the-rust-programming-language-blog-announcing-rust-1970/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3693286/tools/the-rust-programming-language-blog-announcing-rust-1970/</guid>
<pubDate>Sat, 25 Jul 2026 08:37:20 +0200</pubDate>
<category>💾  Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>The Rust team is happy to announce a new version of Rust, 1.97.0. Rust is a programming language empowering everyone to build reliable and efficient software.</p>
<p>If you have a previous version of Rust installed via <code>rustup</code>, you can get 1.97.0 with:</p>
<pre class="giallo z-code"><code><span class="giallo-l"><span>$</span><span> rustup update stable</span></span></code></pre>
<p>If you don't have it already, you can get <a href="https://www.rust-lang.org/install.html" rel="external"><code>rustup</code></a> from the appropriate page on our website, and check out the <a href="https://doc.rust-lang.org/stable/releases.html#version-1970-2026-07-09" rel="external">detailed release notes for 1.97.0</a>.</p>
<p>If you'd like to help us out by testing future releases, you might consider updating locally to use the beta channel (<code>rustup default beta</code>) or the nightly channel (<code>rustup default nightly</code>). Please <a href="https://github.com/rust-lang/rust/issues/new/choose" rel="external">report</a> any bugs you might come across!</p>
<h3><a class="anchor" href="https://blog.rust-lang.org/2026/07/09/Rust-1.97.0/#what-s-in-1-97-0-stable"></a>
What's in 1.97.0 stable</h3>
<h4><a class="anchor" href="https://blog.rust-lang.org/2026/07/09/Rust-1.97.0/#symbol-mangling-v0-enabled-by-default"></a>
Symbol mangling v0 enabled by default</h4>
<p>When Rust is compiled into object files and binaries, each item (functions,
statics, etc) must have a globally unique "symbol" identifying it. To avoid
conflicts when linking together different Rust programs, Rust mangles the
original name of items to include additional context such as the module path,
defining crate, generics, and more. Historically, this mangling was based on
the <a href="https://refspecs.linuxbase.org/cxxabi-1.86.html#mangling" rel="external">Itanium ABI</a>,
also (sometimes) used by C++.</p>
<p>The new mangling scheme resolves a number of drawbacks from the previous one:</p>
<ul>
<li>Generic parameter instantiations preserve their values, rather than being tracked solely behind a hash</li>
<li>Inconsistencies: not all parts used the Itanium ABI, meaning that custom demangling was still necessary</li>
</ul>
<p>Since Rust 1.59, the compiler has supported opting into a Rust-specific
mangling scheme via <code>-Csymbol-mangling-version=v0</code>. Since November 2025, this
scheme has been enabled by default on nightly, and 1.97 is now enabling it on
stable Rust. The legacy mangling scheme can only be enabled on nightly, and the
current plan is to fully remove it.</p>
<p>See the previous <a href="https://blog.rust-lang.org/2025/11/20/switching-to-v0-mangling-on-nightly/" rel="external">blog post</a> for more details.</p>
<h4><a class="anchor" href="https://blog.rust-lang.org/2026/07/09/Rust-1.97.0/#cargo-support-for-denying-warnings"></a>
Cargo support for denying warnings</h4>
<p>It's common practice to deny warnings in CI. Historically, doing so is
typically done through <code>RUSTFLAGS=-Dwarnings</code>. With Rust 1.97, Cargo controls
how warnings interact with build success: either silencing them (via <code>allow</code>
level), rendering without failing (default, <code>warn</code>), or denying them (via <code>deny</code>).</p>
<p>As a  result of Cargo configuration determining the behavior, using this
feature doesn't invalidate the underlying build cache, meaning that it's easy
to temporarily opt-in. For example, if warnings are adding unwanted noise while
working through fixing errors after a refactor, you can run
<code>CARGO_BUILD_WARNINGS=allow cargo check</code>, temporarily silencing them.</p>
<p>In CI, jobs can instead set <code>CARGO_BUILD_WARNINGS=deny</code> to deny warnings. This
can be combined with <code>--keep-going</code> to collect all errors and warnings rather
than stopping on the first failing package.</p>
<p>See the <a href="https://doc.rust-lang.org/cargo/reference/config.html#buildwarnings" rel="external">documentation</a> for more details.</p>
<h4><a class="anchor" href="https://blog.rust-lang.org/2026/07/09/Rust-1.97.0/#linker-output-no-longer-hidden-by-default"></a>
Linker output no longer hidden by default</h4>
<p>rustc invokes a linker on behalf of users. Historically, rustc has silenced
linker output by default if the link completes successfully. This can mask real
problems, though, so in Rust 1.97 we are enabling linker messages by default.
These are emitted as a warning lint, for example:</p>
<pre class="giallo z-code"><code><span class="giallo-l"><span>warning: linker stderr: ignoring deprecated linker optimization setting '1'</span></span>
<span class="giallo-l"><span>  |</span></span>
<span class="giallo-l"><span>  = note: `#[warn(linker_messages)]` on by default</span></span></code></pre>
<p>Common linker messages that have been diagnosed as false positives or intentional behavior
are filtered out by rustc. Several defects have already been fixed as a result
of no longer hiding this output on nightly.</p>
<p>Note that currently, <code>linker_messages</code> is a special lint that is <em>not</em> affected
by the <code>warnings</code> lint group. This is intentional as rustc generally doesn't
control linker output as precisely, and it's not uncommon for output to only
appear on some platforms. If you are seeing what you think is a false positive
output from the linker, please <a href="https://github.com/rust-lang/rust/issues/new/choose" rel="external">file an issue</a>.</p>
<p>To silence the warning in the mean time, you can configure the lint level to
allow. This can be done through <code>Cargo.toml</code> by adding a <a href="https://doc.rust-lang.org/nightly/cargo/reference/manifest.html#the-lints-section" rel="external">lints section</a> like this:</p>
<pre class="giallo z-code"><code><span class="giallo-l"><span>[</span><span>lints</span><span>.</span><span>rust</span><span>]</span></span>
<span class="giallo-l"><span class="z-variable">linker_messages</span><span> =</span><span class="z-punctuation z-definition z-string z-string"> "</span><span class="z-string z-quoted z-string">allow</span><span class="z-punctuation z-definition z-string z-string">"</span></span></code></pre><h4><a class="anchor" href="https://blog.rust-lang.org/2026/07/09/Rust-1.97.0/#stabilized-apis"></a>
Stabilized APIs</h4>
<ul>
<li><a href="https://doc.rust-lang.org/stable/std/iter/struct.RepeatN.html#impl-Default-for-RepeatN%3CA%3E" rel="external"><code>Default for RepeatN</code></a></li>
<li><a href="https://doc.rust-lang.org/stable/std/ffi/struct.FromBytesUntilNulError.html#impl-Copy-for-FromBytesUntilNulError" rel="external"><code>Copy for ffi::FromBytesUntilNulError</code></a></li>
<li><a href="https://github.com/rust-lang/rust/pull/154003" rel="external"><code>Send for std::fs::File</code> on UEFI</a></li>
<li><a href="https://doc.rust-lang.org/stable/std/primitive.u32.html#method.isolate_highest_one" rel="external"><code>&lt;{integer}&gt;::isolate_highest_one</code></a></li>
<li><a href="https://doc.rust-lang.org/stable/std/primitive.u32.html#method.isolate_lowest_one" rel="external"><code>&lt;{integer}&gt;::isolate_lowest_one</code></a></li>
<li><a href="https://doc.rust-lang.org/stable/std/primitive.u32.html#method.highest_one" rel="external"><code>&lt;{integer}&gt;::highest_one</code></a></li>
<li><a href="https://doc.rust-lang.org/stable/std/primitive.u32.html#method.lowest_one" rel="external"><code>&lt;{integer}&gt;::lowest_one</code></a></li>
<li><a href="https://doc.rust-lang.org/stable/std/primitive.u32.html#method.bit_width" rel="external"><code>&lt;{uN}&gt;::bit_width</code></a></li>
<li><a href="https://doc.rust-lang.org/stable/std/num/struct.NonZero.html#method.isolate_highest_one" rel="external"><code>NonZero&lt;{integer}&gt;::isolate_highest_one</code></a></li>
<li><a href="https://doc.rust-lang.org/stable/std/num/struct.NonZero.html#method.isolate_lowest_one" rel="external"><code>NonZero&lt;{integer}&gt;::isolate_lowest_one</code></a></li>
<li><a href="https://doc.rust-lang.org/stable/std/num/struct.NonZero.html#method.highest_one" rel="external"><code>NonZero&lt;{integer}&gt;::highest_one</code></a></li>
<li><a href="https://doc.rust-lang.org/stable/std/num/struct.NonZero.html#method.lowest_one" rel="external"><code>NonZero&lt;{integer}&gt;::lowest_one</code></a></li>
<li><a href="https://doc.rust-lang.org/stable/std/num/struct.NonZero.html#method.bit_width" rel="external"><code>NonZero&lt;{uN}&gt;::bit_width</code></a></li>
</ul>
<p>These previously stable APIs are now stable in const contexts:</p>
<ul>
<li><a href="https://doc.rust-lang.org/stable/std/primitive.char.html#method.is_control" rel="external"><code>char::is_control</code></a></li>
</ul>
<h4><a class="anchor" href="https://blog.rust-lang.org/2026/07/09/Rust-1.97.0/#other-changes"></a>
Other changes</h4>
<p>Check out everything that changed in <a href="https://github.com/rust-lang/rust/releases/tag/1.97.0" rel="external">Rust</a>, <a href="https://doc.rust-lang.org/nightly/cargo/CHANGELOG.html#cargo-197-2026-07-09" rel="external">Cargo</a>, and <a href="https://github.com/rust-lang/rust-clippy/blob/master/CHANGELOG.md#rust-197" rel="external">Clippy</a>.</p>
<h3><a class="anchor" href="https://blog.rust-lang.org/2026/07/09/Rust-1.97.0/#contributors-to-1-97-0"></a>
Contributors to 1.97.0</h3>
<p>Many people came together to create Rust 1.97.0. We couldn't have done it without all of you. <a href="https://thanks.rust-lang.org/rust/1.97.0/" rel="external">Thanks!</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[The Rust Programming Language Blog: Announcing Rust 1.97.1]]></title>
<description><![CDATA[The Rust team has published a new point release of Rust, 1.97.1. Rust is a programming language that is empowering everyone to build reliable and efficient software.
If you have a previous version of Rust installed via rustup, getting Rust 1.97.1 is as easy as:
rustup update stable
If you don't h...]]></description>
<link>https://tsecurity.de/de/3693284/tools/the-rust-programming-language-blog-announcing-rust-1971/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3693284/tools/the-rust-programming-language-blog-announcing-rust-1971/</guid>
<pubDate>Sat, 25 Jul 2026 08:37:17 +0200</pubDate>
<category>💾  Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>The Rust team has published a new point release of Rust, 1.97.1. Rust is a programming language that is empowering everyone to build reliable and efficient software.</p>
<p>If you have a previous version of Rust installed via rustup, getting Rust 1.97.1 is as easy as:</p>
<pre class="giallo z-code"><code><span class="giallo-l"><span>rustup update stable</span></span></code></pre>
<p>If you don't have it already, you can <a href="https://www.rust-lang.org/install.html" rel="external">get <code>rustup</code></a> from the appropriate page on our website.</p>
<h3><a class="anchor" href="https://blog.rust-lang.org/2026/07/16/Rust-1.97.1/#what-s-in-1-97-1"></a>
What's in 1.97.1</h3>
<p>Rust 1.97.1 fixes a <a href="https://github.com/rust-lang/rust/issues/159035" rel="external">miscompilation in an LLVM optimization</a>.</p>
<p>We have backported both an LLVM fix and a disable of the underlying change in Rust 1.97.0 of
Rust's generated IR that increased the likelihood of this happening. However,
note that the underlying miscompilation has been present since at least Rust
1.87.</p>
<p>If you'd like to help us out by testing future releases, you might consider
running your code's CI or locally using the beta channel (<code>rustup default beta</code>) or the nightly
channel (<code>rustup default nightly</code>). Please
<a href="https://github.com/rust-lang/rust/issues/new/choose" rel="external">report</a> any bugs you
might come across!</p>
<h4><a class="anchor" href="https://blog.rust-lang.org/2026/07/16/Rust-1.97.1/#contributors-to-1-97-1"></a>
Contributors to 1.97.1</h4>
<p>Many people came together to create Rust 1.97.1. We couldn't have done it without all of you. <a href="https://thanks.rust-lang.org/rust/1.97.1/" rel="external">Thanks!</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Framework’s premium laptop is shipping with less RAM]]></title>
<description><![CDATA[RAMageddon has claimed yet another victim, with Framework now announcing a "major and unfortunate" pricing update for its upcoming premium laptop - which also impacts folks who preordered it. Memory configurations for the Laptop 13 Pro have been adjusted after Framework says it received cost upda...]]></description>
<link>https://tsecurity.de/de/3688547/it-nachrichten/frameworks-premium-laptop-is-shipping-with-less-ram/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3688547/it-nachrichten/frameworks-premium-laptop-is-shipping-with-less-ram/</guid>
<pubDate>Thu, 23 Jul 2026 11:43:12 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[RAMageddon has claimed yet another victim, with Framework now announcing a "major and unfortunate" pricing update for its upcoming premium laptop - which also impacts folks who preordered it. Memory configurations for the Laptop 13 Pro have been adjusted after Framework says it received cost updates from its memory supplier that "are more than double […]]]></content:encoded>
</item>
<item>
<title><![CDATA[This Week In Rust: This Week in Rust 661]]></title>
<description><![CDATA[Hello and welcome to another issue of This Week in Rust!
Rust is a programming language empowering everyone to build reliable and efficient software.
This is a weekly summary of its progress and community.
Want something mentioned? Tag us at
@thisweekinrust.bsky.social on Bluesky or
@ThisWeekinRu...]]></description>
<link>https://tsecurity.de/de/3688059/tools/this-week-in-rust-this-week-in-rust-661/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3688059/tools/this-week-in-rust-this-week-in-rust-661/</guid>
<pubDate>Thu, 23 Jul 2026 07:18:12 +0200</pubDate>
<category>💾  Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Hello and welcome to another issue of <em>This Week in Rust</em>!
<a href="https://www.rust-lang.org/">Rust</a> is a programming language empowering everyone to build reliable and efficient software.
This is a weekly summary of its progress and community.
Want something mentioned? Tag us at
<a href="https://bsky.app/profile/thisweekinrust.bsky.social">@thisweekinrust.bsky.social</a> on Bluesky or
<a href="https://mastodon.social/@thisweekinrust">@ThisWeekinRust</a> on mastodon.social, or
<a href="https://github.com/rust-lang/this-week-in-rust">send us a pull request</a>.
Want to get involved? <a href="https://github.com/rust-lang/rust/blob/main/CONTRIBUTING.md">We love contributions</a>.</p>
<p><em>This Week in Rust</em> is openly developed <a href="https://github.com/rust-lang/this-week-in-rust">on GitHub</a> and archives can be viewed at <a href="https://this-week-in-rust.org/">this-week-in-rust.org</a>.
If you find any errors in this week's issue, <a href="https://github.com/rust-lang/this-week-in-rust/pulls">please submit a PR</a>.</p>
<p>Want TWIR in your inbox? <a href="https://this-week-in-rust.us11.list-manage.com/subscribe?u=fd84c1c757e02889a9b08d289&amp;id=0ed8b72485">Subscribe here</a>.</p>
<h4><a class="toclink" href="https://this-week-in-rust.org/atom.xml#updates-from-rust-community">Updates from Rust Community</a></h4>


<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#official">Official</a></h5>
<ul>
<li><a href="https://blog.rust-lang.org/2026/07/16/Rust-1.97.1/">Announcing Rust 1.97.1</a></li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#newsletters">Newsletters</a></h5>
<ul>
<li><a href="https://www.theembeddedrustacean.com/p/the-embedded-rustacean-issue-76">The Embedded Rustacean Issue #76</a></li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#projecttooling-updates">Project/Tooling Updates</a></h5>
<ul>
<li><a href="https://tokio.rs/blog/2026-07-22-announcing-topcoat">Announcing Topcoat: a framework for building full-stack reactive web apps with Rust</a></li>
<li><a href="https://github.com/dtolnay/syn/releases/tag/3.0.0">Syn 3.0.0</a></li>
<li><a href="https://blog.jetbrains.com/rust/2026/07/22/whats-new-in-rustrover-2026-2/">What’s New in RustRover 2026.2</a></li>
<li><a href="https://github.com/kunobi-ninja/kobe/releases/tag/v0.35.0">kobe 0.35.0: readiness gates and cert recycling</a></li>
<li><a href="https://github.com/Eoin-McMahon/comhad/releases/tag/v0.1.0">Comhad v0.1.0: a ranger-style tui cyberduck replacement for browsing S3</a></li>
<li><a href="https://github.com/bigduu/Nova/releases/tag/v0.2.1">Nova v0.2.1: computer-use MCP server</a></li>
<li><a href="https://github.com/rust-windowing/winit/pull/4571">winit now has comprehensive cross-platform drag-and-drop support, exposing most of the power of the underlying OS APIs</a></li>
<li><a href="https://github.com/singhpratech/crimson-crab/releases/tag/v0.1.0">crimson-crab v0.1.0 - a production-grade Rust SDK for the Claude API (streaming, tool use, prompt caching, batches)</a></li>
<li><a href="https://singhpratech.github.io/ferrovec/">ferrovec: dependency-light HNSW vector search in Rust, compiled to WebAssembly for private in-browser semantic search</a></li>
<li><a href="https://github.com/ordokr/ordofp/releases/tag/v0.1.0">OrdoFP 0.1.0 released — a functional-programming toolbelt for Rust (HList, GAT type classes, optics, effects, monad transformers)</a></li>
<li><a href="https://freyaui.dev/posts/0.4">Freya 0.4</a></li>
<li><a href="https://dev.to/nabsei/buildline-merging-cargo-and-ninjas-build-profiling-into-one-timeline-2373">buildline: merging cargo and ninja's build profiling into one timeline</a></li>
<li><a href="https://richer-richard.github.io/cochlea/determinism.html#030-additions-2026-07-22">cochlea 0.3.0: melody read-back, MFCC timbre, a master limiter, and MIDI import for the deterministic agent-audio engine</a></li>
<li><a href="https://flodl.dev/blog/then-the-cpu-died">flodl 0.6.0: multi-host heterogeneous DDP - mismatched GPUs across hosts beat the fastest card alone</a></li>
<li><a href="https://hongnoul.github.io/hwatu/">hwatu: a daemon-based WebKitGTK browser for tiling WMs with ~13ms window spawn</a></li>
<li><a href="https://github.com/kunobi-ninja/kache/releases/tag/v0.11.0">kache 0.11.0: broader compiler coverage and libc-aware keys</a></li>
<li><a href="https://mladedav.github.io/blog/blog/tracing-reload/"><code>tracing-reload</code> - reload layer without panics</a></li>
<li><a href="https://www.opentypeless.com/en/blog/introducing-talkmore">Introducing OpenTypeless: Voice Input That Actually Works</a></li>
<li><a href="https://dev.to/booyaka101/reading-a-rust-crates-capabilities-out-of-its-compiled-symbols-58pb">Reading a Rust crate's capabilities out of its compiled symbols</a></li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#observationsthoughts">Observations/Thoughts</a></h5>
<ul>
<li><a href="https://smallcultfollowing.com/babysteps/blog/2026/07/15/battery-packs/">Battery packs: Let's talk about crates, baby</a></li>
<li><a href="https://blog.yoshuawuyts.com/capture-clauses-as-effects">Capture Clauses as Effects</a></li>
<li><a href="https://corrode.dev/blog/hardening-rust/">Hardening Rust Code For Production</a></li>
<li><a href="https://pranitha.dev/posts/tokio-gives-progress-not-ordering/">Tokio Gives Progress, Not Ordering: Scheduling 1M Tasks</a></li>
<li><a href="https://kerkour.com/rust-service-hardening-and-production-checklist">Rust service hardening and production checklist</a></li>
<li>[audio] <a href="https://corrode.dev/podcast/s06e08-rust-foundation/">The Rust Foundation with Rebecca Rumbul, Lori Lorusso, and David Wood, Rust Foundation leadership and board</a></li>
<li>[video] <a href="https://www.youtube.com/watch?v=bAINppA0BSU">Jon Gjengset: Open Source Maintenance 2026-07-18</a></li>
<li>[video] <a href="https://www.youtube.com/watch?v=lUoQ3uGSQA0">Rust Release Changelog - 1.97.0</a></li>
<li>[video] <a href="https://www.youtube.com/live/Doqwh1b4QyA">Livestream: Rust in Ubuntu</a></li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#rust-walkthroughs">Rust Walkthroughs</a></h5>
<ul>
<li><a href="https://kriyanative.com/blog/13-chain-breaks/">I hash-chained my agent's audit log. Then I found 13 breaks in it — all mine, all benign.</a></li>
<li><a href="https://dev.to/scripthpp/two-bugs-i-only-found-by-running-my-rust-sync-daemon-against-real-infrastructure-4278">Two tricky bugs in a Rust daemon</a></li>
<li>[video] <a href="https://www.youtube.com/watch?v=u91eX3J6lPU">Backend Concepts in Rust: Securely Managing App Secrets</a></li>
<li>[video] <a href="https://www.youtube.com/watch?v=tIrSvJFRxAg">Build with Naz - Ep 21: High Performance Flat 2D Arrays in Rust (SIMD, L1 cache)</a></li>
</ul>
<h4><a class="toclink" href="https://this-week-in-rust.org/atom.xml#crate-of-the-week">Crate of the Week</a></h4>
<p>This week's crate is <a href="https://github.com/medialab/xan">xan</a>, a TUI toolkit to work with CSV files.</p>
<p>Thanks to <a href="https://users.rust-lang.org/t/crate-of-the-week/2704/1630">Simeon H.K. Fitch</a> for the suggestion!</p>
<p><a href="https://users.rust-lang.org/t/crate-of-the-week/2704">Please submit your suggestions and votes for next week</a>!</p>
<h4><a class="toclink" href="https://this-week-in-rust.org/atom.xml#calls-for-testing">Calls for Testing</a></h4>
<p>An important step for RFC implementation is for people to experiment with the
implementation and give feedback, especially before stabilization.</p>
<p>If you are a feature implementer and would like your RFC to appear in this list, add a
<code>call-for-testing</code> label to your RFC along with a comment providing testing instructions and/or
guidance on which aspect(s) of the feature need testing.</p>
<p><em>No calls for testing were issued this week by
<a href="https://github.com/rust-lang/rust/issues?q=state%3Aopen%20label%3Acall-for-testing%20state%3Aopen">Rust</a>,
<a href="https://github.com/rust-lang/cargo/issues?q=state%3Aopen%20label%3Acall-for-testing%20state%3Aopen">Cargo</a>,
<a href="https://github.com/rust-lang/rustup/issues?q=state%3Aopen%20label%3Acall-for-testing%20state%3Aopen">Rustup</a> or
<a href="https://github.com/rust-lang/rfcs/issues?q=label%3Acall-for-testing%20state%3Aopen">Rust language RFCs</a>.</em></p>
<p><a href="https://github.com/rust-lang/this-week-in-rust/issues">Let us know</a> if you would like your feature to be tracked as a part of this list.</p>
<h4><a class="toclink" href="https://this-week-in-rust.org/atom.xml#call-for-participation-projects-and-speakers">Call for Participation; projects and speakers</a></h4>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#cfp-projects">CFP - Projects</a></h5>
<p>Always wanted to contribute to open-source projects but did not know where to start?
Every week we highlight some tasks from the Rust community for you to pick and get started!</p>
<p>Some of these tasks may also have mentors available, visit the task page for more information.</p>



<ul>
<li><em>No Calls for participation were submitted this week.</em></li>
</ul>
<p>If you are a Rust project owner and are looking for contributors, please submit tasks <a href="https://github.com/rust-lang/this-week-in-rust?tab=readme-ov-file#call-for-participation-guidelines">here</a> or through a <a href="https://github.com/rust-lang/this-week-in-rust">PR to TWiR</a> or by reaching out on <a href="https://bsky.app/profile/thisweekinrust.bsky.social">Bluesky</a> or <a href="https://mastodon.social/@thisweekinrust">Mastodon</a>!</p>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#cfp-events">CFP - Events</a></h5>
<p>Are you a new or experienced speaker looking for a place to share something cool? This section highlights events that are being planned and are accepting submissions to join their event as a speaker.</p>


<ul>
<li><em>No Calls for papers or presentations were submitted this week.</em></li>
</ul>
<p>If you are an event organizer hoping to expand the reach of your event, please submit a link to the website through a <a href="https://github.com/rust-lang/this-week-in-rust">PR to TWiR</a> or by reaching out on <a href="https://bsky.app/profile/thisweekinrust.bsky.social">Bluesky</a> or <a href="https://mastodon.social/@thisweekinrust">Mastodon</a>!</p>
<h4><a class="toclink" href="https://this-week-in-rust.org/atom.xml#updates-from-the-rust-project">Updates from the Rust Project</a></h4>
<p>576 pull requests were <a href="https://github.com/search?q=is%3Apr+org%3Arust-lang+is%3Amerged+merged%3A2026-07-14..2026-07-21">merged in the last week</a></p>
<h6><a class="toclink" href="https://this-week-in-rust.org/atom.xml#compiler">Compiler</a></h6>
<ul>
<li><a href="https://github.com/rust-lang/rust/pull/159256">account for async closures when pointing at lifetime in return type</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/157824">comptime inherent impls</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/159115"><code>dep_graph</code>: deduplicate task reads with an epoch-filtered index recorder</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/158976">eagerly check for ambiguity in macro parsing</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/158608">implement <code>#[diagnostic::opaque]</code> attribute to hide backtraces of macros</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/158720">shrink <code>ast::Expr64</code></a></li>
</ul>
<h6><a class="toclink" href="https://this-week-in-rust.org/atom.xml#library">Library</a></h6>
<ul>
<li><a href="https://github.com/rust-lang/rust/pull/159467">add explicit <code>Iterator::count</code> impl for <code>str::EncodeUtf16</code></a></li>
<li><a href="https://github.com/rust-lang/rust/pull/159296">implement <code>bool::toggle</code></a></li>
<li><a href="https://github.com/rust-lang/rust/pull/159528">implement <code>const_binary_search</code></a></li>
<li><a href="https://github.com/rust-lang/rust/pull/159302">implement <code>Debug</code> helpers via <code>Cell</code></a></li>
<li><a href="https://github.com/rust-lang/rust/pull/156220">implement <code>VecDeque::truncate_to_range</code></a></li>
<li><a href="https://github.com/rust-lang/rust/pull/158061">make <code>pin!()</code> more foolproof</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/158546">move <code>std::io::BufRead</code> to <code>alloc::io</code></a></li>
<li><a href="https://github.com/rust-lang/rust/pull/158544">move <code>std::io::Read</code> to <code>alloc::io</code></a></li>
<li><a href="https://github.com/rust-lang/rust/pull/158545">move <code>std::io::read_to_string</code> to <code>alloc::io</code></a></li>
</ul>
<h6><a class="toclink" href="https://this-week-in-rust.org/atom.xml#cargo">Cargo</a></h6>
<ul>
<li><a href="https://github.com/rust-lang/rust/pull/159149">use PGO for Cargo</a></li>
<li><a href="https://github.com/rust-lang/cargo/pull/17238"><code>timings</code>: only report units the job queue actually ran</a></li>
<li><a href="https://github.com/rust-lang/cargo/pull/17236">do not include proc-macro deps in rustc search path args</a></li>
<li><a href="https://github.com/rust-lang/cargo/pull/17216">include SBOM outputs in fingerprints</a></li>
<li><a href="https://github.com/rust-lang/cargo/pull/17226">lazily initialize git2 fetch transports</a></li>
</ul>
<h6><a class="toclink" href="https://this-week-in-rust.org/atom.xml#rustdoc">Rustdoc</a></h6>
<ul>
<li><a href="https://github.com/rust-lang/rust/pull/159194">fix auto trait normalization env</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/159091">use PGO for rustdoc</a></li>
</ul>
<h6><a class="toclink" href="https://this-week-in-rust.org/atom.xml#clippy">Clippy</a></h6>
<ul>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/16855">add <code>block_scrutinee</code> lint</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17415">avoid invalid <code>ref_as_ptr</code> suggestions in const/static initializers</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/16800">detect <code>== 0</code> on unsigned types as a <code>manual_clamp</code> lower bound</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17405">fix <code>if_not_else</code> linting on macro expanded conditions</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17383">fix <code>needless_collect</code> suggests a suggestion that cannot be typed</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17385"><code>non_zero_suggestions</code>: don't lint signed integer div/rem as NonZero</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17377"><code>manual_filter</code>: don't eat comments in the <code>and_then</code> suggestion</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17369">require the use of <code>as _</code> for indirectly used traits in clippy sources</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17362">rewrite <code>min_ident_chars</code></a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/16633">use <code>#[must_use]</code> determination from the compiler</a></li>
</ul>
<h6><a class="toclink" href="https://this-week-in-rust.org/atom.xml#rust-analyzer">Rust-Analyzer</a></h6>
<ul>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22634">avoid index panic when flycheck list is empty</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22811">add capture hints to coroutines</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22813">add handler for E0572</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22483">do not assume array destructuring assignments with rest pattern are constant-sized</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22852">eagerly normalize <code>.await</code>'s <code>IntoFuture::Output</code></a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22791">enable auto trait inference</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22792">extract variable preserving whitespace from macro input</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22832">fix coroutines not recording binding owners correctly</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22759">fix crashes in assists due to <code>.unwrap()</code> calls in SyntaxFactory</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22810">fix <code>hir</code> crate leaking bound variables from skipped binders</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22855">fix <code>InferenceContext:identity_args</code> using the wrong DefId</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22849">fix syntax bridge panic when spilting float</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22857">handle <code>enum</code> variants in next-solver <code>generics</code></a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22818">implement lowering of HRTB</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22789">invalid <code>pattern_matching_variant</code> lowering due to recovery</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22867">merge <code>WherePredicate::ForLifetimes</code> into <code>WherePredicate::TypeBound</code></a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22804">only write anon const ty in parent's inference result if it doesn't have its own inference</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22822">panic with a function item and a proc macro item having a duplicate name</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22827">parser to error on macro type bound</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22865">spawn proc-macro servers on requests clearing the client cache</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22782">use quote! inside <code>ast::make::expr_call()</code></a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22793">use <code>Result</code> for the lsp-server <code>Response</code> payload type</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22861">record expressions in types in <code>ExprScope</code></a></li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#rust-compiler-performance-triage">Rust Compiler Performance Triage</a></h5>
<p>The two most notable changes this week were <a href="https://github.com/rust-lang/rust/pull/159115">#159115</a>,
which resulted in pretty nice instruction count wins for full incremental builds on several benchmarks,
and <a href="https://github.com/rust-lang/rust/pull/159091">#159091</a>, which enabled PGO for rustdoc, which
makes it ~3-4% faster across the board.</p>
<p>There were two large rollups with tiny performance regressions, which made it difficult to find
the offending PRs.</p>
<p>Triage done by <strong>@Kobzol</strong>.
Revision range: <a href="https://perf.rust-lang.org/?start=5503df87342a73d0c29126a7e08dc9c1255c46ad&amp;end=d527bc9bfa297ca7fd7f5ae93781eeec42073170&amp;absolute=false&amp;stat=instructions%3Au">5503df87..d527bc9b</a></p>
<p><strong>Summary</strong>:</p>
<table>
<thead>
<tr>
<th>(instructions:u)</th>
<th>mean</th>
<th>range</th>
<th>count</th>
</tr>
</thead>
<tbody>
<tr>
<td>Regressions ❌ <br> (primary)</td>
<td>0.4%</td>
<td>[0.2%, 1.0%]</td>
<td>40</td>
</tr>
<tr>
<td>Regressions ❌ <br> (secondary)</td>
<td>0.7%</td>
<td>[0.2%, 4.6%]</td>
<td>69</td>
</tr>
<tr>
<td>Improvements ✅ <br> (primary)</td>
<td>-2.0%</td>
<td>[-6.2%, -0.2%]</td>
<td>136</td>
</tr>
<tr>
<td>Improvements ✅ <br> (secondary)</td>
<td>-2.6%</td>
<td>[-8.4%, -0.2%]</td>
<td>119</td>
</tr>
<tr>
<td>All ❌✅ (primary)</td>
<td>-1.4%</td>
<td>[-6.2%, 1.0%]</td>
<td>176</td>
</tr>
</tbody>
</table>
<p>2 Regressions, 3 Improvements, 6 Mixed; 4 of them in rollups
34 artifact comparisons made in total</p>
<p><a href="https://github.com/rust-lang/rustc-perf/blob/189822607d8d09acd85c234b2c245e817591ca67/triage/2026/2026-07-21.md">Full report here</a>.</p>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#approved-rfcs"></a><a href="https://github.com/rust-lang/rfcs/commits/master">Approved RFCs</a></h5>
<p>Changes to Rust follow the Rust <a href="https://github.com/rust-lang/rfcs#rust-rfcs">RFC (request for comments) process</a>. These
are the RFCs that were approved for implementation this week:</p>
<ul>
<li><em>No RFCs were approved this week.</em></li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#final-comment-period">Final Comment Period</a></h5>
<p>Every week, <a href="https://www.rust-lang.org/team.html">the team</a> announces the 'final comment period' for RFCs and key PRs
which are reaching a decision. Express your opinions now.</p>
<h6><a class="toclink" href="https://this-week-in-rust.org/atom.xml#tracking-issues-prs">Tracking Issues &amp; PRs</a></h6>
<a class="toclink" href="https://this-week-in-rust.org/atom.xml#rust"></a><a href="https://github.com/rust-lang/rust/issues?q=is%3Aopen%20label%3Afinal-comment-period%20sort%3Aupdated-desc%20state%3Aopen">Rust</a>
<ul>
<li><a href="https://github.com/rust-lang/rust/issues/159298">Tracking Issue for <code>bool::toggle</code></a></li>
<li><a href="https://github.com/rust-lang/rust/issues/146954">Tracking Issue for vec_try_remove</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/157562">Avoid computing layout of enums with non-int discriminants</a></li>
<li><a href="https://github.com/rust-lang/rust/issues/71835">Tracking Issue for const_btree_len</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/138230">Add <code>raw_borrows_via_references</code> lint</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/157572">stabilize size_of_val_raw, align_of_val_raw, Layout::for_value_raw</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/158835">rustc_passes: lint unused <code>#[path]</code> attributes on inline modules</a></li>
</ul>
<a class="toclink" href="https://this-week-in-rust.org/atom.xml#compiler-team-mcps-only"></a><a href="https://github.com/rust-lang/compiler-team/issues?q=label%3Amajor-change%20label%3Afinal-comment-period%20state%3Aopen">Compiler Team</a> <a href="https://forge.rust-lang.org/compiler/mcp.html">(MCPs only)</a>
<ul>
<li><a href="https://github.com/rust-lang/compiler-team/issues/1019">Emit <code>note</code> when calling <code>rustc</code> without specifying an edition</a></li>
<li><a href="https://github.com/rust-lang/compiler-team/issues/1011">Let the OS handle stack growth</a></li>
<li><a href="https://github.com/rust-lang/compiler-team/issues/1010">Add <code>target_feature_available_at_call_site</code></a></li>
</ul>
<a class="toclink" href="https://this-week-in-rust.org/atom.xml#leadership-council"></a><a href="https://github.com/rust-lang/leadership-council/issues?q=state%3Aopen%20label%3Afinal-comment-period%20state%3Aopen">Leadership Council</a>
<ul>
<li><a href="https://github.com/rust-lang/leadership-council/pull/314">Deallocate post-2026 funds from PM and compiler-ops</a></li>
</ul>
<a class="toclink" href="https://this-week-in-rust.org/atom.xml#unsafe-code-guidelines"></a><a href="https://github.com/rust-lang/unsafe-code-guidelines/issues?q=is%3Aopen%20label%3Afinal-comment-period%20sort%3Aupdated-desc%20state%3Aopen">Unsafe Code Guidelines</a>
<ul>
<li><a href="https://github.com/rust-lang/unsafe-code-guidelines/issues/558">Do the bytes of a pointer have to stay in the same order?</a></li>
</ul>
<p><em>No Items entered Final Comment Period this week for
  <a href="https://github.com/rust-lang/cargo/issues?q=is%3Aopen%20label%3Afinal-comment-period%20sort%3Aupdated-desc%20state%3Aopen">Cargo</a>,
  <a href="https://github.com/rust-lang/reference/issues?q=is%3Aopen%20label%3Afinal-comment-period%20sort%3Aupdated-desc%20state%3Aopen">Language Reference</a>,
  <a href="https://github.com/rust-lang/lang-team/issues?q=is%3Aopen%20label%3Afinal-comment-period%20sort%3Aupdated-desc%20state%3Aopen">Language Team</a> or
  <a href="https://github.com/rust-lang/rfcs/issues?q=state%3Aopen%20label%3Afinal-comment-period%20state%3Aopen">Rust RFCs</a>.</em></p>
<p>Let us know if you would like your PRs, Tracking Issues or RFCs to be tracked as a part of this list.</p>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#new-and-updated-rfcs"></a><a href="https://github.com/rust-lang/rfcs/pulls">New and Updated RFCs</a></h5>
<ul>
<li><a href="https://github.com/rust-lang/rfcs/pull/3984">RFC: Refactor the libs team</a></li>
</ul>
<h4><a class="toclink" href="https://this-week-in-rust.org/atom.xml#upcoming-events">Upcoming Events</a></h4>
<p>Rusty Events between 2026-07-22 - 2026-08-19 🦀</p>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#virtual">Virtual</a></h5>
<ul>
<li>2026-07-24 | Virtual (Girona, ES) | <a href="https://luma.com/rust-girona">Rust Girona</a><ul>
<li><a href="https://luma.com/hd8mlw56"><strong>Sessió setmanal de codificació / Weekly coding session</strong></a></li>
</ul>
</li>
<li>2026-07-28 | Virtual (Dallas, TX, US) | <a href="https://www.meetup.com/dallasrust">Dallas Rust User Meetup</a><ul>
<li><a href="https://www.meetup.com/dallasrust/events/310254777/"><strong>Fourth Tuesday</strong></a></li>
</ul>
</li>
<li>2026-07-28 | Virtual (Washington, DC, US) | <a href="https://www.meetup.com/rustdc">Rust DC</a><ul>
<li><a href="https://www.meetup.com/rustdc/events/315279653/"><strong>Mid-month Rustful</strong></a></li>
</ul>
</li>
<li>2026-07-30 | Virtual (Berlin, DE) | <a href="https://www.meetup.com/rust-berlin">Rust Berlin</a><ul>
<li><a href="https://www.meetup.com/rust-berlin/events/312045928/"><strong>Rust Hack and Learn</strong></a></li>
</ul>
</li>
<li>2026-07-31 | Virtual (Girona, ES) | <a href="https://luma.com/rust-girona">Rust Girona</a><ul>
<li><a href="https://luma.com/uo5ek1f4"><strong>Sessió setmanal de codificació / Weekly coding session</strong></a></li>
</ul>
</li>
<li>2026-08-01 | Virtual (Kampala, UG) | <a href="https://www.eventbrite.com/e/rust-circle-meetup-tickets-628763176587">Rust Circle Meetup</a><ul>
<li><a href="https://www.eventbrite.com/e/rust-circle-meetup-tickets-628763176587"><strong>Rust Circle Meetup</strong></a></li>
</ul>
</li>
<li>2026-08-02 | Virtual (Dallas, TX, US) | <a href="https://www.meetup.com/dallasrust">Dallas Rust User Meetup</a><ul>
<li><a href="https://www.meetup.com/dallasrust/events/314095294/"><strong>Rust Deep Learning: First Sunday</strong></a></li>
</ul>
</li>
<li>2026-08-04 | Virtual (London, UK) | <a href="https://www.meetup.com/women-in-rust">Women in Rust</a><ul>
<li><a href="https://www.meetup.com/women-in-rust/events/315213885/"><strong>👋 Community Catch Up</strong></a></li>
</ul>
</li>
<li>2026-08-05 | Virtual (Indianapolis, IN, US) | <a href="https://www.meetup.com/indyrs">Indy Rust</a><ul>
<li><a href="https://www.meetup.com/indyrs/events/315210367/"><strong>Indy.rs - with Social Distancing</strong></a></li>
</ul>
</li>
<li>2026-08-07 | Virtual (Girona, ES) | <a href="https://luma.com/rust-girona">Rust Girona</a><ul>
<li><a href="https://luma.com/ii2jrwva"><strong>Sessió setmanal de codificació / Weekly coding session</strong></a></li>
</ul>
</li>
<li>2026-08-11 | Virtual (Dallas, TX, US) | <a href="https://www.meetup.com/dallasrust">Dallas Rust User Meetup</a><ul>
<li><a href="https://www.meetup.com/dallasrust/events/310254776/"><strong>Second Tuesday</strong></a></li>
</ul>
</li>
<li>2026-08-13 | Virtual (Berlin, DE) | <a href="https://www.meetup.com/rust-berlin">Rust Berlin</a><ul>
<li><a href="https://www.meetup.com/rust-berlin/events/313345333/"><strong>Rust Hack and Learn</strong></a></li>
</ul>
</li>
<li>2026-08-13 | Virtual (Nürnberg, DE) | <a href="https://www.meetup.com/rust-noris">Rust Nuremberg</a><ul>
<li><a href="https://www.meetup.com/rust-noris/events/315619609/"><strong>Rust Nürnberg online</strong></a></li>
</ul>
</li>
<li>2026-08-14 | Virtual (Girona, ES) | <a href="https://luma.com/rust-girona">Rust Girona</a><ul>
<li><a href="https://luma.com/f2hnzrug"><strong>Sessió setmanal de codificació / Weekly coding session</strong></a></li>
</ul>
</li>
<li>2026-08-18 | Virtual (Washington, DC, US) | <a href="https://www.meetup.com/rustdc">Rust DC</a><ul>
<li><a href="https://www.meetup.com/rustdc/events/315604176/"><strong>Mid-month Rustful</strong></a></li>
</ul>
</li>
<li>2026-08-19 | Hybrid (Vancouver, BC, CA) | <a href="https://www.meetup.com/vancouver-rust">Vancouver Rust</a><ul>
<li><a href="https://www.meetup.com/vancouver-rust/events/314105333/"><strong>Dealing with Dependencies</strong></a></li>
</ul>
</li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#africa">Africa</a></h5>
<ul>
<li>2026-08-11 | Johannesburg, ZA | <a href="https://www.meetup.com/johannesburg-rust-meetup">Johannesburg Rust Meetup</a><ul>
<li><a href="https://www.meetup.com/johannesburg-rust-meetup/events/315750593/"><strong>Rust's extended standard library</strong></a></li>
</ul>
</li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#asia">Asia</a></h5>
<ul>
<li>2026-07-25 | Mumbai, IN | <a href="https://luma.com/mumbai">Rust Mumbai</a><ul>
<li><a href="https://luma.com/7ksabwbm/"><strong>​Rust Mumbai — July Meetup 🦀</strong></a></li>
</ul>
</li>
<li>2026-07-26 | Pune, IN | <a href="https://www.meetup.com/rust-pune">Rust Pune</a><ul>
<li><a href="https://www.meetup.com/rust-pune/events/315651505/"><strong>Rust Pune: July 2026</strong></a></li>
</ul>
</li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#europe">Europe</a></h5>
<ul>
<li>2026-07-23 | Berlin, DE | <a href="https://www.meetup.com/rust-berlin">Rust Berlin</a><ul>
<li><a href="https://www.meetup.com/rust-berlin/events/315484101/"><strong>Rust Berlin Talks: The next generation</strong></a></li>
</ul>
</li>
<li>2026-07-23 | London, UK | <a href="https://www.meetup.com/rust-london-user-group">Rust London User Group</a><ul>
<li><a href="https://www.meetup.com/rust-london-user-group/events/315612916/"><strong>LDN Talks: July 2026 Antithesis Takeover</strong></a></li>
</ul>
</li>
<li>2026-07-23 | London, UK | <a href="https://www.meetup.com/london-rust-project-group">London Rust Project Group</a><ul>
<li><a href="https://www.meetup.com/london-rust-project-group/events/315366453/"><strong>Rama modular service framework for Rust</strong></a></li>
</ul>
</li>
<li>2026-07-23 | Paris, FR | <a href="https://www.meetup.com/rust-paris">Rust Paris</a><ul>
<li><a href="https://www.meetup.com/rust-paris/events/315309633/"><strong>Rust meetup #87</strong></a></li>
</ul>
</li>
<li>2026-07-25 | Stockholm, SE | <a href="https://www.meetup.com/stockholm-rust">Stockholm Rust</a><ul>
<li><a href="https://www.meetup.com/stockholm-rust/events/315749994/"><strong>Ferris' Fika Forum #28</strong></a></li>
</ul>
</li>
<li>2026-07-27 | Augsburg, DE | <a href="https://rust-augsburg.github.io/meetup">Rust Meetup Augsburg</a><ul>
<li><a href="https://rust-augsburg.github.io/meetup/Meetup_20.html"><strong>Rust Meetup #20: Julian Dickert - Supply chain security in Rust: Evaluating crates for production</strong></a></li>
</ul>
</li>
<li>2026-07-29 | Poland, PL | <a href="https://www.meetup.com/rust-poland-meetup">Rust Poland</a><ul>
<li><a href="https://www.meetup.com/rust-poland-meetup/events/315582674/"><strong>Rust Poland x Kraków #10</strong></a></li>
</ul>
</li>
<li>2026-07-30 | Copenhagen, DK | <a href="https://www.meetup.com/copenhagen-rust-community">Copenhagen Rust Community</a><ul>
<li><a href="https://www.meetup.com/copenhagen-rust-community/events/315767999/"><strong>Rust meetup #70</strong></a></li>
</ul>
</li>
<li>2026-07-30 | Manchester, UK | <a href="https://www.meetup.com/rust-manchester">Rust Manchester</a><ul>
<li><a href="https://www.meetup.com/rust-manchester/events/315037685/"><strong>Rust Manchester July Code Night</strong></a></li>
</ul>
</li>
<li>2026-08-18 | Aarhus, DK | <a href="https://www.meetup.com/rust-aarhus">Rust Aarhus</a><ul>
<li><a href="https://www.meetup.com/rust-aarhus/events/315683629/"><strong>Hack Night: Trust but verify the LLM</strong></a></li>
</ul>
</li>
<li>2026-08-18 | Leipzig, DE | <a href="https://www.meetup.com/rust-modern-systems-programming-in-leipzig">Rust - Modern Systems Programming in Leipzig</a><ul>
<li><a href="https://www.meetup.com/rust-modern-systems-programming-in-leipzig/events/313816474/"><strong>Topic TBD</strong></a></li>
</ul>
</li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#north-america">North America</a></h5>
<ul>
<li>2026-07-22 | Austin, TX, US | <a href="https://www.meetup.com/rust-atx">Rust ATX</a><ul>
<li><a href="https://www.meetup.com/rust-atx/events/xvkdgtyjckbdc/"><strong>Rust Lunch - Fareground</strong></a></li>
</ul>
</li>
<li>2026-07-22 | Los Angeles, CA, US | <a href="https://www.meetup.com/rust-los-angeles">Rust Los Angeles</a><ul>
<li><a href="https://www.meetup.com/rust-los-angeles/events/315376271/"><strong>Rust LA: Rust in Distributed Systems with Flight Science!</strong></a></li>
</ul>
</li>
<li>2026-07-22 | New York, NY, US | <a href="https://www.meetup.com/rust-nyc/events/">Rust NYC</a><ul>
<li><a href="https://www.meetup.com/rust-nyc/events/315636854/"><strong>Rust NYC: Write A Custom Coding Agent and wasm_zero</strong></a></li>
</ul>
</li>
<li>2026-07-23 | Mountain View, CA, US | <a href="https://www.meetup.com/hackerdojo/events/">Hacker Dojo</a><ul>
<li><a href="https://www.meetup.com/hackerdojo/events/315418155/"><strong>RUST MEETUP at HACKER DOJO</strong></a></li>
</ul>
</li>
<li>2026-07-25 | Boston, MA, US | <a href="https://www.meetup.com/bostonrust">Boston Rust Meetup</a><ul>
<li><a href="https://www.meetup.com/bostonrust/events/315582650/"><strong>Porter Square Rust Lunch, July 25</strong></a></li>
</ul>
</li>
<li>2026-07-25 | Brooklyn, NY, US | <a href="https://flowercomputer.com/">Flower</a><ul>
<li><a href="https://partiful.com/e/Vq9fyDNCMSO7ia4ulK5b"><strong>BOG-A-THON 2</strong></a></li>
</ul>
</li>
<li>2026-07-30 | Atlanta, GA, US | <a href="https://www.meetup.com/rust-atl">Rust Atlanta</a><ul>
<li><a href="https://www.meetup.com/rust-atl/events/313539329/"><strong>Rust-Atl</strong></a></li>
</ul>
</li>
<li>2026-08-01 | Boston, MA, US | <a href="https://www.meetup.com/bostonrust">Boston Rust Meetup</a><ul>
<li><a href="https://www.meetup.com/bostonrust/events/315582653/"><strong>Chinatown Rust Lunch, Aug 1</strong></a></li>
</ul>
</li>
<li>2026-08-04 | Boston, MA, US | <a href="https://www.meetup.com/bostonrust">Boston Rust Meetup</a><ul>
<li><a href="https://www.meetup.com/bostonrust/events/314660176/"><strong>Evening Boston Rust Meetup at Red Hat, Aug 4</strong></a></li>
</ul>
</li>
<li>2026-08-06 | Saint Louis, MO, US | <a href="https://www.meetup.com/stl-rust">STL Rust</a><ul>
<li><a href="https://www.meetup.com/stl-rust/events/314701905/"><strong>Shipping Temporal: How a Global Rust Ecosystem Built Chrome’s Newest Web API</strong></a></li>
</ul>
</li>
<li>2026-08-13 | Lehi, UT, US | <a href="https://www.meetup.com/utah-rust">Utah Rust</a><ul>
<li><a href="https://www.meetup.com/utah-rust/events/314696652/"><strong>Utah Rust August Meetup</strong></a></li>
</ul>
</li>
<li>2026-08-13 | San Diego, CA, US | <a href="https://www.meetup.com/san-diego-rust">San Diego Rust</a><ul>
<li><a href="https://www.meetup.com/san-diego-rust/events/315601099/"><strong>San Diego Rust August Meetup - Back in person!</strong></a></li>
</ul>
</li>
<li>2026-08-15 | San Francisco, CA, US | <a href="https://flowercomputer.com/">Flower</a><ul>
<li><a href="https://partiful.com/e/juWAwRs3XMWP7s9wLNWK"><strong>BOG-A-THON 3</strong></a></li>
</ul>
</li>
<li>2026-08-18 | San Francisco, CA, US | <a href="https://www.meetup.com/san-francisco-rust-study-group">San Francisco Rust Study Group</a><ul>
<li><a href="https://www.meetup.com/san-francisco-rust-study-group/events/314997215/"><strong>Rust Hacking in Person</strong></a></li>
</ul>
</li>
<li>2026-08-19 | Hybrid (Vancouver, BC, CA) | <a href="https://www.meetup.com/vancouver-rust">Vancouver Rust</a><ul>
<li><a href="https://www.meetup.com/vancouver-rust/events/314105333/"><strong>Dealing with Dependencies</strong></a></li>
</ul>
</li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#oceania">Oceania</a></h5>
<ul>
<li>2026-07-23 | Perth, AU | <a href="https://www.meetup.com/perth-rust-meetup-group">Rust Perth Meetup Group</a><ul>
<li><a href="https://www.meetup.com/perth-rust-meetup-group/events/315451138/"><strong>Rust Perth: July Meetup!</strong></a></li>
</ul>
</li>
<li>2026-07-30 | Melbourne, AU | <a href="https://www.meetup.com/rust-melbourne">Rust Melbourne</a><ul>
<li><a href="https://www.meetup.com/rust-melbourne/events/315039480/"><strong>Rust Melbourne July 2026</strong></a></li>
</ul>
</li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#south-america">South America</a></h5>
<ul>
<li>2026-08-08 | São Paulo, SP | <a href="https://luma.com/calendar/cal-bif2oHITU1aVvsr">Rust-SP</a><ul>
<li><a href="https://luma.com/41oiyhtk"><strong>Rust SP - Aug/2026</strong></a></li>
</ul>
</li>
</ul>
<p>If you are running a Rust event please add it to the <a href="https://www.google.com/calendar/embed?src=apd9vmbc22egenmtu5l6c5jbfc%40group.calendar.google.com">calendar</a> to get
it mentioned here. Please remember to add a link to the event too.
Email the <a href="mailto:community-team@rust-lang.org">Rust Community Team</a> for access.</p>
<h4><a class="toclink" href="https://this-week-in-rust.org/atom.xml#jobs">Jobs</a></h4>
<p>Please see the latest <a href="https://www.reddit.com/r/rust/comments/1ttbtf5/official_rrust_whos_hiring_thread_for_jobseekers/">Who's Hiring thread on r/rust</a></p>
<h3><a class="toclink" href="https://this-week-in-rust.org/atom.xml#quote-of-the-week">Quote of the Week</a></h3>
<blockquote>
<p>We were planning on publishing a blog post announcing this at the same time as making the repo public, but ran out of private repo CI usage 😭.</p>
</blockquote>
<p>– <a href="https://www.reddit.com/r/rust/comments/1uzknzl/tokiorstopcoat_a_batteriesincluded_framework_for/oy8k2nn/">Carl Lerche on r/rust</a> about the launch of topcoat</p>
<p>Despite a lamentable lack of suggestions, llogiq is glad to have found this quote.</p>
<p><a href="https://users.rust-lang.org/t/twir-quote-of-the-week/328">Please submit quotes and vote for next week!</a></p>
<p>This Week in Rust is edited by:</p>
<ul>
<li><a href="https://github.com/nellshamrell">nellshamrell</a></li>
<li><a href="https://github.com/llogiq">llogiq</a></li>
<li><a href="https://github.com/ericseppanen">ericseppanen</a></li>
<li><a href="https://github.com/extrawurst">extrawurst</a></li>
<li><a href="https://github.com/U007D">U007D</a></li>
<li><a href="https://github.com/mariannegoldin">mariannegoldin</a></li>
<li><a href="https://github.com/bdillo">bdillo</a></li>
<li><a href="https://github.com/opeolluwa">opeolluwa</a></li>
<li><a href="https://github.com/bnchi">bnchi</a></li>
<li><a href="https://github.com/KannanPalani57">KannanPalani57</a></li>
<li><a href="https://github.com/tzilist">tzilist</a></li>
</ul>
<p><em>Email list hosting is sponsored by <a href="https://foundation.rust-lang.org/">The Rust Foundation</a></em></p>
<p><small><a href="https://www.reddit.com/r/rust/comments/1v41dgv/this_week_in_rust_661/">Discuss on r/rust</a></small></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[iPhone 18 Pro Release Date: Here’s Exactly When Apple Is Expected to Launch It]]></title>
<description><![CDATA[Apple is expected to unveil the iPhone 18 Pro this September, continuing its long-running tradition of launching new flagship iPhones in the fall. While the company has not confirmed an official date yet, multiple reports and Apple's previous launch history point to an announcement during the sec...]]></description>
<link>https://tsecurity.de/de/3687150/ios-mac-os/iphone-18-pro-release-date-heres-exactly-when-apple-is-expected-to-launch-it/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3687150/ios-mac-os/iphone-18-pro-release-date-heres-exactly-when-apple-is-expected-to-launch-it/</guid>
<pubDate>Wed, 22 Jul 2026 19:26:27 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Apple is expected to unveil the iPhone 18 Pro this September, continuing its long-running tradition of launching new flagship iPhones in the fall. While the company has not confirmed an official date yet, multiple reports and Apple's previous launch history point to an announcement during the second week of September.



This year could also bring one of the biggest changes to Apple's iPhone launch strategy. Instead of releasing the entire iPhone 18 lineup together, reports suggest Apple will focus on its premium models first, with the standard iPhone 18 arriving several months later in early 2027.



When will Apple announce the iPhone 18 Pro?



Apple has followed a very consistent launch schedule over the past several years.



Here are the recent iPhone announcement dates:



iPhoneAnnouncement DateiPhone 17September 9, 2025iPhone 16September 9, 2024iPhone 15September 12, 2023



Based on this pattern, industry watchers expect Apple to hold its iPhone 18 event on either:




Wednesday, September 9, 2026



Monday, September 14, 2026




The slight uncertainty comes from the Labor Day calendar this year, which falls later than usual. Apple often schedules its iPhone event shortly after the holiday, making both dates realistic possibilities.



Expected iPhone 18 Pro release date



Apple usually opens pre-orders on the Friday after announcing new iPhones, followed by retail availability one week later.



If Apple announces the iPhone 18 lineup on September 9, the expected schedule would be:



EventExpected DateAnnouncementSeptember 9Pre-ordersSeptember 11ReleaseSeptember 18



If Apple chooses September 14 instead, the schedule would likely be:



EventExpected DateAnnouncementSeptember 14Pre-ordersSeptember 18ReleaseSeptember 25



Unless Apple changes its usual launch pattern, buyers should expect to receive the iPhone 18 Pro on either September 18 or September 25.



Which iPhone models are expected this fall?



Reports suggest Apple will introduce only its premium devices during the September event.



The expected lineup includes:




iPhone 18 Pro



iPhone 18 Pro Max



iPhone Ultra




There are also mixed reports about a new iPhone Air joining the lineup, although its release timing remains unclear. Meanwhile, the regular iPhone 18 is widely expected to launch in spring 2027 instead of September.



What could be new on the iPhone 18 Pro?







Although Apple has not officially revealed any features, recent leaks point to several notable upgrades.



Expected improvements include:




A new A20 Pro chip built on a 2nm manufacturing process



A smaller Dynamic Island with more Face ID components placed under the display



Camera upgrades, including a possible variable aperture system



Improved battery efficiency



Apple's next-generation C2 modem for better connectivity



New color options for the Pro models




As with all pre-release reports, these features remain rumors until Apple makes an official announcement.



Why is Apple reportedly delaying the standard iPhone 18?



Several reliable reports indicate Apple plans to split its iPhone launches into two seasons. Premium models would continue arriving in September, while the standard iPhone 18 and iPhone 18e would move to spring 2027.



This strategy would allow Apple to give more attention to its high-end devices during the holiday shopping season while creating another major product launch in the first half of the following year.



Expected iPhone 18 Pro launch timeline



Here is the most likely schedule based on current reports:



StageExpected TimingApple eventSeptember 9 or September 14, 2026Pre-ordersSeptember 11 or September 18Official releaseSeptember 18 or September 25Available modelsiPhone 18 Pro, iPhone 18 Pro Max, iPhone Ultra



Wrap Up



Apple has not announced the iPhone 18 Pro release date yet, but its launch history makes early to mid September the strongest prediction. If the company follows its familiar schedule, pre-orders will begin within days of the announcement, and the first devices will reach customers before the end of September.



At the same time, this year's launch could mark the beginning of a new release strategy, with the standard iPhone 18 arriving several months after the Pro models.]]></content:encoded>
</item>
<item>
<title><![CDATA[FAQ Claude Mythos: Fähigkeiten, Zugang, Wettbewerber, Auswirkungen]]></title>
<description><![CDATA[Claude Mythos steht immer mehr Unternehmen testweise zur Verfügung. Doch was genau steckt in Anthropics neuestem Modell?T. Schneider / Shutterstock



Was ist Claude Mythos?



Claude Mythos ist ein KI-Modell, das von Anthropic entwickelt wurde und für Anwendungen in den Bereichen Cybersicherheit...]]></description>
<link>https://tsecurity.de/de/3685218/it-security-nachrichten/faq-claude-mythos-faehigkeiten-zugang-wettbewerber-auswirkungen/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3685218/it-security-nachrichten/faq-claude-mythos-faehigkeiten-zugang-wettbewerber-auswirkungen/</guid>
<pubDate>Wed, 22 Jul 2026 06:10:27 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2024/04/shutterstock_editorial_2338803257.jpg?quality=50&amp;strip=all&amp;w=1024" alt="Anthropic and Claude" class="wp-image-2096337" width="1024" height="576" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption"><p>Claude Mythos steht immer mehr Unternehmen testweise zur Verfügung. Doch was genau steckt in Anthropics neuestem Modell?</p></figcaption></figure><p class="imageCredit">T. Schneider / Shutterstock</p></div>



<h2 class="wp-block-heading">Was ist Claude Mythos?</h2>



<p class="wp-block-paragraph">Claude Mythos ist ein KI-Modell, das von Anthropic entwickelt wurde und für Anwendungen in den Bereichen Cybersicherheit und Gesundheitswesen optimiert ist. Ursprünglich wurde Mythos 5 im April einer kleinen Gruppe geprüfter Technologiepartner zugänglich gemacht – im Vorfeld eines geplanten, breiter angelegten Rollouts.</p>



<p class="wp-block-paragraph">Zu diesem Zweck rief das KI-Unternehmen das <a href="https://www.computerwoche.de/article/4156536/wie-claude-mythos-die-it-sicherheit-veraendert.html">Projekt „Glasswing“</a> ins Leben, ein Konsortium, das Infrastrukturanbietern, Open-Source-Entwicklern und großen Technologieunternehmen einen begrenzten, kontrollierten Zugriff zu Mythos gewährt. Ziel der Initiative ist es, Verteidigern zu ermöglichen, Schwachstellen schneller aufzuspüren und zu beheben, als Angreifer sie identifizieren können. Das erscheint auch dringend notwendig, setzen diese doch zunehmend selbst auf <a href="https://www.computerwoche.de/article/4193820/ki-fuhrt-eigenstandig-cyber-attacken-aus.html">KI-gestützte Werkzeuge</a>.</p>



<h2 class="wp-block-heading">Über welche Fähigkeiten verfügt Claude Mythos?</h2>



<p class="wp-block-paragraph">Die ersten 50 Partner von Project Glasswing konnten mithilfe von Mythos mehr als 10.000 Schwachstellen mit hohem oder kritischem Schweregrad in allen gängigen Betriebssystemen und Webbrowsern aufspüren.</p>



<p class="wp-block-paragraph">So identifizierte das Modell Sicherheitslücken, die selbst den fähigsten Sicherheitsforschern jahrelang entgangen waren – etwa einen 27 Jahre alten Fehler in OpenBSD. Zudem hat Mythos bewiesen, dass es mehrere Schwachstellen miteinander verknüpfen kann.</p>



<h2 class="wp-block-heading">Wie schränkt Anthropic den Zugang zu Claude Mythos ein?</h2>



<p class="wp-block-paragraph">Anthropic teilte bei der Vorstellung von Claude Mythos mit, es schränke die Verfügbarkeit des Spitzen-KI-Modells bewusst ein, da dessen Fähigkeiten von Angreifern leicht missbraucht werden könnten.</p>



<p class="wp-block-paragraph">Im Juni wurde die Technologie dann für weitere 150 Organisationen freigegeben. Alle Mythos-Partner müssen hierbei aber zustimmen, dass ihre Daten 30 Tage lang zu Sicherheitsüberwachungszwecken gespeichert werden.</p>



<p class="wp-block-paragraph">Am 15. Juni verhängte die Trump-Regierung allerdings Exportbeschränkungen für <a href="https://www.csoonline.com/article/4183094/anthropic-releases-mythos-class-fable-5-model-with-safeguards-for-cyber-risks.html" target="_blank">Claude Fable 5</a> und Claude Mythos 5. Diese sollten ausländischen Staatsangehörigen sowohl innerhalb als auch außerhalb der USA den Zugang verwehren. Am 30. Juni wurden die Beschränkungen jedoch bereits wieder aufgehoben.</p>



<h2 class="wp-block-heading">Was ist Claude Fable?</h2>



<p class="wp-block-paragraph">Für einen breiteren Einsatzbereich bietet Anthropic Claude Fable 5 an. Das Modell basiert auf derselben technischen Grundlage wie Mythos. Es verfügt jedoch über strenge Sicherheitsmechanismen, die den Betrieb in als „riskant“ eingestuften Bereichen der Cybersicherheit einschränken. Alle als problematisch deklarierten Anfragen werden stattdessen automatisch an das ältere und weniger leistungsfähige Large Language Model (LLM) Opus 4.8 weitergeleitet.</p>



<h2 class="wp-block-heading">Wie nutzen Security-Partner von Anthropic den Zugriff auf Mythos?</h2>



<p class="wp-block-paragraph">Cisco, einer der Projekt-Glasswing-Partner, hat seine „<a href="https://blogs.cisco.com/ai/announcing-foundry-security-spec" target="_blank" rel="noreferrer noopener">Foundry Security Spec</a>“ als Open-Source-Lösung veröffentlicht. Hierbei handelt es sich um ein modellunabhängiges Framework für Sicherheitstests, das es anderen Anbietern und Sicherheitsexperten in Unternehmen ermöglichen soll, ähnliche Arbeitsabläufe zu entwickeln, ohne bei Null anfangen zu müssen.</p>



<p class="wp-block-paragraph">Vor kurzem betonten Vertreter von Cisco auf einer Online-Veranstaltung, dass Verteidiger KI nutzen können, um Sicherheitsprobleme wesentlich schneller und in größerem Umfang zu identifizieren, zu bestätigen und zu beheben. Ältere Modelle, die nach dem Prinzip „eine Schwachstelle finden und patchen“ funktionieren, seien nicht mehr zeitgemäß. Dies liege daran, dass Angreifer KI einsetzen, um den Weg von der Entdeckung einer Schwachstelle bis zu deren Ausnutzung zu beschleunigen. Cisco wiederum setzt KI intern bereits in der Defensive ein, um 1,8 Milliarden Zeilen Code im gesamten Produktportfolio zu scannen.</p>



<p class="wp-block-paragraph">Gleichzeitig betonen die Experten, dass kleinere Unternehmen keinen Zugriff auf eingeschränkte KI-Modelle benötigen, um ihre Sicherheit zu verbessern. In solchen Betrieben lasse sich stattdessen mehr erreichen, indem grundlegende Sicherheitsmaßnahmen optimiert werden. Hierzu zählen laut Cisco unter anderem Authentifizierung, Netzwerk-Segmentierung, Zero Trust und die Behebung aktiv ausgenutzter Schwachstellen.</p>



<h2 class="wp-block-heading">Bieten andere KI-Anbieter etwas Vergleichbares zu Claude Mythos an?</h2>



<p class="wp-block-paragraph">Mythos ist das prominenteste Beispiel für Frontier-KI-Modelle. Mit ihnen kann die Suche nach Zero-Day-Lücken in einem Tempo und Ausmaß automatisiert werden, die weit über die Fähigkeiten menschlicher Teams hinausgeht.</p>



<p class="wp-block-paragraph">Allerdings arbeiten auch etliche andere Anbieter an hochleistungsfähigen, auf Sicherheit ausgerichteten „Frontier“-KI-Modellen. Zudem gibt es andere leistungsstarke Open-Source-Modelle, die sich problemlos für die Cybersicherheitsforschung nutzen lassen. Claude Mythos ist also bei weitem nicht die einzige verfügbare Option.</p>



<p class="wp-block-paragraph">So werden beispielsweise die Modelle GPT-5.4-Cyber sowie GPT-5.5 von OpenAI genutzt, um Schwachstellen zu erkennen und zu analysieren. Auch in der Malware-Analyse und der Bedrohungsmodellierung kommen sie zum Einsatz. Zugang zu diesen Technologien können Sicherheitsanbieter, Unternehmen und Forscher über das Programm „Trusted Access for Cyber“ (TAC) von OpenAI erhalten.</p>



<p class="wp-block-paragraph">Zusätzlich hat das chinesische <a href="https://www.reuters.com/legal/litigation/chinas-360-says-it-has-developed-tools-match-anthropics-mythos-2026-06-24/" target="_blank" rel="noreferrer noopener">Cybersicherheitsunternehmen 360 Security Technology mit Tulongfeng</a> ein System entwickelt, das als Gegenstück zu Anthropics „Mythos“ beschrieben wird.</p>



<p class="wp-block-paragraph">Privat lassen sich leistungsstarke offene Modelle – darunter DeepSeek V3.2 von DeepSeek und Llama 4 von Meta – auf GPU-Infrastrukturen betreiben und in der Cybersicherheitsforschung einsetzen. Fugu des japanischen Anbieters Sakana AI ist eine weitere Option in dieser Kategorie.</p>



<h2 class="wp-block-heading">Was kritisieren Cybersicherheitsexperten an Claude Mythos?</h2>



<p class="wp-block-paragraph">Kritiker aus dem Cybersecurity-Bereich räumen ein, dass Claude Mythos zweifellos hochentwickelt sei. Die Marketing-Behauptung, wonach es zuverlässig produktive IT-Systeme lahmlegen könne, übersteige jedoch die tatsächlichen Fähigkeiten.</p>



<p class="wp-block-paragraph">Darüber hinaus beklagen sich Sicherheitsexperten – <a href="https://www.youtube.com/watch?v=mx0CpTp3Q4Y" target="_blank" rel="noreferrer noopener">etwa in Podcasts</a> – über die übertrieben restriktiven Sicherheitsmechanismen von Claude Fable: Bereits Anfragen, einen sicherheitsrelevanten Blogbeitrag zusammenzufassen oder sogar das Wort „Exploit“ zu buchstabieren, würden auf das deutlich schwächere Modell Opus 4.8 zurückgestuft. Dadurch würden selbst alltägliche Aufgaben in der Informationssicherheit unnötig erschwert.</p>



<p class="wp-block-paragraph">Andere Experten warnen davor, dass Frontier-KI-Modelle anfällig für False Positives seien. Eher grundsätzlich ist die Kritik, dass das schnellere Aufspüren von mehr Schwachstellen das eigentliche Problem nicht löst, nämlich zuverlässig Sicherheitslücken zu beheben oder nicht-technische Angriffsvektoren wie Social Engineering zu verhindern.</p>



<h2 class="wp-block-heading">Wie sollten CISOs auf Mythos reagieren?</h2>



<p class="wp-block-paragraph">Die Nachrichtendienste der „Five Eyes“ (USA, Großbritannien, Kanada, Australien und Neuseeland) <a href="https://www.ncsc.gov.uk/sites/default/files/2026-06/Five-Eyes-cyber-security-agencies-statement-ai-shift.pdf"></a> warnen davor, dass hochmoderne KI-Modelle wie Claude Mythos „sowohl offensive als auch defensive Cyber-Fähigkeiten grundlegend verändern werden“ – und zwar in einem Zeitraum von Monaten statt Jahren.</p>



<p class="wp-block-paragraph">„Während KI uns dabei helfen wird, die Cyberabwehr im Laufe der Zeit zu verbessern, erhöht sie zugleich Geschwindigkeit, Ausmaß und Raffinesse von Cyberbedrohungen“, heißt es in der Erklärung der Gruppe. Unternehmen sollen daher KI nutzen, um ihre Abwehrmechanismen im Rahmen umfassenderer Strategien zur Stärkung der Cybersicherheits-Resilienz zu verbessern.</p>



<p class="wp-block-paragraph">Die meisten Unternehmen seien jedoch bei weitem noch nicht darauf vorbereitet, was dies für ihre Bedrohungsmodelle bedeutet, warnt ein Experte. „Wir verfügen heute über KI-Systeme, die realistische Angriffswege über Software, Anbieter und kritische Infrastrukturen hinweg schneller abbilden können, als menschliche Angreifer sie erfassen können“, erläutert <a href="https://www.linkedin.com/in/jhubback/" target="_blank" rel="noreferrer noopener">Joe Hubback</a>, Partner und CISO beim Beratungsunternehmen Elixirr sowie ehemaliger McKinsey-Partner. Dadurch, dass „Fähigkeiten der ‚Mythos-Klasse‘ vor der breiten kommerziellen Einführung stünden, handle es sich nicht mehr um „ein Nischenproblem der Forschung“, ergänzt er. Vielmehr sei es jetzt ein Faktor, den jedes Unternehmen in sein Bedrohungsmodell einbeziehen müsse, so der Experte.</p>



<p class="wp-block-paragraph">Auch ein <a href="https://labs.cloudsecurityalliance.org/wp-content/uploads/2026/04/mythosready-20260413.pdf" target="_blank" rel="noreferrer noopener">Bericht der Cloud Security Alliance</a> warnt davor, dass KI die Zeitspanne zwischen der Entdeckung einer Schwachstelle und deren Ausnutzung drastisch verkürzt habe. Damit seien herkömmliche Sicherheitsmodelle, die auf „Patchen und Reagieren“ basieren, überholt. Unternehmen sollten sich vielmehr auf anhaltende Wellen von Schwachstellen einstellen, die durch „Project Glasswing“ und andere Quellen mittels KI aufgedeckt werden.</p>



<p class="wp-block-paragraph">„Die bei Mythos beobachteten Fähigkeiten werden schon bald breiter verfügbar sein. Dadurch wird sich die Anzahl sowie Häufigkeit komplexer, neuartiger Angriffe, denen sich Unternehmen gegenübersehen, drastisch erhöhen“, heißt es in der Warnung. Sicherheitsverantwortliche müssten daher ihre Verteidigungsstrategien auf einen „Mythos-ready“-Ansatz umstellen, der auf kontinuierlichem Schwachstellenmanagement, schnellerer Priorisierung und verbesserter Reaktion auf Sicherheitsvorfälle basiert. (tf)</p>



<p class="wp-block-paragraph"><strong>Dieser Artikel basiert auf einem <a href="https://www.csoonline.com/article/4198019/claude-mythos-faq-capabilities-access-competitors-implications.html" target="_blank">Beitrag</a> von CSO.</strong></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Announcing Windows 11 Insider Preview Build 28120.2546 for Experimental (26H1)]]></title>
<description><![CDATA[Hello Windows Insiders,
Today we're releasing build 28120.2546 for the Experimental (26H1) channel. Release notes can be found over in the Announcing Windows 11 Insider Preview Build 28120.2546 for Experimental (26H1) appeared first on Windows Insider Blog.]]></description>
<link>https://tsecurity.de/de/3684863/windows-tipps/announcing-windows-11-insider-preview-build-281202546-for-experimental-26h1/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3684863/windows-tipps/announcing-windows-11-insider-preview-build-281202546-for-experimental-26h1/</guid>
<pubDate>Tue, 21 Jul 2026 23:08:59 +0200</pubDate>
<category>🪟 Windows Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Hello Windows Insiders,</p>
<p>Today we're releasing build 28120.2546 for the Experimental (26H1) channel. Release notes can be found over in the <a href="https://learn.microsoft.com/en-us/windows-insider/release-notes/experimental-26-h1/preview-build-2812%0A%3C/p%3E%0A%3Cp%3EThe%20post%20%3Ca%20href=" https:>Announcing Windows 11 Insider Preview Build 28120.2546 for Experimental (26H1)</a> appeared first on <a href="https://blogs.windows.com/windows-insider">Windows Insider Blog</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[We’re announcing the Alliance for America’s Skilled Trades.]]></title>
<description><![CDATA[Google is joining BlackRock, Carhartt and Ford to launch the Alliance for America’s Skilled Trades.]]></description>
<link>https://tsecurity.de/de/3683940/it-nachrichten/were-announcing-the-alliance-for-americas-skilled-trades/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3683940/it-nachrichten/were-announcing-the-alliance-for-americas-skilled-trades/</guid>
<pubDate>Tue, 21 Jul 2026 16:03:30 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<img src="https://storage.googleapis.com/gweb-uniblog-publish-prod/images/Skilled_Trades_Alliance_social.max-600x600.format-webp.webp">Google is joining BlackRock, Carhartt and Ford to launch the Alliance for America’s Skilled Trades.]]></content:encoded>
</item>
<item>
<title><![CDATA[Announcing new builds for 20 July 2026]]></title>
<description><![CDATA[Hello Windows Insiders,
Today we are releasing new Windows 11 Insider Preview Builds across Beta, Experimental and Release Preview. See your channel release notes here:

Beta: Announcing new builds for 20 July 2026 appeared first on Windows Insider Blog.]]></description>
<link>https://tsecurity.de/de/3682253/windows-tipps/announcing-new-builds-for-20-july-2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3682253/windows-tipps/announcing-new-builds-for-20-july-2026/</guid>
<pubDate>Mon, 20 Jul 2026 23:57:39 +0200</pubDate>
<category>🪟 Windows Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Hello Windows Insiders,</p>
<p>Today we are releasing new Windows 11 Insider Preview Builds across Beta, Experimental and Release Preview. See your channel release notes here:</p>
<ul>
<li>Beta: <a href="https://learn.microsoft.com/en-us/windows-insider/rel%20%0A%3Cbr%20/%3E%0A%3Cp%3EThe%20post%20%3Ca%20href=" https:>Announcing new builds for 20 July 2026</a> appeared first on <a href="https://blogs.windows.com/windows-insider">Windows Insider Blog</a>.</li></ul>]]></content:encoded>
</item>
<item>
<title><![CDATA[Claude Mythos FAQ: Capabilities, access, competitors, implications]]></title>
<description><![CDATA[1.
What is Claude Mythos?




Claude Mythos is an advanced AI model developed by Anthropic and is optimized for cybersecurity and healthcare applications.



Mythos 5 was originally released in April to a small group of vetted technology partners ahead of a planned wider rollout.



Anthropic est...]]></description>
<link>https://tsecurity.de/de/3680433/it-security-nachrichten/claude-mythos-faq-capabilities-access-competitors-implications/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3680433/it-security-nachrichten/claude-mythos-faq-capabilities-access-competitors-implications/</guid>
<pubDate>Mon, 20 Jul 2026 08:38:28 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<div class="wp-block-idg-base-theme-faq-block faq-block">
<div class="wp-block-idg-base-theme-faq-inner-block faq-save-block"><div class="faq-save-content"><span class="faq-rank">1.</span>
<h2 class="wp-block-heading">What is Claude Mythos?</h2>



<div class="wp-block-idg-base-theme-faq-answer-block how-to-tip">
<p class="wp-block-paragraph">Claude Mythos is an advanced AI model developed by Anthropic and is optimized for cybersecurity and healthcare applications.</p>



<p class="wp-block-paragraph"><a href="https://www.anthropic.com/claude/mythos">Mythos 5</a> was originally released in April to a small group of vetted technology partners ahead of a planned wider rollout.</p>



<p class="wp-block-paragraph">Anthropic established <strong>Project Glasswing</strong>, a consortium that gives limited, controlled access to Mythos to infrastructure providers, open-source developers, and major technology companies. The scheme was designed to enable defenders to find and resolve vulnerabilities faster than they could be identified by attackers, <a href="https://www.csoonline.com/article/4154222/6-ways-attackers-abuse-ai-services-to-hack-your-business.html">many of which are also beginning to rely heavily on AI tools</a>.</p>
</div>
</div></div>



<div class="wp-block-idg-base-theme-faq-inner-block faq-save-block"><div class="faq-save-content"><span class="faq-rank">2.</span>
<h2 class="wp-block-heading">What are the capabilities of Claude Mythos?</h2>



<div class="wp-block-idg-base-theme-faq-answer-block how-to-tip">
<p class="wp-block-paragraph">The <a href="https://www.csoonline.com/article/4155342/what-anthropic-glasswing-reveals-about-the-future-of-vulnerability-discovery.html">50 initial partners of Project Glasswing</a> were able to use Mythos to find more than <a href="https://www.csoonline.com/article/4176865/project-glasswing-has-uncovered-10000-vulnerabilities-anthropic.html">10,000 high- or critical-severity vulnerabilities</a> in every major operating system and <a href="https://www.csoonline.com/article/4162259/claude-mythos-signals-a-new-era-in-ai-driven-security-finding-271-flaws-in-firefox.html">every major web browser</a>.</p>



<p class="wp-block-paragraph">The model is identifying security flaws that had evaded even the most capable security researchers for years, such as a <a href="https://www.csoonline.com/article/4159617/behind-the-mythos-hype-glasswing-has-just-one-confirmed-cve.html">27-year-old bug in OpenBSD</a>. It has also proved capable of chaining multiple vulnerabilities together.</p>
</div>
</div></div>



<div class="wp-block-idg-base-theme-faq-inner-block faq-save-block"><div class="faq-save-content"><span class="faq-rank">3.</span>
<h2 class="wp-block-heading">How is Anthropic restricting access to Claude Mythos?</h2>



<div class="wp-block-idg-base-theme-faq-answer-block how-to-tip">
<p class="wp-block-paragraph">Anthropic said it was restricting the more widespread availability of the frontier AI model because its capabilities might easily be misused by attackers.</p>



<p class="wp-block-paragraph">In June the technology was released to an <a href="https://www.csoonline.com/article/4180265/anthropic-grants-project-glasswing-access-to-150-more-companies-with-a-focus-on-critical-infrastructure.html">additional 150 organizations</a>. All Mythos partners are required to accept a 30-day data retention policy for safety monitoring.</p>



<p class="wp-block-paragraph">After the availability of Mythos forced the <a href="https://www.csoonline.com/article/4166824/anthropic-mythos-spurs-white-house-to-weigh-pre-release-reviews-for-high-risk-ai-models.html">Trump administration to reconsider its “hands off” approach to AI oversight</a>, the US government applied export controls to Claude Fable 5 and Claude Mythos 5 on June 15. The restrictions — which were supposed to block access to foreign nationals both inside and outside the US — were lifted on June 30.</p>
</div>
</div></div>



<div class="wp-block-idg-base-theme-faq-inner-block faq-save-block"><div class="faq-save-content"><span class="faq-rank">4.</span>
<h2 class="wp-block-heading">What is Claude Fable?</h2>



<div class="wp-block-idg-base-theme-faq-answer-block how-to-tip">
<p class="wp-block-paragraph">For broader use, Anthropic is offering <a href="https://www.csoonline.com/article/4183094/anthropic-releases-mythos-class-fable-5-model-with-safeguards-for-cyber-risks.html">Claude Fable 5</a>, which is based on the same underlying technology but comes with strict guardrails that limit operations in “risky” cybersecurity domains. Flagged queries are automatically routed to the earlier and less capable Opus 4.8 large language model (LLM) instead.</p>
</div>
</div></div>



<div class="wp-block-idg-base-theme-faq-inner-block faq-save-block"><div class="faq-save-content"><span class="faq-rank">5.</span>
<h2 class="wp-block-heading">How are Anthropic’s security vendor partners using access to Mythos?</h2>



<div class="wp-block-idg-base-theme-faq-answer-block how-to-tip">
<p class="wp-block-paragraph">Cisco, one of Anthropic’s Project Glasswing partners, <a href="https://blogs.cisco.com/ai/announcing-foundry-security-spec">open-sourced its Foundry Security Spec</a>, a model-agnostic “harness” for security testing, so that other vendors and enterprise security defenders could build similar workflows without starting from scratch.</p>



<p class="wp-block-paragraph">During a recent web conference, representatives from Cisco argued that defenders can use AI to identify, confirm, and resolve security issues at much greater speed and scale. Older vulnerability remediation models based on “find one issue, patch one issue” are no longer adequate because attackers are using AI moving to accelerate the path from vulnerability discovery to exploitation.</p>



<p class="wp-block-paragraph">Cisco has been using AI internally to scan 1.8 billion lines of code across its whole product portfolio.</p>



<p class="wp-block-paragraph">Smaller businesses do not need access to restricted AI models to improve security and more can be achieved in smaller shops by improving security fundamentals such as authentication, segmentation, zero trust, and prioritizing the remediation of actively exploited vulnerabilities, according to Cisco.</p>
</div>
</div></div>



<div class="wp-block-idg-base-theme-faq-inner-block faq-save-block"><div class="faq-save-content"><span class="faq-rank">6.</span>
<h2 class="wp-block-heading">Do other AI vendors offer anything comparable to Claude Mythos?</h2>



<div class="wp-block-idg-base-theme-faq-answer-block how-to-tip">
<p class="wp-block-paragraph">Mythos is the most prominent example of frontier AI models that can automate zero-day discovery at a scale and speed far beyond the capability of human teams.</p>



<p class="wp-block-paragraph">Several other vendors have frontier AI models aimed towards high-capability, security-oriented operations while others have capable open models that might easily be applied to cybersecurity research.</p>



<p class="wp-block-paragraph">As a result, Claude Mythos is far from the only game in town.</p>



<p class="wp-block-paragraph">For example, OpenAI’s GPT-5.4-Cyber (and <a href="https://openai.com/index/gpt-5-5-with-trusted-access-for-cyber/">GPT-5.5</a>) has applications in vulnerability analysis and discovery as well as malware analysis and threat modelling. Security vendors, enterprises, and researchers can gain access to the technology through OpenAI’s Trusted Access for Cyber (TAC) scheme.</p>



<p class="wp-block-paragraph">Chinese cybersecurity firm <a href="https://www.reuters.com/legal/litigation/chinas-360-says-it-has-developed-tools-match-anthropics-mythos-2026-06-24/">360 Security Technology has developed Tulongfeng</a>, described as a domestic answer to Anthropic’s Mythos.</p>



<p class="wp-block-paragraph">High performance open models — including DeepSeek V3.2 and Llama 4 — can be run privately on GPU infrastructure and applied to cybersecurity research. Fugu from Japanese vendor Sakana AI offers another option in this category.</p>
</div>
</div></div>



<div class="wp-block-idg-base-theme-faq-inner-block faq-save-block"><div class="faq-save-content"><span class="faq-rank">7.</span>
<h2 class="wp-block-heading">What do cybersecurity critics say about Claude Mythos?</h2>



<div class="wp-block-idg-base-theme-faq-answer-block how-to-tip">
<p class="wp-block-paragraph">Infosecurity critics note that while Claude Mythos is unquestionably advanced, marketing claims that it is reliably breaking production systems overstate its capabilities.</p>



<p class="wp-block-paragraph">Security professionals are complaining through <a href="https://www.youtube.com/watch?v=mx0CpTp3Q4Y">podcasts</a> and elsewhere about the overly sensitive guardrails in Claude Fable that downgrade to Opus 4.8 upon requests to summarize a security-related blog post or even spell the word “exploit” much less tackle any everyday information security task.</p>



<p class="wp-block-paragraph">Other experts warn that false positives are likely to be an issue for cybersecurity research using frontier AI models.</p>



<p class="wp-block-paragraph">The wider criticism is that finding more vulnerabilities faster fails to address the bigger problem of reliability fixing security bugs or non-technical attack paths such as social engineering.</p>
</div>
</div></div>



<div class="wp-block-idg-base-theme-faq-inner-block faq-save-block"><div class="faq-save-content"><span class="faq-rank">8.</span>
<h2 class="wp-block-heading">How should enterprise CISOs respond to the development of Mythos?</h2>



<div class="wp-block-idg-base-theme-faq-answer-block how-to-tip">
<p class="wp-block-paragraph">Western intelligence agencies that form the <a href="https://www.ncsc.gov.uk/sites/default/files/2026-06/Five-Eyes-cyber-security-agencies-statement-ai-shift.pdf">Fives Eyes alliance issued a statement warning that frontier AI models such as Claude Mythos</a> are “fundamentally transforming both offensive and defensive cyber capabilities” in a scale of months rather than years.</p>



<p class="wp-block-paragraph">“While Al will help us improve cyber defence over time, it also accelerates the speed, scale, and sophistication of cyber threats,” the group, which includes the US National Security Agency and the UK’s National Cyber Security Centre, warns.</p>



<p class="wp-block-paragraph">Enterprises need to be using AI to strengthen defenses as part of broader plans to improve cybersecurity resilience.</p>



<p class="wp-block-paragraph">AI-based systems capable of mapping realistic attack paths faster than any human adversary are fast becoming a pervasive threat, while most organizations are nowhere near ready for what that means for their threat models, one expert warns.</p>



<p class="wp-block-paragraph">“We now have AI systems that can map realistic attack paths across software, vendors, and critical infrastructure faster than human adversaries can catalog them,” says Joe Hubback, partner and CISO at consultancy Elixirr and former McKinsey Partner. “And as Mythos-class capabilities are prepared for broad commercial release, that’s no longer a niche research problem, it’s something every organization will have to factor into its threat model.”</p>



<p class="wp-block-paragraph">An <a href="https://labs.cloudsecurityalliance.org/wp-content/uploads/2026/04/mythosready-20260413.pdf">AI safety paper from the Cloud Security Alliance</a> warns that AI has significantly compressed the time between vulnerability discovery and exploitation, outpacing traditional patch-and-react security models. Organizations should brace for ongoing waves of AI-discovered vulnerabilities from Project Glasswing and other sources.</p>



<p class="wp-block-paragraph">“The capabilities seen in Mythos will quickly become more widely available, dramatically increasing the number and frequency of complex, novel attacks organizations will face,” it warns.</p>



<p class="wp-block-paragraph">Enterprise security defenders need to shift to a “Mythos-ready” approach built around continuous vulnerability operations, faster prioritization, and improved incident response.</p>
</div>
</div></div>
</div>



<p class="wp-block-paragraph"><strong>See also:</strong></p>



<ul class="wp-block-list">
<li><a href="https://www.csoonline.com/article/4155342/what-anthropic-glasswing-reveals-about-the-future-of-vulnerability-discovery.html">What Anthropic Glasswing reveals about the future of vulnerability discovery</a></li>



<li><a href="https://www.csoonline.com/article/4158117/anthropics-mythos-signals-a-structural-cybersecurity-shift.html">Anthropic’s Mythos signals a structural cybersecurity shift</a></li>



<li><a href="https://www.csoonline.com/article/4180920/beware-the-son-of-mythos-security-experts-warn.html">Beware the ‘son of Mythos,’ security experts warn</a></li>



<li><a href="https://www.csoonline.com/article/4189600/mythos-is-a-signal-not-a-siren-what-frontier-ai-should-change-for-cisos.html">Mythos is a signal, not a siren: What frontier AI should change for CISOs</a></li>
</ul>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Announcing the General Availability of Prisma AIRS AI Gateway]]></title>
<description><![CDATA[Every modern enterprise is moving from an organization run by software to one orchestrated by AI, creating a tension between velocity and control. To resolve this tension, organizations require a unified architecture. … The post Announcing the General Availability of…
Read more →
The post Announc...]]></description>
<link>https://tsecurity.de/de/3673950/it-security-nachrichten/announcing-the-general-availability-of-prisma-airs-ai-gateway/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3673950/it-security-nachrichten/announcing-the-general-availability-of-prisma-airs-ai-gateway/</guid>
<pubDate>Thu, 16 Jul 2026 17:23:42 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Every modern enterprise is moving from an organization run by software to one orchestrated by AI, creating a tension between velocity and control. To resolve this tension, organizations require a unified architecture. … The post Announcing the General Availability of…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/announcing-the-general-availability-of-prisma-airs-ai-gateway/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/announcing-the-general-availability-of-prisma-airs-ai-gateway/">Announcing the General Availability of Prisma AIRS AI Gateway</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[PlayStation has postponed the release of its FlexStrike Wireless Fight Stick 'due to unexpected production delays,' says it 'will launch at a later date']]></title>
<description><![CDATA[PlayStation has issued an update on the release of its FlexStrike Wireless Fight Stick, announcing that the hardware has been postponed.]]></description>
<link>https://tsecurity.de/de/3673452/it-nachrichten/playstation-has-postponed-the-release-of-its-flexstrike-wireless-fight-stick-due-to-unexpected-production-delays-says-it-will-launch-at-a-later-date/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3673452/it-nachrichten/playstation-has-postponed-the-release-of-its-flexstrike-wireless-fight-stick-due-to-unexpected-production-delays-says-it-will-launch-at-a-later-date/</guid>
<pubDate>Thu, 16 Jul 2026 14:33:36 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[PlayStation has issued an update on the release of its FlexStrike Wireless Fight Stick, announcing that the hardware has been postponed.]]></content:encoded>
</item>
<item>
<title><![CDATA[Qantas Did Everything “Right” — And Got Breached Anyway. Regulators Say That’s the Point.]]></title>
<description><![CDATA[A vishing call to an overseas contact center agent. A fake IT ticket. A default setting nobody thought to lock down. That's all it took to expose the personal data of roughly 5 million Australians — and now the country's privacy regulator has decided Qantas isn't to blame for it.
The Office of t...]]></description>
<link>https://tsecurity.de/de/3672634/it-security-nachrichten/qantas-did-everything-right-and-got-breached-anyway-regulators-say-thats-the-point/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3672634/it-security-nachrichten/qantas-did-everything-right-and-got-breached-anyway-regulators-say-thats-the-point/</guid>
<pubDate>Thu, 16 Jul 2026 09:24:38 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1200" height="800" src="https://thecyberexpress.com/wp-content/uploads/Qantas_Data_Breach.webp" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="Qantas, Qantas Data Breach, Data Breach, Cyber aattack, Socail Engineering, OAIC, OAIC Report, Privacy Commissioner" decoding="async" srcset="https://thecyberexpress.com/wp-content/uploads/Qantas_Data_Breach.webp 1200w, https://thecyberexpress.com/wp-content/uploads/Qantas_Data_Breach-300x200.webp 300w, https://thecyberexpress.com/wp-content/uploads/Qantas_Data_Breach-1024x683.webp 1024w, https://thecyberexpress.com/wp-content/uploads/Qantas_Data_Breach-768x512.webp 768w, https://thecyberexpress.com/wp-content/uploads/Qantas_Data_Breach-600x400.webp 600w, https://thecyberexpress.com/wp-content/uploads/Qantas_Data_Breach-150x100.webp 150w, https://thecyberexpress.com/wp-content/uploads/Qantas_Data_Breach-750x500.webp 750w, https://thecyberexpress.com/wp-content/uploads/Qantas_Data_Breach-1140x760.webp 1140w, https://thecyberexpress.com/wp-content/uploads/Qantas_Data_Breach.webp 1200w, https://thecyberexpress.com/wp-content/uploads/Qantas_Data_Breach-300x200.webp 300w, https://thecyberexpress.com/wp-content/uploads/Qantas_Data_Breach-1024x683.webp 1024w, https://thecyberexpress.com/wp-content/uploads/Qantas_Data_Breach-768x512.webp 768w, https://thecyberexpress.com/wp-content/uploads/Qantas_Data_Breach-600x400.webp 600w, https://thecyberexpress.com/wp-content/uploads/Qantas_Data_Breach-150x100.webp 150w, https://thecyberexpress.com/wp-content/uploads/Qantas_Data_Breach-750x500.webp 750w, https://thecyberexpress.com/wp-content/uploads/Qantas_Data_Breach-1140x760.webp 1140w" sizes="(max-width: 1200px) 100vw, 1200px" title="Qantas Did Everything &quot;Right&quot; — And Got Breached Anyway. Regulators Say That's the Point. 3"></p><p class="font-claude-response-body break-words whitespace-normal" data-sourcepos="3:1-3:281;93-373">A vishing call to an overseas contact center agent. A fake IT ticket. A default setting nobody thought to lock down. That's all it took to expose the personal <a class="wpil_keyword_link" href="https://thecyberexpress.com/what-is-data/" title="data" data-wpil-keyword-link="linked" data-wpil-monitor-id="28992">data</a> of roughly 5 million Australians — and now the country's privacy regulator has decided Qantas isn't to blame for it.</p>
<p class="font-claude-response-body break-words whitespace-normal" data-sourcepos="5:1-5:574;375-948">The Office of the Australian Information Commissioner (OAIC) closed the book this week on its year-long preliminary inquiry into the June 2025 Qantas <a class="wpil_keyword_link" href="https://cyble.com/knowledge-hub/what-is-a-data-breach/" target="_blank" rel="noopener" title="data breach" data-wpil-keyword-link="linked" data-wpil-monitor-id="28995">data breach</a>, and the conclusion cuts against the instinct to punish the victim of a cyberattack.</p>

<h5 data-sourcepos="5:1-5:574;375-948"><strong>Also read:</strong> <a href="https://thecyberexpress.com/qantas-cyberattack-confirmed/">Australia’s Qantas Confirms Cyberattack: 6 Million Service Records Compromised</a></h5>
<p class="font-claude-response-body break-words whitespace-normal" data-sourcepos="5:1-5:574;375-948">According to the OAIC's <a href="https://www.oaic.gov.au/privacy/privacy-assessments-and-decisions/privacy-decisions/Investigation-inquiry-reports/report-into-preliminary-inquiries-of-qantas" target="_blank" rel="nofollow noopener">report</a>, the evidence gathered did not indicate a likelihood that Qantas had "failed" to take reasonable steps to protect the personal information it held, nor that it failed to ensure its overseas third-party provider complied with Australia's privacy principles. No investigation. No enforcement action.</p>

<blockquote>
<p data-sourcepos="5:1-5:574;375-948"><em>"After more than a year of making inquiries and obtaining information on the data breach, we're satisfied that the evidence does not support the likelihood that a breach of <a class="wpil_keyword_link" href="https://thecyberexpress.com/what-is-privacy/" title="privacy" data-wpil-keyword-link="linked" data-wpil-monitor-id="28998">privacy</a> law occurred. As a result, we've decided not to commence a full investigation of Qantas at this stage."</em> <strong>- Carly Kind, Australian Privacy Commissioner.</strong></p>
</blockquote>
<h3 class="font-claude-response-body break-words whitespace-normal" data-sourcepos="7:1-7:20;950-969"><strong>How It Happened</strong></h3>
<p class="font-claude-response-body break-words whitespace-normal" data-sourcepos="9:1-9:569;971-1539">The breach traces back to a single phone call. A <a class="wpil_keyword_link" href="https://cyble.com/threat-actor/" target="_blank" rel="noopener" title="threat actor" data-wpil-keyword-link="linked" data-wpil-monitor-id="28993">threat actor</a> posing as "Qantas IT help" convinced a contact center agent to visit a website tied to the customer relationship management platform used by Qantas agents, walking them through steps framed as necessary to close an IT support ticket. That interaction connected the agent's CRM session to a data extraction tool controlled by the attacker, who then pulled data from every contact profile the agent could access. It was pure social engineering — no malware, no exploited <a class="wpil_keyword_link" href="https://thecyberexpress.com/firewall-daily/vulnerabilities/" title="vulnerability" data-wpil-keyword-link="linked" data-wpil-monitor-id="28989">vulnerability</a>, just a convincing lie.</p>
<p class="font-claude-response-body break-words whitespace-normal" data-sourcepos="11:1-11:360;1541-1900">Qantas caught it fast. A staff member spotted an unusual spike in login-attempt alerts on the morning of June 30, two days after the call, and escalated it to the <a class="wpil_keyword_link" href="https://thecyberexpress.com/what-is-cybersecurity/" title="cybersecurity" data-wpil-keyword-link="linked" data-wpil-monitor-id="28990">cybersecurity</a> team. Within hours, the company had frozen the compromised account, assessed for data exfiltration, and triggered its <a class="wpil_keyword_link" href="https://cyble.com/knowledge-hub/what-is-incident-response/" target="_blank" rel="noopener" title="incident response" data-wpil-keyword-link="linked" data-wpil-monitor-id="28994">incident response</a> process. Public disclosure followed on July 2.</p>

<h3 class="font-claude-response-body break-words whitespace-normal" data-sourcepos="13:1-13:39;1902-1940"><strong>What Was Exposed — And What Wasn't</strong></h3>
<p class="font-claude-response-body break-words whitespace-normal" data-sourcepos="15:1-15:545;1942-2486">The regulator's numbers are more precise than what circulated publicly last year. Roughly 5.67 million customer records were compromised, with about 4 million exposing names, phone numbers, email addresses and Frequent Flyer details, and a further 1.7 million records including combinations of home or business addresses, dates of birth, gender and meal preferences. Critically, no credit card numbers, financial information or passport details lived on the compromised platform, and customer passwords and login credentials were never touched.</p>

<h5 data-sourcepos="15:1-15:545;1942-2486"><strong>Also read:</strong> <a href="https://thecyberexpress.com/qantas-airways-confirms-data-breach/">Qantas Airways Cyberattack Update: Customer Data Released, Security Measures Enhanced</a></h5>
<h3 class="font-claude-response-body break-words whitespace-normal" data-sourcepos="17:1-17:32;2488-2519"><strong>Why The Regulator Let It Go</strong></h3>
<p class="font-claude-response-body break-words whitespace-normal" data-sourcepos="19:1-19:562;2521-3082">The OAIC's reasoning is a rare, explicit acknowledgment that good controls don't guarantee immunity. Investigators found that <a class="wpil_keyword_link" href="https://cyble.com/knowledge-hub/what-is-social-engineering/" target="_blank" rel="noopener" title="social engineering" data-wpil-keyword-link="linked" data-wpil-monitor-id="28996">social engineering</a> training generally targets credential theft, not the rarer tactic of talking an employee into authorizing a legitimate-looking system connection — meaning the attack likely would have succeeded even with standard training in place. They also noted the flaw was structural: a default configuration let the agent authorize a third-party app connection, a setting the CRM vendor has since changed for all its customers.</p>
<p class="font-claude-response-body break-words whitespace-normal" data-sourcepos="21:1-21:339;3084-3422">Commissioner Carly Kind put the broader stakes plainly in the OAIC's statement announcing the report, warning that AI-driven threats are only raising the bar. As she framed it, agentic and advanced AI will keep escalating the cybersecurity <a class="wpil_keyword_link" href="https://thecyberexpress.com/what-are-risks-in-cybersecurity/" title="risks" data-wpil-keyword-link="linked" data-wpil-monitor-id="28991">risks</a> businesses face, making continuous review of security posture non-negotiable — not optional.</p>
“Data breaches are a persistent feature of today’s digital world, and can occur despite organisations taking steps to protect personal information,” Commissioner Carly <a href="https://www.oaic.gov.au/news/media-centre/privacy-commissioner-completes-preliminary-inquiries-into-qantas-2025-data-incident" target="_blank" rel="nofollow noopener">said</a>.

“Agentic and advanced AI will only increase the cybersecurity risks that businesses face, and it is critical that all organisations continuously review and enhance their <a class="wpil_keyword_link" href="https://thecyberexpress.com/" title="security" data-wpil-keyword-link="linked" data-wpil-monitor-id="28997">security</a> to protect against this growing threat.”
<p class="font-claude-response-body break-words whitespace-normal" data-sourcepos="23:1-23:207;3424-3630">The takeaway here isn't that Qantas got a pass. It's that a regulator has now drawn, in writing, the line between negligence and the limits of what training and access controls can realistically stop.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[This Week In Rust: This Week in Rust 660]]></title>
<description><![CDATA[Hello and welcome to another issue of This Week in Rust!
Rust is a programming language empowering everyone to build reliable and efficient software.
This is a weekly summary of its progress and community.
Want something mentioned? Tag us at
@thisweekinrust.bsky.social on Bluesky or
@ThisWeekinRu...]]></description>
<link>https://tsecurity.de/de/3672376/tools/this-week-in-rust-this-week-in-rust-660/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3672376/tools/this-week-in-rust-this-week-in-rust-660/</guid>
<pubDate>Thu, 16 Jul 2026 07:09:13 +0200</pubDate>
<category>💾  Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Hello and welcome to another issue of <em>This Week in Rust</em>!
<a href="https://www.rust-lang.org/">Rust</a> is a programming language empowering everyone to build reliable and efficient software.
This is a weekly summary of its progress and community.
Want something mentioned? Tag us at
<a href="https://bsky.app/profile/thisweekinrust.bsky.social">@thisweekinrust.bsky.social</a> on Bluesky or
<a href="https://mastodon.social/@thisweekinrust">@ThisWeekinRust</a> on mastodon.social, or
<a href="https://github.com/rust-lang/this-week-in-rust">send us a pull request</a>.
Want to get involved? <a href="https://github.com/rust-lang/rust/blob/main/CONTRIBUTING.md">We love contributions</a>.</p>
<p><em>This Week in Rust</em> is openly developed <a href="https://github.com/rust-lang/this-week-in-rust">on GitHub</a> and archives can be viewed at <a href="https://this-week-in-rust.org/">this-week-in-rust.org</a>.
If you find any errors in this week's issue, <a href="https://github.com/rust-lang/this-week-in-rust/pulls">please submit a PR</a>.</p>
<p>Want TWIR in your inbox? <a href="https://this-week-in-rust.us11.list-manage.com/subscribe?u=fd84c1c757e02889a9b08d289&amp;id=0ed8b72485">Subscribe here</a>.</p>
<h4><a class="toclink" href="https://this-week-in-rust.org/atom.xml#updates-from-rust-community">Updates from Rust Community</a></h4>


<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#official">Official</a></h5>
<ul>
<li><a href="https://blog.rust-lang.org/2026/07/09/Rust-1.97.0/">Announcing Rust 1.97.0</a></li>
<li><a href="https://blog.rust-lang.org/2026/07/13/crates-io-development-update/">crates.io: development update</a></li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#projecttooling-updates">Project/Tooling Updates</a></h5>
<ul>
<li><a href="https://bun.com/blog/bun-in-rust">Rewriting Bun in Rust</a></li>
<li><a href="https://bullmq.io/news/260712/rust-release/">Announcing BullMQ for Rust</a></li>
<li><a href="https://github.com/zs-dima/prost-protovalidate/releases/tag/v0.6.0">prost-protovalidate 0.6 — buf.validate (protovalidate) for prost and buffa: compile-time codegen + runtime CEL, 2872/2872 conformance</a></li>
<li><a href="https://github.com/StaszeKrk/plaza/releases/tag/v1.0.0">plaza 1.0: a ratatui package-manager TUI that searches pacman, the AUR, apt, dnf, and Flatpak at once</a></li>
<li><a href="https://github.com/danube-messaging/danube/releases/tag/v0.15.1">Danube v0.15.1: native Apache Iceberg integration for streaming-to-lakehouse export</a></li>
<li><a href="https://www.willsearch.com.br/sentinel/">Guardian Sentinel. The Terminal User Interface for Guardian Decentralized Database - P2P</a></li>
<li><a href="https://github.com/kunobi-ninja/kobe/releases/tag/v0.33.0">kobe 0.33.0: a Rust operator for instant CI Kubernetes clusters</a></li>
<li><a href="https://navigatorbuilds.github.io/elara-mesh/blog/black-box-for-ai-agents.html">Elara Mesh: what the black box for AI agents actually does</a></li>
<li>
<p><a href="https://github.com/kunobi-ninja/kache/releases/tag/v0.10.0">kache 0.10.0: instant download dedup, no more polling</a></p>
</li>
<li>
<p><a href="https://richer-richard.github.io/cochlea/">cochlea 0.1.0: a headless, deterministic audio engine for AI agents</a></p>
</li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#observationsthoughts">Observations/Thoughts</a></h5>
<ul>
<li><a href="https://opensourcesecurity.io/2026/2026-07-rfmf-lori-niko/">Open Source Security Podcast: Rust Foundation Maintainers Fund with Lori and Niko</a></li>
<li><a href="https://pulsebeam.dev/blog/moving-to-thread-per-core">Moving a Rust WebRTC SFU to thread-per-core</a></li>
<li><a href="https://abundance.build/blog/2026-07-11-faster-rust-tests-in-ci-with-parallel-steps/">Faster Rust tests in CI with parallel steps</a></li>
<li>[video] <a href="https://www.youtube.com/watch?v=fugcSHD-9Jw">The Only Diagram You Need to Understand Rust Ownership</a></li>
<li><a href="https://encore.dev/blog/typescript-parser-wasm">We compiled our TypeScript parser to WASM</a></li>
<li><a href="https://kerkour.com/rust-hype">Understanding the Rust hype for the busy developer</a></li>
<li><a href="https://dev.to/akavlabs_69/i-red-teamed-my-own-llm-security-gateway-in-four-passes-heres-every-gap-i-found-5cl9">I red-teamed my own LLM security gateway (Rust) in four passes — every detection gap and how I closed it</a></li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#rust-walkthroughs">Rust Walkthroughs</a></h5>
<ul>
<li>[video] <a href="https://www.youtube.com/watch?v=DJhhy6YQe8k">Backend Concepts in Rust: HTTP Servers</a></li>
<li><a href="https://dystroy.org/blog/picamobile/">Fearless Embedded Rust: A FPV Lego car</a></li>
<li><a href="https://www.aravpanwar.com/writing/building-decayfmt-in-rust/">What I learned building a self-corrupting file format in Rust</a></li>
<li><a href="https://corentin-core.github.io/posts/ruxe-async-runtime-agnostic/">Come Async You Are</a></li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#miscellaneous">Miscellaneous</a></h5>
<ul>
<li><a href="https://blog.theembeddedrustacean.com/oxidize-xiao">Oxidize XIAO — An Embedded Rust Community Program</a></li>
</ul>
<h4><a class="toclink" href="https://this-week-in-rust.org/atom.xml#crate-of-the-week">Crate of the Week</a></h4>
<p>This week's crate is <a href="https://crates.io/crates/dashu">dashu</a>, a pure Rust set of libraries of arbitrary precision numbers.</p>
<p>Thanks to <a href="https://users.rust-lang.org/t/crate-of-the-week/2704/1628">JacobZ</a> for the self-suggestion!</p>
<p><a href="https://users.rust-lang.org/t/crate-of-the-week/2704">Please submit your suggestions and votes for next week</a>!</p>
<h4><a class="toclink" href="https://this-week-in-rust.org/atom.xml#calls-for-testing">Calls for Testing</a></h4>
<p>An important step for RFC implementation is for people to experiment with the
implementation and give feedback, especially before stabilization.</p>
<p>If you are a feature implementer and would like your RFC to appear in this list, add a
<code>call-for-testing</code> label to your RFC along with a comment providing testing instructions and/or
guidance on which aspect(s) of the feature need testing.</p>
<p><em>No calls for testing were issued this week by
<a href="https://github.com/rust-lang/rust/issues?q=state%3Aopen%20label%3Acall-for-testing%20state%3Aopen">Rust</a>,
<a href="https://github.com/rust-lang/cargo/issues?q=state%3Aopen%20label%3Acall-for-testing%20state%3Aopen">Cargo</a>,
<a href="https://github.com/rust-lang/rustup/issues?q=state%3Aopen%20label%3Acall-for-testing%20state%3Aopen">Rustup</a> or
<a href="https://github.com/rust-lang/rfcs/issues?q=label%3Acall-for-testing%20state%3Aopen">Rust language RFCs</a>.</em></p>
<p><a href="https://github.com/rust-lang/this-week-in-rust/issues">Let us know</a> if you would like your feature to be tracked as a part of this list.</p>
<h4><a class="toclink" href="https://this-week-in-rust.org/atom.xml#call-for-participation-projects-and-speakers">Call for Participation; projects and speakers</a></h4>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#cfp-projects">CFP - Projects</a></h5>
<p>Always wanted to contribute to open-source projects but did not know where to start?
Every week we highlight some tasks from the Rust community for you to pick and get started!</p>
<p>Some of these tasks may also have mentors available, visit the task page for more information.</p>



<ul>
<li><a href="https://github.com/supernovae-st/nika/issues/424">Nika - showcase: CSV → chart PNG → markdown report (nika:chart has no example yet)</a></li>
</ul>


<p>If you are a Rust project owner and are looking for contributors, please submit tasks <a href="https://github.com/rust-lang/this-week-in-rust?tab=readme-ov-file#call-for-participation-guidelines">here</a> or through a <a href="https://github.com/rust-lang/this-week-in-rust">PR to TWiR</a> or by reaching out on <a href="https://bsky.app/profile/thisweekinrust.bsky.social">Bluesky</a> or <a href="https://mastodon.social/@thisweekinrust">Mastodon</a>!</p>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#cfp-events">CFP - Events</a></h5>
<p>Are you a new or experienced speaker looking for a place to share something cool? This section highlights events that are being planned and are accepting submissions to join their event as a speaker.</p>



<p>If you are an event organizer hoping to expand the reach of your event, please submit a link to the website through a <a href="https://github.com/rust-lang/this-week-in-rust">PR to TWiR</a> or by reaching out on <a href="https://bsky.app/profile/thisweekinrust.bsky.social">Bluesky</a> or <a href="https://mastodon.social/@thisweekinrust">Mastodon</a>!</p>
<h4><a class="toclink" href="https://this-week-in-rust.org/atom.xml#updates-from-the-rust-project">Updates from the Rust Project</a></h4>
<p>550 pull requests were <a href="https://github.com/search?q=is%3Apr+org%3Arust-lang+is%3Amerged+merged%3A2026-07-07..2026-07-14">merged in the last week</a></p>
<h6><a class="toclink" href="https://this-week-in-rust.org/atom.xml#compiler">Compiler</a></h6>
<ul>
<li><a href="https://github.com/rust-lang/rust/pull/158931">inline some <code>Symbol</code> functions</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/157104">predicate/clause cleanups</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/158942">remove some AST <code>tokens</code> fields</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/159019">resolver: wrap arenas in <code>WorkerLocal</code></a></li>
<li><a href="https://github.com/rust-lang/rust/pull/158794">rework read deduplication with pooled read recorders</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/159012">shrink <code>mir::Statement</code> to 40 bytes</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/157491">shrink no-op drop elaboration</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/158865">specialize common <code>(1, 1)</code> case for arg unification</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/158842">use SmallVec for return places in MIR</a></li>
</ul>
<h6><a class="toclink" href="https://this-week-in-rust.org/atom.xml#library">Library</a></h6>
<ul>
<li><a href="https://github.com/rust-lang/rust/pull/158866">add explicit <code>Iterator::count</code> impl for <code>ChunkBy</code></a></li>
<li><a href="https://github.com/rust-lang/rust/pull/157153">allow <code>Allocator</code>s to be used as <code>#[global_allocator]</code>s</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/158876">fix multiple logic bugs in <code>Arc::make_mut</code></a></li>
<li><a href="https://github.com/rust-lang/rust/pull/158940">implement feature <code>char_to_u32</code></a></li>
<li><a href="https://github.com/rust-lang/rust/pull/159092">make volatile operations const</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/158541">move <code>std::io::Write</code> to <code>core::io</code></a></li>
<li><a href="https://github.com/rust-lang/rust/pull/159099">stabilize <code>String::from_utf8_lossy_owned</code></a></li>
<li><a href="https://github.com/rust-lang/rust/pull/151379">stabilize <code>VecDeque::retain_back</code> from <code>truncate_front</code></a></li>
</ul>
<h6><a class="toclink" href="https://this-week-in-rust.org/atom.xml#cargo">Cargo</a></h6>
<ul>
<li><a href="https://github.com/rust-lang/cargo/pull/17199"><code>install</code>: Move --debug to Compilation options</a></li>
<li><a href="https://github.com/rust-lang/cargo/pull/17204"><code>source</code>: incorrect duplicate package warning</a></li>
<li><a href="https://github.com/rust-lang/cargo/pull/17202">fix manifest schema generation: <code>TomlDebugInfo</code> enum-variants doesn't renamed</a></li>
<li><a href="https://github.com/rust-lang/cargo/pull/17198">dont apply host-config gating to stable behavior</a></li>
<li><a href="https://github.com/rust-lang/cargo/pull/17191">reduce library search path length in new build dir layout</a></li>
<li><a href="https://github.com/rust-lang/cargo/pull/17168">reduce rustc <code>-L</code> args used in the new <code>build-dir</code> layout</a></li>
<li><a href="https://github.com/rust-lang/cargo/pull/17149">rename <code>-Zno-embed-metadata</code> to <code>-Zembed-metadata=no</code></a></li>
<li><a href="https://github.com/rust-lang/cargo/pull/17203">test: fix race in <code>cargo_compile_with_invalid_code_in_deps</code></a></li>
</ul>
<h6><a class="toclink" href="https://this-week-in-rust.org/atom.xml#clippy">Clippy</a></h6>
<ul>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/15000">add new lints: <code>rest_pattern_accessible_field</code> and <code>unnecessary_rest_pattern</code></a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/16965">new lint: <code>definition_in_module_root</code></a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17343"><code>arbitrary_source_item_ordering</code>: add configurable trait impl item ordering modes</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17387"><code>tests_outside_test_module</code>: put code in backticks in the lint message</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17215">count length of the first paragraph by its text</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/16980">fix <code>suboptimal_flops</code> false negative with ambiguous float literals</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17416">partly disable <code>unneeded_wildcard_pattern</code> when <code>rest_pattern_accessible_field</code> is enabled</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17404">respect the configured MSRV in <code>implicit_saturating_sub</code>'s <code>if x != 0 { x -= 1 }</code> rewrite</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/16513">trigger <code>single_element_loop</code> if the block contains only a final expression</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/16808">optimize <code>nonstandard_macro_braces</code> by 99.9683% (1.1b → 351K)</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17381">perf: bail out of the <code>disallowed_methods</code> rule if the disallowed list is empty</a></li>
</ul>
<h6><a class="toclink" href="https://this-week-in-rust.org/atom.xml#rust-analyzer">Rust-Analyzer</a></h6>
<ul>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22771">ask for disclosure in AI contributions</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22734">add fixes for array length for <code>type_mismatch</code></a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22741">add parens in transformed dyn type in ref type</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22736">avoid panic in merge imports on trailing path separator</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22654">change some things for <code>#[doc = macro!()]</code> expansion</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22770">clamp cttz const-eval result to type width</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22751">correctly handled cfg'ed tail expr, take 2</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22749">crash on code actions when an unresolved module is present</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22707">crash when computing diagnostics with MIR and error types</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22744">don't complete default in default impl</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22283">early late classification of lifetimes</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22583">fix <code>render_const_using_debug_impl</code> constructing outdated std layouts</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22735">fix proc macros <code>TokenStream::from_str()</code> for doc comments</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22464">hide private fields on hover depending on context</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22753">make lsp-server <code>Response</code> type closer aligned to JSON-RPC</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22535">pretty assoc const when trait in macro</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22747">reimplement <code>crate_supports_no_std</code> syntactic heuristic</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22773">resolve non-plain paths in blocks correctly</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22683">support Cargo 1.97.0 lockfile path setting</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22405">hir-ty: walk container exprs for <code>unused_must_use</code></a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22768">fix onEnter erroneously deleting/interpreting <code>$foo</code></a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22726">suggest code action fixes produced from diagnostics under cursor, even if they have effects elsewhere</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22777">treat library files as truly client immutable</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22534">turn <code>BlockLoc</code> into a tracked struct, take 3</a></li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#rust-compiler-performance-triage">Rust Compiler Performance Triage</a></h5>
<p>This week many new optimizations landed, making this a very good week for performance.
The only real regression was a fix for a miscompile that will likely be re-landed in the future.</p>
<p>Triage done by <strong>@JonathanBrouwer</strong>.
Revision range: <a href="https://perf.rust-lang.org/?start=3659db0d3e2cd634c766fcda79ed118eca31a9fd&amp;end=5503df87342a73d0c29126a7e08dc9c1255c46ad&amp;absolute=false&amp;stat=instructions%3Au">3659db0d..5503df87</a></p>
<p><strong>Summary</strong>:</p>
<table>
<thead>
<tr>
<th>(instructions:u)</th>
<th>mean</th>
<th>range</th>
<th>count</th>
</tr>
</thead>
<tbody>
<tr>
<td>Regressions ❌ <br> (primary)</td>
<td>0.3%</td>
<td>[0.2%, 0.4%]</td>
<td>3</td>
</tr>
<tr>
<td>Regressions ❌ <br> (secondary)</td>
<td>0.9%</td>
<td>[0.1%, 2.5%]</td>
<td>25</td>
</tr>
<tr>
<td>Improvements ✅ <br> (primary)</td>
<td>-1.2%</td>
<td>[-9.9%, -0.2%]</td>
<td>195</td>
</tr>
<tr>
<td>Improvements ✅ <br> (secondary)</td>
<td>-3.4%</td>
<td>[-92.1%, -0.1%]</td>
<td>174</td>
</tr>
<tr>
<td>All ❌✅ (primary)</td>
<td>-1.2%</td>
<td>[-9.9%, 0.4%]</td>
<td>198</td>
</tr>
</tbody>
</table>
<p>2 Regressions, 10 Improvements, 10 Mixed; 7 of them in rollups
36 artifact comparisons made in total</p>
<p><a href="https://github.com/rust-lang/rustc-perf/blob/212da2d63f1edf2ab22293547a99f0fbf8cb68a8/triage/2026/2026-07-13.md">Full report here</a></p>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#approved-rfcs"></a><a href="https://github.com/rust-lang/rfcs/commits/master">Approved RFCs</a></h5>
<p>Changes to Rust follow the Rust <a href="https://github.com/rust-lang/rfcs#rust-rfcs">RFC (request for comments) process</a>. These
are the RFCs that were approved for implementation this week:</p>
<ul>
<li><a href="https://github.com/rust-lang/rfcs/pull/3955">Named <code>Fn</code> trait parameters</a></li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#final-comment-period">Final Comment Period</a></h5>
<p>Every week, <a href="https://www.rust-lang.org/team.html">the team</a> announces the 'final comment period' for RFCs and key PRs
which are reaching a decision. Express your opinions now.</p>
<h6><a class="toclink" href="https://this-week-in-rust.org/atom.xml#tracking-issues-prs">Tracking Issues &amp; PRs</a></h6>
<a class="toclink" href="https://this-week-in-rust.org/atom.xml#rust"></a><a href="https://github.com/rust-lang/rust/issues?q=is%3Aopen%20label%3Afinal-comment-period%20sort%3Aupdated-desc%20state%3Aopen">Rust</a>
<ul>
<li><a href="https://github.com/rust-lang/rust/pull/159179">enable <code>unreachable_cfg_select_predicates</code> lint as part of <code>unused</code> lint group</a></li>
<li><a href="https://github.com/rust-lang/rust/issues/156906">Stabilize <code>dyn Allocator</code></a></li>
<li><a href="https://github.com/rust-lang/rust/issues/146954">Tracking Issue for vec_try_remove</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/157226">Partially stabilize <code>box_vec_non_null</code></a></li>
<li><a href="https://github.com/rust-lang/rust/issues/152761">Never break between empty parens</a></li>
</ul>
<a class="toclink" href="https://this-week-in-rust.org/atom.xml#compiler-team-mcps-only"></a><a href="https://github.com/rust-lang/compiler-team/issues?q=label%3Amajor-change%20label%3Afinal-comment-period%20state%3Aopen">Compiler Team</a> <a href="https://forge.rust-lang.org/compiler/mcp.html">(MCPs only)</a>
<ul>
<li><a href="https://github.com/rust-lang/compiler-team/issues/1015">Enable <code>-Zpolonius=next</code> on nightly</a></li>
<li><a href="https://github.com/rust-lang/compiler-team/issues/1014">Enable <code>-Znext-solver</code> on nightly by default for testing</a></li>
<li><a href="https://github.com/rust-lang/compiler-team/issues/1012">Stabilizing the state of the debuginfo test suite</a></li>
<li><a href="https://github.com/rust-lang/compiler-team/issues/922">Optimize <code>repr(Rust)</code> enums by omitting tags in more cases involving uninhabited variants.</a></li>
<li><a href="https://github.com/rust-lang/compiler-team/issues/841">Proposal for Adapt Stack Protector for Rust</a></li>
</ul>
<p><em>No Items entered Final Comment Period this week for
<a href="https://github.com/rust-lang/cargo/issues?q=is%3Aopen%20label%3Afinal-comment-period%20sort%3Aupdated-desc%20state%3Aopen">Cargo</a>,
<a href="https://github.com/rust-lang/reference/issues?q=is%3Aopen%20label%3Afinal-comment-period%20sort%3Aupdated-desc%20state%3Aopen">Language Reference</a>,
<a href="https://github.com/rust-lang/lang-team/issues?q=is%3Aopen%20label%3Afinal-comment-period%20sort%3Aupdated-desc%20state%3Aopen">Language Team</a>,
<a href="https://github.com/rust-lang/leadership-council/issues?q=state%3Aopen%20label%3Afinal-comment-period%20state%3Aopen">Leadership Council</a>,
<a href="https://github.com/rust-lang/rfcs/issues?q=state%3Aopen%20label%3Afinal-comment-period%20state%3Aopen">Rust RFCs</a> or
<a href="https://github.com/rust-lang/unsafe-code-guidelines/issues?q=is%3Aopen%20label%3Afinal-comment-period%20sort%3Aupdated-desc%20state%3Aopen">Unsafe Code Guidelines</a>.</em></p>
<p>Let us know if you would like your PRs, Tracking Issues or RFCs to be tracked as a part of this list.</p>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#new-and-updated-rfcs"></a><a href="https://github.com/rust-lang/rfcs/pulls">New and Updated RFCs</a></h5>
<ul>
<li><a href="https://github.com/rust-lang/rfcs/pull/3983">bf16 primitive type</a></li>
</ul>
<h4><a class="toclink" href="https://this-week-in-rust.org/atom.xml#upcoming-events">Upcoming Events</a></h4>
<p>Rusty Events between 2026-07-15 - 2026-08-12 🦀</p>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#virtual">Virtual</a></h5>
<ul>
<li>2026-07-15 | Virtual (Girona, ES) | <a href="https://luma.com/rust-girona">Rust Girona</a><ul>
<li><a href="https://luma.com/21k797xr"><strong>Sessió setmanal de codificació / Weekly coding session</strong></a></li>
</ul>
</li>
<li>2026-07-15 | Hybrid (Vancouver, BC, CA) | <a href="https://www.meetup.com/vancouver-rust">Vancouver Rust</a><ul>
<li><a href="https://www.meetup.com/vancouver-rust/events/314233743/"><strong>Jiff</strong></a></li>
</ul>
</li>
<li>2026-07-16 | Hybrid (Seattle, WA, US) | <a href="https://www.meetup.com/join-srug">Seattle Rust User Group</a><ul>
<li><a href="https://www.meetup.com/seattle-rust-user-group/events/314520812/"><strong>July, 2026 SRUG (Seattle Rust User Group) Meetup</strong></a></li>
</ul>
</li>
<li>2026-07-16 | Virtual (Berlin, DE) | <a href="https://www.meetup.com/rust-berlin">Rust Berlin</a><ul>
<li><a href="https://www.meetup.com/rust-berlin/events/312045926/"><strong>Rust Hack and Learn</strong></a></li>
</ul>
</li>
<li>2026-07-19 | Virtual (Dallas, TX, US) | <a href="https://www.meetup.com/dallasrust">Dallas Rust User Meetup</a><ul>
<li><a href="https://www.meetup.com/dallasrust/events/314329045/"><strong>Rust Deep Learning: Third Sunday</strong></a></li>
</ul>
</li>
<li>2026-07-21 | Virtual (London, UK) | <a href="https://www.meetup.com/women-in-rust">Women in Rust</a><ul>
<li><a href="https://www.meetup.com/women-in-rust/events/315102297/"><strong>Lunch &amp; Learn: Learning Rust as First Programming Language</strong></a></li>
</ul>
</li>
<li>2026-07-21 | Virtual (Tel Aviv-yafo, IL) | <a href="https://www.meetup.com/rust-tlv/events/">Rust 🦀 TLV</a><ul>
<li><a href="https://www.meetup.com/rust-tlv/events/315676843/"><strong>שיחה חופשית ווירטואלית על ראסט</strong></a></li>
</ul>
</li>
<li>2026-07-21 | Virtual (Washington, DC, US) | <a href="https://www.meetup.com/rustdc">Rust DC</a><ul>
<li><a href="https://www.meetup.com/rustdc/events/315279653/"><strong>Mid-month Rustful</strong></a></li>
</ul>
</li>
<li>2026-07-22 | Virtual (Girona, ES) | <a href="https://luma.com/rust-girona">Rust Girona</a><ul>
<li><a href="https://luma.com/hd8mlw56"><strong>Sessió setmanal de codificació / Weekly coding session</strong></a></li>
</ul>
</li>
<li>2026-07-23 | Mountain View, CA, US | <a href="https://www.meetup.com/hackerdojo/events/">Hacker Dojo</a><ul>
<li><a href="https://www.meetup.com/hackerdojo/events/315418155/"><strong>RUST MEETUP at HACKER DOJO</strong></a></li>
</ul>
</li>
<li>2026-07-28 | Virtual (Dallas, TX, US) | <a href="https://www.meetup.com/dallasrust">Dallas Rust User Meetup</a><ul>
<li><a href="https://www.meetup.com/dallasrust/events/310254777/"><strong>Fourth Tuesday</strong></a></li>
</ul>
</li>
<li>2026-07-29 | Virtual (Girona, ES) | <a href="https://luma.com/rust-girona">Rust Girona</a><ul>
<li><a href="https://luma.com/uo5ek1f4"><strong>Sessió setmanal de codificació / Weekly coding session</strong></a></li>
</ul>
</li>
<li>2026-07-30 | Virtual (Berlin, DE) | <a href="https://www.meetup.com/rust-berlin/events/">Rust Berlin</a><ul>
<li><a href="https://www.meetup.com/rust-berlin/events/312045928/"><strong>Rust Hack and Learn</strong></a></li>
</ul>
</li>
<li>2026-08-02 | Virtual (Dallas, TX, US) | <a href="https://www.meetup.com/dallasrust/events/">Dallas Rust User Meetup</a><ul>
<li><a href="https://www.meetup.com/dallasrust/events/314095294/"><strong>Rust Deep Learning: First Sunday</strong></a></li>
</ul>
</li>
<li>2026-08-04 | Virtual (London, GB) | <a href="https://www.meetup.com/women-in-rust/events/">Women in Rust</a><ul>
<li><a href="https://www.meetup.com/women-in-rust/events/315213885/"><strong>👋 Community Catch Up</strong></a></li>
</ul>
</li>
<li>2026-08-05 | Virtual (Girona, ES) | <a href="https://luma.com/rust-girona">Rust Girona</a><ul>
<li><a href="https://luma.com/f2hnzrug"><strong>Sessió setmanal de codificació / Weekly coding session</strong></a></li>
</ul>
</li>
<li>2026-08-05 | Virtual (Indianapolis, IN, US) | <a href="https://www.meetup.com/indyrs/events/">Indy Rust</a><ul>
<li><a href="https://www.meetup.com/indyrs/events/315210367/"><strong>Indy.rs - with Social Distancing</strong></a></li>
</ul>
</li>
<li>2026-08-11 | Virtual (Dallas, TX, US) | <a href="https://www.meetup.com/dallasrust/events/">Dallas Rust User Meetup</a><ul>
<li><a href="https://www.meetup.com/dallasrust/events/310254776/"><strong>Second Tuesday</strong></a></li>
</ul>
</li>
<li>2026-08-12 | Virtual (Girona, ES) | <a href="https://luma.com/rust-girona">Rust Girona</a><ul>
<li><a href="https://luma.com/f2hnzrug"><strong>Sessió setmanal de codificació / Weekly coding session</strong></a></li>
</ul>
</li>
<li>2026-07-19 | Virtual (Bangalore, IN) | <a href="https://discord.gg/VJyv3NfVdw">Embedded Rust Discord</a><ul>
<li><a href="https://discord.gg/6gwCNpFP?event=1526087936234225814"><strong>Silicon Sundays</strong></a></li>
</ul>
</li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#asia">Asia</a></h5>
<ul>
<li>2026-07-18 | Bangalore, IN | <a href="https://hasgeek.com/rustbangalore">Rust Bangalore</a><ul>
<li><a href="https://hasgeek.com/rustbangalore/july-2026-rustacean-meetup/"><strong>July 2026 Rustacean Meetup</strong></a></li>
</ul>
</li>
<li>2026-07-19 | Virtual (Bangalore, IN) | <a href="https://discord.gg/VJyv3NfVdw">Embedded Rust Discord</a><ul>
<li><a href="https://discord.gg/6gwCNpFP?event=1526087936234225814"><strong>Silicon Sundays</strong></a></li>
</ul>
</li>
<li>2026-07-25 | Mumbai, IN | <a href="https://luma.com/mumbai">Rust Mumbai</a><ul>
<li><a href="https://luma.com/7ksabwbm/"><strong>​Rust Mumbai — July Meetup 🦀</strong></a></li>
</ul>
</li>
<li>2026-07-26 | Pune, MA, IN | <a href="https://www.meetup.com/rust-pune/events/">Rust Pune</a><ul>
<li><a href="https://www.meetup.com/rust-pune/events/315651505/"><strong>Rust Pune: July 2026</strong></a></li>
</ul>
</li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#europe">Europe</a></h5>
<ul>
<li>2026-07-15 | Dortmund, DE | <a href="https://www.meetup.com/rust-dortmund/events/">Rust Dortmund</a><ul>
<li><a href="https://www.meetup.com/rust-dortmund/events/315496876/"><strong>Teach and Hack at Projektspeicher</strong></a></li>
</ul>
</li>
<li>2026-07-21 | Leipzig, DE | <a href="https://www.meetup.com/rust-modern-systems-programming-in-leipzig">Rust - Modern Systems Programming in Leipzig</a><ul>
<li><a href="https://www.meetup.com/rust-modern-systems-programming-in-leipzig/events/313816470/"><strong>Supercharge Rust funcs with implicit arguments and context-generic programming</strong></a></li>
</ul>
</li>
<li>2026-07-23 | Berlin, DE | <a href="https://www.meetup.com/rust-berlin">Rust Berlin</a><ul>
<li><a href="https://www.meetup.com/rust-berlin/events/315484101/"><strong>Rust Berlin Talks: The next generation</strong></a></li>
</ul>
</li>
<li>2026-07-23 | London, UK | <a href="https://www.meetup.com/london-rust-project-group">London Rust Project Group</a><ul>
<li><a href="https://www.meetup.com/london-rust-project-group/events/315366453/"><strong>Rama modular service framework for Rust</strong></a></li>
</ul>
</li>
<li>2026-07-23 | London, UK | <a href="https://www.meetup.com/rust-london-user-group/events/">Rust London User Group</a><ul>
<li><a href="https://www.meetup.com/rust-london-user-group/events/315612916/"><strong>LDN Talks: July 2026 Antithesis Takeover</strong></a></li>
</ul>
</li>
<li>2026-07-23 | Paris, FR | <a href="https://www.meetup.com/rust-paris">Rust Paris</a><ul>
<li><a href="https://www.meetup.com/rust-paris/events/315309633/"><strong>Rust meetup #87</strong></a></li>
</ul>
</li>
<li>2026-07-29 | Poland, PL | <a href="https://www.meetup.com/rust-poland-meetup">Rust Poland</a><ul>
<li><a href="https://www.meetup.com/rust-poland-meetup/events/315582674/"><strong>Rust Poland x Kraków #10</strong></a></li>
</ul>
</li>
<li>2026-07-30 | Manchester, GB | <a href="https://www.meetup.com/rust-manchester/events/">Rust Manchester</a><ul>
<li><a href="https://www.meetup.com/rust-manchester/events/315037685/"><strong>Rust Manchester July Code Night</strong></a></li>
</ul>
</li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#north-america">North America</a></h5>
<ul>
<li>2026-07-15 | Hybrid (Vancouver, BC, CA) | <a href="https://www.meetup.com/vancouver-rust">Vancouver Rust</a><ul>
<li><a href="https://www.meetup.com/vancouver-rust/events/314233743/"><strong>Jiff</strong></a></li>
</ul>
</li>
<li>2026-07-16 | Hybrid (Seattle, WA, US) | <a href="https://www.meetup.com/join-srug">Seattle Rust User Group</a><ul>
<li><a href="https://www.meetup.com/seattle-rust-user-group/events/314520812/"><strong>July, 2026 SRUG (Seattle Rust User Group) Meetup</strong></a></li>
</ul>
</li>
<li>2026-07-18 | Boston, MA, US | <a href="https://www.meetup.com/bostonrust">Boston Rust Meetup</a><ul>
<li><a href="https://www.meetup.com/bostonrust/events/315225872/"><strong>North End Rust Lunch, July 18</strong></a></li>
</ul>
</li>
<li>2026-07-21 | San Francisco, CA, US | <a href="https://www.meetup.com/san-francisco-rust-study-group">San Francisco Rust Study Group</a><ul>
<li><a href="https://www.meetup.com/san-francisco-rust-study-group/events/314997214/"><strong>Rust Hacking in Person</strong></a></li>
</ul>
</li>
<li>2026-07-22 | Austin, TX, US | <a href="https://www.meetup.com/rust-atx">Rust ATX</a><ul>
<li><a href="https://www.meetup.com/rust-atx/events/xvkdgtyjckbdc/"><strong>Rust Lunch - Fareground</strong></a></li>
</ul>
</li>
<li>2026-07-22 | Los Angeles, CA, US | <a href="https://www.meetup.com/rust-los-angeles">Rust Los Angeles</a><ul>
<li><a href="https://www.meetup.com/rust-los-angeles/events/315376271/"><strong>Rust LA: Rust in Distributed Systems with Flight Science!</strong></a></li>
</ul>
</li>
<li>2026-07-22 | New York, NY, US | <a href="https://www.meetup.com/rust-nyc/events/">Rust NYC</a><ul>
<li><a href="https://www.meetup.com/rust-nyc/events/315636854/"><strong>Rust NYC: Write A Custom Coding Agent and wasm_zero</strong></a></li>
</ul>
</li>
<li>2026-07-25 | Boston, MA, US | <a href="https://www.meetup.com/bostonrust/events/">Boston Rust Meetup</a><ul>
<li><a href="https://www.meetup.com/bostonrust/events/315582650/"><strong>Porter Square Rust Lunch, July 25</strong></a></li>
</ul>
</li>
<li>2026-07-25 | Brooklyn, NY, US | <a href="https://flowercomputer.com/">Flower</a><ul>
<li><a href="https://partiful.com/e/Vq9fyDNCMSO7ia4ulK5b"><strong>BOG-A-THON 2</strong></a></li>
</ul>
</li>
<li>2026-07-30 | Atlanta, GA, US | <a href="https://www.meetup.com/rust-atl/events/">Rust Atlanta</a><ul>
<li><a href="https://www.meetup.com/rust-atl/events/313539329/"><strong>Rust-Atl</strong></a></li>
</ul>
</li>
<li>2026-08-01 | Boston, MA, US | <a href="https://www.meetup.com/bostonrust/events/">Boston Rust Meetup</a><ul>
<li><a href="https://www.meetup.com/bostonrust/events/315582653/"><strong>Chinatown Rust Lunch, Aug 1</strong></a></li>
</ul>
</li>
<li>2026-08-04 | Boston, MA, US | <a href="https://www.meetup.com/bostonrust/events/">Boston Rust Meetup</a><ul>
<li><a href="https://www.meetup.com/bostonrust/events/314660176/"><strong>Evening Boston Rust Meetup at Red Hat, Aug 4</strong></a></li>
</ul>
</li>
<li>2026-08-06 | Saint Louis, MO, US | <a href="https://www.meetup.com/stl-rust/events/">STL Rust</a><ul>
<li><a href="https://www.meetup.com/stl-rust/events/314701905/"><strong>Shipping Temporal: How a Global Rust Ecosystem Built Chrome’s Newest Web API</strong></a></li>
</ul>
</li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#south-america">South America</a></h5>
<ul>
<li>2026-08-08 | São Paulo, SP | <a href="https://luma.com/calendar/cal-bif2oHITU1aVvsr">Rust-SP</a><ul>
<li><a href="https://luma.com/41oiyhtk"><strong>Rust SP - Aug/2026</strong></a></li>
</ul>
</li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#oceania">Oceania</a></h5>
<ul>
<li>2026-07-21 | Barton, AU | <a href="https://www.meetup.com/rust-canberra">Canberra Rust User Group</a><ul>
<li><a href="https://www.meetup.com/rust-canberra/events/315307280/"><strong>July Meetup</strong></a></li>
</ul>
</li>
<li>2026-07-23 | Perth, AU | <a href="https://www.meetup.com/perth-rust-meetup-group">Rust Perth Meetup Group</a><ul>
<li><a href="https://www.meetup.com/perth-rust-meetup-group/events/315451138/"><strong>Rust Perth: July Meetup!</strong></a></li>
</ul>
</li>
<li>2026-07-30 | Melbourne, AU | <a href="https://www.meetup.com/rust-melbourne/events/">Rust Melbourne</a><ul>
<li><a href="https://www.meetup.com/rust-melbourne/events/315039480/"><strong>Rust Melbourne July 2026</strong></a></li>
</ul>
</li>
</ul>
<p>If you are running a Rust event please add it to the <a href="https://www.google.com/calendar/embed?src=apd9vmbc22egenmtu5l6c5jbfc%40group.calendar.google.com">calendar</a> to get
it mentioned here. Please remember to add a link to the event too.
Email the <a href="mailto:community-team@rust-lang.org">Rust Community Team</a> for access.</p>
<h4><a class="toclink" href="https://this-week-in-rust.org/atom.xml#jobs">Jobs</a></h4>
<p>Please see the latest <a href="https://www.reddit.com/r/rust/comments/1ttbtf5/official_rrust_whos_hiring_thread_for_jobseekers/">Who's Hiring thread on r/rust</a></p>
<h3><a class="toclink" href="https://this-week-in-rust.org/atom.xml#quote-of-the-week">Quote of the Week</a></h3>
<blockquote>
<p>Thank you for your PR, but please edit the description like you are a chainsaw-wielding maniac that just discovered the sentences are young adults who came to the lake at summer camp after sunset.</p>
</blockquote>
<p>– <a href="https://github.com/rust-lang/rust/pull/159039#issuecomment-4931084997">workingjubilee on Rust github</a></p>
<p>Thanks to <a href="https://users.rust-lang.org/t/twir-quote-of-the-week/328/1786">Theemathas</a> for the suggestion!</p>
<p><a href="https://users.rust-lang.org/t/twir-quote-of-the-week/328">Please submit quotes and vote for next week!</a></p>
<p>This Week in Rust is edited by:</p>
<ul>
<li><a href="https://github.com/nellshamrell">nellshamrell</a></li>
<li><a href="https://github.com/llogiq">llogiq</a></li>
<li><a href="https://github.com/ericseppanen">ericseppanen</a></li>
<li><a href="https://github.com/extrawurst">extrawurst</a></li>
<li><a href="https://github.com/U007D">U007D</a></li>
<li><a href="https://github.com/mariannegoldin">mariannegoldin</a></li>
<li><a href="https://github.com/bdillo">bdillo</a></li>
<li><a href="https://github.com/opeolluwa">opeolluwa</a></li>
<li><a href="https://github.com/bnchi">bnchi</a></li>
<li><a href="https://github.com/KannanPalani57">KannanPalani57</a></li>
<li><a href="https://github.com/tzilist">tzilist</a></li>
</ul>
<p><em>Email list hosting is sponsored by <a href="https://foundation.rust-lang.org/">The Rust Foundation</a></em></p>
<p><small><a href="https://www.reddit.com/r/rust/comments/1uxsigp/this_week_in_rust_660/">Discuss on r/rust</a></small></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Go-based TypeScript 7.0 arrives]]></title>
<description><![CDATA[Microsoft has released TypeScript 7.0, a native port of the company’s strongly typed version of the JavaScript language based on the Go programming language. 



With this new codebase, TypeScript 7.0 brings native code speed, shared memory multithreading, and a number of new optimizations that t...]]></description>
<link>https://tsecurity.de/de/3671163/ai-nachrichten/go-based-typescript-70-arrives/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3671163/ai-nachrichten/go-based-typescript-70-arrives/</guid>
<pubDate>Wed, 15 Jul 2026 17:19:36 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div><div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Microsoft has released TypeScript 7.0, a native port of the company’s <a href="https://www.infoworld.com/article/2257305/what-is-typescript-strongly-typed-javascript.html" data-type="link" data-id="https://www.infoworld.com/article/2257305/what-is-typescript-strongly-typed-javascript.html">strongly typed version of the JavaScript language</a> based on the <a href="https://www.infoworld.com/article/2253031/whats-the-go-language-really-good-for-3.html">Go programming language</a>. </p>



<p class="wp-block-paragraph">With this new codebase, TypeScript 7.0 brings native code speed, shared memory multithreading, and a number of new optimizations that typically yield speedups between 8x and 12x on full builds, Microsoft said in a <a href="https://devblogs.microsoft.com/typescript/announcing-typescript-7-0/">July 8 announcement</a>. This port of TypeScript to native code was done as faithfully as possible, writing new code while maintaining the structure and logic of the original codebase to keep results consistent and compatible between the two compilers, according to Microsoft. </p>



<p class="wp-block-paragraph">TypeScript 7.0 is available via npm:</p>



<pre class="wp-block-code"><code>npm install -D typescript</code></pre>



<p class="wp-block-paragraph">To help with the TypeScript 6.0 to TypeScript 7.0 transition process, Microsoft has published a new compatibility package, <code>@typescript/typescript6</code>. This package provides an executable named <code>tsc6</code>, so that if needed, a developer can install TypeScript 7.0 (which ships its own <code>tsc</code> binary) side-by-side with TypeScript 6.0 without naming conflicts. The new package also re-exports the TypeScript 6.0 API, so that a developer can use <code>tsc</code> for TypeScript 7, while other tooling can continue to rely on TypeScript 6.0.</p>



<p class="wp-block-paragraph">TypeScript 7.0 is a major milestone in the TypeScript project, Microsoft said. This port has been the primary focus for Microsoft’s team for more than a year. With TypeScript 7.0 now out, the team will return to new feature work, ergonomic improvements, more performance wins, and implementing a new API for the broader ecosystem. Microsoft expects a fairly similar timeline to releases prior to TypeScript 7.0, with new versions published every three to four months. </p>



<p class="wp-block-paragraph">TypeScript 7.0 was announced as a <a href="https://www.infoworld.com/article/4191918/typescript-7-0-reaches-release-candidate-stage.html">release candidate</a> on June 18. </p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[New bugs in Claude for Chrome allow extensions to abuse AI privileges]]></title>
<description><![CDATA[Two vulnerabilities found in Anthropic’s Claude for Chrome extension remain exploitable months after they were reported to the company, a research by Manifold Security noted.



According to the researchers, the flaws can allow a malicious browser extension to trigger Claude into performing privi...]]></description>
<link>https://tsecurity.de/de/3670562/it-security-nachrichten/new-bugs-in-claude-for-chrome-allow-extensions-to-abuse-ai-privileges/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3670562/it-security-nachrichten/new-bugs-in-claude-for-chrome-allow-extensions-to-abuse-ai-privileges/</guid>
<pubDate>Wed, 15 Jul 2026 14:08:04 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Two vulnerabilities found in Anthropic’s Claude for Chrome extension remain exploitable months after they were reported to the company, a research by Manifold Security noted.</p>



<p class="wp-block-paragraph">According to the researchers, the flaws can allow a malicious browser extension to trigger Claude into performing privileged actions, including reading Gmail messages, Google Docs content, and Calendar entries on behalf of a user.</p>



<p class="wp-block-paragraph">In a new blog post, the researchers said the issues are reproducible in Claude for Chrome version 1.0.80, released on July 7, and remain unresolved eight releases after they were first reported in May.</p>



<p class="wp-block-paragraph">“Anthropic shipped v1.0.73 through v1.0.80 in the weeks following our report,” the researchers <a href="https://www.manifold.security/blog/claude-for-chrome-extension-bypass" target="_blank" rel="noreferrer noopener">added</a>. “The internal tracking issue covering this class of vulnerability was marked ‘resolved’ in the weeks following our report.”</p>



<p class="wp-block-paragraph">However, the content script and side-panel handlers in the latest version remain “byte-identical” to v1.0.72 the researchers originally tested. Researchers drew parallels with the earlier <a href="https://www.csoonline.com/article/4168867/claude-in-chrome-is-taking-orders-from-the-wrong-extensions.html">ClaudeBleed</a> disclosure, where the issue was found exploitable despite Anthropic announcing a fix.</p>



<p class="wp-block-paragraph">Anthropic did not immediately respond to CSO’s request for comment.</p>



<h2 class="wp-block-heading">Synthetic clicks trick trusted AI</h2>



<p class="wp-block-paragraph">The first vulnerability stems from how Claude for Chrome handles user interaction before executing privileged actions. According to Manifold, the extension’s click handler does not verify whether an approval click originated from a real user through the browser’s “event.isTrusted” property.</p>



<p class="wp-block-paragraph">Meaning, another browser extension capable of injecting scripts into Claude.ai can generate synthetic clicks that Claude accepts as legitimate.</p>



<p class="wp-block-paragraph">In default configurations, the attack can automatically trigger one of Claude’s predefined browser tasks before presenting an approval dialog. However, if users have enabled the extension’s “Act without asking” mode, Claude may execute those actions silently, allowing an attacker to retrieve Gmail content, Google Docs data, or Calendar information, the researcher noted.</p>



<p class="wp-block-paragraph">Rather than exploiting a flaw in Chrome itself, the attack abuses the trust placed in <a href="https://www.csoonline.com/article/4154201/claude-code-is-still-vulnerable-to-an-attack-anthropic-has-already-fixed-2.html">Claude </a>as an authorized browser agent. Manifold demonstrated an exploit in six lines of JavaScript.</p>



<p class="wp-block-paragraph">The researchers said the flaw can simply be fixed with one added line, “if (!n.isTrusted) return;” at the top of the click handler.</p>



<h2 class="wp-block-heading"><a></a>A problematic privilege mode</h2>



<p class="wp-block-paragraph">The second finding focuses on how Claude’s side panel initializes its permission model.</p>



<p class="wp-block-paragraph">Manifold found that loading the panel with “?skipPermissions=true” parameter makes the extension enter a privileged mode meant to bypass repeated confirmation prompts. While the researchers did not identify a direct external path to control this parameter today, they argued that the design creates a latent security risk because privileged behavior depends on a URL value rather than user-controlled inputs.</p>



<p class="wp-block-paragraph">Any future vulnerability capable of influencing that parameter could inherit elevated privileges without requiring additional security checks, the researchers noted.</p>



<p class="wp-block-paragraph">To address both findings, Manifold recommends validating genuine user interactions before executing privileged actions, avoiding URL-driven privilege transitions, and strengthening the authentication of internal extension workflows.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[How to unionize your tech workplace]]></title>
<description><![CDATA[This is Part 2 of a series on tech worker unionization. See Part 1: “A brewing battle: More IT workers want unions. The industry doesn’t.”



The best time for tech workers to unionize was 20 years ago, when they had plenty of leverage. The second-best time is now, when they don’t.



Mass layoff...]]></description>
<link>https://tsecurity.de/de/3670454/it-nachrichten/how-to-unionize-your-tech-workplace/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3670454/it-nachrichten/how-to-unionize-your-tech-workplace/</guid>
<pubDate>Wed, 15 Jul 2026 13:18:09 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph"><em>This is Part 2 of a series on tech worker unionization. See Part 1: “<a href="https://www.computerworld.com/article/4191760/brewing-battle-more-tech-workers-want-unions-but-the-industry-doesnt.html">A brewing battle: More IT workers want unions. The industry doesn’t</a>.”</em></p>



<p class="wp-block-paragraph">The best time for tech workers to unionize was 20 years ago, when they had plenty of leverage. The second-best time is now, when they don’t.</p>



<p class="wp-block-paragraph">Mass layoffs, AI-driven displacement, corporate surveillance, workplace disillusionment have created conditions that have made organizing compelling for tech professionals. But the federal labor board that has historically protected workers’ right to organize has been weakened, and the companies that once feared it are openly defying it.</p>



<p class="wp-block-paragraph">Here’s how organizers and labor experts describe the pros and cons to organizing — and how you can get started.</p>



<h2 class="wp-block-heading">What unions can — and can’t — do for you</h2>



<p class="wp-block-paragraph">The single biggest benefit of a union contract for most tech workers isn’t pay — it’s protection against arbitrary termination, especially in the wake of recent mass layoffs in tech. In the United States, nonunion “at-will” workers can be fired at any time without a stated reason, while unionized workers negotiate protections written into their contracts.</p>



<p class="wp-block-paragraph">“That fear of the company letting you go for anything at any time…with a union they just can’t do that,” says <a href="https://www.linkedin.com/in/zthompson1/" target="_blank" rel="noreferrer noopener">Zak Thompson</a>, a senior software engineer at Kickstarter and union steward at Kickstarter United. Now that Kickstarter employees are unionized, people are less worried that saying something negative will result in termination.</p>



<p class="wp-block-paragraph">“I’ve been shocked at the willingness of my co-workers to speak up against what they see as poor or controversial business decisions,” Thompson says.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-full is-resized"> width="972" height="972" sizes="auto, (max-width: 972px) 100vw, 972px"&gt;<figcaption class="wp-element-caption"><p>Zak Thompson from Kickstarter United</p><br></figcaption></figure><p class="imageCredit">Fee Christoph</p></div>



<p class="wp-block-paragraph"><strong>Beyond job security, unions can deliver concrete material gains.</strong> <a href="https://kickstarterunited.org/about/" target="_blank" rel="noreferrer noopener">Kickstarter United was formed in 2020</a>, although getting there wasn’t easy: two employees were fired during the organizing campaign — which itself became a galvanizing event. And while the union hasn’t been able to prevent layoffs, it did negotiate better terms: four months of severance pay and four to six months of continued health insurance, versus the two to three weeks per year of work that management had initially proposed.</p>



<p class="wp-block-paragraph">Other benefits include a four-day work week; AI protections; a minimum pay floor; and standards for raises, promotions, and time off for the company’s 59 employees.</p>



<p class="wp-block-paragraph"><strong>Unions can give tech workers a voice in decisions that affect their daily work — including how AI tools are deployed.</strong> “Nobody I’ve spoken to is against new technology or getting trained in it,” says <a href="https://www.linkedin.com/in/mbelasco/" target="_blank" rel="noreferrer noopener">Max Belasco</a>, a business systems analyst at the University of California Los Angeles School of Law and co-chair of the UCLA chapter of the University Professional and Technical Employees/Communications Workers of America (UPTE-CWA) Local 9119.</p>



<p class="wp-block-paragraph">“But when new technology is being implemented, we want to know: what’s the five-year vision, the 10-year vision? Are we implementing this in a way that betters staffing, increases efficiency, or eases the lives of people already working? Or are we trying to take away jobs, automate people out of their pension or paycheck?” Belasco says.</p>



<p class="wp-block-paragraph"><strong>The challenges are real.</strong> Tech professionals are less inclined to leave their jobs in the current market because wages haven’t been increasing as fast as they once were, and it can take longer to land another job.</p>



<p class="wp-block-paragraph">“Tech moved from a very tight labor market in 2022 (1.85% unemployment rate) to a noticeably weaker one in 2024–2026 (3.49%),” although that’s still better than the national unemployment rate of 4.36% through May of this year, says <a href="https://www.mercatus.org/scholars/liya-palagashvili" target="_blank" rel="noreferrer noopener">Liya Palagashvili</a>, senior research fellow and director of the Labor Policy Project at the Mercatus Center at George Mason University.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-full is-resized"> width="960" height="640" sizes="auto, (max-width: 960px) 100vw, 960px"&gt;<figcaption class="wp-element-caption"><p>Liya Palagashvili of the Mercatus Center at George Mason University</p></figcaption></figure><p class="imageCredit">Mercatus Center at George Mason University</p></div>



<p class="wp-block-paragraph"><strong>Flexibility is a concern.</strong> The more substantive challenge, raised by economists including Palagashvili, is that traditional union contracts impose uniform terms across an entire bargaining unit, limiting the flexibility that many tech workers — and their employers —currently enjoy. Tech firms need to move fast, adjusting teams, products, and roles on the fly.</p>



<p class="wp-block-paragraph">“Collective bargaining agreements can make those adjustments much more difficult, whether by making them slower, costlier, or inconsistent with the contract,” she says.</p>



<p class="wp-block-paragraph">Workers skeptical of unions in a <a href="https://www.teamblind.com/blog/why-are-unions-not-common-tech-industry/" target="_blank" rel="noreferrer noopener">survey of 1,900 tech professionals</a> conducted by the career site Blind cited specific concerns: that unions are “not meritocratic,” “prevent innovation,” and “hold back earnings of top performers.”</p>



<p class="wp-block-paragraph">Thompson from Kickstarter United pushes back: “We have nothing in our contract about ‘you can’t bend down and pick up a piece of trash because that’s someone else’s job.’ The company is free to give bonuses and individual raises as much as they like. This is all just up to the people who are bargaining the contract from the union side.”</p>



<p class="wp-block-paragraph"><strong>Organizing carries potentially serious personal risks.</strong> During negotiations for a second three-year contract in 2025, Kickstarter United went on strike for 42 days. A few months later, the company announced layoffs.</p>



<p class="wp-block-paragraph">“They let go strong union leaders, including a person who had bargained our last contract,” Thompson says. The union appealed, and the issue is now going to arbitration.</p>



<p class="wp-block-paragraph">If you form a union, don’t expect much support from the <a href="https://www.nlrb.gov/" target="_blank" rel="noreferrer noopener">National Labor Relations Board</a>, the agency that certifies US labor unions and protects workers’ right to organize, in terms of prosecuting complaints of unfair labor practices, Thompson warns. “We’re in a political moment in this country with a pretty weakened NLRB. You have to be ready to organize and withhold worker power without any guarantee of safety.”</p>



<p class="wp-block-paragraph"><strong>Organizers are up against an enormous union avoidance industry.</strong> Organizers can expect fierce pushback as soon as the business discovers that organizing is underway.</p>



<p class="wp-block-paragraph">“There’s a multi-billion-dollar industry in union avoidance,” says <a href="https://www.linkedin.com/in/alan-mcavinney-a386b8122/" target="_blank" rel="noreferrer noopener">Alan McAvinney</a>, a Google software engineer and organizing chair, Alphabet Workers Union-CWA, a 1,400-member minority union of Alphabet employees. (Google is a subsidiary of Alphabet.)</p>



<p class="wp-block-paragraph">US employers spend roughly $1.7 billion a year on union avoidance consultants and law firms, according to a <a href="https://www.epi.org/press/u-s-employers-spend-roughly-1-7-billion-annually-on-union-avoidance/" target="_blank" rel="noreferrer noopener">May 2026 report</a> by the Economic Policy Institute and LaborLab.</p>



<p class="wp-block-paragraph"><strong>Expect hardball tactics. </strong>Management may play hardball during the time between when organizers announce their intention to unionize and the actual vote. For example, management can threaten to fire foreign-born workers in the US on H-1B visas if they support the union. Those workers would then have just 60 days to find a new sponsoring employer or lose their H-1B status, according to a recent <a href="https://techworkerscoalition.org/blog/2025/03/14/immigrant-rights-are-labor-rights-tech-workers-and-h-1b-visas/" target="_blank" rel="noreferrer noopener">Tech Workers Coalition blog post</a>.</p>



<p class="wp-block-paragraph">And at venture capital-backed startups, investment agreements sometimes require management to attest there is no union activity — meaning a public organizing drive can trigger funding withdrawal. Or, if a unionized company is acquired, the new management can dissolve the union overnight by reclassifying unionized workers as new hires.</p>



<p class="wp-block-paragraph">With these sobering facts in mind, here is how organizers who have done it describe the process of creating a union.</p>



<h2 class="wp-block-heading">Step 1: Start a conversation with your co-workers</h2>



<p class="wp-block-paragraph">At the University of California, a two-tier system had evolved where some tech workers were unionized and some weren’t, Belasco says. Management created new titles that fell outside the union even though they had similar job descriptions and responsibilities to those in the union. Those nonunion employees received lower pay and benefits than their unionized peers, which created resentment and instability.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large is-resized"> width="1024" height="683" sizes="auto, (max-width: 1024px) 100vw, 1024px"&gt;<figcaption class="wp-element-caption"><p>Max Belasco from the UCLA chapter of UPTE-CWA</p>
</figcaption></figure><p class="imageCredit">Zac Goldstein</p></div>



<p class="wp-block-paragraph">Belasco and other organizers wanted to eliminate that division by bringing everyone under the same contract. But when they began their unionization drive, “the biggest barrier we faced wasn’t management opposition — it was that people felt this was just the best-case scenario realistically available: ‘We have this job at the university, we have concerns about automation and layoffs, but what can we really do about it?'” he says.</p>



<p class="wp-block-paragraph">The antidote to that fatalism, organizers say, is simple: “Just start talking to your immediate co-workers. Are they experiencing the same challenges you are experiencing?” says McAvinney. “There’s no need to start talking about a union at this point.”</p>



<p class="wp-block-paragraph">Just get a consensus and start building a group of like-minded individuals, Thompson advises. “Always start with one-on-one conversations, and that’s what you should do the whole time. That’s the key to organizing,” he says.</p>



<p class="wp-block-paragraph">Tech workers often think they’re a special case, says Thompson, and therefore that unionization isn’t a good fit. “You’re not special. You are a company of workers, you are organizing, and there is a playbook for that. Trust the process, because it tends to work pretty well,” he says.</p>



<h2 class="wp-block-heading">Step 2: Who’s on board, and who’s not? Map your workplace, but keep it quiet</h2>



<p class="wp-block-paragraph">Once there’s a consensus, continue to grow your network. Keep a list of everyone you’ve spoken with and note their disposition: “Is this person union-friendly or anti-union? Would they be a strong organizer?” Thompson says.</p>



<p class="wp-block-paragraph">Maintaining secrecy early on is essential, because anti-union tactics will start immediately, and that can stop union organizing before it can gain momentum.</p>



<p class="wp-block-paragraph">“Generally, employers do not want to share power with their workforce,” McAvinney says. Employers will deploy every means at their disposal to stop organizing efforts and peel away potential yes votes.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large is-resized"> width="1024" height="839" sizes="auto, (max-width: 1024px) 100vw, 1024px"&gt;<figcaption class="wp-element-caption"><p>Alan McAvinney from Alphabet Workers Union-CWA</p><br></figcaption></figure><p class="imageCredit">Aran Per Ink</p></div>



<p class="wp-block-paragraph">“If you look at historical examples, having 70% approval before the employer finds out about you results in a high percentage of wins when you actually cast the vote. Historically, that’s an effective buffer,” he says.</p>



<p class="wp-block-paragraph">There’s a real threat of firing and layoffs<em>.</em> The traditional tech worker belief that job mobility makes collective action unnecessary is now being tested by a tighter job market, McAvinney says, noting that workers who many believe <a href="https://www.newsweek.com/google-fires-thanksgiving-four-workers-crush-dissent-1474102" target="_blank" rel="noreferrer noopener">were fired for speaking out</a> back in 2019 were a galvanizing factor in his union’s formation.</p>



<p class="wp-block-paragraph">“You generally don’t want to be in a situation where the employer feels comfortable firing everyone. Part of that is thinking from a cynical standpoint about what the consequences would be to the employer if they did fire everyone,” he says.</p>



<p class="wp-block-paragraph">One-on-one conversations that include personally asking co-workers to keep conversations confidential are key to keeping things quiet, Belasco says. When <a href="https://upte.org/news/2100-tech-workers-vote-to-join-upte" target="_blank" rel="noreferrer noopener">2,100 UC tech workers voted to unionize</a> in May, 96% voted in favor. To stay out of earshot of managers, avoid employee surveillance tools, and sidestep conference calls that could be recorded, organizers met with workers in their homes.</p>



<p class="wp-block-paragraph">“That tactic is probably what made the difference between winning the election and getting the majority we got,” he says.</p>



<h2 class="wp-block-heading">Step 3: Find the right union affiliation or go it alone</h2>



<p class="wp-block-paragraph">“Running a campaign against major employers requires the resources and expertise of the larger labor movement, even if workers publicly present as independent,” says <a href="https://www.ilr.cornell.edu/people/kate-l-bronfenbrenner">Kate Bronfenbrenner</a>, director of labor education research and senior lecturer emeritus at Cornell University’s School of Industrial and Labor Relations.</p>



<p class="wp-block-paragraph">Options include the <a href="https://cwa-union.org/" target="_blank" rel="noreferrer noopener">Communications Workers of America</a> (CWA), <a href="https://www.seiu.org/" target="_blank" rel="noreferrer noopener">Service Employees International Union</a> (SEIU), and the <a href="https://www.opeiu.org/" target="_blank" rel="noreferrer noopener">Office and Professional Employees International Union</a> (OPEIU), among others. Another resource, the <a href="https://techworkerscoalition.org/">Tech Workers Coalition</a> (TWC), provides training on organizing tactics, AI-in-workplace issues, and contract negotiation, and can match workers to the right unions for their needs.</p>



<p class="wp-block-paragraph">The <a href="https://www.alphabetworkersunion.org/" target="_blank" rel="noreferrer noopener">Alphabet Workers Union</a> decided early on to affiliate with CWA. “They gave us a bunch of support early on in our campaign with no strings attached,” McAvinney says.</p>



<p class="wp-block-paragraph">Kickstarter is organized through OPEIU, Thompson says. “They’ll usually have resources and staff that can help you through the next steps: collecting signatures in support of a union, bringing that to management, holding a vote — the more formalized things that interact with US labor law. They’ll also help with organizing along the way,” he says.</p>



<p class="wp-block-paragraph">For workers at institutions where a union already exists, there may be a faster path. Organizers at UCLA did what’s called a “unit modification,” aligning with UPTE. By organizing under UPTE, the workers didn’t have to negotiate a new contract from scratch — they joined an already-negotiated contract covering existing UPTE tech members, which put them in “a much stronger position” than starting fresh, Belasco says.</p>



<h2 class="wp-block-heading">Step 4: Choose your union model: majority vs. pre-majority or minority</h2>



<p class="wp-block-paragraph">Assess what’s practical for your organizing effort. In a majority union, more than 50% of all workers in a defined bargaining unit must vote to join the union through an NLRB-supervised election in the private sector, or a Public Employment Relations Board (PERB)-supervised election for public sector workers.</p>



<p class="wp-block-paragraph">The NLRB must certify the union, which then operates under its legal protections. This means, for example, that the employer must bargain, negotiated contracts are enforceable, violations must go to the NLRB or arbitration, and workers can’t be dismissed without just cause.</p>



<p class="wp-block-paragraph">A pre-majority or minority union is a minority labor organization operating without NLRB protections or collective bargaining agreements. “Pre-majority means that workers are able to demonstrate majority support — through signed cards, petitions, a walkout, or everyone wearing solidarity T-shirts — without going through a formal election,” Bronfenbrenner says.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large is-resized"> width="1024" height="683" sizes="auto, (max-width: 1024px) 100vw, 1024px"&gt;<figcaption class="wp-element-caption"><p>Kate Bronfenbrenner from the School of Industrial and Labor Relations, Cornell University</p><br></figcaption></figure><p class="imageCredit">ILR School/Cornell University</p></div>



<p class="wp-block-paragraph">The Alphabet Workers Union-CWA (AWU-CWA) formed as a pre-majority union because achieving majority status across a globally distributed workforce of over 100,000 was not a realistic near-term goal. “An underground model where you try to reach 70% support across a workforce of over 100,000 people isn’t realistic,” McAvinney says.</p>



<p class="wp-block-paragraph">A pre-majority union can still make a difference, he says. For example, the Alphabet Workers Union-CWA convinced management to offer voluntary exit packages — buyouts — prior to announcing layoffs.</p>



<p class="wp-block-paragraph">For smaller organizations, a majority union may be the more practical option — it’s more attainable, McAvinney says. “I don’t think [the pre-majority union model] is the correct thing to do in all situations. I certainly would not recommend it to a 200-person shop.”</p>



<p class="wp-block-paragraph">Kickstarter, which had fewer than 100 employees, was able to form a majority union, with 55% voting to organize.</p>



<p class="wp-block-paragraph">Ultimately, says McAvinney, “there’s no inflection point where you go from being able to win nothing to winning everything, even with a contract and a supermajority. But the more people you have who are willing and able to fight for what they want, the more you’ll be able to get.”</p>



<h2 class="wp-block-heading">Step 5: Who should — and should not — be in your union?</h2>



<p class="wp-block-paragraph">Belasco’s situation at UCLA illustrates a broader strategic choice that every organizing campaign must make. He had been in a union position in educational technology when he was told his role would be reclassified as a non-union position.</p>



<p class="wp-block-paragraph">“I was given a choice: apply to the new non-union position to continue doing the work I’d trained for, or stay in my union position doing service desk work I wasn’t used to,” he says. “Essentially, it was a choice between job security and career progression.”</p>



<p class="wp-block-paragraph">Belasco joined a “wall-to-wall” union, which represents a broad range of university professional and technical employees across the UC system rather than a single job category, such as engineers or tech professionals.</p>



<p class="wp-block-paragraph">Kickstarter United is another example of a wall-to-wall union. “It’s not just the engineers who are unionized, but also customer support, designers — everyone,” Thompson says.</p>



<p class="wp-block-paragraph">Wall-to-wall unions are more powerful, but they’re also more difficult to achieve. <a href="https://www.law.cornell.edu/uscode/text/29/159" target="_blank" rel="noreferrer noopener">Under US labor law</a>, “professionals have to vote separately on whether they want to be combined with other workers,” says Bronfenbrenner. “You can never have a wall-to-wall unit without giving professionals the chance to decide whether they want to be separate.”</p>



<p class="wp-block-paragraph">The law’s “professional employees” category includes roles like software engineers and developers but not necessarily others. For example, customer support specialists and QA analysts would fall into the “non-professional workers” category.</p>



<p class="wp-block-paragraph">“For decades, the pattern was either to organize everybody except the engineers, or manage to organize the engineers and fail to bring in everybody else — neither of which builds real worker power,” says <a href="https://www.linkedin.com/in/simonerobutti/" target="_blank" rel="noreferrer noopener">Simone Robutti</a>, an organizer with Tech Workers Coalition Global, an international branch of TWC based in Berlin.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-full is-resized"> width="959" height="713" sizes="auto, (max-width: 959px) 100vw, 959px"&gt;<figcaption class="wp-element-caption"><p>Simone Robutti from Tech Workers Coalition Global</p><br></figcaption></figure><p class="imageCredit">TWC</p></div>



<h2 class="wp-block-heading">Step 6: You won the vote. Get ready for what comes next</h2>



<p class="wp-block-paragraph">Winning a union vote means having a seat at the table, says Thompson. “Once the workers have come together and agreed they want that seat, you bring that to management, and they have a chance to voluntarily recognize a union,” he says.</p>



<p class="wp-block-paragraph">But in most cases employers contest the results, which must be certified by the NLRB or PERB. That process, in which the employer uses various tactics to challenge the legitimacy of the outcome, can take weeks or months.</p>



<p class="wp-block-paragraph">Unfortunately, the legal framework that is supposed to protect workers during this process has been <a href="https://workerorganizing.org/elon-musk-spacex-nlrb-15975/#:~:text=CAN%20THE%20NLRB%20STILL%20ENFORCE%20LAWS%3F" target="_blank" rel="noreferrer noopener">significantly weakened</a> in the last few years. In a potentially more ominous development, <a href="https://apnews.com/article/amazon-nlrb-unconstitutional-spacex-elon-musk-ab42977117d883e97110a7bf8e8b257f" target="_blank" rel="noreferrer noopener">SpaceX</a>, <a href="https://apnews.com/article/amazon-nlrb-50ee06d87d4eaef22386382761335ef8" target="_blank" rel="noreferrer noopener">Amazon</a>, <a href="https://www.huffpost.com/entry/trader-joes-attorney-nlrb-unconstitutional_n_65b41e7ae4b014b873b11cc2" target="_blank" rel="noreferrer noopener">Trader Joe’s</a>, <a href="https://news.bloomberglaw.com/daily-labor-report/starbucks-is-latest-company-to-call-labor-board-unconstitutional" target="_blank" rel="noreferrer noopener">Starbucks</a>, and the <a href="https://capitalandmain.com/usc-follows-amazon-and-musks-spacex-in-calling-labor-board-unconstitutional" target="_blank" rel="noreferrer noopener">University of Southern California</a> have in separate legal actions <a href="https://www.epi.org/blog/whats-behind-the-corporate-effort-to-kneecap-the-national-labor-relations-board-spacex-amazon-trader-joes-and-starbucks-are-trying-to-have-the-nlrb-declared-unconstitutional/" target="_blank" rel="noreferrer noopener">challenged the constitutionality of the NLRB</a>, arguing that the agency’s structure violates the separation of powers. The Fifth Circuit Court of Appeals <a href="https://law.justia.com/cases/federal/appellate-courts/ca5/24-50627/24-50627-2025-08-19.html?__cf_chl_f_tk=do9nl63o6rfY2sxOjPeR5MkVGY4u1OTRYOVYjTQTOG0-1782836265-1.0.1.1-IXqkGFSiOH5hYYOqqrEqH6VFIApNL3MRHW6YNiDwERI" target="_blank" rel="noreferrer noopener">upheld injunctions against the NLRB</a> in SpaceX’s case in August 2025 — a serious challenge to the agency’s authority.</p>



<p class="wp-block-paragraph">In the meantime, some companies may disregard negotiated contracts, which can lead to lengthy legal appeals or extended arbitration.</p>



<p class="wp-block-paragraph">“The NLRB can still force an election, but it can’t force a contract, and companies are saying they simply won’t comply,” Bronfenbrenner says. This is where the expertise and resources of affiliation with a major union can help, she adds.</p>



<p class="wp-block-paragraph">As a result, contract negotiations can take far longer than workers might expect. At Kickstarter, for example, two years and four months elapsed from the time of the union vote to the first contract, and that was at a 59-person company with a relatively cooperative employer. At larger companies with more aggressive legal teams, the timeline will be longer.</p>



<p class="wp-block-paragraph">Forming a union is hard work, Robutti says. “It’s not a service you pay for and they protect you. It doesn’t happen spontaneously, and it doesn’t happen magically. It’s the choice to take responsibility for improving your workplace.”</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Apple wins major iCloud lawsuit after judge dismisses $32.8 billion CSAM case]]></title>
<description><![CDATA[Apple has won a proposed class action lawsuit that accused the company of failing to stop child sexual abuse material from being stored and shared through iCloud after a US federal judge ruled that the claims fall under legal protections provided by Section 230 of the Communications Decency Act. ...]]></description>
<link>https://tsecurity.de/de/3669876/ios-mac-os/apple-wins-major-icloud-lawsuit-after-judge-dismisses-328-billion-csam-case/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3669876/ios-mac-os/apple-wins-major-icloud-lawsuit-after-judge-dismisses-328-billion-csam-case/</guid>
<pubDate>Wed, 15 Jul 2026 09:23:56 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Apple has won a proposed class action lawsuit that accused the company of failing to stop child sexual abuse material from being stored and shared through iCloud after a US federal judge ruled that the claims fall under legal protections provided by Section 230 of the Communications Decency Act. 



The decision ends the current case with prejudice, which means the same lawsuit cannot be filed again, although the plaintiffs are considering an appeal.



According to Reuters, US District Judge Noël Wise ruled that Apple cannot be held legally responsible for content created and shared by users on its platform. The lawsuit claimed Apple failed to take action to prevent images of childhood sexual abuse from continuing to circulate through iCloud, but the court concluded that federal law broadly shields online services from this type of claim.



Judge says Congress must address the issue



The lawsuit was filed in 2024 by two survivors identified as Amy and Jessica, who argued that Apple knew child sexual abuse material continued to appear on iCloud but chose not to use available detection tools. They also criticized Apple's decision to abandon its planned NeuralHash system after announcing it in 2021. Court filings estimated the proposed class included about 2,680 people and sought compensatory damages of up to $32.8 billion, along with changes to Apple's iCloud policies.



Judge Noël Wise wrote:




"Nothing in federal law requires Apple to proactively utilize available technology or develop new technology to identify and report child sexual abuse material on its cloud platform. Lawmakers can fix this problem that is contributing to the exploitation of children. This Court cannot."




Reuters reported that Apple argued it adopted different methods instead of NeuralHash because it wanted to reduce risks to user privacy and security. The company has also maintained that it continues working to combat the spread of child sexual abuse material across its products and services.



James Marsh, the attorney representing the plaintiffs, said the legal team is reviewing its options after the dismissal.




"While the plaintiffs disagree with the judge's conclusion on the law, we agree with her conclusion that Congress should do more to protect children online and address the skyrocketing harms from online exploitation."




Although this case has ended, Apple still faces a separate lawsuit filed by West Virginia's attorney general over similar allegations involving child sexual abuse material on iCloud.]]></content:encoded>
</item>
<item>
<title><![CDATA[Announcing atrium v0.4.0 - a multiseat display manager]]></title>
<description><![CDATA[atrium is a lightweight Linux display manager with first-class multiseat support, targeting modern systemd + Wayland environments. GitHub AUR What is multiseat? A multiseat setup allows multiple users to work on a single computer at the same time. By connecting multiple monitors, keyboards, and m...]]></description>
<link>https://tsecurity.de/de/3669402/linux-tipps/announcing-atrium-v040-a-multiseat-display-manager/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3669402/linux-tipps/announcing-atrium-v040-a-multiseat-display-manager/</guid>
<pubDate>Wed, 15 Jul 2026 04:08:46 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p><strong>atrium</strong> is a lightweight Linux display manager with first-class multiseat support, targeting modern systemd + Wayland environments.</p> <p><a href="https://github.com/kavau/atrium">GitHub</a><br> <a href="https://aur.archlinux.org/packages/atrium">AUR</a></p> <p><strong>What is multiseat?</strong></p> <p>A multiseat setup allows multiple users to work on a single computer at the same time. By connecting multiple monitors, keyboards, and mice, each user gets their own separate desktop and a fully isolated user session. Great for co-working or multiplayer gaming. Each seat requires its own GPU (integrated graphics, a discrete card, or a USB graphics adapter).</p> <p><strong>Why atrium?</strong></p> <p>The Linux kernel and low-level system stack are fully capable of multiseat operation. The weak link has always been the display manager. Existing ones usually treat multiseat as an afterthought, with implementations that are brittle and difficult to get working reliably.</p> <p><strong>atrium</strong> is designed around multiseat from the start, focusing on correct seat discovery, VT handling, and isolated session management. The project targets a modern Linux stack using systemd/logind, PAM, and a Wayland graphical environment. The lack of historical baggage keeps atrium's code base lean and tractable.</p> <p><strong>What's new in v0.4?</strong></p> <ul> <li><strong>Support for greeter background images</strong> - configure a background image in the settings, or a directory to pick a random image on each greeter launch.</li> <li><strong>Greeter themes</strong> - override built-in colors and styles via a theme `.css` file. A handful of themes are shipped with atrium.</li> <li><strong>Architectural redesign</strong> - making atrium's core architecture simpler and more robust (changes are purely internal and should not be visible to the user).</li> </ul> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/kavaunix"> /u/kavaunix </a> <br> <span><a href="https://www.reddit.com/r/linux/comments/1uwltsf/announcing_atrium_v040_a_multiseat_display_manager/">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/1uwltsf/announcing_atrium_v040_a_multiseat_display_manager/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[The Google Images homepage will recommend photos even before you search]]></title>
<description><![CDATA[Google is announcing a big change to the Google Images homepage in honor of the platform's 25th anniversary this week. Instead of a mostly blank page with a search bar, the homepage will soon show you a bunch of images that it thinks you might like before you even start searching. The company say...]]></description>
<link>https://tsecurity.de/de/3668544/it-nachrichten/the-google-images-homepage-will-recommend-photos-even-before-you-search/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3668544/it-nachrichten/the-google-images-homepage-will-recommend-photos-even-before-you-search/</guid>
<pubDate>Tue, 14 Jul 2026 18:05:18 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Google is announcing a big change to the Google Images homepage in honor of the platform's 25th anniversary this week. Instead of a mostly blank page with a search bar, the homepage will soon show you a bunch of images that it thinks you might like before you even start searching. The company says the […]]]></content:encoded>
</item>
<item>
<title><![CDATA[SUSE Multi-Linux Manager 5.2 Announcement: Enabling Operational Sovereignty Across Mixed Linux Estates]]></title>
<description><![CDATA[Enterprises increasingly run large, mixed Linux estates spanning data centers, public clouds, edge locations, branches, and specialized workloads. To help organizations govern that reality from a single control plane, SUSE is announcing the global availability of SUSE Multi-Linux Manager 5.2 and ...]]></description>
<link>https://tsecurity.de/de/3668176/unix-server/suse-multi-linux-manager-52-announcement-enabling-operational-sovereignty-across-mixed-linux-estates/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3668176/unix-server/suse-multi-linux-manager-52-announcement-enabling-operational-sovereignty-across-mixed-linux-estates/</guid>
<pubDate>Tue, 14 Jul 2026 16:01:01 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Enterprises increasingly run large, mixed Linux estates spanning data centers, public clouds, edge locations, branches, and specialized workloads. To help organizations govern that reality from a single control plane, SUSE is announcing the global availability of SUSE Multi-Linux Manager 5.2 and SUSE Multi-Linux Manager for Retail 5.2. This milestone release provides a practical entry point for […]</p>
<p>The post <a href="https://www.suse.com/c/suse-multi-linux-manager-5-2-linux-fleet-management/">SUSE Multi-Linux Manager 5.2 Announcement: Enabling Operational Sovereignty Across Mixed Linux Estates</a> appeared first on <a href="https://www.suse.com/c">SUSE Communities</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Anthony Albanese promises fast-track approvals for datacentres to shore up AI investment]]></title>
<description><![CDATA[PM to declare Australia the first country worldwide to bring economic, social, security and environmental issues from AI under single office in major speechGet our breaking news email, free app or daily news podcastAnthony Albanese says the federal government will introduce faster approval proces...]]></description>
<link>https://tsecurity.de/de/3667943/ai-nachrichten/anthony-albanese-promises-fast-track-approvals-for-datacentres-to-shore-up-ai-investment/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3667943/ai-nachrichten/anthony-albanese-promises-fast-track-approvals-for-datacentres-to-shore-up-ai-investment/</guid>
<pubDate>Tue, 14 Jul 2026 14:37:17 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>PM to declare Australia the first country worldwide to bring economic, social, security and environmental issues from AI under single office in major speech</p><ul><li><p>Get our <a href="https://www.theguardian.com/email-newsletters?CMP=cvau_sfl">breaking news email</a>, <a href="https://app.adjust.com/w4u7jx3">free app</a> or <a href="https://www.theguardian.com/australia-news/series/full-story?CMP=cvau_sfl">daily news podcast</a></p></li></ul><p>Anthony Albanese says the federal government will introduce faster approval processes for AI projects, including datacentres, across Australia, seeking to shore up investor certainty and maintain community confidence in the <a href="https://www.theguardian.com/australia-news/2026/jul/14/anthony-albanese-ai-speech-safety-copyright-datacentres-social-licence">rapidly advancing technology</a>.</p><p>Announcing the creation of a new office of AI to be established within his department in a major speech on Wednesday, the prime minister will declare Australia is set to become the first country in the world to bring the economic, social, national security and environmental issues stemming from AI into a single, national framework.</p> <a href="https://www.theguardian.com/technology/2026/jul/14/anthony-albanese-promises-fast-track-approvals-for-datacentres-to-shore-up-ai-investment">Continue reading...</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[How AI agents are shaping the future of work]]></title>
<description><![CDATA[I attended several major technology conferences in 2025 where the first AI agents embedded in enterprise SaaS platforms were announced. Some of these agents showed promise and a glimpse into the future of work, while others looked like natural language extensions of a platform’s existing function...]]></description>
<link>https://tsecurity.de/de/3667534/it-security-nachrichten/how-ai-agents-are-shaping-the-future-of-work/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3667534/it-security-nachrichten/how-ai-agents-are-shaping-the-future-of-work/</guid>
<pubDate>Tue, 14 Jul 2026 12:07:53 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">I attended several major technology conferences in 2025 where the first AI agents embedded in enterprise SaaS platforms were announced. Some of these agents showed promise and a glimpse into the future of work, while others looked like natural language extensions of a platform’s existing functionality.  </p>



<p class="wp-block-paragraph">At the end of 2025, Anthropic and OpenAI launched new AI models and code-generating capabilities. More developers tried <a href="https://www.infoworld.com/article/4058076/vibe-coding-and-the-future-of-software-development.html">vibe coding</a>, and some platforms launched <a href="https://www.infoworld.com/article/4166817/vibe-coding-or-spec-driven-development.html">spec-driven development capabilities</a>. By February 2026, even The New York Times reported that <a href="https://www.nytimes.com/2026/02/18/opinion/ai-software.html">the AI disruption had arrived</a>, noting that code generators were building “apps that may be flawed, but credible.”</p>



<p class="wp-block-paragraph">Wall Street investors took notice of the code-generation improvements and other disruptive factors, driving a selloff in SaaS stocks, now referred to as the “<a href="https://www.bloomberg.com/news/articles/2026-02-03/-get-me-out-traders-dump-software-stocks-as-ai-fears-take-hold">SaaSpocalypse</a>.” Part of their concern stemmed from the belief that CIOs would use AI to <a href="https://www.cio.com/article/4148303/cios-rethink-softwares-future-as-ai-agents-advance.html">write software that would replace SaaS solutions</a>.</p>



<h2 class="wp-block-heading">AI innovations from SaaS and solution providers</h2>



<p class="wp-block-paragraph">But I thought differently and wrote a response in my article asking whether <a href="https://www.cio.com/article/4146669/is-ai-the-end-of-saas-as-we-know-it.html">AI is the end of SaaS as we know it</a>. CIOs might use AI to accelerate application modernization, but I doubt they would replace their ERP, CRM, and even smaller SaaS point solutions by building them.</p>



<p class="wp-block-paragraph">Instead, I believed it would be SaaS companies that would take the most advantage of AI code-generation capabilities.</p>



<p class="wp-block-paragraph">This hypothesis drove me to attend nine conferences this spring to see how SaaS companies were launching AI agents and defining a new future of work. I wrote eight articles on <a href="https://drive.starcio.com/cios-need-to-know">what CIOs need to know</a> about data management, agile organizations, marketing, ERPs, critical process management, and other evolutions to plan for in the AI era.</p>



<p class="wp-block-paragraph">Now, looking across all nine conferences, I can draw some conclusions about how AI agents are shaping the future of work. Here are my learnings and what CIOs need to consider when evaluating and deploying AI agents in the workplace.</p>



<h2 class="wp-block-heading">Agentic, human-in-the-middle, or augmenting human?</h2>



<p class="wp-block-paragraph">SaaS companies have very distinct perspectives on the future of work, including the extent to which humans will play which roles and whether and how quickly we’ll see agentic, fully automated work.</p>



<p class="wp-block-paragraph">For example, Atlassian proclaimed, “<a href="https://www.atlassian.com/company/events">step into the future of human-AI collaboration</a>,” while SAP unveiled “<a href="https://news.sap.com/2026/05/sap-sapphire-sap-unveils-autonomous-enterprise/">the autonomous enterprise</a>.” Snowflake aimed to “<a href="https://www.snowflake.com/en/summit/">make AI real for business</a>,” while Appian targeted “<a href="https://www.appianworld.com/">serious AI built on process</a>.”</p>



<p class="wp-block-paragraph">These vendors’ marketers had to decide whether to lead with AI, people, or business in their messaging, but so must CIOs as they contemplate their AI strategies and how to get employees to fully adopt AI agents.</p>



<p class="wp-block-paragraph">Some CIOs see a fully automated agentic AI as the future, with human-in-the-middle as a transitional phase as departments build trust in AI agents’ decision-making and automation capabilities.</p>



<p class="wp-block-paragraph">Other CIOs see AI more as a tool that delivers productivity improvements by augmenting human decision-making capabilities. Many of these CIOs see human augmentation as essential to supporting critical thinking, innovation, and creativity.</p>



<p class="wp-block-paragraph"><a href="https://www.deloitte.com/us/en/what-we-do/capabilities/applied-artificial-intelligence/content/state-of-ai-in-the-enterprise.html">Deloitte’s State of AI Report</a>, published in January, provides a benchmark. It states that 36% of IT leaders expect at least 10% of their jobs to be fully automated in the next year, and 82% expect to reach that benchmark in three years.</p>



<p class="wp-block-paragraph">Many organizations will have a mix of AI agents, choosing automation where reliability at scale is possible, but opting for human augmentation in operationally critical or customer-facing domains. But how CIOs position AI agents is not only an operational strategy; it’s also a cultural statement that shapes employees’ embrace of AI and whether <a href="https://drive.starcio.com/2026/03/ai-leadership-job-at-risk-or-career-opportunity/">detractors vocalize job-loss fears</a>.</p>



<p class="wp-block-paragraph">In the short term, it will also weigh in on which AI agents to use from different partners and which areas to build in-house.</p>



<h2 class="wp-block-heading">Many options to test and deploy AI agents</h2>



<p class="wp-block-paragraph">Many solution providers are demonstrating significantly more AI agents this year. For example, SAP went from <a href="https://drive.starcio.com/2026/05/autonomous-enterprise-ai-cios/">40 Joule Agents in 2025 to over 200 in 2026.</a> Three technology capabilities are fueling this significant growth:</p>



<ul class="wp-block-list">
<li>Adobe, Appian, Boomi, Cisco, Domo, Salesforce, SAP, Snowflake, and others offer <a href="https://www.infoworld.com/article/3497094/does-your-organization-need-a-data-fabric.html">data fabrics</a> and <a href="https://www.infoworld.com/article/3487711/the-definitive-guide-to-data-pipelines.html">data-pipeline</a> capabilities to connect data sources outside the primary workflows supported by their platforms. Appian, Pega, Quickbase, and SAP also centralize business process automation, an important starting point for developing AI agents.  </li>



<li><a href="https://www.infoworld.com/article/4124612/5-requirements-for-using-mcp-servers-to-connect-ai-agents.html">MCP servers</a> enable integration and communication between AI agents and are used to facilitate multistep agentic workflows. Virtually all the companies announcing major investments in AI agents are also announcing MCP integration capabilities and related partnerships.</li>



<li>Solution providers are not just using AI code-generating capabilities; many are launching their own AI agent development tools. The first beneficiaries of these development tools are the solution providers themselves and their integration partners, who use them to accelerate the development of AI agents and make them available to customers.</li>
</ul>



<p class="wp-block-paragraph">The result is that <a href="https://drive.starcio.com/2025/10/ai-agents-definitive-guide-saas-security-titans/">CIOs will have many options about which agents to test</a>, but will have to dedicate analysts to understand the capability, cost, and compliance trade-offs. Additionally, expect AI agent capabilities to evolve significantly over the next few years, so CIOs should continuously revisit their decisions regarding deployed AI agents, focusing on performance, benefits, and ROI.</p>



<p class="wp-block-paragraph">CIOs should also watch for signs of <a href="https://www.cio.com/article/1247890/7-steps-for-turning-shadow-it-into-a-competitive-edge.html">shadow AI</a> and employee confusion about which AI agents to experiment with on different platforms. The AI strategy should include a transparent, defined process for selecting, reviewing, evaluating, procuring, deploying, driving adoption, monitoring, and collecting end-user feedback around AI agents.</p>



<h2 class="wp-block-heading">AI development capabilities for engineers and citizen builders</h2>



<p class="wp-block-paragraph">The apparent ease-of-use of AI code generators may lead some engineering teams to <a href="https://www.cio.com/article/4097339/your-next-big-ai-decision-isnt-build-vs-buy-its-how-to-combine-the-two.html">build AI agents rather than buy them</a> from SaaS providers. But CIOs should quickly realize that coding is just one step in developing AI agents, and that aggressively pursuing a build strategy can lead to <a href="https://www.cio.com/article/4178324/7-sources-of-ai-debt-and-how-to-avoid-them.html">AI debt</a> and <a href="https://www.cio.com/article/4107377/cios-will-underestimate-ai-infrastructure-costs-by-30.html">increased AI costs</a>.</p>



<p class="wp-block-paragraph">DevOps teams can code AI agents using tools such as Claude, Codex, Lovable, and Replit — a do-it-yourself approach. Some SaaS companies are providing an alternative, with AI agent development tools that leverage the data, infrastructure, and governance baked into their platforms. Many of these development tools offer flexibility, allowing developer teams to select AI models and development environments.</p>



<p class="wp-block-paragraph">Examples of new and enhanced AI development tools I saw at conferences this quarter include:</p>



<ul class="wp-block-list">
<li><a href="https://appian.com/blog/2025/appian-25-4-release-enterprise-ai-agents">Appian Composer and Agent Studio</a></li>



<li><a href="https://www.atlassian.com/software/rovo-dev">Atlassian Rovo Dev</a></li>



<li><a href="https://boomi.com/platform/companion/">Boomi Companion</a></li>



<li><a href="https://www.cisco.com/site/us/en/solutions/artificial-intelligence/agentic-ops/cloud-control-studio/index.html">Cisco Cloud Control Studio</a></li>



<li><a href="https://www.domo.com/app-catalyst">Domo App Catalyst</a></li>



<li><a href="https://www.pega.com/about/news/press-releases/pega-harnesses-best-practices-and-ai-coding-agents-build-apps-mission">Pega Infinity Studio</a></li>



<li><a href="https://www.quickbase.com/pave">Quickbase Pave</a></li>



<li><a href="https://www.snowflake.com/en/product/snowflake-coco/">Snowflake CoCo</a></li>



<li><a href="https://www.sap.com/products/artificial-intelligence/joule-studio.html">SAP Joule Studio</a>.</li>
</ul>



<p class="wp-block-paragraph">I also reviewed <a href="https://www.nutanix.com/solutions/ai">Nutanix Agentic AI</a>, a platform-as-a-service for accelerating the deployment of agentic AI workloads, and <a href="https://www.adobe.com/products/firefly/features/ai-assistant.html">Adobe Firefly AI Assistant</a> for creatives.</p>



<p class="wp-block-paragraph">These development tools can target different audiences. Some look like low-code development tools targeted at software developers, whereas others are <a href="https://drive.starcio.com/2026/05/low-code-in-the-ai-era-cios-need-to-know/">no-code and enable citizen developers</a>, i.e., businesspeople, to <a href="https://www.cio.com/article/4176062/cios-are-enlisting-business-users-to-vibe-code-their-own-apps.html">develop applications and agents</a>. Additionally, some of these tools support spec-driven development and generate artifacts such as product requirement documents (PRDs), data models, and testing capabilities.</p>



<p class="wp-block-paragraph">Before commissioning AI development for apps and agents, CIOs should sponsor proofs of technical, data, modeling, security, and governance capabilities.</p>



<h2 class="wp-block-heading">The context layer powering AI agents</h2>



<p class="wp-block-paragraph">Between AI agents and the enterprise’s intelligence, including structured data sources, defined business processes, and agent interactions (both human-to-agent and agent-to-agent), lies an evolving “context layer.”</p>



<p class="wp-block-paragraph">This layer refers to the enterprise knowledge that AI agents draw on when evaluating signals and recommending or taking actions. Context may include a knowledge graph, a semantic layer, cleansed document repositories, and other knowledge bases.</p>



<p class="wp-block-paragraph">The context layer, skills, tools, out-of-the-box agents, and governance capabilities are some areas to review where solution providers differentiate. Some examples: </p>



<ul class="wp-block-list">
<li>Many support the <a href="https://open-semantic-interchange.org/">Open Semantic Interchange</a>, and some brand their context layers, such as the <a href="https://www.atlassian.com/platform/teamwork-graph">Atlassian Teamwork Graph</a>, <a href="https://boomi.com/knowledge-hub-early-access/">Boomi Knowledge Hub</a>, and the <a href="https://www.sap.com/products/artificial-intelligence/knowledge-graph.html">SAP Knowledge Graph</a>.</li>



<li>Some are branding their guardrails, such as <a href="https://business.adobe.com/products/brand-intelligence.html">Adobe’s AI Brand Intelligence</a>, <a href="https://appian.com/products/platform/artificial-intelligence">Appian’s Private AI</a>, and <a href="https://www.quickbase.com/intelligence-pack/ai-control-center">Quickbase AI Control Center</a>.</li>



<li>To manage AI agents at scale, some are extending the notion of data catalogs and other governance tools to the AI domain with products such as <a href="https://boomi.com/platform/connect/">Boomi Connect</a>, <a href="https://www.sap.com/products/artificial-intelligence/ai-agent-hub.html">SAP AI Agent Hub</a>, and <a href="https://www.snowflake.com/en/product/features/horizon/">Snowflake Horizon Catalog</a>.</li>
</ul>



<p class="wp-block-paragraph">CIOs should recognize that while solution providers will compete on capabilities, the real “secret sauce” of the context layer lies in the company’s trusted data, well-defined business processes, and employee adoption of AI agents.</p>



<h2 class="wp-block-heading">Conversational user experiences and coworkers</h2>



<p class="wp-block-paragraph">AI agents use the context layer, but also tap into skills, which encode the procedures they can follow, and tools, which prescribe the actions they can take. Before AI agents are ready to pilot, their governance, including permissions, approval gates, and other guardrails, must be defined. Other capabilities to look for when defining AI agents include orchestration, testing evals, and observability.</p>



<p class="wp-block-paragraph">In 2025, many solution providers bolted on AI agents to their existing user experiences. This year, many solution providers showcased new conversational user experiences that employees can use instead of traditional ones built with forms, flows, reports, and static dashboards. Conversational user experiences are where AI agents and people come together, whether it’s human-in-the-middle or human augmentation.</p>



<p class="wp-block-paragraph">Solution providers also grouped their AI agents into assistants or coworkers. For example, <a href="https://business.adobe.com/products/cx-enterprise-coworker.html">Adobe CX Coworker</a> illustrates human augmentation, helping marketers manage campaigns with prompts and monitor their performance. SAP launched <a href="https://www.sap.com/products/artificial-intelligence/ai-assistant.html">Joule Assistants</a> across several business functions, including finance, human capital, supply chain, and customer experience. Other assistants, such as <a href="https://docs.appian.com/suite/help/26.5/appian-ai-copilot.html">Appian AI Copilot</a>, <a href="https://www.atlassian.com/software/rovo">Atlassian Rovo</a>, <a href="https://www.cisco.com/site/us/en/solutions/artificial-intelligence/ai-assistant/index.html">Cisco AI Assistant</a>, <a href="https://www.nutanix.com/blog/nutanix-intelligent-virtual-agent">Nutanix NIVA</a>, and <a href="https://www.snowflake.com/en/product/snowflake-cowork/">Snowflake CoWork</a>, offer AI-first user experiences to assist different end-user types.</p>



<p class="wp-block-paragraph">CIOs should demo these <a href="https://www.infoworld.com/article/4178415/what-will-ai-first-ux-look-like.html">AI-first user experiences</a> to glimpse the future of work.</p>



<p class="wp-block-paragraph">Developers are already getting used to these experiences through code generators and vibe coding tools. Now, similar capabilities are being tailored across all business functions. CIOs should ramp up their <a href="https://www.cio.com/article/4082282/preparing-your-workforce-for-ai-agents-a-change-management-guide.html">change management programs</a> to accelerate the adoption of these AI capabilities.</p>



<p class="wp-block-paragraph">Solution providers are showcasing AI capabilities that can help CIOs <a href="https://drive.starcio.com/2026/04/ai-reshaping-business-not-digital-transformation-yet/">reshape their businesses</a>. But in Q2, there were only a few examples of how AI can help CIOs drive growth, evolve business models, or embed AI into customer-facing products. I expect to see a wave of further AI innovations that will go beyond productivity improvements and efficiencies and help CIOs pursue <a href="https://drive.starcio.com/2025/02/cios-drive-genai-digital-transformation/">growth-driving digital transformation strategies</a>.  </p>



<p class="wp-block-paragraph"><em>Sacolick travelled to conferences mentioned in this article as a guest of Adobe, Appian, Atlassian, Domo, Nutanix, SAP, and Snowflake. In addition, he was hired by Quickbase to speak at its conference.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[EU, UK Attribute Russia Cyberattack to FSB, Announce Sanctions]]></title>
<description><![CDATA[The Russia cyberattack targeting Poland's critical infrastructure has been formally attributed to Russia's Federal Security Service (FSB), with the European Union and the United Kingdom announcing a coordinated package of cyber sanctions against Russian-linked hackers and organizations. The move ...]]></description>
<link>https://tsecurity.de/de/3666927/it-security-nachrichten/eu-uk-attribute-russia-cyberattack-to-fsb-announce-sanctions/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3666927/it-security-nachrichten/eu-uk-attribute-russia-cyberattack-to-fsb-announce-sanctions/</guid>
<pubDate>Tue, 14 Jul 2026 07:38:35 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1536" height="1024" src="https://thecyberexpress.com/wp-content/uploads/Russia-cyberattack.webp" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="Russia cyberattack" decoding="async" srcset="https://thecyberexpress.com/wp-content/uploads/Russia-cyberattack.webp 1536w, https://thecyberexpress.com/wp-content/uploads/Russia-cyberattack-300x200.webp 300w, https://thecyberexpress.com/wp-content/uploads/Russia-cyberattack-1024x683.webp 1024w, https://thecyberexpress.com/wp-content/uploads/Russia-cyberattack-768x512.webp 768w, https://thecyberexpress.com/wp-content/uploads/Russia-cyberattack-600x400.webp 600w, https://thecyberexpress.com/wp-content/uploads/Russia-cyberattack-150x100.webp 150w, https://thecyberexpress.com/wp-content/uploads/Russia-cyberattack-750x500.webp 750w, https://thecyberexpress.com/wp-content/uploads/Russia-cyberattack-1140x760.webp 1140w, https://thecyberexpress.com/wp-content/uploads/Russia-cyberattack.webp 1536w, https://thecyberexpress.com/wp-content/uploads/Russia-cyberattack-300x200.webp 300w, https://thecyberexpress.com/wp-content/uploads/Russia-cyberattack-1024x683.webp 1024w, https://thecyberexpress.com/wp-content/uploads/Russia-cyberattack-768x512.webp 768w, https://thecyberexpress.com/wp-content/uploads/Russia-cyberattack-600x400.webp 600w, https://thecyberexpress.com/wp-content/uploads/Russia-cyberattack-150x100.webp 150w, https://thecyberexpress.com/wp-content/uploads/Russia-cyberattack-750x500.webp 750w, https://thecyberexpress.com/wp-content/uploads/Russia-cyberattack-1140x760.webp 1140w" sizes="(max-width: 1536px) 100vw, 1536px" title="EU, UK Attribute Russia Cyberattack to FSB, Announce Sanctions 1"></p><p class="PDq2pG_selectionAnchorContainer" data-start="401" data-end="873">The Russia cyberattack targeting Poland's critical infrastructure has been formally attributed to Russia's Federal Security Service (FSB), with the <a href="https://thecyberexpress.com/europe-union-tightens-cybersecurity-grip/" target="_blank" rel="noopener">European Union</a> and the United Kingdom announcing a coordinated package of cyber sanctions against <a href="https://thecyberexpress.com/russia-targeting-cisco-network-gear/" target="_blank" rel="noopener">Russian-linked hackers</a> and organizations. The move follows an attempted disruption of Poland's energy sector last winter that officials said came close to triggering a major blackout affecting nearly half a million people.</p>
<p data-start="875" data-end="1258">According to statements released by the EU and UK on Monday, the FSB's Center 16 was responsible for attempted <a href="https://thecyberexpress.com/tce-weekly-roundup-global-threats-ai-risks/" target="_blank" rel="noopener">cyber sabotage</a> against Poland's heating and power infrastructure, as well as cyber intrusions targeting water treatment facilities. The allies also accused the agency of conducting broader <a class="wpil_keyword_link" href="https://thecyberexpress.com/cyber-news/" title="cyber" data-wpil-keyword-link="linked" data-wpil-monitor-id="28947">cyber</a> operations against governments and critical infrastructure across Europe.</p>

<h3 data-section-id="1ojdcbi" data-start="1260" data-end="1322"><span role="text"><strong data-start="1263" data-end="1322">Russia Cyberattack Linked to FSB's Center 16 Operations</strong></span></h3>
<p data-start="1324" data-end="1762">The European Union <a href="https://www.consilium.europa.eu/en/press/press-releases/2026/07/13/cyber-russia-statement-by-the-high-representative-on-behalf-of-the-european-union-denouncing-russia-s-malicious-cyber-ecosystem-targeting-the-eu-its-member-states-and-international-partners/" target="_blank" rel="nofollow noopener">said</a> Center 16, the signals intelligence arm of the FSB, has conducted malicious cyber activities affecting multiple member states and international partners. According to the bloc, these operations have included infiltration of government networks, cyber espionage, and sabotage targeting <a href="https://thecyberexpress.com/ci-fortify-targets-critical-infrastructure/" target="_blank" rel="noopener">critical infrastructure </a>in France, Germany, Poland, Cyprus, the Netherlands, Austria, Slovakia, Romania, and Finland.</p>
<p data-start="1764" data-end="2152">The EU also stated that Center 16 controls several cyber threat groups, including TURLA, and has been involved in cyber operations against strategic government entities in France since 2010 and the country's defense industry in 2025. In Germany, it allegedly targeted government institutions, while in Poland it carried out disruptive operations against combined heating and power plants.</p>
<p data-start="2154" data-end="2342">British authorities <a href="https://www.gov.uk/government/news/uk-and-eu-strike-russian-cyber-networks-with-new-sanctions" target="_blank" rel="nofollow noopener">described</a> last December's attempted attack on Poland's energy grid as "reckless," saying it was another example of Russia's attempts to create disruption across Europe.</p>

<h3 data-section-id="1xky3g3" data-start="2344" data-end="2396"><span role="text"><strong data-start="2347" data-end="2396">Poland Attack Nearly Triggered Major Blackout</strong></span></h3>
<p data-start="2398" data-end="2612">The <a href="https://thecyberexpress.com/poland-cyberattack-energy-grid-blackout/" target="_blank" rel="noopener">cyber incident targeting Poland's energy infrastructure</a> last winter was initially linked by cybersecurity firms ESET and Dragos to Sandworm, a threat group associated with Russia's military intelligence agency.</p>
<p data-start="2614" data-end="2802">However, Poland's national cybersecurity agency, <a href="https://thecyberexpress.com/default-credentials-polish-energy-grid-attack/" target="_blank" rel="noopener">CERT Polska</a>, later disputed that assessment after tracing the attack infrastructure and connecting it to a cluster associated with the FSB.</p>
<p data-start="2804" data-end="2996">Separately, Poland's domestic intelligence service <a href="https://www.abw.gov.pl/pl/aktualnosci/2815,Agencja-Bezpieczenstwa-Wewnetrznego-2024-2025-Wybrane-aktywnosci.html" target="_blank" rel="nofollow noopener">warned in May</a> that cyber intrusions targeting the country's water treatment facilities posed a direct risk to the continuity of water supply.</p>

<h3 data-section-id="1k2aqc9" data-start="2998" data-end="3037"><span role="text"><strong data-start="3001" data-end="3037">EU and UK Expand Cyber Sanctions</strong></span></h3>
<p data-start="3039" data-end="3350">In response, the European Union imposed restrictive measures on nine individuals and four entities linked to Russia's cyber ecosystem. The sanctions target intelligence officers, cybercriminals, self-proclaimed hacktivists, and private companies accused of supporting or facilitating malicious cyber operations.</p>
<p data-start="3352" data-end="3656">The wider sanctions package announced by European partners targets more than 30 individuals and organizations, including operators behind the Lumma Stealer <a class="wpil_keyword_link" href="https://thecyberexpress.com/what-is-malware/" title="malware" data-wpil-keyword-link="linked" data-wpil-monitor-id="28948">malware</a>, companies accused of recruiting hackers from Russian universities, and individuals associated with the pro-Kremlin Rybar military blog.</p>
<p data-start="3658" data-end="3877">EU foreign policy chief Kaja Kallas <a href="https://www.eeas.europa.eu/eeas/foreign-affairs-council-remarks-high-representative-kaja-kallas-press-conference-2_en" target="_blank" rel="nofollow noopener">said</a> Russia continues to rely on intelligence agencies, cybercriminal groups, hacktivists, and private companies to conduct malicious cyber operations against Europe and its partners.</p>
<p data-start="3879" data-end="4083">She added that the bloc strongly condemns the misuse of this cyber ecosystem, which has targeted public services and critical infrastructure, resulting in operational disruptions and financial losses.</p>

<h3 data-section-id="aubtqe" data-start="4085" data-end="4121"><span role="text"><strong data-start="4088" data-end="4121">France Details FSB Activities</strong></span></h3>
<p data-start="4123" data-end="4311">France also a<a href="https://www.diplomatie.gouv.fr/en/presse-et-ressources/decouvrir-et-informer/actualites/attribution-a-la-russie-d-activites-cyber-malveillantes-a-des-fins-d-espionnage-en-france" target="_blank" rel="nofollow noopener">nnounced</a> additional sanctions and said it would summon the Russian ambassador over what it described as persistent malicious cyber activities conducted for espionage purposes.</p>
<p data-start="4313" data-end="4523">A <a href="https://www.cert.ssi.gouv.fr/cti/CERTFR-2026-CTI-005/" target="_blank" rel="nofollow noopener">technical report</a> from France's Cyber Crisis Coordination Center (C4) identified 11 interception centers operated by Center 16 across Russia, including Unit 61240, which it said specifically focused on France.</p>
<p data-start="4525" data-end="4792">French authorities alleged that the unit targeted government ministry systems in 2014, compromised the French Embassy network in Moscow in 2018, and stole significant volumes of <a class="wpil_keyword_link" href="https://thecyberexpress.com/what-is-data/" title="data" data-wpil-keyword-link="linked" data-wpil-monitor-id="28949">data</a> from a research institute working with the French defense industry in February 2025.</p>
<p data-start="4794" data-end="4954">France also stated that one newly sanctioned group had claimed responsibility for destabilization efforts targeting the <a href="https://thecyberexpress.com/russian-government-2024-paris-olympics-games/" target="_blank" rel="noopener">2024 Paris Olympic</a> and Paralympic Games.</p>

<h3 data-section-id="1wps0k5" data-start="4956" data-end="5003"><span role="text"><strong data-start="4959" data-end="5003">Allied Advisory Warns of Ongoing Threats</strong></span></h3>
<p data-start="5005" data-end="5283">Alongside the sanctions, the United States and intelligence agencies from a dozen allied countries published a <a href="https://media.defense.gov/2026/Jul/09/2003959498/-1/-1/1/CSA_IMPROVE_ROUTER_HYGIENE.PDF" target="_blank" rel="nofollow noopener">joint cybersecurity advisory</a> warning that Russian operators linked to Center 16 have been scanning internet-connected devices protected by weak or default credentials.</p>
<p data-start="5285" data-end="5731">The United Kingdom separately <a href="https://blogs.microsoft.com/on-the-issues/2025/05/21/microsoft-leads-global-action-against-favored-cybercrime-tool/" target="_blank" rel="nofollow noopener">sanctioned</a> individuals connected to Lumma Stealer, describing it as one of the world's most widely used information-stealing malware families. British officials said credentials stolen through the <a class="wpil_keyword_link" href="https://cyble.com/knowledge-hub/what-is-malware/" target="_blank" rel="noopener" title="malware" data-wpil-keyword-link="linked" data-wpil-monitor-id="28950">malware</a> have been used to support Russian espionage operations globally. According to the UK's National <a class="wpil_keyword_link" href="https://thecyberexpress.com/" title="Crime" data-wpil-keyword-link="linked" data-wpil-monitor-id="28946">Crime</a> Agency, more than 2,100 victims in the country were infected by Lumma Stealer during the past six months.</p>
<p data-start="5733" data-end="5994">British Foreign Secretary Yvette Cooper said the sanctions are intended to disrupt the cybercriminal ecosystem supporting Moscow's intelligence services, while emphasizing that the coordinated measures send a clear message against the use of proxy cyber groups.</p>
<p data-start="5996" data-end="6250">The Kremlin has repeatedly denied conducting offensive cyber operations. Russian President Vladimir Putin has <a href="https://ria.ru/20260604/putin-2096920826.html" target="_blank" rel="nofollow noopener">dismissed European allegations</a> of sabotage and cyberattacks as baseless, saying they are intended to justify aggressive policies against Russia.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Do programming certifications still matter?]]></title>
<description><![CDATA[If you’re a software developer or architect, you might wonder if programming certifications are still worth the effort, especially in the era of rapid AI-driven evolution. The short answer is, it depends.



“Certifications are shifting from a checkbox to a compass. They’re less about proving you...]]></description>
<link>https://tsecurity.de/de/3665678/ai-nachrichten/do-programming-certifications-still-matter/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3665678/ai-nachrichten/do-programming-certifications-still-matter/</guid>
<pubDate>Mon, 13 Jul 2026 17:04:44 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">If you’re a software developer or architect, you might wonder if programming certifications are still worth the effort, especially in the era of rapid <a href="https://www.infoworld.com/article/2338115/what-is-generative-ai-artificial-intelligence-that-creates.html" data-type="link" data-id="https://www.infoworld.com/article/2338115/what-is-generative-ai-artificial-intelligence-that-creates.html">AI-driven evolution</a>. The short answer is, it depends.</p>



<p class="wp-block-paragraph">“Certifications are shifting from a checkbox to a compass. They’re less about proving you memorized syntax and more about proving you can architect systems, instruct AI coding assistants, and solve problems end-to-end,” says Faizel Khan, lead AI engineer at <a href="https://landingpoint.com/">Landing Point</a>, an executive search and recruiting firm.</p>



<p class="wp-block-paragraph">“In the AI era, fewer students will get trained on the job, which means they have to train themselves,” Khan says. “Certifications—especially architectural ones like AWS, Kubernetes, Terraform—are still the clearest path to do that.”</p>



<h2 class="wp-block-heading">Pros and cons of programming certifications</h2>



<p class="wp-block-paragraph">It’s not all black and white when it comes to deciding whether to pursue programming certifications. The effort involves both pros and cons.</p>



<p class="wp-block-paragraph">“In terms of pros, certifications concretely demonstrate that you have a skillset at a documented level,” says Chris Riccio, vice president of engineering at <a href="https://uplevelteam.com/">Uplevel</a>, an engineering optimization system provider. “They also show that you’ve put in the time and effort to learn, study, and prepare.”</p>



<p class="wp-block-paragraph">Programming certifications are “a useful way to validate foundational skills and show that someone understands core concepts,” says Greg Fuller, vice president of Skillsoft’s training provider, <a href="https://www.codecademy.com/">Codecademy</a>. “They’re especially helpful for people entering the field or shifting from adjacent roles.”</p>



<p class="wp-block-paragraph">Certifications offer a structured path to demonstrate proficiency, and they can confirm your ability to build and deploy in various environments, Fuller says.</p>



<p class="wp-block-paragraph">These types of certifications often demonstrate baseline proficiency and continuous learning, says Reshmi Ramachandran, head of partnerships and GTM strategy for <a href="https://www.cprime.com/">Cprime</a>, a consultancy. “These are often key indications of proficiency for companies looking to filter large candidate pools,” she says.</p>



<p class="wp-block-paragraph">Certifications really do two things, Khan adds. “First, they force you to learn by doing,” he says. “If you’re taking AWS Solutions Architect or Terraform, you don’t pass by guessing—you plan, build, and test systems. That practice matters. Second, they act as a public signal. Think of it like a micro-degree. You’re not just saying, ‘I know cloud.’ You’re showing you’ve crossed a bar that thousands of other engineers recognize.”</p>



<p class="wp-block-paragraph">But there are cons, too. “In tech, employers don’t just want credentials, they want proof you can deliver,” says Kevin Miller, CTO at <a href="https://www.ifs.com/industries/manufacturing/industrial-manufacturing">IFS</a>, a maker of factory automation software. “Programming certifications can be a valuable indicator of your baseline knowledge and competencies, especially if you’re early in your career or pivoting into tech, but their importance is dwindling.”</p>



<p class="wp-block-paragraph"><a href="https://www.infoworld.com/generative-ai/">AI tools</a> that can generate, debug, and optimize code are <a href="https://www.infoworld.com/article/4077352/85-of-developers-use-ai-regularly-jetbrains-survey.html" data-type="link" data-id="https://www.infoworld.com/article/4077352/85-of-developers-use-ai-regularly-jetbrains-survey.html">already performing tasks once done by entry-level developers</a>, “which means fewer traditional programming roles are available,” Miller says. “As a result, the job market is becoming more competitive, and certifications aren’t seen as the noteworthy achievement they once were.”</p>



<p class="wp-block-paragraph">What’s more, not all certifications carry the same weight, Riccio says. “Some may reflect only familiarity rather than true expertise,” he says. “Certifications also often measure ‘book knowledge’ rather than practical experience, and they don’t always map clearly to the requirements of a specific role.”</p>



<p class="wp-block-paragraph">Programming certifications “can be a helpful signal, especially for confirming baseline knowledge in areas like cloud, security, or devops, but they’re not the full picture,” says Morgan Watts, vice president of IT at <a href="https://developer.8x8.com/">8×8</a>, a contact center platform developer.</p>



<p class="wp-block-paragraph">“I’m more interested in a candidate’s attitude and aptitude: what problems they’ve solved, what they’ve built, and how they’ve approached challenges,” Watts says. “Certifications can show commitment and discipline, and they’re especially useful in highly specialized roles. But I’m cautious when someone presents a laundry list of certifications with little evidence of real-world application.”</p>



<p class="wp-block-paragraph">A certification without experience doesn’t carry much weight, Watts says, and over-certification can sometimes signal the wrong focus. “Ultimately, it’s the ability to apply knowledge, collaborate, and adapt that sets great developers apart,” he says.</p>



<p class="wp-block-paragraph">Finally, certifications can age fast, Khan says. “Tech stacks evolve and a badge from two years ago may already feel dusty,” he says. “And some certifications are paper-thin—multiple-choice exams that don’t prove you can debug production at 2 a.m. So, the risk is you collect badges but still can’t ship.”</p>



<h2 class="wp-block-heading">Which certifications will get you noticed?</h2>



<p class="wp-block-paragraph">Despite the drawbacks, certifications are still very much in demand, and some carry more weight than others.</p>



<p class="wp-block-paragraph">The most in-demand certifications are typically platform-based—Amazon Web Services (AWS), Google Cloud Platform (GCP), Microsoft Azure, and others, Riccio says. “Many of these platforms provide managed services that integrate with existing systems or serve as the glue between them,” he says. “Today’s engineering teams aren’t just building standalone systems in isolation; they’re using other systems to store data, orchestrate business workflows, and connect applications.”</p>



<p class="wp-block-paragraph">A certification that demonstrates the ability to build solutions on these platforms can put a development professional ahead of the competition, Riccio says.</p>



<p class="wp-block-paragraph">“The certifications I see in highest demand tend to reflect the evolving tech landscape,” Watts says. “Cloud certifications from AWS, Azure, and GCP are incredibly valuable, especially as distributed systems become the norm.”</p>



<p class="wp-block-paragraph">Also in demand are certifications for <a href="https://www.infoworld.com/article/3632270/the-devops-certifications-tech-companies-want.html">devops and CI/CD tools</a> including <a href="https://www.infoworld.com/article/3529526/how-to-succeed-with-kubernetes.html">Kubernetes</a>, <a href="https://www.infoworld.com/article/2257241/why-you-should-use-docker-and-oci-containers.html">Docker</a>, and <a href="https://www.infoworld.com/article/2260091/what-is-jenkins-the-ci-server-explained.html">Jenkins</a>, Watts says, “because deployment automation and reliability are critical at scale. Also, with AI reshaping development, we’re seeing growing interest in certifications around machine learning, data science, and AI model integration. These certifications stand out because they align directly with the skills that teams need to move faster and more intelligently.”</p>



<aside class="sidebar large">
<h3>More about developer certifications</h3>
<p>Learn more about developer courses and certifications tech companies want:</p>
<ul>
<li><a href="https://www.infoworld.com/article/4055032/ai-developer-certifications-tech-companies-want.html">AI developer certifications</a></li>
<li><a href="https://www.infoworld.com/article/3583466/the-machine-learning-certifications-tech-companies-want.html">Machine learning certifications</a></li>
<li><a href="https://www.infoworld.com/article/2337635/4-cloud-certifications-that-will-help-you-stand-out.html">Cloud development certifications</a></li>
<li><a href="https://www.infoworld.com/article/3632270/the-devops-certifications-tech-companies-want.html">Devops and CI/CD certifications</a></li>
</ul>
</aside>




<p class="wp-block-paragraph">On the AI front, certifications in <a href="https://www.infoworld.com/article/2255099/what-is-tensorflow-the-machine-learning-library-explained.html">TensorFlow</a> and other <a href="https://www.infoworld.com/article/3583466/the-machine-learning-certifications-tech-companies-want.html">machine learning platforms</a> are gaining traction as organizations look to embed AI across the development process, Watts says. “These are the certifications that align closely with where modern engineering is headed—scalable, secure, and AI-enabled,” he says.</p>



<p class="wp-block-paragraph">And then there are <a href="https://www.csoonline.com/article/3970107/the-14-most-valuable-cybersecurity-certifications.html">cybersecurity credentials</a> that continue to be in high demand. Security certifications, such as CompTIA Security+ or Certified Ethical Hacker, “have become essential as every company faces increasing cyber threats and compliance requirements,” Miller says.</p>



<p class="wp-block-paragraph">“Core programming certifications are still a bit niche, but the adjacent skills, like those that help developers deploy, secure, and scale their code, are driving demand,” Fuller says. “Companies want developers who understand the full lifecycle, not just how to write code.”</p>



<p class="wp-block-paragraph"><strong>Also see: <a href="https://www.infoworld.com/article/3980325/the-java-certifications-tech-companies-want.html">The best Java certifications for software developers</a>.</strong></p>



<h2 class="wp-block-heading">Certifications in the hiring process</h2>



<p class="wp-block-paragraph">Experts are clear that programming certifications alone will not get you the job. But they do play a role in the hiring process.</p>



<p class="wp-block-paragraph">“The information technology world is characterized by rapid and continuous evolution, including the skills and knowledge required to work in the field,” says Diane Rafferty, managing director of the National Technology Group at <a href="https://www.atriumglobal.com/">Atrium</a>, a global talent solutions and extended workforce management firm.</p>



<p class="wp-block-paragraph">“Certifications not only prove that you have the skills and knowledge needed, but they also show employers that you’re invested in your education and career growth,” Rafferty says. “They can give you a competitive edge when looking for a job, as many companies now require candidates to have them.”</p>



<p class="wp-block-paragraph">Certifications are one part of the hiring equation, “but never the only part,” Watts says. “They help validate that a candidate has taken the time to build foundational knowledge, and that’s a good sign. But I put more weight on how a person thinks, solves problems, and contributes to the team. I look for people who are curious and proactive, who are learning because they want to, not just because a course told them to.”</p>



<p class="wp-block-paragraph">Certifications can also play a valuable role in retention, Watts says. “I encourage team members to pursue growth, and when they invest in their own development, the whole organization benefits,” he says. “But again, it’s that balance of knowledge, attitude, and applied experience that really moves the needle.”</p>



<p class="wp-block-paragraph">Certifications “may allow you to breeze through the initial résumé screening process, potentially getting you to the next stage faster,” Riccio says. “At a minimum, they will set your profile apart from the rest of the pack. They also demonstrate that you’ve reached a baseline level of expertise, allowing hiring managers to quickly evaluate whether you have the skills for the role.”</p>



<p class="wp-block-paragraph">Employers today “care far less about whether someone has passed an exam and far more about whether they can apply knowledge effectively in real-world situations, leverage AI tools, and solve complex problems,” Miller says. “A certification might get someone an interview, but being able to demonstrate problem-solving skills, teamwork, and adaptability will really make them stand out.”</p>



<h2 class="wp-block-heading">Popular programming certifications</h2>



<p class="wp-block-paragraph">The following certifications consistently rose to the top in my conversations with tech leaders and hiring managers.</p>



<h3 class="wp-block-heading">AWS Certified Developer—Associate</h3>



<p class="wp-block-paragraph">Showcases skills and knowledge in developing, optimizing, packaging, and deploying applications, using CI/CD workflows, and identifying and resolving application issues, according to AWS. This certification is said to be a good starting point on the AWS certification journey for professionals in IT or cloud developer job roles.</p>



<h3 class="wp-block-heading">Azure Developer Associate</h3>



<p class="wp-block-paragraph">This certificate from Microsoft is intended for developers participating in all phases of cloud development, including design, deployment, maintenance, and monitoring. The course teaches developers how to create end-to-end solutions in Microsoft Azure, using the Microsoft Learn Sandbox environment to access Azure resources and services.</p>



<h3 class="wp-block-heading">Certified Kubernetes Application Developer (CKAD)</h3>



<p class="wp-block-paragraph">This certification was created by the Linux Foundation and Cloud Native Computing Foundation. It demonstrates that candidates can design, build, and deploy cloud-native applications for Kubernetes.</p>



<h3 class="wp-block-heading">Certified Secure Software Lifecycle Professional (CSSLP)</h3>



<p class="wp-block-paragraph">This certification, from ISC2, focuses on secure software development practices. It recognizes leading application security skills and demonstrates advanced technical skills and knowledge needed for authentication, authorization, and auditing throughout the software development lifecycle.</p>



<h3 class="wp-block-heading">Databricks Certified Machine Learning Professional</h3>



<p class="wp-block-paragraph">Professionals learn about the latest data and AI techniques and how they can use the Databricks Data Intelligence Platform to build a variety of solutions across data engineering, data warehousing, data science, and AI.</p>



<h3 class="wp-block-heading">Professional Cloud Architect</h3>



<p class="wp-block-paragraph">This certification from Google assesses the ability to design and plan a cloud solution architecture, manage and provision the cloud solution infrastructure, design for security and compliance, analyze and optimize technical and business processes manage implementations of cloud architecture, and ensure solution and operations reliability.</p>



<h3 class="wp-block-heading">Terraform Associate</h3>



<p class="wp-block-paragraph">This certification from HashiCorp is for cloud engineers specializing in operations, IT, or development who know the basic concepts and skills associated with Terraform. It validates foundational skills in using <a href="https://www.infoworld.com/article/3893387/how-terraform-is-evolving-infrastructure-as-code.html">Terraform</a> for <a href="https://www.infoworld.com/article/2259359/what-is-infrastructure-as-code-automating-your-infrastructure-builds.html">infrastructure as code</a> development.</p>
</div></div></div>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[16 open source projects transforming AI and machine learning]]></title>
<description><![CDATA[For several decades now, the most innovative software has always emerged from the world of open source software. It’s no different with machine learning and large language models. If anything, the open source ecosystem has grown richer and more complex, because now there are open source models to...]]></description>
<link>https://tsecurity.de/de/3665665/ai-nachrichten/16-open-source-projects-transforming-ai-and-machine-learning/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3665665/ai-nachrichten/16-open-source-projects-transforming-ai-and-machine-learning/</guid>
<pubDate>Mon, 13 Jul 2026 17:04:27 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">For several decades now, the most innovative software has always emerged from the world of open source software. It’s no different with machine learning and <a href="https://www.infoworld.com/article/2335213/large-language-models-the-foundations-of-generative-ai.html">large language models</a>. If anything, the open source ecosystem has grown richer and more complex, because now there are open source models to complement the open source code.</p>



<p class="wp-block-paragraph">For this article, we’ve pulled together some of the most intriguing and useful projects for <a href="https://www.infoworld.com/article/2338115/what-is-generative-ai-artificial-intelligence-that-creates.html">AI and machine learning</a>. Many of these are foundation projects, nurturing their own niche ecology of open source plugins and extensions. Once you’ve started with the basic project, you can keep adding more parts.</p>



<p class="wp-block-paragraph">Most of these projects offer demonstration code, so you can start up a running version that already tackles a basic task. Additionally, the companies that build and maintain these projects often sell a service alongside them. In some cases, they’ll deploy the code for you and save you the hassle of keeping it running. In others, they’ll sell custom add-ons and modifications. The code itself is still open, so there’s no vendor lock in. The services simply make it easier to adopt the code by paying someone to help.</p>



<p class="wp-block-paragraph">Here are 16 open source projects that developers can use to unlock the potential in machine learning and large language models of any size—from small to large, and even extra large.</p>



<h2 class="wp-block-heading">Agent Skills</h2>



<p class="wp-block-paragraph">AI coding agents are often used to tackle standard tasks like <a href="https://www.infoworld.com/article/3981588/putting-agentic-ai-to-work-in-firebase-studio.html">writing React components</a> or <a href="https://www.infoworld.com/article/4025088/how-coderabbit-brings-ai-to-code-reviews.html">reviewing parts of the user interface</a>. If you are writing a coding agent, it makes sense to use vetted solutions that are focused on the task at hand. <a href="https://github.com/vercel-labs/agent-skills">Agent Skills</a> are pre-coded tools that your AI can deploy as needed. The result is a focused set of vetted operations capable of producing refined, useful code that stays within standard guidelines. License: MIT.</p>



<h2 class="wp-block-heading">Awesome LLM Apps</h2>



<p class="wp-block-paragraph">If you are looking for good examples of agentic coding, see the <a href="https://github.com/Shubhamsaboo/awesome-llm-apps">Awesome LLM Apps collection</a>. Currently, the project hosts several dozen applications that leverage some combination of <a href="https://www.infoworld.com/article/2335814/what-is-retrieval-augmented-generation-more-accurate-and-reliable-llms.html">RAG databases</a> and LLMs. Some are simple, like a meme generator, while others handle deeper research like the Journalist agent. The most complex examples deploy multi-agent teams to converge upon an answer. Every application comes with working examples for experimentation, so you can learn from what’s been successful in the past. Altogether, the apps in this collection are great inspiration for your own projects. License: Apache 2.0.</p>



<h2 class="wp-block-heading">Bifrost</h2>



<p class="wp-block-paragraph">If your application requires access to an LLM service, and you don’t have a particular one in mind, check out <a href="https://github.com/maximhq/bifrost">Bifrost</a>. A fast, unified gateway to more than 15 LLM providers, this OpenAI-compatible API quickly abstracts away the differences between models, including all the major ones. It includes essential features like governance, caching, budget management, load balancing, and it has guardrails to catch problems before they are sent out to service providers, who will just bill you for the time. With dozens of great LLM providers constantly announcing new and better models, why limit yourself? License: Apache 2.0.</p>



<h2 class="wp-block-heading">Claude Code</h2>



<p class="wp-block-paragraph">If the popularity of AI coding assistants tells us anything, it’s that all developers—and not just the ones building AI apps—appreciate a little help writing and reviewing their code. <a href="https://github.com/anthropics/claude-code">Claude Code</a> is that pair programmer. Trained on all the major programming languages, <a href="https://www.infoworld.com/article/3853805/vibe-coding-with-claude-code.html">Claude Code can help you write code that is better, faster, and cleaner</a>. It digests a codebase and then starts doing your bidding, while also making useful suggestions. Natural language commands plus some vague hand waving are all the Anthropic LLM needs to refactor, document, or even add new features to your existing code. License: Anthropic’s Commercial TOS.</p>



<h2 class="wp-block-heading">Clawdbot</h2>



<p class="wp-block-paragraph">Many of the tools in this list help developers create code for other people. <a href="https://github.com/clawdbot/clawdbot?tab=readme-ov-file">Clawdbot</a> is the AI assistant for you, the person writing the code. It integrates with your desktop to control built-in tools like the camera and large applications like the browser. A multi-channel inbox accepts your commands through more than a dozen different communication channels including WhatsApp, Telegram, Slack, and Discord. A cron job adds timing. It’s the ultimate assistant for you, the ruler of your data. If AI exists to make our lives easier, why not start by organizing the applications on your desktop? License: MIT.</p>



<h2 class="wp-block-heading">Dify</h2>



<p class="wp-block-paragraph">For projects that require more than just one call to an LLM, <a href="https://github.com/langgenius/dify">Dify</a> could be the solution you’ve been looking for. Essentially a development environment for building complex agentic workflows, Dify stitches together LLMs, RAG databases, and other sources. It then monitors how they perform under different prompts and parameters and puts it all together in a handy dashboard, so you can iterate on the results. Developing agentic AI requires rapid experimentation, and Dify provides the environment for those experiments. License: Modified version of Apache 2.0 to exclude some commercial uses.</p>



<h2 class="wp-block-heading">Eigent</h2>



<p class="wp-block-paragraph">The best way to explore the power and limitations of an agentic workflow is to deploy it yourself on your own machine, where it can solve your own problems. Eigent delivers a workforce of specialized agents for handling tasks like writing code, searching the web, and creating documents. You just wave your hands and issue instructions, and Eigent’s LLMs do their best to follow through. Many startups brag about eating their own dogfood. Eigent puts that concept on a platter, making it easy for AI developers to experience directly the abilities and failings of the LLMs they’re building. License: Apache 2.0.</p>



<h2 class="wp-block-heading">Headroom</h2>



<p class="wp-block-paragraph">Programmers often think like packrats. If the data is good, why not pack in some more? This is a challenge for code that uses an LLM because these services charge by the token, and they also have a limited context window. <a href="https://github.com/chopratejas/headroom">Headroom</a> tackles this issue with agile compression algorithms that trim away the excess, especially the extra labels and punctuation found in common formats like JSON. A big part of designing working AI applications is cost engineering, and saving tokens means saving money. License: Apache 2.0.</p>



<h2 class="wp-block-heading">Hugging Face Transformers</h2>



<p class="wp-block-paragraph">When it comes to starting up a brand-new machine learning project, <a href="https://github.com/huggingface/transformers">Hugging Face Transformers</a> is one of the best foundations available. Transformers offers a standard format for defining how the model interacts with the world, which makes it easy to drop a new model into your working infrastructure for training or deployment. This means your model will interact nicely with all the already available tools and infrastructure, whether for text, vision, audio, video, or all of the above. Fitting into a standard paradigm makes it much easier to leverage your existing tools while focusing on the cutting edge of your research. License: Apache 2.0.</p>



<h2 class="wp-block-heading">LangChain</h2>



<p class="wp-block-paragraph">For agentic AI solutions that require endless iteration, <a href="https://github.com/langchain-ai/langchain">LangChain</a> is a way to organize the effort. It harnesses the work of a large collection of models and makes it easier for humans to inspect and curate the answers. When the task requires deeper thinking and planning, LangChain makes it easy to work with agents that can leverage multiple models to converge upon a solution. LangChain’s architecture includes a framework (LangGraph) for organizing easily customizable workflows with long-term memory, and a tool (LangSmith) for evaluating and improving performance. Its Deep Agents library provides teams of sub-agents, which organize problems into subsets then plan and work toward solutions. It is a proven, flexible test bed for agentic experimentation and production deployment. License: MIT.</p>



<h2 class="wp-block-heading">LlamaIndex</h2>



<p class="wp-block-paragraph">Many of the early applications for LLMs are sorting through large collections of semi-structured data and providing users with useful answers to their questions. One of the fastest ways to customize a standard LLM with private data is to use <a href="https://github.com/run-llama/llama_index">LlamaIndex</a> to ingest and index the data. This off-the-shelf tool provides data connectors that you can use to unpack and organize a large collection of documents, tables, and other data, often with just a few lines of code. The layers underneath can be tweaked or extended as the job requires, and LlamaIndex works with many of the data formats common in enterprises. License: MIT.</p>



<h2 class="wp-block-heading">Ollama</h2>



<p class="wp-block-paragraph">For anyone experimenting with LLMs on their laptop, <a href="https://github.com/ollama/ollama">Ollama</a> is one of the simplest ways to <a href="https://www.infoworld.com/article/2338922/5-easy-ways-to-run-an-llm-locally.html" data-type="link" data-id="https://www.infoworld.com/article/2338922/5-easy-ways-to-run-an-llm-locally.html">download one or more of them and get started</a>. Once it’s installed, your command line becomes a small version of the classic ChatGPT interface, but with the ability to pull a huge collection of models from a growing library of open source options. Just enter: <code>ollama run </code> and the model is ready to go. Some developers are using it as a back-end server for LLM results. The tool provides a stable, trustworthy interface to LLMs, something that once required quite a bit of engineering and fussing. The server simplifies all this work so you can tackle higher level chores with many of the <a href="https://ollama.com/library">most popular open source LLMs</a> at your fingertips. License: MIT.</p>



<h2 class="wp-block-heading">OpenWebUI</h2>



<p class="wp-block-paragraph">One of the fastest ways to put up a website with a chat interface and a dedicated RAG database is to spin up an instance of <a href="https://github.com/open-webui/open-webui">OpenWebUI</a>. This project knits together a feature-rich front end with an open back end, so that starting up a customizable chat interface only requires pulling a few <a href="https://www.infoworld.com/article/2257241/why-you-should-use-docker-and-oci-containers.html">Docker containers</a>. The project, though, is just a beginning, because it offers the opportunity to add plugins and extensions to enhance the data at each stage. Practically every part of the chain from prompt to answer can be tweaked, replaced, or improved. While some teams might be happy to set it up and be done, the advantages come from adding your own code. The project isn’t just open source itself, but a constellation of hundreds of little bits of contributed code and ancillary projects that can be very helpful. Being able to customize the pipeline and leverage the <a href="https://www.infoworld.com/article/4029634/what-is-model-context-protocol-how-mcp-bridges-ai-and-external-services.html">MCP protocol</a> supports the delivery of precision solutions. License: Modified BSD designed to restrict removing OpenWebUI branding without an enterprise license.</p>



<h2 class="wp-block-heading">Sim</h2>



<p class="wp-block-paragraph">The drag-and-drop canvas for <a href="https://github.com/simstudioai/sim">Sim</a> is meant to make it easier to experiment with <a href="https://www.infoworld.com/article/4086884/how-to-automate-the-testing-of-ai-agents.html">agentic workflows</a>. The tool handles the details of interacting with the various LLMs and vector databases; you just decide how to fit them together. Interfaces like Sim make the agentic experience accessible to everyone on your team, even those who don’t know how to write code. License: Apache 2.0.</p>



<h2 class="wp-block-heading">Sloth</h2>



<p class="wp-block-paragraph">One of the most straightforward ways to leverage the power of foundational LLMs is to start with an open source model and fine-tune it with your own data. <a href="https://github.com/unslothai/unsloth">Unsloth</a> does this, often faster than other solutions do. Most major open source models can be transformed with reinforcement learning. Unsloth is designed to work with most of the standard precisions and some of the largest context windows. The best answers won’t always come directly from RAG databases. Sometimes, adjusting the models is the best solution. License: Apache 2.0.</p>



<h2 class="wp-block-heading">vLLM</h2>



<p class="wp-block-paragraph">One of the best ways to turn an LLM into a useful service for the rest of your code is to start it up with <a href="https://github.com/vllm-project/vllm">vLLM</a>. The tool loads many of the available open source models from repositories like Hugging Face and then orchestrates the data flows so they keep running. That means batching the incoming prompts and managing the pipelines so the model will be a continual source of fast answers. It supports not just the CUDA architecture but also AMD CPUs and GPUs, Intel CPUs and GPUs, PowerPC CPUs, Arm CPUs, and TPUs. It’s one thing to experiment with lots of models on a laptop. It’s something else entirely to deploy the model in a production environment. vLLM handles many of the endless chores that deliver better performance. License: Apache-2.0.</p>



<p class="wp-block-paragraph"></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Infrastructure for the agentic era: A new conversation layer for the Twilio Platform]]></title>
<description><![CDATA[A new era of customer engagement is taking shape. AI agents are quickly becoming integral to the way businesses serve, support, and sell to customers — able to respond, reason, and take action in ways that go far beyond scripted automation.



Many customer journeys, however, are still built on s...]]></description>
<link>https://tsecurity.de/de/3664598/it-security-nachrichten/infrastructure-for-the-agentic-era-a-new-conversation-layer-for-the-twilio-platform/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3664598/it-security-nachrichten/infrastructure-for-the-agentic-era-a-new-conversation-layer-for-the-twilio-platform/</guid>
<pubDate>Mon, 13 Jul 2026 10:09:19 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>A new era of customer engagement is taking shape. AI agents are quickly becoming integral to the way businesses serve, support, and sell to customers — able to respond, reason, and take action in ways that go far beyond scripted automation.</p>



<p>Many customer journeys, however, are still built on systems that don’t talk to each other. Customer data lives in one place, channel history in another, and AI agents often operate with only part of the picture. Customers feel the pain when they switch between channels like voice and messaging, get transferred, and have to repeat themselves yet again. It doesn’t matter that they’ve been loyal to a brand for years, every interaction feels like a cold start. That is the conversation gap.</p>



<p>It’s clear that AI isn’t the problem, infrastructure is. Closing the gap requires new building blocks that focus on continuity, so context can carry forward across systems, channels, human agents, and AI agents.</p>



<p>To bridge the gap, at <a href="https://signal.twilio.com/?_gl=1*qsec1h*_gcl_aw*R0NMLjE3Nzk3MTY4MzguQ2p3S0NBanc1c19RQmhBZEVpd0FERF9nQnUyRVR4YTdGTFRCNDVPcktsd2dvbnZrQ3hZdlNtQXRJRHVoS09lOVJySXFsQ3k2eHZZajBob0NRZkVRQXZEX0J3RQ..*_gcl_au*MTAwMjE5MDU2OS4xNzc5MzUyNjYz*_ga*MTA5NDA4OTEuMTc3MTU2MTMzNg..*_ga_RRP8K4M4F3*czE3ODA5NzUwMjYkbzE3NyRnMSR0MTc4MDk3NzU4NiRqNjAkbDAkaDA.&amp;utm_source=foundry&amp;utm_medium=contentsyn&amp;utm_campaign=abm_brand_icp_sa_aw_tofu_apac_en&amp;utm_content=abm_lo_cs_ungatedcontent_infra-agentic-era_brandposthub" target="_blank" rel="sponsored">SIGNAL 2026</a>, we are introducing a new conversation layer for the Twilio Platform.</p>



<p>Twilio Conversation Orchestrator, Twilio Conversation Memory, and Twilio Conversation Intelligence are now generally available. Together, they help businesses coordinate interactions, preserve context, and connect human and AI agents so every conversation is more continuous and useful.</p>



<p>In addition to the new Conversations layer, we’re also announcing platform updates that make it easier to build, manage, and scale customer engagement on Twilio — from a reimagined Twilio Console to expanded channels and new voice AI capabilities.</p>



<h2 class="wp-block-heading">New building blocks for connected conversations</h2>



<p>The conversation gap does more than create inconsistent customer experiences. It hurts conversion and retention, increases operational costs, adds integration complexity, and makes agents less productive. The new platform capabilities we’re introducing are designed to fix that by coordinating interactions, maintaining context, and surfacing signals as conversations happen.</p>



<h2 class="wp-block-heading"><a></a>Conversation Orchestrator</h2>



<p><a href="https://www.twilio.com/en-us/blog/products/conversation-orchestrator?utm_source=foundry&amp;utm_medium=contentsyn&amp;utm_campaign=abm_brand_icp_sa_aw_tofu_apac_en&amp;utm_content=abm_lo_cs_ungatedcontent_infra-agentic-era_brandposthub" target="_blank" rel="sponsored">Conversation Orchestrator</a> helps businesses coordinate interactions across Twilio channels without complex custom logic. Teams can configure it in Console or configure their implementation with the API. It connects interactions into a single thread and manages handoffs between human agents and automated systems.</p>



<h2 class="wp-block-heading">Conversation Memory</h2>



<p><a href="https://www.twilio.com/en-us/blog/products/launches/conversation-memory?utm_source=foundry&amp;utm_medium=contentsyn&amp;utm_campaign=abm_brand_icp_sa_aw_tofu_apac_en&amp;utm_content=abm_lo_cs_ungatedcontent_infra-agentic-era_brandposthub" target="_blank" rel="noreferrer noopener">Conversation Memory</a> creates a living, identity-resolved profile by connecting customer data with conversation history and customer traits. That means each interaction starts with the right context. It’s built specifically for LLMs to reduce latency and token usage by surfacing the most relevant details when they matter.</p>



<p>A new Enterprise Knowledge API (now generally available) also allows teams to deliver more relevant experiences and ground interactions in trusted business knowledge such as FAQs, policies, and product documentation.</p>



<h2 class="wp-block-heading">Conversation Intelligence</h2>



<p><a href="https://www.twilio.com/en-us/blog/products/launches/conversation-intelligence?utm_source=foundry&amp;utm_medium=contentsyn&amp;utm_campaign=abm_brand_icp_sa_aw_tofu_apac_en&amp;utm_content=abm_lo_cs_ungatedcontent_infra-agentic-era_brandposthub" target="_blank" rel="noreferrer noopener">Conversation Intelligence</a> provides real-time understanding of live interactions. Using prebuilt and custom LLM-based operators, it can detect changes in sentiment, flag potential escalations, and trigger action during a conversation, not only after it ends.</p>



<p>That gives teams the ability to respond sooner, support agents more effectively, and improve customer outcomes while the conversation is still in progress.</p>



<p>Together, these products help businesses create customer experiences that feel more connected across channels.</p>



<h2 class="wp-block-heading">Open by design</h2>



<p>Twilio remains neutral by design. We start with the premise that you know your business. We aren’t here to prescribe a model, framework, or data strategy. We provide the infrastructure that helps you build customer engagement in the way that works best for your business. You pick the model and agent runtime. You own the data.</p>



<p>That doesn’t mean you need to start from scratch, either. We partnered with Microsoft, AWS, and others to create blueprints that support faster development. We are also introducing an open-source developer toolkit, <a href="https://www.twilio.com/en-us/blog/products/launches/agent-connect?utm_source=foundry&amp;utm_medium=contentsyn&amp;utm_campaign=abm_brand_icp_sa_aw_tofu_apac_en&amp;utm_content=abm_lo_cs_ungatedcontent_infra-agentic-era_brandposthub" target="_blank" rel="noreferrer noopener">Twilio Agent Connect</a> (now generally available), that lets your teams connect agents built on any LLM or framework directly to Twilio’s infrastructure.</p>



<p>For developers, this means more flexibility. For businesses, it means less lock-in and the ability to get value from existing investments. For partners, it means more ways to build with Twilio.</p>



<h2 class="wp-block-heading">A new front door</h2>



<p>We are also introducing a reimagined <a href="https://www.twilio.com/en-us/blog/products/launches/new-twilio-console?utm_source=foundry&amp;utm_medium=contentsyn&amp;utm_campaign=abm_brand_icp_sa_aw_tofu_apac_en&amp;utm_content=abm_lo_cs_ungatedcontent_infra-agentic-era_brandposthub" target="_blank" rel="noreferrer noopener">Twilio Console</a>, because as customer engagement grows more complex, managing the infrastructure behind it should feel effortless.</p>



<p>The new Console is a single mission control center that brings your communications, identity, and data into one experience: one login, consistent logs across every surface, an intelligent Console Assistant, transparent billing insights, and streamlined compliance workflows that no longer slow you down.</p>



<p>Over the coming months, we’ll roll out this new Console experience to customers automatically. You can also opt in to gain early access.</p>



<h2 class="wp-block-heading">More channels, more control, smarter conversations</h2>



<p>In addition to these launches, we are announcing several updates that expand customer reach, support enterprise requirements, and make it simpler to build on Twilio.</p>



<ul class="wp-block-list">
<li><a href="https://www.twilio.com/en-us/messaging/channels/apple-messages-for-business?utm_source=foundry&amp;utm_medium=contentsyn&amp;utm_campaign=abm_brand_icp_sa_aw_tofu_apac_en&amp;utm_content=abm_lo_cs_ungatedcontent_infra-agentic-era_brandposthub" target="_blank" rel="sponsored">Apple Messages for Business</a> (Private beta) and Twilio Email (GA) give teams new ways to reach customers on the channels they already use.</li>



<li>Data Residency for SMS (EU) (Public beta) enables teams to manage personal data locally to support regional data requirements.</li>



<li><a href="https://www.twilio.com/en-us/blog/products/launches/the-evolution-of-conversation-relay?utm_source=foundry&amp;utm_medium=contentsyn&amp;utm_campaign=abm_brand_icp_sa_aw_tofu_apac_en&amp;utm_content=abm_lo_cs_ungatedcontent_infra-agentic-era_brandposthub" target="_blank" rel="sponsored">Conversation Relay</a> enhancements add PCI compliance, HIPAA eligibility, Insights, and support for Deepgram Flux for smarter turn detection — helping AI agents better understand when a person has finished speaking.</li>



<li><a href="https://www.twilio.com/en-us/blog/partners/integrations/provision-twilio-communications-channels-stripe-projects?utm_source=foundry&amp;utm_medium=contentsyn&amp;utm_campaign=abm_brand_icp_sa_aw_tofu_apac_en&amp;utm_content=abm_lo_cs_ungatedcontent_infra-agentic-era_brandposthub" target="_blank" rel="sponsored">Stripe Projects integration</a> enables developers and AI agents to seamlessly provision Twilio within Stripe Projects in a single, programmable CLI workflow.</li>
</ul>



<h2 class="wp-block-heading">Built with our customers</h2>



<p>Bringing these new products to life required a close partnership with many beta customers and partners. This helped us understand real-world signals and needs to help make the capabilities robust from the start.</p>



<p>Among dozens of others, Centerfield, Constellation Dealerships, Car Finance 247, and Meera.ai leveraged Twilio to solve their own customer engagement challenges. These teams showed what is possible when businesses carry context forward, act on live conversation signals, and connect AI agents with human teams in the moments that matter.</p>



<p><a href="https://www.carfinance247.co.uk/" target="_blank" rel="noreferrer noopener">Car Finance 247</a>, a leading UK online car finance broker, is using Twilio to help recover stalled loan applications. When customers miss a field, need to correct information, or still need to confirm terms and conditions, AI-powered outreach across voice, SMS, and RCS, Conversation Memory tracks the application state. Conversation Orchestrator manages the outreach journey, and Flex helps bring in a human agent as needed. As Reg Rix, Co-Founder and CEO, shared:</p>



<p><em>“Because the platform remembers where each customer left off, we can pick up right where they stopped, helping them cross the finish line in a way that is modern, responsive, and genuinely helpful.”</em></p>



<p><a href="https://www.centerfield.com/" target="_blank" rel="sponsored">Centerfield</a>, a technology company powering AI-driven commerce, helps brands connect with consumers across digital and phone-based journeys. With Twilio, the team is connecting real-time conversation data with customer context to guide agents and AI systems in the moment, standardise what works, and improve performance at scale. As Aniketh Parmar, Chief Technology Officer, said:</p>



<p><em>“Performance comes down to how well every interaction moves a customer forward. We’re capturing each conversation in real time and applying what we already know about the customer to guide our agents and AI systems in the moment. With the Twilio Platform, including Conversation Orchestrator, Conversation Memory, and Conversation Intelligence, we can see what’s driving conversations so we can standardise what works, eliminate what doesn’t, and continuously improve outcomes at scale.”</em></p>



<p><a href="https://constellationdealer.com/" target="_blank" rel="sponsored">Constellation Dealerships</a> is using Twilio’s agent infrastructure to accelerate AI-powered engagement across its dealer network, moving from evaluation to measurable outcomes in days. As Richard Pineault, Director of R&amp;D, shared:</p>



<p><em>“The value of this partnership is evident—our team progressed from evaluating Twilio’s agent infrastructure to realising measurable outcomes within days. This rapid speed-to-value exemplifies the agility and innovation required to propel the dealership industry into the future.”</em></p>



<p><a href="http://meera.ai/" target="_blank" rel="sponsored">Meera.ai </a>is building on Twilio to modernise outbound engagement, replacing repeated manual follow-ups with always-on conversations across voice, SMS, and messaging. Vivek Zaveri, Chief Executive Officer, said:</p>



<p><em>“Meera.ai has partnered with Twilio since our inception to champion a conversation-first future for commerce. As the industry shifts toward real-time LLM-enabled interactions, Twilio’s Platform and the new Conversations products will help us reach customers in the moment.”</em></p>



<p>Together, these customers and partners show that the Twilio Platform can help businesses recover stalled journeys, improve live interactions, accelerate time to value, and create more connected experiences across AI agents, human teams, and every customer channel.</p>



<h2 class="wp-block-heading">The next era of customer engagement starts here</h2>



<p>As AI agents own more of customer engagement, businesses need infrastructure that keeps conversations connected across channels, systems, and teams. That means preserving context, coordinating handoffs, and acting on what is happening in real time.</p>



<p>That is what we are building with this next generation of the Twilio Platform: a new layer that connects channels, context, intelligence, and human and AI agents, helping businesses make every digital interaction more connected, more useful, and more amazing.</p>



<p>For 17 years, Twilio has helped builders create better ways for businesses to connect with their customers. In this next era, that connection matters more than ever.</p>



<p><a href="https://www.twilio.com/en-us/why-twilio?utm_source=foundry&amp;utm_medium=contentsyn&amp;utm_campaign=abm_brand_icp_sa_aw_tofu_apac_en&amp;utm_content=abm_lo_cs_ungatedcontent_end-cta-infra-agentic-era_brandposthub" target="_blank" rel="noreferrer noopener">Explore the new Conversations layer</a>, try the products, and let’s build what comes next, together.</p>



<hr class="wp-block-separator has-alpha-channel-opacity">
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Meta kills Muse Image feature that let anyone generate AI photos of Instagram users without consent]]></title>
<description><![CDATA[Meta pulled a controversial feature from its new Muse Image model after widespread criticism. The feature let users generate AI images of other people by @-mentioning their public Instagram accounts. No consent needed, just a username. Meta admits "this feature missed the mark" and shut it down d...]]></description>
<link>https://tsecurity.de/de/3663216/ai-nachrichten/meta-kills-muse-image-feature-that-let-anyone-generate-ai-photos-of-instagram-users-without-consent/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3663216/ai-nachrichten/meta-kills-muse-image-feature-that-let-anyone-generate-ai-photos-of-instagram-users-without-consent/</guid>
<pubDate>Sun, 12 Jul 2026 13:48:21 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1376" height="768" src="https://the-decoder.com/wp-content/uploads/2026/04/meta_ai_logo_wall_muse.png" class="attachment-full size-full wp-post-image" alt="" decoding="async"></p>
<p>        Meta pulled a controversial feature from its new Muse Image model after widespread criticism. The feature let users generate AI images of other people by @-mentioning their public Instagram accounts. No consent needed, just a username. Meta admits "this feature missed the mark" and shut it down days after announcing it.</p>
<p>The article <a href="https://the-decoder.com/meta-kills-muse-image-feature-that-let-anyone-generate-ai-photos-of-instagram-users-without-consent/">Meta kills Muse Image feature that let anyone generate AI photos of Instagram users without consent</a> appeared first on <a href="https://the-decoder.com/">The Decoder</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Facial Recognition in UK Shops Will Soon Instantly Alert Police About Offenders]]></title>
<description><![CDATA[Facial recognition technology in U.K. shops "will soon alert police in real time to the presence of serious offenders," reports The Guardian, "with civil liberties groups warning of a 'dangerous escalation' towards surveillance and criminalisation in the retail sector."

Facewatch, a facial recog...]]></description>
<link>https://tsecurity.de/de/3662955/it-security-nachrichten/facial-recognition-in-uk-shops-will-soon-instantly-alert-police-about-offenders/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3662955/it-security-nachrichten/facial-recognition-in-uk-shops-will-soon-instantly-alert-police-about-offenders/</guid>
<pubDate>Sun, 12 Jul 2026 10:07:44 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Facial recognition technology in U.K. shops "will soon alert police in real time to the presence of serious offenders," reports The Guardian, "with civil liberties groups warning of a 'dangerous escalation' towards surveillance and criminalisation in the retail sector."

Facewatch, a facial recognition system used by more than 100 businesses including Sainsbury's, B&amp;M and Spar to monitor thieves, said it was launching a UK-first feature to "alert police instantly when the most serious offenders trigger a live facial recognition match". Facewatch's chief executive, Nick Fisher, said the "unique technical development" would be launched in autumn and would warn police in an average of four seconds when the "worst offenders" were flagged on its network... Charlie Whelton, the policy and campaigns officer at [civil liberties nonprofit] Liberty, said it was concerned about this "untested, opaque development" and the way facial recognition technology had been allowed to "proliferate without anything to govern it". 
"It's not against the law to walk into a shop even if you've committed crimes in the past," he said. "The idea of calling the police on somebody who hasn't committed a crime, but there's a concern they might, is really upending the way we do things. And of course, it's not infallible. These systems do make mistakes, and it's very hard to argue with that when it happens to you." A number of people have been forced to leave shops after being falsely identified by Facewatch technology as a shoplifter, with some describing it as "Orwellian" and saying they felt as though they were "guilty until proven innocent"... 

The use of the Facewatch technology looks set to quickly expand, with Sainsbury's recently announcing plans to increase its use from 55 stores to more than 200 by the end of the year. Facewatch said it alerted retailers almost 300,000 times that a "known repeat offender" had entered a store during the first six months of 2026, and that its system allowed staff to intervene "before theft, abuse or violence could occur or escalate"... [E]xperts argue the use of facial recognition technology in shops to catch shoplifters is disproportionate. Nuala Polo, the UK public policy lead at the Ada Lovelace Institute, which studies the impact of AI on society, said: "There are other, much less intrusive means that you can use to catch shoplifters where you don't need to be scanning millions of faces every day, virtually without consent...." 

The campaign group Big Brother Watch has criticised police for "inserting themselves into this cowboy operation" and said people would be matched against "a secret blacklist compiled by unaccountable businesses and private security guards".<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=Facial+Recognition+in+UK+Shops+Will+Soon+Instantly+Alert+Police+About+Offenders%3A+https%3A%2F%2Fnews.slashdot.org%2Fstory%2F26%2F07%2F12%2F0259226%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fnews.slashdot.org%2Fstory%2F26%2F07%2F12%2F0259226%2Ffacial-recognition-in-uk-shops-will-soon-instantly-alert-police-about-offenders%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://news.slashdot.org/story/26/07/12/0259226/facial-recognition-in-uk-shops-will-soon-instantly-alert-police-about-offenders?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Cache is king: Announcing lower pricing for Cloud CDN]]></title>
<description><![CDATA[Organizations all over the world rely on Cloud CDN for fast, reliable web and video content delivery. Now, we’re making it even easier for you to take advantage of our global network and cache infrastructure by reducing the cost of Cloud CDN for your content delivery going forward.First, we’re re...]]></description>
<link>https://tsecurity.de/de/3662841/it-security-nachrichten/cache-is-king-announcing-lower-pricing-for-cloud-cdn/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3662841/it-security-nachrichten/cache-is-king-announcing-lower-pricing-for-cloud-cdn/</guid>
<pubDate>Sun, 12 Jul 2026 08:07:04 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div class="block-paragraph"><p>Organizations all over the world rely on Cloud CDN for fast, reliable web and video content delivery. Now, we’re making it even easier for you to take advantage of our global network and cache infrastructure by reducing the cost of Cloud CDN for your content delivery going forward.</p><p>First, we’re reducing the price of cache fill (content fetched from your origin) charges across the board, by up to 80%. You still get the benefit of our global private backbone for cache fill though—ensuring continued high performance, at a reduced cost. We’ve also removed cache-to-cache fill charges and cache invalidation charges for all customers going forward.</p><p>This price reduction, along with our recent introduction of <a href="https://cloud.google.com/cdn/docs/release-notes#September_14_2020">a new set of flexible caching capabilities</a>, makes it even easier to use Cloud CDN to optimize the performance of your applications. Cloud CDN can now automatically cache web assets, video content or software downloads, control exactly how they should be cached, and directly set response headers to help meet web security best practices.</p><p>You can <a href="https://cloud.google.com/cdn/pricing">review our updated pricing</a> in our public documentation, and customers egressing over 1PB per month should <a href="https://cloud.google.com/contact">reach out to our sales team</a> to discuss commitment-based discounts as part of your migration to Google Cloud.</p><p>To read more about Cloud CDN, or begin using it, <a href="https://cloud.google.com/cdn">start here</a>.</p></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Unifiedpost and Google collaborate on Document AI to automate procurement data capture]]></title>
<description><![CDATA[Belgian fintech company, Unifiedpost Group has deployed Procurement DocAI to process nearly 350 million invoices and other procure-to-pay docs per year, in 15 countries across Europe. Procurement DocAI, which was announced at Google Cloud Next OnAir, automates the capture of invoices, receipts an...]]></description>
<link>https://tsecurity.de/de/3662837/it-security-nachrichten/unifiedpost-and-google-collaborate-on-document-ai-to-automate-procurement-data-capture/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3662837/it-security-nachrichten/unifiedpost-and-google-collaborate-on-document-ai-to-automate-procurement-data-capture/</guid>
<pubDate>Sun, 12 Jul 2026 08:06:59 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div class="block-paragraph"><p>Belgian fintech company, <a href="https://www.unifiedpost.com/news/articles/pressrelease/pressrelease21oct2020" target="_blank">Unifiedpost Group</a> has deployed<a href="https://cloud.google.com/solutions/procurement-doc-ai"> Procurement DocAI</a> to process nearly 350 million invoices and other procure-to-pay docs per year, in 15 countries across Europe. </p><p>Procurement DocAI, which was <a href="https://cloud.google.com/blog/products/ai-machine-learning/ai-and-machine-learning-news-from-google-cloud">announced</a> at Google Cloud Next OnAir, automates the capture of invoices, receipts and other procurement data at scale. It takes unstructured documents across a variety of formats and turns them into cleanly structured data, increasing operational efficiency and improving document processing accuracy.    </p><p><i>“At Unifiedpost, we believe that administrative and financial processes should be simple and smart. Google Cloud’s Procurement DocAI solution helps us achieve that goal by providing the best in class document automation processing with high accuracy and global, multi-language support.” - <b>Hans Leybaert, CEO, Unifiedpost Group</b></i><br></p></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/original_images/Procurement_DocAI.gif" alt="DocAI.gif">
        
        
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph"><p>Large enterprise procurement and distribution networks as well as small and medium enterprises (SMEs) generate millions of invoices, receipts, and other related documents a year. These processes generate significant overhead for every procured item. With competitive pressures increasing, businesses are finding new ways to automate one of their highest volume business processes -- the procurement cycle.</p><p>A key part of our strategy at Google Cloud is the creation of industry-specific solutions that address vertical needs. Cross-industry solutions like <a href="https://cloud.google.com/solutions/document-ai">Document AI</a> are built to plug into your existing workflows and deliver business results from AI without having to hire an army of AI experts, or manage cloud infrastructure to get there.</p><p><a href="https://cloud.google.com/solutions/procurement-doc-ai">Procurement DocAI</a> is one of our newest solutions, and it’s deployed by many customers and partners including Unifiedpost. The company currently serves 400k SMEs and 250+ corporations; their offering includes: documents (e.g., invoice PDF to XML conversion, e-invoicing), identity (e.g., KYC), and payments (e.g., IBAN accounts, online collection services, PSD2 payment services). </p><p>With a large, rapidly growing, and heavily multi-language footprint, Unifiedpost sought the best industry solutions to meet their automation challenges and connect their customers such as Billtobox.com or JeFacture.com. Google Cloud’s Procurement DocAI delivered two key benefits to address Unifiedpost’s business needs:</p><ul><li><p><b>Lower TCO of procure-to-pay processing</b>. Unifiedpost will be able to lower their TCO of procure-to-pay processing costs by up to 60% with Procurement DocAI. This solution provided them a cost effective approach for data extraction for invoices, receipts, and other valuable documents in the procurement cycle of procure to invoice, and invoice to pay.</p></li><li><p><b>Improve procurement document processing accuracy</b>. Procurement DocAI also helped boost data accuracy by 250% for Unifiedpost’s document extraction through specialized DocAI parsers with advanced OCR, computer vision, and Natural Language Processing. Additionally, Unifiedpost needed rapid multi-language expansion to enable regionalization support across Europe, particularly for French and Dutch to begin with, which Google delivered in less than a month.</p></li></ul><p>The collaboration between Google Cloud and Unifiedpost is just one of the latest examples of how we’re providing AI-powered functional solutions to solve business problems by leveraging our <a href="https://cloud.google.com/blog/products/ai-machine-learning/see-how-google-cloud-customers-transform-their-businesses-with-ai">Deployed AI approach</a>.</p><h3>Let’s connect</h3><p>For more customer stories from EMEA, check out <a href="https://cloud.google.com/blog/topics/google-cloud-next/announcing-google-cloud-next20-onair-emea">Google Cloud Next OnAir EMEA</a>, which has tailored content to support the needs of our customers in Europe, Middle East, and Africa, kicking off from 29 September - 27 October. <br></p></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Buildpacks vs Jib vs Dockerfile: Comparing containerization methods]]></title>
<description><![CDATA[As developers we work on source code, but production systems don't run source, they need a runnable thing. Starting many years ago, most enterprises were using Java EE (aka J2EE) and the runnable "thing" we would deploy to production was a ".jar", ".war", or ".ear" file. Those files consisted of ...]]></description>
<link>https://tsecurity.de/de/3662836/it-security-nachrichten/buildpacks-vs-jib-vs-dockerfile-comparing-containerization-methods/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3662836/it-security-nachrichten/buildpacks-vs-jib-vs-dockerfile-comparing-containerization-methods/</guid>
<pubDate>Sun, 12 Jul 2026 08:06:57 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div class="block-paragraph"><p>As developers we work on source code, but production systems don't run source, they need a runnable thing. Starting many years ago, most enterprises were using Java EE (aka J2EE) and the runnable "thing" we would deploy to production was a ".jar", ".war", or ".ear" file. Those files consisted of the compiled Java classes and would run inside of a "container" running on the JVM. As long as your class files were compatible with the JVM and container, the app would just work.</p><p>That all worked great until people started building non-JVM stuff: Ruby, Python, NodeJS, Go, etc. Now we needed another way to package up apps so they could be run on production systems. To do this we needed some kind of virtualization layer that would allow anything to be run. Heroku was one of the first to tackle this and they used a Linux virtualization system called "lxc" - short for Linux Containers. Running a "container" on lxc was half of the puzzle because still a "container" needed to be created from source code, so Heroku invented what they called "Buildpacks" to create a standard way to convert source into a container.</p><p>A bit later a Heroku competitor named dotCloud was trying to tackle similar problems and went a different route which ultimately led to Docker, a standard way to create and run containers across platforms including Windows, Mac, Linux, Kubernetes, and Google Cloud Run. Ultimately the container specification behind Docker became a standard under the <a href="https://opencontainers.org/" target="_blank">Open Container Initiative (OCI)</a> and the virtualization layer switched from lxc to <a href="https://github.com/opencontainers/runc" target="_blank">runc</a> (also an OCI project).</p><p>The traditional way to build a Docker container is built into the <code>docker</code> tool and uses a sequence of special instructions usually in a file named <code>Dockerfile</code> to compile the source code and assemble the "layers" of a container image.</p><p>Yeah, this is confusing because we have all sorts of different "containers" and ways to run stuff in those containers. And there are also many ways to create the things that run in containers. The bit of history is important because it helps us categorize all of this into three parts:</p><ul><li>Container Builders - Turn source code into a Container Image</li><li>Container Images - Archive files containing a "runnable" application</li><li>Containers - Run Container Images</li></ul><p>With Java EE those three categories map to technologies like:</p><ul><li>Container Builders == Ant or Maven</li><li>Container Images == .jar, .war, or .ear</li><li>Containers == JBoss, WebSphere, WebLogic</li></ul><p>With Docker / OCI those three categories map to technologies like:</p><ul><li>Container Builders == Dockerfile, Buildpacks, or Jib</li><li>Container Images == .tar files usually not dealt with directly but through a "container registry"</li><li>Containers == Docker, Kubernetes, Cloud Run</li></ul><h3>Java Sample Application</h3>Let's explore the Container Builder options further on a little Java server application.  If you want to follow along, clone my <a href="https://github.com/jamesward/comparing-docker-methods" target="_blank">comparing-docker-methods project</a>:<p><code>git clone https://github.com/jamesward/comparing-docker-methods.git</code><br></p><p><code>cd comparing-docker-methods</code></p><p></p><p>In that project you'll see a basic Java web server in <code>src/main/java/com/google/WebApp.java</code> that just responds with "hello, world" on a GET request to <code>/</code>. Here is the source:<br></p><p></p></div>
<div class="block-code"><dl>
    <dt>code_block</dt>
    <dd>&lt;ListValue: [StructValue([('code', 'package com.google;\r\n\r\nimport com.sun.net.httpserver.HttpServer;\r\nimport java.io.IOException;\r\nimport java.io.OutputStream;\r\nimport java.net.InetSocketAddress;\r\n\r\npublic class WebApp {\r\n\r\n  public static void main(String[] args) throws IOException {\r\n    int port = Integer.parseInt(System.getenv().getOrDefault("PORT", "8080"));\r\n    HttpServer server = HttpServer.create(new InetSocketAddress(port), 0);\r\n\r\n    server.createContext("/", handler -&gt; {\r\n      byte[] response = "hello, world".getBytes();\r\n      handler.sendResponseHeaders(200, response.length);\r\n      try (OutputStream os = handler.getResponseBody()) {\r\n        os.write(response);\r\n      }\r\n    });\r\n\r\n    System.out.println("Listening at http://localhost:" + port);\r\n\r\n    server.start();\r\n  }\r\n}'), ('language', ''), ('caption', &lt;wagtail.rich_text.RichText object at 0x7f58aa860670&gt;)])]&gt;</dd>
</dl></div>
<div class="block-paragraph"><p>This project uses Maven with a minimal <code>pom.xml</code> build config file for compiling and running the Java server:</p></div>
<div class="block-code"><dl>
    <dt>code_block</dt>
    <dd>&lt;ListValue: [StructValue([('code', '&lt;?xml version="1.0" encoding="UTF-8"?&gt;\r\n&lt;project xmlns="http://maven.apache.org/POM/4.0.0" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"\r\n    xsi:schemaLocation="http://maven.apache.org/POM/4.0.0 http://maven.apache.org/maven-v4_0_0.xsd"&gt;\r\n  &lt;modelVersion&gt;4.0.0&lt;/modelVersion&gt;\r\n\r\n  &lt;groupId&gt;com.google&lt;/groupId&gt;\r\n  &lt;artifactId&gt;sample-java-mvn&lt;/artifactId&gt;\r\n  &lt;packaging&gt;jar&lt;/packaging&gt;\r\n  &lt;version&gt;0.1.0-SNAPSHOT&lt;/version&gt;\r\n\r\n  &lt;properties&gt;\r\n    &lt;maven.compiler.source&gt;8&lt;/maven.compiler.source&gt;\r\n    &lt;maven.compiler.target&gt;8&lt;/maven.compiler.target&gt;\r\n  &lt;/properties&gt;\r\n\r\n  &lt;build&gt;\r\n    &lt;plugins&gt;\r\n      &lt;plugin&gt;\r\n        &lt;groupId&gt;org.codehaus.mojo&lt;/groupId&gt;\r\n        &lt;artifactId&gt;exec-maven-plugin&lt;/artifactId&gt;\r\n        &lt;version&gt;1.6.0&lt;/version&gt;\r\n        &lt;executions&gt;\r\n          &lt;execution&gt;\r\n            &lt;goals&gt;\r\n              &lt;goal&gt;java&lt;/goal&gt;\r\n            &lt;/goals&gt;\r\n          &lt;/execution&gt;\r\n        &lt;/executions&gt;\r\n        &lt;configuration&gt;\r\n          &lt;mainClass&gt;com.google.WebApp&lt;/mainClass&gt;\r\n        &lt;/configuration&gt;\r\n      &lt;/plugin&gt;\r\n\r\n      &lt;plugin&gt;\r\n        &lt;groupId&gt;org.apache.maven.plugins&lt;/groupId&gt;\r\n        &lt;artifactId&gt;maven-jar-plugin&lt;/artifactId&gt;\r\n        &lt;version&gt;3.2.0&lt;/version&gt;\r\n        &lt;configuration&gt;\r\n          &lt;archive&gt;\r\n            &lt;manifest&gt;\r\n              &lt;mainClass&gt;com.google.WebApp&lt;/mainClass&gt;\r\n            &lt;/manifest&gt;\r\n          &lt;/archive&gt;\r\n        &lt;/configuration&gt;\r\n      &lt;/plugin&gt;\r\n    &lt;/plugins&gt;\r\n  &lt;/build&gt;\r\n\r\n&lt;/project&gt;'), ('language', ''), ('caption', &lt;wagtail.rich_text.RichText object at 0x7f58aa860c10&gt;)])]&gt;</dd>
</dl></div>
<div class="block-paragraph"><p>If you want to run this locally make sure you have Java 8 installed and from the project root directory, run:</p><p><code>./mvnw compile exec:java</code></p><p>You can test the server by visiting: <a href="http://localhost:8080/" target="_blank">http://localhost:8080</a></p><h3>Container Builder: Buildpacks</h3><p>We have an application that we can run locally so let's get back to those Container Builders. Earlier you learned that Heroku invented Buildpacks to create standard, polyglot ways to go from source to a Container Image. When Docker / OCI Containers started gaining popularity Heroku and Pivotal worked together to make their Buildpacks work with Docker / OCI Containers. That work is now a sandbox Cloud Native Computing Foundation project: <a href="https://buildpacks.io/" target="_blank">https://buildpacks.io/</a></p><p>To use Buildpacks you will need to <a href="https://docs.docker.com/get-started/" target="_blank">install Docker</a> and <a href="https://github.com/buildpacks/pack/releases" target="_blank">the pack tool</a>. Now from the command line tell Buildpacks to take your source and turn it into a Container Image:</p><p><code>pack build --builder=gcr.io/buildpacks/builder:v1 comparing-docker-methods:buildpacks</code></p><p>Magic! You didn't have to do anything and the Buildpacks knew how to turn that Java application into a Container Image. It even works on Go, NodeJS, Python, and .Net apps out-of-the-box. So what just happened?  Buildpacks inspect your source and try to identify it as something it knows how to build. In the case of our sample application it noticed the <code>pom.xml</code> file and decided it knows how to build Maven-based applications. The <code>--builder</code> flag told it where to get the Buildpacks from. In this case, <code>gcr.io/buildpacks/builder:v1</code> are the Container Image coordinates to <a href="https://cloud.google.com/blog/products/containers-kubernetes/google-cloud-now-supports-buildpacks">Google Cloud's Buildpacks</a>. Alternatively you could use the Heroku or Paketo Buildpacks. The parameter <code>comparing-docker-methods:buildpacks</code> is the Container Image coordinates for where to store the output. In this case it stores on the local docker daemon. You can now run that Container Image locally with <code>docker</code>:</p><p><code>docker run -it -ePORT=8080 -p8080:8080 comparing-docker-methods:buildpacks</code></p><p>Of course you can also run that Container Image anywhere that runs Docker / OCI Containers like Kubernetes and Cloud Run.</p><p>Buildpacks are nice because in many cases they just work and you don't have to do anything special to turn your source into something runnable. But the resulting Container Images created from Buildpacks can be a bit bulky. Let's use a tool called <a href="https://github.com/wagoodman/dive" target="_blank"><code>dive</code></a> to examine what is in the created container image:</p><p><code>dive comparing-docker-methods:buildpacks</code></p><p></p><p></p></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/Dive_comparison.max-1000x1000.png" alt="Container Image">
        
        
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph"><p>Here you can see the Container Image has 11 layers and a total image size of 319MB. With <code>dive</code> you can explore each layer and see what was changed. In this Container Image the first 6 layers are the base operating system. Layer 7 is the JVM and layer 8 is our compiled application. Layering enables great caching so if only layer 8 changes, then layers 1 through 7 do not need to be re-downloaded. One downside of Buildpacks is how (at least for now) all of the dependencies and compiled application code are stored in a single layer. It would be better to have separate layers for the dependencies and the compiled application.</p><p>To recap, Buildpacks are the easy option that "just works" right out-of-the-box. But the Container Images are a bit large and not optimally layered.</p><h3>Container Builder: Jib</h3><p>The open source <a href="https://github.com/GoogleContainerTools/jib" target="_blank">Jib project</a> is a Java library for creating Container Images with Maven and Gradle plugins. To use it on a Maven project (like the one we from above), just add a build plugin to the <code>pom.xml</code> file:</p></div>
<div class="block-code"><dl>
    <dt>code_block</dt>
    <dd>&lt;ListValue: [StructValue([('code', '&lt;plugin&gt;\r\n    &lt;groupId&gt;com.google.cloud.tools&lt;/groupId&gt;\r\n    &lt;artifactId&gt;jib-maven-plugin&lt;/artifactId&gt;\r\n    &lt;version&gt;2.6.0&lt;/version&gt;\r\n&lt;/plugin&gt;'), ('language', ''), ('caption', &lt;wagtail.rich_text.RichText object at 0x7f58aa860d30&gt;)])]&gt;</dd>
</dl></div>
<div class="block-paragraph"><p>Now a Container Image can be created and stored in the local docker daemon by running:</p><p><code>./mvnw compile jib:dockerBuild -Dimage=comparing-docker-methods:jib</code></p><p>Using <code>dive</code> we will see that the Container Image for this application is now only 127MB thanks to slimmer operating system and JVM layers. Also, on a Spring Boot application we can see how Jib layers the dependencies, resources, and compiled application for better caching:</p></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/Spring_Boot_Application.max-1000x1000.png" alt="Spring Boot Application">
        
        
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph"><p>In this example the 18MB layer contains the runtime dependencies and the final layer contains the compiled application. Unlike with Buildpacks the original source code is not included in the Container Image. Jib also has a great feature where you can use it without docker being installed, as long as you store the Container Image on an external Container Registry (like DockerHub or the Google Cloud Container Registry). Jib is a great option with Maven and Gradle builds for Container Images that use the JVM.</p><h3>Container Builder: Dockerfile</h3><p>The traditional way to create Container Images is built into the <code>docker</code> tool and uses a sequence of instructions defined in a file usually named <code>Dockerfile</code>. Here is a <code>Dockerfile</code> you can use with the sample Java application:</p></div>
<div class="block-code"><dl>
    <dt>code_block</dt>
    <dd>&lt;ListValue: [StructValue([('code', 'FROM adoptopenjdk/openjdk8 as builder\r\n\r\nWORKDIR /app\r\nCOPY . /app\r\n\r\nRUN ./mvnw compile jar:jar\r\n\r\nFROM adoptopenjdk/openjdk8:jre\r\n\r\nCOPY --from=builder /app/target/*.jar /server.jar\r\n\r\nCMD ["java", "-jar", "/server.jar"]'), ('language', ''), ('caption', &lt;wagtail.rich_text.RichText object at 0x7f58aa860d90&gt;)])]&gt;</dd>
</dl></div>
<div class="block-paragraph"><p>In this example, the first four instructions start with the AdoptOpenJDK 8 Container Image and build the source to a Jar file. The final Container Image is created from the AdoptOpenJDK 8 JRE Container Image and includes the created Jar file. You can run <code>docker</code> to create the Container Image using the <code>Dockerfile</code> instructions:</p><p><code>docker build -t comparing-docker-methods:dockerfile </code></p><p>Using <code>dive</code> we can see a pretty slim Container Image at 209MB:<br></p></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/Container_image.max-1000x1000.png" alt="Container Image">
        
        
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph"><p>With a <code>Dockerfile</code> we have full control over the layering and base images. For example, we could use the <a href="https://github.com/GoogleContainerTools/distroless/tree/master/java" target="_blank">Distroless Java base image</a> to trim down the Container Image even further. This method of creating Container Images provides a lot of flexibility but we do have to write and maintain the instructions.</p><p>With this flexibility we can do some cool stuff. For example, we can use GraalVM to create a "native image" of our application. This is an ahead-of-time compiled binary which can reduce startup time, reduce memory usage, and alleviate the need for a JVM in the Container Image. And we can go even further and create a statically linked native image which includes everything needed to run so that even an operating system is not needed in the Container Image. Here is the Dockerfile to do that:</p></div>
<div class="block-code"><dl>
    <dt>code_block</dt>
    <dd>&lt;ListValue: [StructValue([('code', 'FROM oracle/graalvm-ce:20.2.0-java11 as builder\r\n\r\nWORKDIR /app\r\nCOPY . /app\r\n\r\nRUN gu install native-image\r\n\r\n# BEGIN PRE-REQUISITES FOR STATIC NATIVE IMAGES FOR GRAAL 20.2.0\r\n# SEE: https://github.com/oracle/graal/blob/master/substratevm/StaticImages.md\r\nARG RESULT_LIB="/staticlibs"\r\n\r\nRUN mkdir ${RESULT_LIB} &amp;&amp; \\\r\n    curl -L -o musl.tar.gz https://musl.libc.org/releases/musl-1.2.1.tar.gz &amp;&amp; \\\r\n    mkdir musl &amp;&amp; tar -xvzf musl.tar.gz -C musl --strip-components 1 &amp;&amp; cd musl &amp;&amp; \\\r\n    ./configure --disable-shared --prefix=${RESULT_LIB} &amp;&amp; \\\r\n    make &amp;&amp; make install &amp;&amp; \\\r\n    cd / &amp;&amp; rm -rf /muscl &amp;&amp; rm -f /musl.tar.gz &amp;&amp; \\\r\n    cp /usr/lib/gcc/x86_64-redhat-linux/4.8.2/libstdc++.a ${RESULT_LIB}/lib/\r\n\r\nENV PATH="$PATH:${RESULT_LIB}/bin"\r\nENV CC="musl-gcc"\r\n\r\nRUN curl -L -o zlib.tar.gz https://zlib.net/zlib-1.2.11.tar.gz &amp;&amp; \\\r\n   mkdir zlib &amp;&amp; tar -xvzf zlib.tar.gz -C zlib --strip-components 1 &amp;&amp; cd zlib &amp;&amp; \\\r\n   ./configure --static --prefix=${RESULT_LIB} &amp;&amp; \\\r\n    make &amp;&amp; make install &amp;&amp; \\\r\n    cd / &amp;&amp; rm -rf /zlib &amp;&amp; rm -f /zlib.tar.gz\r\n#END PRE-REQUISITES FOR STATIC NATIVE IMAGES FOR GRAAL 20.2.0\r\n\r\nRUN ./mvnw compile jar:jar\r\n\r\nRUN native-image \\\r\n  --static \\\r\n  --libc=musl \\\r\n  --no-fallback \\\r\n  --no-server \\\r\n  --install-exit-handlers \\\r\n  -H:Name=webapp \\\r\n  -cp /app/target/*.jar \\\r\n  com.google.WebApp\r\n\r\nFROM scratch\r\n\r\nCOPY --from=builder /app/webapp /webapp\r\n\r\nENTRYPOINT ["/webapp"]'), ('language', ''), ('caption', &lt;wagtail.rich_text.RichText object at 0x7f58aa860df0&gt;)])]&gt;</dd>
</dl></div>
<div class="block-paragraph"><p>You will see there is a bit of setup needed to support static native images. After that setup the Jar is compiled like before with Maven. Then the <code>native-image</code> tool creates the binary from the Jar. The <code>FROM scratch</code> instruction means the final container image will start with an empty one. The statically linked binary created by <code>native-image</code> is then copied into the empty container.</p><p>Like before you can use <code>docker</code> to build the Container Image:</p><p><code>docker build -t comparing-docker-methods:graalvm .</code></p><p>Using <code>dive</code> we can see the final Container Image is only 11MB!</p></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/Dive_Image.max-1000x1000.png" alt="Container Image">
        
        
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph"><p>And it starts up super fast because we don't need the JVM, OS, etc. Of course GraalVM is not always a great option as there are some challenges like dealing with reflection and debugging. You can read more about this in my blog, <a href="https://jamesward.com/2020/05/07/graalvm-native-image-tips-tricks/" target="_blank">GraalVM Native Image Tips &amp; Tricks</a>.</p><p>This example does capture the flexibility of the <code>Dockerfile</code> method and the ability to do anything you need. It is a great escape hatch when you need one.</p><h3>Which Method Should You Choose?</h3><p></p><ul><li>The easiest, polyglot method: Buildpacks</li><li>Great layering for JVM apps: Jib</li><li>The escape hatch for when those methods don't fit: Dockerfile</li></ul><p></p><p>Check out my <a href="https://github.com/jamesward/comparing-docker-methods" target="_blank">comparing-docker-methods project</a> to explore these methods as well as the mentioned Spring Boot + Jib example.</p></div>
<div class="block-related_article_tout">





<div class="uni-related-article-tout h-c-page">
  <section class="h-c-grid">
    <a href="https://cloud.google.com/blog/products/containers-kubernetes/google-cloud-now-supports-buildpacks/" data-analytics='{
                       "event": "page interaction",
                       "category": "article lead",
                       "action": "related article - inline",
                       "label": "article: {slug}"
                     }' class="uni-related-article-tout__wrapper h-c-grid__col h-c-grid__col--8 h-c-grid__col-m--6 h-c-grid__col-l--6
        h-c-grid__col--offset-2 h-c-grid__col-m--offset-3 h-c-grid__col-l--offset-3 uni-click-tracker">
      <div class="uni-related-article-tout__inner-wrapper">
        <p class="uni-related-article-tout__eyebrow h-c-eyebrow">Related Article</p>

        <div class="uni-related-article-tout__content-wrapper">
          <div class="uni-related-article-tout__image-wrapper">
            <div class="uni-related-article-tout__image"></div>
          </div>
          <div class="uni-related-article-tout__content">
            <h4 class="uni-related-article-tout__header h-has-bottom-margin">Announcing Google Cloud buildpacks—container images made easy</h4>
            <p class="uni-related-article-tout__body">Google Cloud buildpacks make it much easier and faster to build applications on top of containers.</p>
            <div class="cta module-cta h-c-copy  uni-related-article-tout__cta muted">
              <span class="nowrap">Read Article
                <svg class="icon h-c-icon" role="presentation">
                  <use xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="#mi-arrow-forward"></use>
                </svg>
              </span>
            </div>
          </div>
        </div>
      </div>
    </a>
  </section>
</div>

</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Enhancing our privacy commitments to customers]]></title>
<description><![CDATA[Around the world, companies in every industry rely on our cloud services to run their businesses, and we take that responsibility seriously. That’s why we’re focused on providing industry-leading security and product capabilities, certifications, and commitments, along with transparency and visib...]]></description>
<link>https://tsecurity.de/de/3662834/it-security-nachrichten/enhancing-our-privacy-commitments-to-customers/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3662834/it-security-nachrichten/enhancing-our-privacy-commitments-to-customers/</guid>
<pubDate>Sun, 12 Jul 2026 08:06:55 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div class="block-paragraph_advanced"><p><span>Around the world, companies in every industry rely on our cloud services to run their businesses, and we take that responsibility seriously. That’s why we’re focused on providing industry-leading security and product capabilities, certifications, and commitments, along with transparency and visibility into when and how customer data is accessed. Today, we’re expanding on these commitments and sharing an update on our latest work in this area. </span></p>
<h3><strong>Commitment to privacy </strong></h3>
<p><span>Our </span><a href="https://cloud.google.com/privacy"><span>Google Cloud Enterprise Privacy Commitments</span></a><span> outline how we protect the privacy of customers whenever they use </span><a href="https://workspace.google.com/" rel="noopener" target="_blank"><span>Google Workspace</span></a><span>, </span><a href="https://edu.google.com/workspace-for-education/editions/education-fundamentals/?hl=en" rel="noopener" target="_blank"><span>Google Workspace for Education</span></a><span> and </span><a href="https://cloud.google.com/gcp/"><span>Google Cloud </span></a><span>. There are two distinct types of data that we consider across both of these platforms</span><strong>—</strong><span>customer data and service data:</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><strong>Customer data: </strong><span>We start from the fundamental premise that, as a Google Cloud customer, you own your customer data. We implement stringent security measures to safeguard that data, and provide you with tools to control it on your terms. Customer data is the data you, including your organization and your users, provide to Google when you access Google Workspace, Google Workspace for Education and Google Cloud, and the data you create using those services.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>Service data: </strong><span>We also secure any service data</span><strong>—</strong><span>the information Google Cloud collects or generates while providing and administering Google Workspace</span><span>, Google Workspace for Education, and Google Cloud </span><strong>— </strong><span>which is </span><span>critical to help ensure the security and availability of our services. </span><span>Service data does not include customer data </span><strong>— </strong><span>it includes information about security settings, operational details, and billing information. </span><span>We process service data for the purposes that are detailed in our </span><a href="http://cloud.google.com/terms/cloud-privacy-notice"><span>Google Cloud Privacy Notice</span></a><span> (newly launched to provide more specific information about how we process service data, and effective November 27, 2020), such as making recommendations to optimize your use of Google Workspace and Google Cloud, and improving performance and functionality.</span></p>
</li>
</ul>
<p><span>When you use Google Cloud services, you can be confident that:</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><strong>You control your data. </strong><span>Customer data is your data, not Google Cloud’s. We only process your data according to your agreement(s). </span></p>
</li>
</ul>
<ul>
<li aria-level="1">
<p role="presentation"><strong>We never use your data for ads targeting.</strong><span> We do not process your customer data or service data to create ads profiles or improve Google Ads products.</span></p>
</li>
</ul>
<ul>
<li aria-level="1">
<p role="presentation"><strong>We are transparent about data collection and use. </strong><span>We’re committed to transparency, compliance with regulations like the GDPR, and privacy best practices.</span></p>
</li>
</ul>
<ul>
<li aria-level="1">
<p role="presentation"><strong>We never sell customer data or service data. </strong><span>We never sell customer data or service data to third parties.</span></p>
</li>
</ul>
<ul>
<li aria-level="1">
<p role="presentation"><strong>Security and privacy are primary design criteria for all of our products. </strong><span>Prioritizing the privacy of our customers means protecting the data you trust us with. We build the strongest security technologies into our products.</span></p>
</li>
</ul>
<p><span>These commitments are backed by the strong contractual privacy commitments we make available to our customers for </span><a href="https://workspace.google.com/" rel="noopener" target="_blank"><span>Google Workspace</span></a><span>, </span><a href="https://edu.google.com/workspace-for-education/editions/education-fundamentals/?hl=en" rel="noopener" target="_blank"><span>Google Workspace for Education</span></a><span> and </span><a href="https://cloud.google.com/terms/data-processing-terms"><span>Google Cloud</span></a><span>. </span></p>
<h3><strong>Enhanced customer controls and new third party certifications</strong></h3>
<p><span>We recently</span><span> released new capabilities that further improve visibility and control over how data in our cloud is accessed and processed. In 2018, we were the first major cloud provider to bring </span><a href="https://cloud.google.com/blog/products/gcp/building-trust-through-access-transparency"><span>Access Transparency</span></a><span> to our customers, providing you with near real-time logs of the rare occasions Google Cloud administrators access your content. To give you even more visibility and control, we’ve made </span><a href="https://cloud.google.com/access-transparency"><span>Access Approval</span></a><span> for Google Cloud generally available to let you approve or dismiss requests for access by Google employees working to support your service. </span></p>
<p><span>Our </span><a href="https://cloud.google.com/recommender/docs/transparency-and-control-center/audit-logging"><span>Transparency &amp; Control Center</span></a><span> is also now generally available as part of the Google Cloud Console. It gives you the ability to </span><a href="https://cloud.google.com/recommender/docs/opting-out"><span>enable and disable data processing</span></a><span> that supports features such as recommendations and insights at the organization and project level. It also allows you to </span><a href="https://cloud.google.com/iam/docs/recommender-exporting-data"><span>export personal data</span></a><span> that may be used to generate recommendations and insights. </span></p>
<p><span>For Google Workspace, in addition to providing granular </span><a href="https://support.google.com/a/answer/9725452?hl=en&amp;ref_topic=9027054" rel="noopener" target="_blank"><span>audit logs</span></a><span>, we offer organization admins and users the ability to download a copy of their data via the </span><a href="https://support.google.com/a/answer/100458?hl=en" rel="noopener" target="_blank"><span>data export tool</span></a><span> and </span><a href="https://support.google.com/accounts/answer/3024190" rel="noopener" target="_blank"><span>Google Takeout</span></a><span>. These are just some of the ways we help support data portability requirements under privacy regulations such as the EU’s GDPR and the California Consumer Privacy Act (CCPA).</span></p>
<p><span>We continue to reinforce our commitment to privacy by meeting the requirements of internationally-recognized privacy laws, regulations, and standards. This summer we announced</span><span> that we are the </span><a href="https://cloud.google.com/blog/products/identity-security/google-cloud-certified-as-a-data-processor"><span>first major cloud provider</span></a><span> and </span><a href="https://cloud.google.com/blog/products/workspace/announcing-new-security-and-privacy-updates-in-google-workspace"><span>productivity suite</span></a><span> to receive accredited</span><span> </span><a href="http://cloud.google.com/security/compliance/iso-27701"><span>ISO/IEC 27701 certification</span></a><span> as a data processor. Our </span><a href="https://services.google.com/fh/files/misc/gcp_iso27701_june_2020.pdf" rel="noopener" target="_blank"><span>accredited ISO/IEC 27701 certifications</span></a><span> for Google Workspace and Google Cloud provide customers with benefits including simplified audit processes, universal privacy controls and greater clarity around privacy-related roles and responsibilities. </span><span>Certifications provide independent validation of our ongoing dedication to world-class security and privacy, and we look forward to obtaining </span><a href="https://cloud.google.com/security/compliance"><span>additional certifications</span></a><span> in the future. </span></p>
<h3><strong>Continued innovation to support customer needs </strong></h3>
<p><span>As the global privacy landscape and our customers’ needs change, Google Cloud will continue to work diligently to maintain our commitments to privacy, control and transparency. To learn more about our efforts, visit </span><a href="https://cloud.google.com/security/"><span>our Trust and Security center</span></a><span>.</span></p></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[What’s new with Google Cloud]]></title>
<description><![CDATA[Want to know the latest from Google Cloud? Find it here in one handy location. Check back regularly for our newest updates, announcements, resources, events, learning opportunities, and more. Tip: Not sure where to find what you’re looking for on the Google Cloud blog? Start here: Google Cloud bl...]]></description>
<link>https://tsecurity.de/de/3662833/it-security-nachrichten/whats-new-with-google-cloud/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3662833/it-security-nachrichten/whats-new-with-google-cloud/</guid>
<pubDate>Sun, 12 Jul 2026 08:06:50 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div class="block-paragraph"><p data-block-key="kgod7">Want to know the latest from Google Cloud? Find it here in one handy location. Check back regularly for our newest updates, announcements, resources, events, learning opportunities, and more. </p><hr><p data-block-key="ru1z9"><b>Tip</b>: Not sure where to find what you’re looking for on the Google Cloud blog? Start here: <a href="https://cloud.google.com/blog/topics/inside-google-cloud/complete-list-google-cloud-blog-links-2021">Google Cloud blog 101: Full list of topics, links, and resources</a>.</p><hr><p data-block-key="b0lnw"></p></div>
<div class="block-aside"><dl>
    <dt>aside_block</dt>
    <dd>&lt;ListValue: []&gt;</dd>
</dl></div>
<div class="block-paragraph_advanced"><h3>Jul 6 - Jul 10</h3>
<ul>
<li><strong>Webinar: Introducing Google Cloud NGFW Enterprise advanced malware protection - powered by Palo Alto Networks<br></strong>Discover the new Cloud NGFW advanced malware sandbox, arriving in preview later this year. Powered by Palo Alto Networks Advanced Wildfire, it leverages data from 70,000+ customers to help defeat advanced malware. Join us on July 16 at 11 AM EDT to learn how to build a resilient, zero-trust cloud infrastructure that protects your apps and data, wherever they reside.<br><br><a class="colors-hyperlink-primary underline focus-visible outline-offset-0 rounded" data-airgap-id="18" href="https://www.brighttalk.com/webcast/18282/668861?utm_source=GCBlog" rel="noreferrer noopener" target="_blank">Register for the webinar now</a></li>
<li><strong>Safely run AI-generated code in Cloud Run sandboxes<br></strong>Cloud Run sandboxes, now in public preview, are lightweight, isolated execution boundaries that you can spawn near-instantly <strong>within your existing Cloud Run service instances</strong>.<br><br>Whether you need to let an LLM run a dynamically generated Python script to calculate business margins or spin up a headless browser to perform web research, Cloud Run sandboxes give you a secure, isolated sandbox to run these tasks without leaving your serverless environment.<br><br><a class="colors-hyperlink-primary underline focus-visible outline-offset-0 rounded" data-airgap-id="22" href="https://cloud.google.com/blog/topics/developers-practitioners/google-cloud-run-sandboxes-are-in-public-preview" rel="noreferrer noopener" target="_blank">Read the blog</a><span> to learn more and get started today.</span></li>
<li><strong>Australia API Horizon: Scaling Enterprise Governed AI Agents<br></strong>The transition from AI chatbots to autonomous agents is the most critical integration point for your business. Join Google Cloud at our upcoming events to explore exclusive deep-dive sessions on architecting for the agentic era.<br><br>Discover how to use Apigee as an intelligent AI Gateway to govern, secure, and scale high-performance architectures. You will learn to seamlessly build AI tools from your existing APIs and maintain control over your entire ecosystem.<br><br>Join us in your preferred city:
<ul>
<li><a class="colors-hyperlink-primary underline focus-visible outline-offset-0 rounded" data-airgap-id="36" href="https://goo.gle/4voh18S" rel="noreferrer noopener" target="_blank"><strong>Sydney:</strong> July 28, 2026, at Google Sydney, One Darling Island.</a></li>
<li><a class="colors-hyperlink-primary underline focus-visible outline-offset-0 rounded" data-airgap-id="37" href="https://goo.gle/4h2x0FS" rel="noreferrer noopener" target="_blank"><strong>Canberra:</strong> July 29, 2026, at Hotel Realm.</a></li>
<li><a class="colors-hyperlink-primary underline focus-visible outline-offset-0 rounded" data-airgap-id="38" href="https://goo.gle/4yisb1F" rel="noreferrer noopener" target="_blank"><strong>Melbourne:</strong> August 4, 2026, at Google Melbourne.</a></li>
</ul>
</li>
<li><strong>Build highly available, multi-region services on Cloud Run<br></strong>Maintaining uptime for business-critical applications just got a lot easier on Cloud Run. Service health, now Generally Available, automates cross-region failover by leveraging readiness probes for instance-level health checks with a simple, two-click setup. You can configure service health with global external Application Load Balancers for public-facing applications or cross-region internal Application Load Balancers for private networking traffic.<br><br><a class="colors-hyperlink-primary underline focus-visible outline-offset-0 rounded" data-airgap-id="42" href="https://cloud.google.com/run/docs/configuring/configure-service-health" rel="noreferrer noopener" target="_blank">Learn how to configure service health for Cloud Run.</a></li>
<li><strong>Report: 83% of organizations need infrastructure upgrades for agentic AI<br></strong>The shift from conversational bots to autonomous agents is breaking legacy systems. Our new <em>State of AI Infrastructure</em> report details how engineering leaders are adapting to these massive new workloads. To eliminate inference bottlenecks, control hidden scaling costs, and manage agent sprawl, the industry is rapidly moving toward fluid compute, centralized governance, and unified, co-designed architectures.<br><br><a class="colors-hyperlink-primary underline focus-visible outline-offset-0 rounded" data-airgap-id="46" href="https://cloud.google.com/blog/products/compute/state-of-ai-infrastructure-report-overview?e=48754805" rel="noreferrer noopener" target="_blank">Explore our key infrastructure insights</a></li>
<li><strong>Stop tinkering, start scaling: the industrialized AI Playbook<br></strong>Did you know that only 5% of custom AI investments actually return measurable business value? The problem isn’t the technology—it’s how organizations are wired to run it.<br><br>In this compelling read, Google Cloud Consulting breaks down the operational blueprint that bridges the stark gap between "cool tech experiments" and real, P&amp;L-impacting enterprise ROI.<br><br><a class="colors-hyperlink-primary underline focus-visible outline-offset-0 rounded" data-airgap-id="50" href="https://www.google.com/url?q=https%3A%2F%2Fmedium.com%2F%40kjouannigot_73547%2Fscaling-trusted-ai-google-cloud-insights-to-capture-enterprise-roi-aa6c9b308adb" rel="noreferrer noopener" target="_blank">Read the full article on Medium</a></li>
<li><strong>AI Agent Clinic: Slashing App Latency by 80%<br></strong>Prototyping an AI agent is easy, but scaling for live traffic presents unique challenges. In the latest AI Agent Clinic, our technical experts partner with a developer to optimize PlaybackIQ, a live football analysis agent. This session demonstrates how to use OpenTelemetry to trace bottlenecks in the Gemini Enterprise Agent Platform and deploy to Cloud Run for high-concurrency scaling, achieving an 80% reduction in response time. Learn production-grade debugging strategies to optimize your own LLM applications.<br><br><a class="colors-hyperlink-primary underline focus-visible outline-offset-0 rounded" data-airgap-id="54" href="https://www.google.com/search?q=https://youtu.be/G7olcqETSn8" rel="noreferrer noopener" target="_blank">Watch the 60-minute teardown</a></li>
</ul>
<h3 data-draftjs-conductor-fragment='{"blocks":[{"key":"865rk","text":"Week of Dec 16 - Dec 20","type":"header-three","depth":0,"inlineStyleRanges":[],"entityRanges":[],"data":{}}],"entityMap":{}}'>Jun 29 - Jul 3</h3>
<ul>
<li><strong>Claude Sonnet 5, Anthropic’s latest model, is now available on Agent Platform</strong>. <br>This addition serves as a drop-in replacement for Sonnet 4.6, giving organizations expanded choice for task completion across enterprise workflows. It features enhanced reasoning, cleaner code generation, and computer use capabilities for desktop and browser workflows.<br><br>By continuing to rapidly bring frontier models to our platform, Google Cloud offers an uncompromised choice of the industry's best technology to build, test, and scale enterprise-grade AI.<br><br><a class="colors-hyperlink-primary underline focus-visible outline-offset-0 rounded" href="https://console.cloud.google.com/agent-platform/publishers/anthropic/model-garden/claude-sonnet-5?hl=en" rel="noreferrer noopener" target="_blank"><em>Get started today.</em></a></li>
<li>
<p><strong>Automate your AI governance with Apigee and YAML<br></strong><span>Manual API gateway configurations can quickly slow down your AI engineering velocity. Join the Apigee community on Thursday, July 16, to discover an automated, declarative blueprint for model garden management. Learn how a simple, repeatable YAML pattern lets your AI practitioners instantly spin up secure, policy-backed enterprise configurations  without friction. Bring your questions and connect during our live Q&amp;A session. </span></p>
<p><a class="colors-hyperlink-primary underline focus-visible outline-offset-0 rounded" href="https://goo.gle/4y4j44A" rel="noreferrer noopener" target="_blank"><strong>Register for the July 16 Community TechTalk</strong></a></p>
</li>
<li>
<p><strong>Build next-generation AI portals for autonomous agents<br></strong><span>Standard developer portals were designed for human developers to subscribe to static APIs. Today, autonomous agents, LLM toolkits, and dynamic runtimes demand a central nervous system for governance. Join our technical deep dive on Thursday, July 23, to explore Apigee's new AI Portals solution. You will see exactly how to deploy full-service, MCP powered hubs to safely manage enterprise self-service for models, tools, and agents. </span></p>
<p><a class="colors-hyperlink-primary underline focus-visible outline-offset-0 rounded" href="https://goo.gle/4y4j44A" rel="noreferrer noopener" target="_blank"><strong>Register for the July 23 Community TechTalk</strong></a></p>
</li>
<li><strong>Protect your infrastructure from advanced cyberattacks at the API layer (Presented in Portuguese)<br></strong>In an era of increasingly sophisticated threats, relying solely on traditional firewalls leaves critical data gaps. Join our technical community TechTalk on Thursday, July 30—conducted in Portuguese—to learn how to proactively mitigate risks directly at the gateway layer. This session demonstrates how to configure and govern essential Apigee security policies to build a robust line of defense, ensuring maximum availability and complete integrity for your enterprise microservices. <br><br><a class="colors-hyperlink-primary underline focus-visible outline-offset-0 rounded" href="https://goo.gle/4y4j44A" rel="noreferrer noopener" target="_blank"><strong>Register for the July 30 Portuguese Community TechTalk</strong></a></li>
</ul>
<h3 data-draftjs-conductor-fragment='{"blocks":[{"key":"865rk","text":"Week of Dec 16 - Dec 20","type":"header-three","depth":0,"inlineStyleRanges":[],"entityRanges":[],"data":{}}],"entityMap":{}}'>Jun 22 - Jun 26</h3>
<ul>
<li><strong>Accelerate TPU model loading while saving RAM on GKE.<br></strong>Large model cold starts often stall scaling and leave high-value TPUs idle. The open-source <strong>Run:ai Model Streamer</strong> now natively supports TPUs with Google Cloud Storage in<strong> </strong><a class="colors-hyperlink-primary underline focus-visible outline-offset-0 rounded" href="https://github.com/vllm-project/tpu-inference" rel="noreferrer noopener" target="_blank"><strong>TPU vLLM 0.18.0</strong>.</a> This integration accelerates inference pipelines on GKE by streaming tensors directly into CPU memory, bypassing local disk bottlenecks and the "double-buffering" trap. In benchmarks, loading a 480B parameter model was <strong>over 2x faster</strong> while cutting peak host memory usage by half. <a class="colors-hyperlink-primary underline focus-visible outline-offset-0 rounded" href="https://discuss.google.dev/t/accelerate-tpu-model-loading-while-saving-ram-on-gke/374835" rel="noreferrer noopener" target="_blank"><strong>Read the full guide and get started today</strong></a>.</li>
<li><strong>Stop Training Blind: Scaling AI with the New OpenTelemetry-Based TPU AI Telemetry Collector Agent<br></strong>Google Cloud’s new AI Telemetry Collector agent standardizes TPU monitoring using OpenTelemetry. It optimizes enterprise ML workloads by identifying silent failures and providing zero-cost operational metrics without draining host CPU cycles. The agent seamlessly routes telemetry to Google Cloud Monitoring or Prometheus and custom Grafana setups. Pre-installed on Google-optimized Ubuntu images or available via Docker, it tracks memory, network latency, and core utilization to maximize multi-node training efficiency.<br><br>You can read more of this capability by clicking this <a class="colors-hyperlink-primary underline focus-visible outline-offset-0 rounded" href="https://discuss.google.dev/t/stop-training-blind-scaling-ai-with-the-new-opentelemetry-based-tpu-ai-telemetry-collector-agent/375210" rel="noreferrer noopener" target="_blank">link</a>.</li>
</ul>
<h3 data-draftjs-conductor-fragment='{"blocks":[{"key":"865rk","text":"Week of Dec 16 - Dec 20","type":"header-three","depth":0,"inlineStyleRanges":[],"entityRanges":[],"data":{}}],"entityMap":{}}'>Jun 15 - Jun 19</h3>
<ul>
<li><strong>Join us for a deep dive into agentic AI control with AppyThings<br></strong>Your integrations aren’t failing—they are evolving. When users interact with AI agents, they no longer arrive directly at your site, resulting in experiences stripped of your context, expertise, and intended experience. Join us on Thursday, June 25, for a community tech talk in partnership with AppyThings to learn how to solve this new gateway challenge. We will explore how MTN laid an integration foundation with the Model Context Protocol (MCP) to deliver accurate, consistent experiences. Our technical experts will demonstrate how to leverage Apigee as a centralized tools management solution to govern agent access. <br><br><a class="colors-hyperlink-primary underline focus-visible outline-offset-0 rounded" href="https://goo.gle/3Sfle0y" rel="noreferrer noopener" target="_blank"><strong>Register for the session</strong></a></li>
<li><strong>Optimize Spot VM Deployments with Capacity Advisor for Spot, Now in Public Preview<br></strong>Google Compute Engine has launched <strong>Capacity Advisor for Spot</strong> to Public Preview, now open to all customers. This tool turns Spot capacity discovery into a data-driven process by providing real-time deployment recommendations to maximize obtainability and minimize preemption risks. Query the <a class="colors-hyperlink-primary underline focus-visible outline-offset-0 rounded" href="https://docs.cloud.google.com/compute/docs/instances/view-vm-availability" rel="noreferrer noopener" target="_blank"><strong>Capacity Advisor API</strong></a> for obtainability and minimum estimated uptimes, or use the new <a class="colors-hyperlink-primary underline focus-visible outline-offset-0 rounded" href="https://console.cloud.google.com/compute/capacityAdvisor" rel="noreferrer noopener" target="_blank"><strong>Console UI</strong></a> featuring a global availability map, spot price lookups, and historical preemption rate trends to visually find the most cost-efficient compute capacity.<br><br><a class="colors-hyperlink-primary underline focus-visible outline-offset-0 rounded" href="https://docs.cloud.google.com/compute/docs/instances/view-vm-availability" rel="noreferrer noopener" target="_blank">Get started today</a> to start optimizing your Spot VM deployments!</li>
<li><strong>Build a multi-tenant agentic AI system<br></strong>When scaling generative AI across different business units, your teams need specialized AI agents with unique operational rules and tools. Our new reference architecture helps you build a centralized multi-tenant platform to prevent fragmented silos, eliminate data exposure risks, and maintain unified compliance. Read the guide to <a class="colors-hyperlink-primary underline focus-visible outline-offset-0 rounded" href="https://docs.cloud.google.com/architecture/multi-tenant-agentic-ai-system" rel="noreferrer noopener" target="_blank">design and deploy a multi-tenant agentic AI system</a> in Google Cloud.</li>
<li><strong>How to Configure Gemini Enterprise to Connect to a Custom MCP Server<br></strong>The Gemini Enterprise MCP Connector was a big announcement at Google Cloud Next because it introduces the ability to connect Gemini Enterprise to MCP servers. This blog <a href="https://medium.com/google-cloud/how-to-configure-gemini-enterprise-to-connect-to-a-custom-mcp-server-2e28adc96420" rel="noopener" target="_blank">post</a> provides a step-by-step guide on how to configure your first Custom MCP Server connector using the Google Maps Ground Lite MCP server as an example. Once you understand this flow, you can configure multiple MCP servers with Gemini Enterprise to bring all the context you need.</li>
</ul>
<h3 data-draftjs-conductor-fragment='{"blocks":[{"key":"865rk","text":"Week of Dec 16 - Dec 20","type":"header-three","depth":0,"inlineStyleRanges":[],"entityRanges":[],"data":{}}],"entityMap":{}}'>Jun 8 - Jun 12</h3>
<ul>
<li><strong>Simplify Multi-Cloud Planning with Cloud Location Finder, now Generally Available</strong> <br>Cloud Location Finder provides up-to-date data on public regions, zones, and Google Distributed Cloud Connected locations across Google Cloud, AWS, Azure, and OCI. You can now programmatically discover locations based on provider, proximity, territory, and carbon footprint to optimize your global infrastructure strategy for performance, compliance, and sustainability. <br><br><a class="colors-hyperlink-primary underline focus-visible outline-offset-0 rounded" data-airgap-id="14" href="https://cloud.google.com/location-finder/docs" rel="noreferrer noopener" target="_blank">Get started for free today</a></li>
</ul>
<h3 data-draftjs-conductor-fragment='{"blocks":[{"key":"865rk","text":"Week of Dec 16 - Dec 20","type":"header-three","depth":0,"inlineStyleRanges":[],"entityRanges":[],"data":{}}],"entityMap":{}}'>Jun 1 - Jun 5</h3>
<ul>
<li><strong>Modeling the physical world with BigQuery Graph</strong><br>Managing complex supply chains requires more than just spreadsheets; it requires a digital replica of the physical world. In this <a class="colors-hyperlink-primary underline focus-visible outline-offset-0 rounded" href="https://cloud.google.com/blog/products/data-analytics/modeling-a-digital-twin-using-bigquery-graph" rel="noreferrer noopener" target="_blank">post</a>, Guru Rangavittal and Candice Chen explore how BigQuery Graph enables organizations to build a digital twin by turning physical assets into an interconnected map of nodes and edges. By moving beyond traditional relational databases, businesses gain real-time clarity into operations—from executing surgical ingredient recalls to analyzing weather-driven logistics risks. Discover how BigQuery Graph transforms reactive firefighting into proactive, precision modeling, allowing you to see critical connections in seconds and future-proof your supply chain.</li>
<li><strong>Apigee for AI: Govern LLMs and MCP Servers (Presented in Spanish)<br></strong>Learn how to securely transition your AI initiatives from experimental prototypes to enterprise-ready deployments. Join Luis Cuellar on June 18 for a technical deep dive (presented in Spanish) exploring Apigee’s latest AI gateway capabilities. Discover how to centralize governance over Model Context Protocol (MCP) servers, protect Large Language Models (LLMs) with robust API gateway security policies, and manage token-based quotas.<br><br><a class="colors-hyperlink-primary underline focus-visible outline-offset-0 rounded" href="https://goo.gle/4dyC2Ie" rel="noreferrer noopener" target="_blank"><strong>Register for the June 18 Spanish Community TechTalk</strong></a></li>
</ul>
<h3 data-draftjs-conductor-fragment='{"blocks":[{"key":"865rk","text":"Week of Dec 16 - Dec 20","type":"header-three","depth":0,"inlineStyleRanges":[],"entityRanges":[],"data":{}}],"entityMap":{}}'>May 25 - May 29</h3>
<ul>
<li>
<p><strong><a href="https://www.anthropic.com/news/claude-opus-4-8" rel="noopener" target="_blank"><span>Anthropic’s Claude Opus 4.8</span></a><span> is now available on </span><a href="https://console.cloud.google.com/vertex-ai/publishers/anthropic/model-garden/claude-opus-4-8"><span>Gemini Enterprise Agent Platform</span></a></strong><span><strong>. </strong></span><span>As we continue to expand our platform's model offerings, this addition gives organizations more options for handling complex, multi-stage enterprise workflows. Claude Opus 4.8 brings strong capabilities in agentic coding, allowing developers to manage extensive refactors and tracking dependencies over extended sessions.</span></p>
</li>
<li><strong>API Horizon Munich July 6, 2026: Orchestrating the Next Era of AI and APIs <br></strong>Master the orchestration of next-gen AI and digital ecosystems. Join Google Cloud experts and DACH tech leaders on July 6 for an exclusive look at the Apigee roadmap, Agent Management, and Model Context Protocol (MCP). Gain real-world insights and connect with the regional integration community.<strong><br><br><a href="https://goo.gle/4dTxQmo" rel="noopener" target="_blank">Register now</a></strong></li>
<li><strong>Securing AI Agents: The Extended Agent Gateway Pattern<br></strong>Learn how to prevent autonomous AI agents from invoking unauthorized APIs. Join Apigee Specialist Joel Gauci on June 4 for a technical deep dive into the Extended Agent Gateway pattern. This session covers enforcing Fine-Grained Authorization (FGA), implementing secure token exchange, and establishing Model Context Protocol (MCP) governance at the API gateway layer to protect enterprise backend services.<br><br><a href="https://goo.gle/4fbAsxg" rel="noopener" target="_blank"><strong>Register for the June 4 Community TechTalk</strong></a></li>
<li><strong>API-to-Agent Security: Exposing REST APIs to Gemini Enterprise via MCP<br></strong>Connect Gemini Enterprise agents to core data without creating security hazards. Join Google Cloud Specialist Nigel Walters on June 11 to learn how to instantly transform legacy REST APIs into secure Model Context Protocol (MCP) servers. We’ll cover how to safely register tools with Gemini while enforcing gateway-level guardrails like rate limiting and access control policies.<br><br><a href="https://goo.gle/4nVyjIr" rel="noopener" target="_blank"><strong>Register for the June 11 Community TechTalk</strong></a></li>
</ul>
<h3 data-draftjs-conductor-fragment='{"blocks":[{"key":"865rk","text":"Week of Dec 16 - Dec 20","type":"header-three","depth":0,"inlineStyleRanges":[],"entityRanges":[],"data":{}}],"entityMap":{}}'>May 18 - May 22</h3>
<ul>
<li><strong>Chinese Webinar | June 4: AI Command and Control<br></strong>As AI agents move from experimental pilots to core enterprise functions, governance has become a critical next step. Join Google Cloud on June 4th at 10:00 AM (Beijing Time) to learn how to build a secure AI management layer architecture. We'll explore how to develop governed MCP (Model Context Protocol) endpoints, manage tool access to enterprise data, and leverage robust audit logs to operationalize AI. This session also includes a practical demonstration of these governance frameworks on Google Cloud.<br><br><a href="https://goo.gle/4dx4Lf5" rel="noopener" target="_blank">Register here</a></li>
<li><strong>GCP Announces New Features to Benchmark and Optimize LLMs for On-Device Use Cases<br></strong>Deploying fine-tuned LLMs from GCP to edge devices like smartphones is complex due to fragmented hardware. Google AI Edge Portal bridges this gap, giving GCP developers the ability to test AI performance on 120+ Android devices, representing the full diversity of high, medium, and low tier smartphones on the market today. This week at I/O, we announced brand new <a href="https://cloud.google.com/blog/products/ai-machine-learning/benchmark-llms-on-device-with-ai-edge-portal" rel="noopener" target="_blank">capabilities</a> to benchmark and debug LLM performance across these devices. <a href="https://docs.google.com/forms/d/e/1FAIpQLSfTcGPycQve8TLAsfH46pBlXBZe9FrgJAClwbF7DeL1LgVn4Q/viewform" rel="noopener" target="_blank">Sign-up</a> to utilize these new features in private preview today.</li>
</ul>
<h3 data-draftjs-conductor-fragment='{"blocks":[{"key":"865rk","text":"Week of Dec 16 - Dec 20","type":"header-three","depth":0,"inlineStyleRanges":[],"entityRanges":[],"data":{}}],"entityMap":{}}'>May 11 - May 15</h3>
<ul>
<li><strong>Build Your AI &amp; MCP Control Tower for Universal Governance<br></strong>Master the future of agentic security with Apigee. Join our Community TechTalk on May 21 to discover how Apigee serves as a central "Control Tower" for the Model Context Protocol (MCP). We will explore how new JSON-RPC tool authorization enables fine-grained access policies across your organization, ensuring secure and scalable AI deployments. Whether managing internal tools or external users, learn to govern your agentic ecosystem with absolute precision. This session is designed for global coverage across EMEA and AMER regions.<br><br><a href="https://goo.gle/4u9slWF" rel="noopener" target="_blank">Register for the May 21 Community TechTalk</a></li>
</ul>
<h3 data-draftjs-conductor-fragment='{"blocks":[{"key":"865rk","text":"Week of Dec 16 - Dec 20","type":"header-three","depth":0,"inlineStyleRanges":[],"entityRanges":[],"data":{}}],"entityMap":{}}'>Apr 27 - May 1</h3>
<ul>
<li><strong>Master Your Launch: The Apigee Production Go-Live Checklist<br></strong>Ensure a secure launch with the Apigee production guide. Join Nicola Cardace on May 28 to explore security guardrails, including IAM roles, mTLS configurations, and encrypted KVM migrations. Scheduled at 11 AM EDT / 5 PM CEST to support EMEA and AMER teams, this TechTalk provides the technical roadmap you need to flip the switch with absolute confidence.<br><br><strong><a href="https://goo.gle/4elMCTI" rel="noopener" target="_blank">Register for the May 28 Community TechTalk</a></strong></li>
<li>
<p><strong>Transforming APIs into Governed Agentic Tools on the Google Cloud Agentic Platform<br></strong><span>Turn your APIs into secure, governed agentic tools on the Google Cloud Agentic Platform. Join Specialist Christophe Lalevée on May 7 for a technical deep dive into AI productization. Scheduled at 5 PM CEST / 11 AM EDT to maximize coverage for developers across EMEA and AMER, this session explores the integration and governance frameworks required to scale enterprise-ready AI with confidence.</span></p>
<p><a href="https://goo.gle/3PfWm7M" rel="noopener" target="_blank">Register for the May 7 Community TechTalk</a></p>
</li>
<li><a href="https://docs.cloud.google.com/compute/docs/accelerator-optimized-machines#g4-machine-types" rel="noopener" target="_blank">Fractional G4 VMs</a> are Generaly Available, providing a highly efficient and cost-effective entry point for AI and graphics workloads. These new configurations, using NVIDIA virtual GPU (vGPU) technology, allow you to leverage the power of the NVIDIA RTX PRO 6000 Blackwell Server Edition GPUs in flexible, smaller increments, so you can right-size your infrastructure to match the specific demands of your applications. By providing more granular access to advanced hardware, fractional G4 VMs let you optimize resource allocation and reduce overhead without sacrificing performance. You can now select from additional GPU slice sizes for your specific needs:
<ul>
<li><strong>1/2 GPU:</strong> Ideal for more intensive tasks such as LLM inference, robotics sensor simulation, and high-fidelity 3D rendering.</li>
<li><strong>1/4 GPU:</strong> Optimized for mainstream workloads, including mid-range creative design, video transcoding, and real-time data visualization.</li>
<li><strong>1/8 GPU:</strong> Great for lightweight applications such as remote desktops, productivity tools, and entry-level streaming services.</li>
</ul>
</li>
<li>
<p>Transitioning AI from a sandbox prototype to an enterprise-grade system is a major hurdle. A monolithic script won't suffice for widespread deployment. To achieve true scale and reliability with Gemini, organizations must adopt service-oriented micro-agent architectures, establish Zero-Trust security, and implement rigorous EvalOps. Master the "Agentic Maturity Ladder" to ensure your AI &amp; Agentic solutions are robust, secure, and ready for the real world.</p>
<p><a href="https://lnkd.in/gHBH8cTv" rel="noopener" target="_blank">Watch the deep dive</a> and <a href="https://discuss.google.dev/t/beyond-the-prototype-scaling-production-grade-agents-with-gemini/356140" rel="noopener" target="_blank">read the developer blog</a> to learn more.</p>
</li>
<li><strong>ML Development in VS Code with Google Cloud Power: Workbench Extension Now Available<br></strong>Data scientists and developers can now combine the local productivity of VS Code with the scalable infrastructure of Google Cloud. The new Google Cloud Workbench Notebooks extension allows you to connect to and run notebooks on managed cloud environments directly within your local IDE. This integration streamlines the ML lifecycle by eliminating context switching and providing high-performance compute for complex workloads in a familiar interface. As part of our commitment to the developer ecosystem, the extension is fully open-sourced to support community-driven innovation.
<ul>
<li><strong>Install from Marketplace:</strong> <a href="https://marketplace.visualstudio.com/items?itemName=GoogleCloudTools.workbench-notebooks" rel="noopener" target="_blank">GoogleCloudTools.workbench-notebooks</a></li>
<li><strong>Contribute on GitHub:</strong> <a href="https://github.com/GoogleCloudPlatform/colab-enterprise-vscode" rel="noopener" target="_blank">colab-enterprise-vscode</a></li>
</ul>
</li>
</ul>
<h3 data-draftjs-conductor-fragment='{"blocks":[{"key":"865rk","text":"Week of Dec 16 - Dec 20","type":"header-three","depth":0,"inlineStyleRanges":[],"entityRanges":[],"data":{}}],"entityMap":{}}'>Apr 20 - Apr 24</h3>
<ul>
<li><strong>Announcing the 2026 Google Cloud Partners of the Year<br></strong>Google Cloud is honored to celebrate the winners of the 2026 Partner of the Year awards! These awards recognize an exceptional group of partners across AI, Security, Infrastructure, and more, who have demonstrated a commitment to customer success. From global system integrators to specialized startups, these winners are leveraging the power of Google Cloud to solve complex challenges and drive digital transformation worldwide. Join us in congratulating these organizations for their innovation, collaboration, and impactful results over the past year.<br><br>See the <a href="https://cloud.google.com/blog/topics/partners/2026-partners-of-the-year-winners-next26">2026 Partner Award winners</a></li>
</ul>
<h3 data-draftjs-conductor-fragment='{"blocks":[{"key":"865rk","text":"Week of Dec 16 - Dec 20","type":"header-three","depth":0,"inlineStyleRanges":[],"entityRanges":[],"data":{}}],"entityMap":{}}'>Apr 13 - Apr 17</h3>
<ul>
<li>We're excited to announce the <strong>Public Preview of Datastream’s metadata integration with Knowledge Catalog</strong>. This is the first step in our vision to provide a centralized, "single pane of glass" for all Datastream assets. The enhancement automatically synchronizes Streams, Connection Profiles, and Private Connections, eliminating data silos. It enhances discoverability, allowing you to search for Datastream assets using the same interface as BigQuery tables. Centralized governance is also provided, making your real-time data estate more transparent and easier to manage.</li>
<li><strong>Upgrading Apigee OPDK to 4.53 with OS Modernization<br></strong>Modernize your infrastructure using Google’s official, sequential upgrade path. Our Technical expert, Rakesh Talanki outlines how to upgrade Apigee OPDK to v4.53 while migrating to a supported OS (RHEL 8.x/9.x). This guide covers the "build-out" methodology, including multi-data center syncing, to ensure a stable, zero-downtime transition<br><br><a href="https://goo.gle/3Oa8uqy" rel="noopener" target="_blank">Read the guide</a></li>
<li><strong>Cloud Run Worker Pools and CREMA: Powering Serverless AI at Scale<br></strong>Google Cloud has announced the General Availability of <strong>Cloud Run worker pools</strong>, a new resource type designed specifically for pull-based, non-HTTP workloads. Unlike traditional Cloud Run services that scale based on request traffic, worker pools provide an "always-on" environment for background tasks like processing message queues or running large-scale AI inference. To support this, Google Cloud also open-sourced the <strong>Cloud Run External Metrics Autoscaler (CREMA)</strong>. Built on KEDA, CREMA enables queue-aware autoscaling for worker pools, allowing them to dynamically scale based on external signals like Pub/Sub backlog or Kafka lag.</li>
<li><strong>Apigee Model Context Protocol (MCP) now Generally Available<br></strong>Expose enterprise APIs as MCP tools for agentic AI applications with the General Availability of MCP in Apigee. This update allows developers to transform APIs into AI-ready tools using OpenAPI Specifications, removing the need for local MCP servers or additional infrastructure. With managed endpoints and semantic search in API hub, you can now provide AI agents with secure, governed access to enterprise data at scale.<br><br><a href="https://goo.gle/3QfoEQ4" rel="noopener" target="_blank"><em>Explore the MCP overview</em></a></li>
</ul>
<h3 data-draftjs-conductor-fragment='{"blocks":[{"key":"865rk","text":"Week of Dec 16 - Dec 20","type":"header-three","depth":0,"inlineStyleRanges":[],"entityRanges":[],"data":{}}],"entityMap":{}}'>Apr 6 - Apr 10</h3>
<ul>
<li><strong>Community TechTalk: Powering Retail Agents with ADK, UCP &amp; Apigee X<br></strong>Move beyond basic chatbots to secure, transactional AI experiences. Join our Community TechTalk on April 16 to learn how Apigee X and Gemini build a "Trust Layer" for AI shopping assistants using UCP standards. We’ll demonstrate how to block prompt injections with Model Armor and implement cost governance via token limits to secure the path from discovery to purchase.<br><br><a href="https://goo.gle/41ocUgq" rel="noopener" target="_blank"><span>Register for the TechTalk</span></a></li>
<li><strong>Implement multimodal capabilities in your AI agents<br></strong>Explore three new reference architectures for building sophisticated multi-agent AI systems that can process and analyze multimodal data. To analyze disparate multimodal data and produce a high-confidence classification, see <a href="https://docs.cloud.google.com/architecture/agentic-ai-classify-multimodal-data"><span>Classify multimodal data</span></a><span>. To create a fluid conversational AI that processes audio and video streams in real time, see</span> <a href="https://docs.cloud.google.com/architecture/agentic-ai-bidirectional-multimodal-streaming"><span>Enable live bidirectional multimodal streaming</span></a><span>. To consolidate fragmented multimodal data into a searchable knowledge graph, see</span> <a href="https://docs.cloud.google.com/architecture/agentic-ai-multimodal-graph-rag-resource-orchestration"><span>Multimodal GraphRAG resource orchestration</span></a><span>.</span></li>
<li><strong>Automate SecOps workflows with an agentic AI system<br></strong>To accelerate incident response and reduce manual toil for your security team, you need a system that can automate remediation playbooks. Our new reference architecture helps you build an AI agent that orchestrates complex triage and investigation workflows across disparate security tools, such as SIEM, CSPM, and EDR, from a single interface. See the full guide to <a href="https://docs.cloud.google.com/architecture/agentic-ai-orchestrate-security-ops-workflows"><span>orchestrate security operations workflows</span></a><span>.</span></li>
</ul>
<h3 data-draftjs-conductor-fragment='{"blocks":[{"key":"865rk","text":"Week of Dec 16 - Dec 20","type":"header-three","depth":0,"inlineStyleRanges":[],"entityRanges":[],"data":{}}],"entityMap":{}}'>Mar 30 - Apr 3</h3>
<ul>
<li><strong>ASEAN Webinar | April 30: Mastering Agentic Governance at Scale with GCP<br></strong>As AI agents move from experimental pilots to core enterprise functions, governance is the critical next step. Join Google Cloud experts <strong>Shilpi Puri &amp; Wely Lau</strong> for a <strong>webinar</strong> on <strong>April 30th at 11:00 AM SGT</strong> to learn how to architect a secure AI Management layer. We’ll explore developing governed MCP endpoints, managing tool access to enterprise data, and operationalizing AI with robust audit logs. The session includes a live demo of these frameworks in action on Google Cloud.<br><br><a href="https://goo.gle/47FX1Wn" rel="noopener" target="_blank"><strong>RSVP here.</strong></a></li>
</ul>
<h3 data-draftjs-conductor-fragment='{"blocks":[{"key":"865rk","text":"Week of Dec 16 - Dec 20","type":"header-three","depth":0,"inlineStyleRanges":[],"entityRanges":[],"data":{}}],"entityMap":{}}'>Mar 23 - Mar 27</h3>
<ul>
<li aria-level="1">
<p role="presentation"><strong>Turn your API sprawl into an agent-ready catalog<br></strong><span>As organizations scale, APIs often become scattered across multiple gateways, creating "blind spots" that hinder AI adoption. To solve this, we’ve introduced two new capabilities for Apigee API hub: a new integration with API Gateway to automatically centralize API metadata into a single control plane, and a specification boost add-on (now in public preview). This add-on uses AI to enhance your API documentation with the precise examples and error codes that AI agents need to function reliably.<br><br></span><a href="https://goo.gle/47dEYqc" rel="noopener" target="_blank"><span>Read the full blog post to get started.</span></a></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>Webinar | April 16: AI Command &amp; Control<br></strong><span>As AI agents move from experimental pilots to core enterprise functions, governance is the critical next step. Join Google Cloud expert Satyam Maloo for a webinar on April 16th at 11:00 AM IST to learn how to architect a secure AI Management layer. We’ll explore developing governed MCP endpoints, managing tool access to enterprise data, and operationalizing AI with robust audit logs. The session includes a live demo of these frameworks in action on Google Cloud.<br><br></span><a href="https://goo.gle/4t43Vg4" rel="noopener" target="_blank"><span>RSVP here.</span></a></p>
</li>
<li aria-level="1">
<p role="presentation"><strong>Modernizing and Decoupling Event Ingestion with Apigee<br></strong><span>In modern cloud-native architectures, decoupling producers from consumers is critical for building resilient systems. While Google Cloud Pub/Sub provides a scalable backbone, exposing it directly to external clients can introduce security and management overhead. This new guide explores how to leverage Apigee as an intelligent HTTP ingestion point. Learn how to handle security, mediation, and traffic control before messages reach your internal bus using the PublishMessage policy or Pub/Sub API.</span><br><br><a href="https://goo.gle/3POgsWF" rel="noopener" target="_blank"><span>Read the full guide.</span></a></p>
</li>
</ul>
<h3 data-draftjs-conductor-fragment='{"blocks":[{"key":"865rk","text":"Week of Dec 16 - Dec 20","type":"header-three","depth":0,"inlineStyleRanges":[],"entityRanges":[],"data":{}}],"entityMap":{}}'>Mar 16 - Mar 20</h3>
<ul>
<li><strong>Gemini-powered Assistant in BigQuery Studio Gets Context-Aware Upgrades<br></strong>The Gemini-powered assistant in BigQuery Studio has been transformed into a fully context-aware analytics partner, supporting your entire data lifecycle. The new capabilities include intelligent resource discovery, which uses Dataplex Universal Catalog search to find resources across projects and deep dive into metadata using natural language. You can now automate tasks, such as scheduling production-grade queries directly through the chat interface, and instantly troubleshoot long-running or failed jobs with root cause analysis and cost control auditing.<br><br><a href="https://docs.cloud.google.com/bigquery/docs/use-cloud-assist">Explore</a> the full range of what the assistant can do.</li>
</ul>
<h3 data-draftjs-conductor-fragment='{"blocks":[{"key":"865rk","text":"Week of Dec 16 - Dec 20","type":"header-three","depth":0,"inlineStyleRanges":[],"entityRanges":[],"data":{}}],"entityMap":{}}'>Mar 9 - Mar 13</h3>
<ul>
<li>
<div><strong>Want to use Gemini to develop code and don't know where to start?</strong><br>This <a href="https://medium.com/google-cloud/supercharge-your-spark-development-with-gemini-1540f1cb47d4" rel="noopener" target="_blank">article</a> includes a couple of examples of developing code with Gemini prompts; it identified changes that were needed to be made to get the code working. The article also refers to other examples that are available on github. </div>
</li>
</ul>
<h3 data-draftjs-conductor-fragment='{"blocks":[{"key":"865rk","text":"Week of Dec 16 - Dec 20","type":"header-three","depth":0,"inlineStyleRanges":[],"entityRanges":[],"data":{}}],"entityMap":{}}'>Mar 2 - Mar 6</h3>
<ul>
<li>
<p><span><strong>Introducing Gemini 3.1 Flash-Lite, our fastest and most cost-efficient Gemini 3 series model.</strong> Built for high-volume developer workloads at scale, 3.1 Flash-Lite delivers high quality for its price and model tier. Gemini 3.1 Flash-Lite can tackle tasks at scale, like high-volume translation and content moderation, where cost is a priority. And it can also handle more complex workloads where more in-depth reasoning is needed, like generating user interfaces and dashboards, creating simulations or following instructions.</span></p>
<p><span>Starting today, 3.1 Flash-Lite is rolling out in preview to enterprises via </span><a href="https://console.cloud.google.com/vertex-ai/studio/multimodal?mode=prompt&amp;model=gemini-3.1-flash-lite-preview"><span>Vertex AI</span></a><span> and </span><span>developers via the Gemini API in </span><a href="https://aistudio.google.com/prompts/new_chat?model=gemini-3.1-flash-lite-preview" rel="noopener" target="_blank"><span>Google AI Studio</span></a><span>.</span></p>
</li>
<li>
<div>
<p><strong>TechTalk: Implementing Device Authorization Grant (RFC 8628) for Apigee</strong><br>Learn how to authorize "headless" devices like Smart TVs or AI agents that lack keyboards and browsers. Join our Community TechTalk on March 19 (5PM CET / 12PM EDT) to go under the hood of Apigee X/Hybrid. We’ll cover the real-world mechanics of state management, polling, and human-in-the-loop security patterns for devices and autonomous agents.</p>
<p><a href="https://goo.gle/4r6o6Zi" rel="noopener" target="_blank">Register for the TechTalk</a></p>
</div>
</li>
</ul>
<h3 data-draftjs-conductor-fragment='{"blocks":[{"key":"865rk","text":"Week of Dec 16 - Dec 20","type":"header-three","depth":0,"inlineStyleRanges":[],"entityRanges":[],"data":{}}],"entityMap":{}}'>Feb 23 - Feb 27</h3>
<ul>
<li>
<p><span><strong>Pro-level image generation gets faster and more accessible with Nano Banana 2<br></strong></span><span>Nano Banana 2 is our state-of-the-art image generation and editing model. It delivers Pro-level image generation and editing at the speed you expect from Flash — making the quality, reasoning, and world knowledge you loved about Nano Banana Pro more accessible. Learn more about the model </span><a href="https://blog.google/innovation-and-ai/technology/ai/nano-banana-2" rel="noopener" target="_blank"><span>here</span></a><span>.</span></p>
</li>
</ul>
<ul>
<li>
<p><strong>The Intelligent Path to Compliance: Transforming Regulatory QC with Google Cloud<br></strong><span>Reducing "Refuse to File" (RTF) risks and submission cycle times is critical for life sciences leaders. Google Cloud’s Regulatory Submission Semantic QC Auditor leverages Gemini and RAG architecture to transform Quality Control from a manual burden into an active, intelligent workflow.</span></p>
<p><span>By automating semantic cross-referencing, narrative coherence checks, and dynamic guidance-based auditing, this solution ensures rigorous accuracy and auditability. Operating within a secure GxP-ready environment, it empowers teams to detect subtle inconsistencies and generate remediation plans without sacrificing data privacy. <br><br></span><a href="https://discuss.google.dev/t/the-intelligent-path-to-compliance-transforming-regulatory-quality-control-with-google-cloud/335276" rel="noopener" target="_blank"><span>Learn more</span></a><span>.</span></p>
</li>
<li><span><span>Stop typing, start interacting! <strong>The Gemini Live Agent Challenge is here</strong>. Build immersive agents that can help you see, hear, and speak using Gemini and Google Cloud. Compete for your share of $80,000+ in prizes and a trip to Google Cloud Next '26!<br><br></span><span>Submissions are open from February 16, 2026 to March 16, 2026. Learn more and register at </span><a href="http://geminiliveagentchallenge.devpost.com/" rel="noopener" target="_blank"><span>geminiliveagentchallenge.devpost.com</span></a></span></li>
</ul>
<h3 data-draftjs-conductor-fragment='{"blocks":[{"key":"865rk","text":"Week of Dec 16 - Dec 20","type":"header-three","depth":0,"inlineStyleRanges":[],"entityRanges":[],"data":{}}],"entityMap":{}}'>Feb 9 - Feb 13</h3>
<ul>
<li>
<p><strong><span>Introducing Gemini 3.1 Pro on Google Cloud. </span></strong></p>
<span>3.1 Pro is a noticeably smarter, more capable baseline for complex problem-solving. We’re shipping 3.1 Pro at scale, building upon our </span><a href="https://cloud.google.com/blog/products/ai-machine-learning/gemini-3-is-available-for-enterprise?e=48754805"><span>goal</span></a><span> to help you transform your business for the agentic future. Learn more about the model’s capabilities </span><a href="https://blog.google/innovation-and-ai/models-and-research/gemini-models/gemini-3-1-pro" rel="noopener" target="_blank"><span>here</span></a><span>. Gemini 3.1 Pro is available starting today in preview in </span><a href="https://cloud.google.com/vertex-ai?e=48754805"><span>Vertex AI</span></a><span> and </span><a href="https://cloud.google.com/gemini-enterprise?e=48754805"><span>Gemini Enterprise</span></a><span>. Developers can access the model in preview via the Gemini API in </span><a href="https://aistudio.google.com/prompts/new_chat?model=gemini-3.1-pro-preview" rel="noopener" target="_blank"><span>Google AI Studio</span></a><span>, </span><a href="https://developer.android.com/studio" rel="noopener" target="_blank"><span>Android Studio</span></a><span>, </span><a href="https://antigravity.google/blog/gemini-3-1-in-google-antigravity" rel="noopener" target="_blank"><span>Google Antigravity</span></a><span>, and </span><a href="https://geminicli.com/" rel="noopener" target="_blank"><span>Gemini CLI</span></a><span>.<br><br></span></li>
<li><strong>Automate Storage Compatibility with GKE Dynamic Default Storage Classes<br></strong>Managing storage across mixed-generation VM clusters in GKE just got easier. With the new <strong>Dynamic Default Storage Class</strong>, Google Kubernetes Engine automatically selects between Persistent Disk (PD) and Hyperdisk based on a node's specific hardware compatibility. This abstraction eliminates the need for complex scheduling rules and manual pairing, ensuring your volumes "just work" regardless of the underlying infrastructure. By defining both variants in a single class, you reduce operational overhead while maintaining peak performance and cost-efficiency across your entire cluster.<br><br><a href="https://docs.cloud.google.com/kubernetes-engine/docs/concepts/hyperdisk#automated_disk_type_selection" rel="noopener" target="_blank">Explore automated disk type selection</a></li>
<li>
<p><strong>Community TechTalk: AI-Powered Apigee Development with strofa.io<br></strong><strong>Join the Apigee community on February 26</strong><span> for a deep dive into</span> <a href="https://www.google.com/search?q=http://strofa.io" rel="noopener" target="_blank"><span>strofa.io</span></a><span>. Guest speaker Denis Kalitviansky will demonstrate how this new AI-powered tool automates and orchestrates Apigee development, from local emulators to large-scale hybrid environments. Discover how to scale your API management and streamline team collaboration using the latest in AI-driven automation.</span></p>
<p><a href="https://goo.gle/3Oerns3" rel="noopener" target="_blank"><span>Register now to reserve your spot.</span></a></p>
</li>
</ul>
<h3 data-draftjs-conductor-fragment='{"blocks":[{"key":"865rk","text":"Week of Dec 16 - Dec 20","type":"header-three","depth":0,"inlineStyleRanges":[],"entityRanges":[],"data":{}}],"entityMap":{}}'>Jan 26 - Jan 30</h3>
<ul>
<li><strong><span>Simplify API Governance with Native OpenAPI v3 Support<br></span></strong>Eliminate integration debt and accelerate deployment velocity with the General Availability of OpenAPI v3 (OASv3) support for API Gateway and Cloud Endpoints. You no longer need to downgrade modern specifications to OASv2. Instead, you can now define API contracts and enforce critical policies—including telemetry, quotas, and security—using native Google-specific extensions directly within your OASv3 files. This update ensures your APIs are secure by design while remaining fully compatible with the modern developer ecosystem and Google Cloud’s AI services.<br><br><a href="https://goo.gle/49Wx58Z" rel="noopener" target="_blank"><span>Get started with OpenAPI v3 on API Gateway and Cloud Endpoints.</span></a></li>
</ul>
<ul>
<li><strong><span>Accelerate API Testing with the New Open Source API Tester<br></span></strong>Start validating your APIs with API Tester, a simple, YAML-based Test Driven Development (TDD) framework. Designed for the Apigee community, this tool allows you to write human-readable tests, run them instantly via a web client or CLI, and perform deep unit testing on Apigee proxies. With native support for JSONPath assertions and Apigee shared flows, you can verify everything from payload data to internal variables like <code>proxy.basepath</code><span> without leaving your terminal.<br><br></span><a href="https://goo.gle/4q5WDGK" rel="noopener" target="_blank"><span>Explore the API Tester guide and start testing your proxies today.</span></a></li>
<li><strong><span>Secure Sensitive Data with Kubernetes Secrets in Apigee hybrid<br></span></strong>Enhance security in Apigee hybrid by accessing Kubernetes Secrets directly within your API proxies. This hybrid-exclusive feature keeps sensitive credentials within your cluster boundary and prevents replication to the management plane. It supports strict separation of duties: operators manage secrets via <code>kubectl</code><span>, while developers reference them as secure flow variables—ideal for high-compliance and GitOps workflows.<br><br></span><a href="https://goo.gle/4qEVffo" rel="noopener" target="_blank"><span>Implement Kubernetes Secrets in your hybrid proxies.</span></a></li>
<li><strong><span>See the Console in a Whole New Light: Dark Mode is Now Generally Available in Google Cloud<br></span></strong>Elevate your cloud management workflow with Dark Mode, now generally available in the Google Cloud console. We have delivered a modern, cohesive, and accessible experience reimagined for maximum comfort and productivity—especially during extended working hours and low-light environments. Dark Mode can be enabled automatically based on your operating system's preference, or manually through the Settings  -&gt; Appearance menu.<br><br><a href="https://docs.cloud.google.com/docs/get-started/console-appearance"><span>Switch to Dark Mode today to enjoy a modern, comfortable, and productive environment!</span></a></li>
<li><strong><span>Apigee X Networking: PSC or VPC Peering?<br></span></strong>Deciding how to connect Apigee X? Watch this video to compare Private Service Connect and VPC Peering. We break down northbound and southbound routing, IP consumption, and how to reach targets on-prem or in the cloud. Learn to simplify your architecture and avoid common networking "gotchas" for a smoother deployment.<br><br><a href="https://goo.gle/4bWBGdV" rel="noopener" target="_blank"><span>Watch the video.</span></a></li>
</ul>
<h3 data-draftjs-conductor-fragment='{"blocks":[{"key":"865rk","text":"Week of Dec 16 - Dec 20","type":"header-three","depth":0,"inlineStyleRanges":[],"entityRanges":[],"data":{}}],"entityMap":{}}'>Jan 19 - Jan 23</h3>
<ul>
<li><strong>Bridge the Gap: Excel-to-API Conversion in Apigee Portals<br></strong><span>Give your customers more ways to connect! This new article by Tyler Ayers explores how to extend the Apigee Integrated Portal to support direct Excel file uploads. By leveraging SheetJS and custom portal scripts, you can enable users to upload spreadsheets, preview data, and submit it directly to your APIs, all without writing a single line of integration code themselves. It’s a powerful way to simplify onboarding for those who aren't yet API-ready.<br><br></span><a href="https://goo.gle/3Nq3Pjo" rel="noopener" target="_blank"><span>Learn how to build it</span></a><span>.</span></li>
<li><strong>Elevate your applications with Firestore’s new advanced query engine<br></strong><span>We have fundamentally reimagined Firestore with pipeline operations for Enterprise edition. Experience a powerful new engine featuring over a hundred new query features, index-less queries, new index types, and observability tooling to improve query performance. Seamlessly migrate using built-in tools and leverage Firestore’s existing differentiated serverless foundation, virtually unlimited scale, and industry-leading SLA. Join a community of 600K developers to craft expressive applications that maximize the benefits of rich queryability, real-time listen queries, robust offline caching, and cutting-edge AI-assistive coding integrations.<br><br></span><a href="https://cloud.google.com/blog/products/data-analytics/new-firestore-query-engine-enables-pipelines?e=48754805"><span>Learn more about Firestore pipeline operations.</span></a></li>
</ul></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Meta Removes Controversial AI Feature On Instagram After Backlash]]></title>
<description><![CDATA["Meta has axed a controversial feature that allowed users to modify photos from public Instagram accounts using AI," reports TechCrunch:

The feature, which wasn't designed to alert a user if their photos were used in this way, prompted immediate backlash... The company issued a blog post Friday ...]]></description>
<link>https://tsecurity.de/de/3662628/it-security-nachrichten/meta-removes-controversial-ai-feature-on-instagram-after-backlash/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3662628/it-security-nachrichten/meta-removes-controversial-ai-feature-on-instagram-after-backlash/</guid>
<pubDate>Sun, 12 Jul 2026 04:23:07 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA["Meta has axed a controversial feature that allowed users to modify photos from public Instagram accounts using AI," reports TechCrunch:

The feature, which wasn't designed to alert a user if their photos were used in this way, prompted immediate backlash... The company issued a blog post Friday announcing that it was removing the feature. Puck News founding partner Dylan Byers was the first to share the company's decision... Byers notes that the decision to do away with the feature came "amid scrutiny from users and talent agencies, including CAA."<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=Meta+Removes+Controversial+AI+Feature+On+Instagram+After+Backlash%3A+https%3A%2F%2Ftech.slashdot.org%2Fstory%2F26%2F07%2F12%2F0150219%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Ftech.slashdot.org%2Fstory%2F26%2F07%2F12%2F0150219%2Fmeta-removes-controversial-ai-feature-on-instagram-after-backlash%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://tech.slashdot.org/story/26/07/12/0150219/meta-removes-controversial-ai-feature-on-instagram-after-backlash?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[The awkward timing of the Xbox CEO’s new Federal Reserve gig]]></title>
<description><![CDATA[Xbox CEO Asha Sharma was named to co-lead a Federal Reserve task force on jobs and productivity — three days after announcing 3,200 job cuts across Microsoft's gaming division. The gaming press is having a field day. Read More]]></description>
<link>https://tsecurity.de/de/3660606/it-nachrichten/the-awkward-timing-of-the-xbox-ceos-new-federal-reserve-gig/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3660606/it-nachrichten/the-awkward-timing-of-the-xbox-ceos-new-federal-reserve-gig/</guid>
<pubDate>Fri, 10 Jul 2026 20:32:07 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<img width="380" height="249" src="https://cdn.geekwire.com/wp-content/uploads/2017/06/Ashma.jpg" class="webfeedsFeaturedVisual wp-post-image" alt="" decoding="async" fetchpriority="high" srcset="https://cdn.geekwire.com/wp-content/uploads/2017/06/Ashma.jpg 380w, https://cdn.geekwire.com/wp-content/uploads/2017/06/Ashma-300x197.jpg 300w, https://cdn.geekwire.com/wp-content/uploads/2017/06/Ashma-200x131.jpg 200w, https://cdn.geekwire.com/wp-content/uploads/2017/06/Ashma-150x98.jpg 150w" sizes="(max-width: 380px) 100vw, 380px"><br>Xbox CEO Asha Sharma was named to co-lead a Federal Reserve task force on jobs and productivity — three days after announcing 3,200 job cuts across Microsoft's gaming division. The gaming press is having a field day. <a href="https://www.geekwire.com/2026/the-awkward-timing-of-the-xbox-ceos-new-federal-reserve-gig/">Read More</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[OpenAI's CEO of AGI Deployment, Fidji Simo, Is Stepping Down]]></title>
<description><![CDATA[OpenAI's CEO of AGI deployment, Fidji Simo, is stepping down from her full-time role and becoming a part-time adviser after taking extended medical leave for a chronic neuroimmune condition. "Three months ago, I had to go on medical leave after a severe exacerbation of a chronic illness I've live...]]></description>
<link>https://tsecurity.de/de/3660193/it-security-nachrichten/openais-ceo-of-agi-deployment-fidji-simo-is-stepping-down/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3660193/it-security-nachrichten/openais-ceo-of-agi-deployment-fidji-simo-is-stepping-down/</guid>
<pubDate>Fri, 10 Jul 2026 17:21:03 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[OpenAI's CEO of AGI deployment, Fidji Simo, is stepping down from her full-time role and becoming a part-time adviser after taking extended medical leave for a chronic neuroimmune condition. "Three months ago, I had to go on medical leave after a severe exacerbation of a chronic illness I've lived with for seven years," Simo wrote in a post Thursday on X. "During that time, it became clear that the road to recovery would be much longer and more complex than I had anticipated -- and that I needed to focus on it fully." Wired reports: Simo joined OpenAI's board of directors in March 2024. The following year, CEO Sam Altman hired her to take on the product and business organizations so he could focus on research and the company's data center buildout. Previously, Simo was the CEO of Instacart and head of the Facebook app at Meta.
 
Shortly before starting at OpenAI, Simo experienced a significant health relapse. She was diagnosed with postural tachycardia syndrome, or POTS, in 2019. "For my entire time here, I've postponed medical tests and new therapies to stay completely focused on the job and not miss a single day of work," she told OpenAI staff in a memo back in April, announcing her temporary departure. "It's now clear that I've pushed a little too far and I really need to try new interventions to stabilize my health."
 
News of Simo's medical leave came amid a larger executive shakeup that saw Brad Lightcap, OpenAI's former COO, transition to a role overseeing special projects. OpenAI president and cofounder Greg Brockman took over OpenAI's product strategy. In the months since Simo stepped back from OpenAI, the company further reorganized its product teams, positioning Thibault Sottiaux as head of the company's core products, including ChatGPT.<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=OpenAI's+CEO+of+AGI+Deployment%2C+Fidji+Simo%2C+Is+Stepping+Down%3A+https%3A%2F%2Fslashdot.org%2Fstory%2F26%2F07%2F10%2F052227%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fslashdot.org%2Fstory%2F26%2F07%2F10%2F052227%2Fopenais-ceo-of-agi-deployment-fidji-simo-is-stepping-down%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://slashdot.org/story/26/07/10/052227/openais-ceo-of-agi-deployment-fidji-simo-is-stepping-down?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Days after announcing mass layoffs, Xbox CEO Asha Sharma tapped to advise the Federal Reserve on jobs]]></title>
<description><![CDATA[That's a choice.]]></description>
<link>https://tsecurity.de/de/3658384/it-nachrichten/days-after-announcing-mass-layoffs-xbox-ceo-asha-sharma-tapped-to-advise-the-federal-reserve-on-jobs/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3658384/it-nachrichten/days-after-announcing-mass-layoffs-xbox-ceo-asha-sharma-tapped-to-advise-the-federal-reserve-on-jobs/</guid>
<pubDate>Fri, 10 Jul 2026 01:02:36 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[That's a choice.]]></content:encoded>
</item>
<item>
<title><![CDATA[Summer of Clearinghouses]]></title>
<description><![CDATA[Everyone seems to have announced a clearinghouse over the past few weeks. We did too. Ours is called Athena, and the main thing that sets it apart is that it was already real and running when we announced it — built quietly months earlier, heads down, taking findings and shipping fixes, because c...]]></description>
<link>https://tsecurity.de/de/3656904/it-security-nachrichten/summer-of-clearinghouses/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3656904/it-security-nachrichten/summer-of-clearinghouses/</guid>
<pubDate>Thu, 09 Jul 2026 13:52:45 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Everyone seems to have announced a clearinghouse over the past few weeks. We did too. Ours is called Athena, and the main thing that sets it apart is that it was already real and running when we announced it — built quietly months earlier, heads down, taking findings and shipping fixes, because customers kept asking us to. We only announced it now because everyone else started announcing theirs,]]></content:encoded>
</item>
<item>
<title><![CDATA[Revving up Microsoft’s 10x faster TypeScript 7]]></title>
<description><![CDATA[It has been a year or so since Microsoft announced its plans to move TypeScript to a new, native runtime based on the Go language. Those first releases were unfinished (you had to compile them yourself) but showed promise, getting close to the expected 10x speed-up. That year has been one of stea...]]></description>
<link>https://tsecurity.de/de/3656432/ai-nachrichten/revving-up-microsofts-10x-faster-typescript-7/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3656432/ai-nachrichten/revving-up-microsofts-10x-faster-typescript-7/</guid>
<pubDate>Thu, 09 Jul 2026 11:03:32 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p><a href="https://www.infoworld.com/article/3849654/typescript-gets-go-faster-stripes.html">It has been a year or so</a> since Microsoft announced its plans to move <a href="https://www.infoworld.com/article/2257305/what-is-typescript-strongly-typed-javascript.html" data-type="link" data-id="https://www.infoworld.com/article/2257305/what-is-typescript-strongly-typed-javascript.html">TypeScript</a> to a new, native runtime based on the <a href="https://www.infoworld.com/article/2253031/whats-the-go-language-really-good-for-3.html" data-type="link" data-id="https://www.infoworld.com/article/2253031/whats-the-go-language-really-good-for-3.html">Go language</a>. Those first releases were unfinished (you had to compile them yourself) but showed promise, getting close to the expected 10x speed-up. That year has been one of steady progress, with <a href="https://devblogs.microsoft.com/typescript/announcing-typescript-7-0-rc/">Microsoft recently announcing the delivery of a release candidate build</a>.</p>



<p>This release candidate is ready for use. It installs from npm like previous versions, and like earlier builds it works in much the same way as previous versions of TypeScript, checking types in your code, compiling it to run on ECMAScript-compliant JavaScript engines, and running just about anywhere. In addition, a native preview of the TypeScript language server for <a href="https://www.infoworld.com/article/2335960/what-is-visual-studio-code-microsofts-extensible-code-editor.html" data-type="link" data-id="https://www.infoworld.com/article/2335960/what-is-visual-studio-code-microsofts-extensible-code-editor.html">Visual Studio Code</a> is available to help you write new TypeScript code and guide you through updating existing applications to the new language features.</p>



<p>All you need to do is enable the <a href="https://marketplace.visualstudio.com/items?itemName=TypeScriptTeam.native-preview" data-type="link" data-id="https://marketplace.visualstudio.com/items?itemName=TypeScriptTeam.native-preview">TypeScript 7 extension</a> through the Visual Studio command palette and start coding. There’s a lot of work going on to get the new tooling ready for the final release of TypeScript 7, and new versions of the language server are being released almost daily. It’s certainly popular, too, with nearly half a million downloads at the time of writing.</p>



<h2 class="wp-block-heading">What makes TypeScript 7 so much faster?</h2>



<p>So how is this new TypeScript so much faster? Key to the improvements is a shift to a new native compiler built in Go. This has allowed the team to change how it operates, adding parallelization where possible. In some cases, this isn’t easy, such as when type checking large codebases split across many files.</p>



<p>Here TypeScript spawns a small number of checker workers that run across your codebase. They work independently, so can duplicate the work — though the output will be the same. You can choose your own number of checkers, but the more you use, the more memory and CPU will be required.</p>



<p>Large monorepos with many projects require a similar approach with independent builder workers. You’ll need to balance this with the number of checkers in use, as this can cause significant resource issues.</p>



<p>There are some significant language and configuration changes from TypeScript 5 (TypeScript 6 has the same changes, which makes it a useful tool for experimenting with migrations). It’s well worth reading the release candidate documentation to understand how these will affect your code, as well as using the TypeScript 7 extension for Visual Studio Code to identify where you need to make changes.</p>



<h2 class="wp-block-heading">Working with users to build language tools</h2>



<p>One important aspect to the development of TypeScript 7 has been collaboration with existing users of the language and its tooling, as well as using the existing suite of TypeScript test tools that have been used to evaluate other versions. As this update is primarily a port of existing code, rather than a bottom-up rewrite, the underlying language semantics and structure are the same as those used in the original JavaScript codebase, ensuring that code will quickly port from old to new versions.</p>



<p>A major internal collaborator was the Visual Studio Code team, who have been using TypeScript to develop the familiar cross-platform development tool. It’s an important partnership between tool and language, as VS Code is a key TypeScript development tool, hosting TypeScript’s language server and using its compiler to provide debugging and code completion features.</p>



<p>The <a href="https://code.visualstudio.com/blogs/2026/06/26/iterating-faster-with-ts-7" data-type="link" data-id="https://code.visualstudio.com/blogs/2026/06/26/iterating-faster-with-ts-7">VS Code team published a long blog post</a> detailing how it has been working with the Go-based TypeScript. The team is both helping to develop the language and beginning the process of moving its codebase to the newer, faster, native platform.</p>



<p>How the VS Code team migrated is a useful case study, one that can help you move your TypeScript development more efficiently and with minimal risk. The team began working with extensions, using daily builds of TypeScript to ensure that bugs and issues could be reported as they occurred and would only have a limited impact as fixes could be rolled out quickly. At the same time, the VS Code team began using a preview version of the TypeScript 7 extension for VS Code, which was being built around the new compiler in parallel with its development.</p>



<h2 class="wp-block-heading">Bridging development with TypeScript 6</h2>



<p>The development of <a href="https://devblogs.microsoft.com/typescript/announcing-typescript-6-0/" data-type="link" data-id="https://devblogs.microsoft.com/typescript/announcing-typescript-6-0/">TypeScript 6 as a bridge between TypeScript 5 and TypeScript 7</a> allowed the VS Code team to transition to code that targeted a newer version of ECMAScript and provided more powerful checks. By moving code from TypeScript 5 to TypeScript 6, developers could validate it with what would become TypeScript 7 language features and get speed and performance boosts while doing so (though nowhere near what TypeScript 7 promised). By completing this first migration of the VS Code codebase, it was possible for developers to be confident that they were ready to shift to the Go-based version when it shipped.</p>



<p>The parallel development of the new language server and extension ensured that by late 2025 it was possible for VS Code development to shift to TypeScript 7, with TypeScript 6 used as a fallback if there were any issues. Those cases could then be reported back to the TypeScript team and used to prioritize development.</p>



<p>As the platform evolved, the use cases for the VS Code team changed. By early 2026 TypeScript 7 was stable and nearly feature-complete, so the team began to use it to build all of their own built-in extensions. This allowed them to rethink their toolchain, changing the bundler from webpack to the one built into esbuild, giving them another speed up. Once that process was tested and working, they could switch all development to TypeScript 7.</p>



<p>Having such a big project take on TypeScript 7 early reaped big rewards, as the resulting virtuous cycle allowed both VS Code and TypeScript to move forward together, fixing issues as they arose and providing valuable feedback. The results speak for themselves. Type checking the entire VS Code codebase is now 7x faster, with most extensions checked in under a second. The only exception was <a href="https://www.infoworld.com/article/3609013/github-copilot-everything-you-need-to-know.html" data-type="link" data-id="https://www.infoworld.com/article/3609013/github-copilot-everything-you-need-to-know.html">GitHub Copilot</a>, which is almost as big as the editor itself, which type checked in 2.5 seconds.</p>



<p>Compilation has been sped up, dropping from 80 seconds to around 20 seconds. This may not seem a lot, but when you’re compiling and rebuilding and debugging, each change in your code now takes a lot less time. That improves developer productivity and ensures they stay in flow, rather than switching away to check email or Teams each time they start a new build. The same goes for using the language server, where loading the entire project (necessary for error detection and refactoring) now takes 10 seconds rather than a minute.</p>



<p>Lots of little time savings like this add up across a big project and a large team, helping developers stay focused and able to solve problems more effectively. The VS Code blog post notes that it cuts down on coffee runs, which take longer than the load or build that inspire a quick cuppa!</p>



<h2 class="wp-block-heading">Getting ready for TypeScript 7 in your build pipeline</h2>



<p>Microsoft is quick to point out that, while the TypeScript 7.0 release will be production ready, TypeScript 7 won’t have a full programmatic API until the release of TypeScript 7.1. As this won’t be for some time, Microsoft is providing <a href="https://devblogs.microsoft.com/typescript/announcing-typescript-7-0-rc/#running-side-by-side-with-typescript-6.0" data-type="link" data-id="https://devblogs.microsoft.com/typescript/announcing-typescript-7-0-rc/#running-side-by-side-with-typescript-6.0">a way to run TypeScript 7 side-by-side with TypeScript 6</a>.</p>



<p>Installing the <code>@typescript/typescript6</code> compatibility package alongside TypeScript 7 adds a new executable, <code>tsc6</code>, that allows you to modify code that uses the TypeScript 5 API to run using TypeScript 6, by renaming the calls to <code>tsc</code> in your scripts to <code>tsc6</code>. This should allow you to keep building to the latest releases at the same time as starting to experiment with using the new runtime.</p>



<p>It’s not a perfect fix. You do need to do some work to implement npm aliases that allow linters and other low-level tools to work with both versions. You can also provide two different dependencies in your package.json to allow TypeScript 6 (<code>tsc6</code>) and TypeScript 7 (<code>tsc</code>) to run side-by-side. The result is a way to help migrate TypeScript code to the newer platform, delivering more efficient code that runs on a more modern ECMAScript in the meantime.</p>



<p>TypeScript 7 will be a big upgrade, though it has taken surprisingly little time to deliver. With users like the Visual Studio Code team already building on the new release, it’s clear that beginning your own migration should be easier than you might have thought.</p>



<p>The final release is due sometime in July 2026. If you haven’t started looking at TypeScript 7, now is the time to start.</p>
</div></div></div>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[SpaceX's Grok 4.5 launches at half the price of rivals — here's why that could rattle Anthropic and OpenAI]]></title>
<description><![CDATA[Elon Musk's SpaceX released Grok 4.5 on Wednesday, the first artificial intelligence model the company has trained specifically for coding and autonomous agents — and the first tangible product of its $60 billion acquisition of the AI coding startup Cursor, completed just weeks ago.The launch mar...]]></description>
<link>https://tsecurity.de/de/3655560/it-nachrichten/spacexs-grok-45-launches-at-half-the-price-of-rivals-heres-why-that-could-rattle-anthropic-and-openai/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3655560/it-nachrichten/spacexs-grok-45-launches-at-half-the-price-of-rivals-heres-why-that-could-rattle-anthropic-and-openai/</guid>
<pubDate>Thu, 09 Jul 2026 00:47:48 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Elon Musk's <a href="https://www.spacex.com/">SpaceX</a> released <a href="https://x.ai/news/grok-4-5">Grok 4.5</a> on Wednesday, the first artificial intelligence model the company has trained specifically for coding and autonomous agents — and the first tangible product of its <a href="https://www.cnbc.com/2026/06/16/spacex-spcx-cursor-acquisition-ipo.html">$60 billion acquisition</a> of the AI coding startup Cursor, completed just weeks ago.</p><p>The launch marks a pivotal test of the sprawling, vertically integrated AI empire Musk has assembled over the past six months, and of a strategy that bets developers care less about topping benchmark leaderboards than about speed, cost, and whether a model can actually do the work.</p><p>"Announcing Grok 4.5, our first model trained specifically for coding and agents," the company said in a post on X. "It was trained with Cursor and offers frontier intelligence at leading speeds and cost efficiency."</p><div></div><h2><b>Why Grok 4.5's pricing strategy matters more than its benchmark scores</b></h2><p><a href="https://www.spacex.com/">SpaceX</a> is not claiming <a href="https://x.ai/news/grok-4-5">Grok 4.5</a> is the smartest model in the world. Instead, it is making an economic argument. The company says the model uses half as many tokens per task as comparable models, delivers higher throughput, and costs less than half as much — priced at $2 per million input tokens and $6 per million output tokens. That undercuts the premium tiers of rivals like Anthropic's Claude Opus line and OpenAI's frontier models by a wide margin.</p><p>Musk framed the positioning candidly. "Our internal assessment is that Grok 4.5 is roughly comparable to Opus 4.7, but much faster," <a href="https://x.com/elonmusk/status/2074911038286295049?s=20">he wrote on X</a>. "The combination of capability, faster speed and lower cost is what makes it competitive. We are closing the loop on real-world usefulness, not benchmarks. Hardcore engineers at Tesla &amp; SpaceX find Grok 4.5 genuinely useful, which is what actually matters."</p><p>That framing is both a philosophy and a hedge. Independent evaluations released Wednesday suggest Grok 4.5 is genuinely competitive but not dominant on raw capability. The benchmarking firm <a href="https://artificialanalysis.ai/models/grok-4-5">Artificial Analysis</a> ranked the model fourth on its <a href="https://artificialanalysis.ai/evaluations/gdpval-aa">GDPval-AA v2 index</a> of real-world agentic knowledge work, with an Elo score of 1543, "behind only the latest Claude releases from Anthropic." But the cost figures are where the model stands out. Artificial Analysis measured Grok 4.5 at <a href="https://artificialanalysis.ai/models/grok-4-5">$0.49 per completed task</a> — "nearly 90% cheaper than the models ahead of it on our leaderboard," the firm wrote, placing it "clearly on the Pareto frontier for performance versus cost."</p><p>For enterprise buyers, that math matters enormously. Agentic workloads — where a model works autonomously for minutes or hours, reading codebases, calling tools, and iterating on its own output — consume tokens voraciously. A model that is <a href="https://artificialanalysis.ai/models/grok-4-5">90% cheaper per completed task</a>, even if slightly less capable, changes the calculus for any engineering organization deploying agents across hundreds of developers. Investor <a href="https://x.com/GavinSBaker/status/2074943300725887104">Gavin Baker</a> captured the market's cautious optimism: "Pareto dominant for coding by the numbers. We will see on the all-important vibes."</p><div></div><h2><b>How the $60 billion Cursor acquisition shaped Grok 4.5's training</b></h2><p>Grok 4.5 is the first concrete evidence of what SpaceX bought when it acquired Cursor, and the deal itself unfolded in stages. In April, SpaceX struck an <a href="https://www.businessinsider.com/spacex-cursor-coding-xai-deal-acquisition-2026-4">unusual arrangement</a> giving it the right to buy the coding startup for $60 billion — or pay billions in fees and compute if it walked away, as <a href="https://www.businessinsider.com/spacex-cursor-coding-xai-deal-acquisition-2026-4">Business Insider</a> reported at the time. Days after SpaceX's record-setting Nasdaq debut in June, the company exercised that right, announcing an all-stock acquisition that <a href="https://www.cnbc.com/2026/06/16/spacex-spcx-cursor-acquisition-ipo.html">CNBC reported</a> is roughly 3.4% dilution at the IPO valuation. SpaceX shares rose 16% on the news.</p><p>The strategic logic was always about data as much as product. Cursor's AI-first code editor generates an enormous stream of high-quality interaction data: how expert engineers write, edit, review, and debug code in real production environments. Musk said openly this spring that <a href="https://cursor.com/blog/grok-4-5">Cursor interaction data was being fed directly into Grok's training</a>. Cursor, for its part, got access to SpaceX's Colossus supercomputer in Memphis — roughly 200,000 Nvidia GPUs with plans to scale toward one million — after publicly acknowledging it had been "<a href="https://cursor.com/blog/spacex-model-training">bottlenecked by compute</a>."</p><p>"We've partnered with SpaceXAI to train Grok 4.5," Cursor's official account <a href="https://x.com/cursor_ai/status/2074915744999969059">posted</a> Wednesday. "It's our most powerful model yet and the first we've built for more than software engineering." SpaceX says the model reflects that pedigree: it "excels in large codebases and handles long-running tasks that span multiple repositories, hundreds of skills, and a variety of tools" — precisely the messy, multi-file reality of professional software engineering that clean coding benchmarks often fail to capture. Early developer reactions suggest the training paid off. "Ok Grok 4.5 is wild," <a href="https://x.com/Baconbrix/status/2074945996799504876">posted</a> developer Evan Bacon. "It just built me this rocket tracking app with live data and a 3D globe. I might need a new benchmark after this."</p><div></div><h2><b>Inside xAI's turbulent year of scandals, departures, and rebuilding</b></h2><p>The polished launch belies how chaotic the road here has been. Grok has spent much of the past year in crisis. In mid-2025, the <a href="https://www.npr.org/2025/07/09/nx-s1-5462609/grok-elon-musk-antisemitic-racist-content">chatbot generated antisemitic content</a> and at one point called itself "<a href="https://www.npr.org/2025/07/09/nx-s1-5462609/grok-elon-musk-antisemitic-racist-content">MechaHitler</a>," episodes covered extensively by <a href="https://www.npr.org/2025/07/09/nx-s1-5462609/grok-elon-musk-antisemitic-racist-content">NPR</a> and <a href="https://www.cnn.com/2025/07/08/tech/grok-ai-antisemitism">CNN</a>. Earlier this year, its image-generation features allowed users to create sexualized deepfakes, including of children — drawing investigations from the European Commission and Britain's Ofcom, as the BBC reported, and prompting SpaceX to list the behavior as a business risk in its own IPO filings.</p><p>The organization behind the model was fracturing, too. All 11 of Musk's xAI co-founders had departed by the end of March, according to <a href="https://techcrunch.com/2026/03/28/elon-musks-last-co-founder-reportedly-leaves-xai/">TechCrunch</a>, and Musk publicly conceded that xAI "was not built right [the] first time around," saying he was rebuilding it "from the foundations up." Musk himself admitted at a conference this spring that Grok was "currently behind in coding" — a rare public concession from an executive not known for them.</p><p>Against that backdrop, <a href="https://x.ai/news/grok-4-5">Grok 4.5</a> reads as the first product of the rebuilt organization — and the first proof point for the audacious story SpaceX told public market investors. During its IPO roadshow, the company pitched a total <a href="https://fortune.com/2026/05/20/spacex-ipo-filing-s1-total-addressable-market-make-life-multiplanetary/">addressable market of roughly $28 trillion</a>, with about $26 trillion tied to AI, including a $22.7 trillion "enterprise applications" opportunity. Those numbers strained credulity even by Silicon Valley standards. A competitive, cheap coding model is the most direct route from that narrative to actual revenue, which is why Wednesday's launch carries weight far beyond a routine model release.</p><h2><b>Grok 4.5 vs. Claude: the battle for the AI coding market</b></h2><p>The competitive stakes are hard to overstate, because the AI coding market has been consolidating around a single leader — and it isn't Musk. Even as Cursor's revenue exploded, its market share was eroding. <a href="https://www.cnbc.com/2026/06/16/spacex-spcx-cursor-acquisition-ipo.html">Spending data from Ramp cited by CNBC</a> showed Cursor's share of the AI coding category falling from 41% in June 2025 to about 26% by May 2026, while Anthropic came to control roughly half the market. Anthropic also topped CNBC's Disruptor 50 list this year and, by Artificial Analysis's own measure, still holds the top spots on <a href="https://artificialanalysis.ai/models/capabilities/agentic">agentic performance rankings</a>.</p><p>That is the gap <a href="https://x.ai/news/grok-4-5">Grok 4.5</a> is engineered to close — not by out-thinking Claude, but by underpricing it. The model's economics create a classic disruption dynamic: if it delivers most of the frontier's capability at a fraction of the cost per task, price-sensitive enterprise workloads will migrate, and incumbents will face pressure on their most profitable API traffic. The counterargument is that in coding, quality compounds. A model that resolves a complex bug correctly on the first attempt can be cheaper in practice than one that costs half as much per token but requires three tries. That is why Baker's caveat about "vibes" — the developer community's shorthand for a model's felt reliability on real work — will determine more than any launch-day benchmark.</p><p>There is also a structural question buried in the deal. Cursor built its business on offering developers their choice of models, including Claude and GPT. If Grok becomes the favored child inside Cursor — and Musk was already urging users to "Try out Grok 4.5 in Cursor!" within hours of launch — the product risks alienating the very users whose data made Grok 4.5 possible. Regulators, already scrutinizing Grok on safety grounds in two jurisdictions, may take a keen interest in a company that controls the training data, the model, and a dominant distribution channel simultaneously.</p><div></div><h2><b>What Musk's trillion-dollar vertical integration bet means for AI's future</b></h2><p>Grok 4.5 also crystallizes what Musk's frenetic dealmaking was building toward. In February, SpaceX absorbed xAI in a share-exchange merger that CNBC confirmed valued the combined company at <a href="https://www.cnbc.com/2026/02/03/musk-xai-spacex-biggest-merger-ever.html">$1.25 trillion</a> — the largest merger of all time, valuing SpaceX at $1 trillion and xAI at $250 billion. The June IPO followed, the biggest in history, and the stock has since surged past $200 from its $135 offering price, vaulting SpaceX past Amazon and Microsoft to become the fourth most valuable company in the United States.</p><p>The result is a single public company that owns nearly the entire stack: Colossus for training compute, ambitions for orbital data centers to power future scaling, a frontier model in Grok, a distribution channel in Cursor's developer base, and captive demand from Tesla and SpaceX's own engineering organizations. Neither OpenAI nor Anthropic can fully replicate that integration; both must reach developers through third-party tools, some of which Musk now owns. Whether that concentration proves to be an unassailable moat or a regulatory target — or both — is now one of the defining questions in enterprise AI.</p><div></div><p>The next few weeks will start to answer it. Artificial Analysis says its full <a href="https://x.com/ArtificialAnlys/status/2074942097158021371">Intelligence Index</a> results are forthcoming. Enterprise pilots will reveal whether the token-efficiency claims survive contact with real codebases. And Anthropic, which has answered every serious challenge this cycle with a rapid counter-release, is unlikely to cede the price-performance frontier quietly.</p><p>But the deeper story of <a href="https://x.ai/news/grok-4-5">Grok 4.5</a> may be what it says about where the AI race has moved. For three years, the industry's scoreboard was intelligence: whose model was smartest. Musk, arriving late and battered, has chosen to compete on a different axis entirely — whose model is cheapest to actually use. It is a telling choice from a man who built his fortune not by inventing the rocket or the electric car, but by relentlessly driving down the cost of making them. If the strategy works, Musk will have done to AI what he did to spaceflight. If it doesn't, he'll have spent $60 billion to learn that in software, unlike rockets, the cheapest ride isn't always the one engineers choose.</p><p>
</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Introducing Claude apps gateway for AWS]]></title>
<description><![CDATA[Today, we're announcing the Claude apps gateway for AWS, a self-hosted control plane that gives organizations a single point of control over access, cost, and policy for Claude Code and Claude Desktop. In this post, we show how to set up and run Claude apps gateway for AWS with Amazon Bedrock and...]]></description>
<link>https://tsecurity.de/de/3655367/ai-nachrichten/introducing-claude-apps-gateway-for-aws/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3655367/ai-nachrichten/introducing-claude-apps-gateway-for-aws/</guid>
<pubDate>Wed, 08 Jul 2026 22:04:18 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Today, we're announcing the Claude apps gateway for AWS, a self-hosted control plane that gives organizations a single point of control over access, cost, and policy for Claude Code and Claude Desktop. In this post, we show how to set up and run Claude apps gateway for AWS with Amazon Bedrock and Claude Platform on AWS.]]></content:encoded>
</item>
<item>
<title><![CDATA['Knockoff' Browser Extension Hides Sketchy Brands On Amazon]]></title>
<description><![CDATA[alternative_right shares a report from 404 Media: A software developer made a Chrome and Firefox extension called Knockoff that automatically hides, grays out, or filters products from sketchy brands on Amazon, which highlights just how many shady brands are on the platform and how commonly they ...]]></description>
<link>https://tsecurity.de/de/3655160/it-security-nachrichten/knockoff-browser-extension-hides-sketchy-brands-on-amazon/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3655160/it-security-nachrichten/knockoff-browser-extension-hides-sketchy-brands-on-amazon/</guid>
<pubDate>Wed, 08 Jul 2026 20:23:50 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[alternative_right shares a report from 404 Media: A software developer made a Chrome and Firefox extension called Knockoff that automatically hides, grays out, or filters products from sketchy brands on Amazon, which highlights just how many shady brands are on the platform and how commonly they show up on searches for basic items. In just a few minutes of using the extension, Knockoff dimmed product listings for screwdrivers made by "SUNHZMCKP," spoons made by "SACATR," and a lamp made by "ROTTOGOON."
 
In a tweet announcing the extension, developer Josh Pigford wrote "Sorry to brands like WNPETHOME, EHEYCIGA, YXYL, LU&amp;MN, JOYIN, TOMY, GODONLIF, YOOJEE, LINGTENG, LANEIGE, VISCOO, BIODANCE, COOFANDY, BALENNZ, TOSY, and LUENX." The extension can also hide all sponsored product listings. The extension quickly went viral as a much-needed filter for people who still use Amazon and, for those who don't use Amazon because of its horrendous labor practices and other concerns, it is evidence of what an incredible wasteland the platform has become.<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status='Knockoff'+Browser+Extension+Hides+Sketchy+Brands+On+Amazon%3A+https%3A%2F%2Ftech.slashdot.org%2Fstory%2F26%2F07%2F08%2F1643256%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Ftech.slashdot.org%2Fstory%2F26%2F07%2F08%2F1643256%2Fknockoff-browser-extension-hides-sketchy-brands-on-amazon%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://tech.slashdot.org/story/26/07/08/1643256/knockoff-browser-extension-hides-sketchy-brands-on-amazon?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[We’re boosting agroforestry efforts to help the atmosphere and farmer livelihoods.]]></title>
<description><![CDATA[Google is announcing a long-term agreement with Thryve.Earth for 260,000 tons of carbon removal.]]></description>
<link>https://tsecurity.de/de/3654360/it-nachrichten/were-boosting-agroforestry-efforts-to-help-the-atmosphere-and-farmer-livelihoods/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3654360/it-nachrichten/were-boosting-agroforestry-efforts-to-help-the-atmosphere-and-farmer-livelihoods/</guid>
<pubDate>Wed, 08 Jul 2026 15:03:29 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<img src="https://storage.googleapis.com/gweb-uniblog-publish-prod/images/Thryve_Symbiosis_herosocial.max-600x600.format-webp.webp">Google is announcing a long-term agreement with Thryve.Earth for 260,000 tons of carbon removal.]]></content:encoded>
</item>
<item>
<title><![CDATA[Talk, talk, talk: The rise of AI dictation tools at work]]></title>
<description><![CDATA[For workers who routinely spend hours a day interacting with various AI assistants, banging out prompts on a keyboard can quickly become a chore. 



“Whether it’s a coding task, helping write a document or think about strategy — there’s just so much typing and typing and typing you do as a part ...]]></description>
<link>https://tsecurity.de/de/3651342/it-nachrichten/talk-talk-talk-the-rise-of-ai-dictation-tools-at-work/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3651342/it-nachrichten/talk-talk-talk-the-rise-of-ai-dictation-tools-at-work/</guid>
<pubDate>Tue, 07 Jul 2026 13:32:41 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>For workers who routinely spend hours a day interacting with various AI assistants, banging out prompts on a keyboard can quickly become a chore. </p>



<p>“Whether it’s a coding task, helping write a document or think about strategy — there’s just so much typing and typing and typing you do as a part of that,” said <a href="https://www.linkedin.com/in/patalano" target="_blank" rel="noreferrer noopener">Chris Patalano</a>, chief technology officer at Thumbtack, an online marketplace for professional services.</p>



<p>With that in mind, Patalano and other senior colleagues last year began experimenting with new ways to interact with AI systems within Thumbtack. The idea was to test AI-assisted dictation tools developed by startups such as <a href="https://www.monologue.to/" target="_blank" rel="noreferrer noopener">Monologue</a>, <a href="https://superwhisper.com/" target="_blank" rel="noreferrer noopener">Superwhisper</a>, <a href="https://willowvoice.com/">Willow </a><a href="https://willowvoice.com/" target="_blank" rel="noreferrer noopener">Voice</a>, and <a href="https://wisprflow.ai/" target="_blank" rel="noreferrer noopener">Wispr</a>. </p>



<p>Unlike previous generations of dictation apps that aimed to produce a verbatim transcript, newer tools rely on large language models (LLMs) to craft polished, edited text. The companies behind them claim users can produce text several times faster than typing, with greater accuracy than voice tools built into other apps.</p>



<p>That has sparked renewed interest in <a href="https://www.computerworld.com/article/4175881/ai-will-kill-the-skill-of-typing.html">using voice prompts to carry out routine tasks</a> in the workplace.</p>



<p>After one of Thumbtack’s principal engineers suggested Wispr Flow, Patalano kicked off a small pilot project with a handful of colleagues over a couple of months. The pilot was a success, and Wispr Flow is now available to more than 200 IT and engineering staffers; they use it for a variety of tasks, including interactions with AI assistants and drafting Slack messages to colleagues.<em> </em></p>



<p>Although Patalano said he still prefers typing for certain apps, Wispr Flow’s AI dictation tool has become a part of his daily workflow. “It’s becoming the primary interface that I have for any AI tools. It’s just so much more effective and efficient than having to type,” he said. </p>



<p>“I’ve used it to help me build prototypes, explore the code base, help me explore my own technical strategy. I’ve used it to do analytics across data sets — even very specific acute things, like ‘What do I need to make sure is on my to-do list this week?’”</p>



<h2 class="wp-block-heading">A new generation of dictation tools</h2>



<p>Software that translates spoken words into text isn’t new to the workplace. Speech-to-text dictation tools have been around in various forms for decades. The earliest example dates back to 1952, when Bell Labs created Audrey, widely regarded as the first automatic speech recognition system. (Audrey <a href="https://www.bbc.com/future/article/20170214-the-machines-that-learned-to-listen" target="_blank" rel="noreferrer noopener">could recognize the spoken digits 0-9</a> with 90% accuracy when used by the machine’s developer, HK Davis.) </p>



<p>Commercial products appeared in the 1980s, with broader adoption in the 1990s via software such as Dragon Dictate. These were specialized — and expensive — applications with limited functionality, appealing mostly to professionals for whom dictation was already a part of their workflow, such as doctors and lawyers, rather than a wide range of office workers. </p>



<p>In recent years, speech-to-text software has become more accessible, especially  with the integration of speech recognition into smartphones and computers by Apple, Google, Microsoft, and others. Deep learning has also significantly improved accuracy.</p>



<p>That’s made <a href="https://www.theguardian.com/technology/2026/may/12/end-of-typing-workers-ditching-keyboards-voicepilling-ai-dictation" target="_blank" rel="noreferrer noopener">voice input more common in the workplace</a> and an important accessibility tool for people who find typing difficult — even though the systems can still be “quite brittle,” said <a href="https://people.ucd.ie/benjamin.cowan" target="_blank" rel="noreferrer noopener">Benjamin Cowan</a>, professor at the School of Information and Communication Studies at University College Dublin. That’s especially true of early voice input technology.</p>



<p>“Not only did they get things wrong all the time, they wrote everything you said — even if you didn’t want it to,” he said. “This meant that a lot of time was taken editing the notes after they were dictated.” </p>



<p>Now, several startups offering AI dictation tools, including Wispr, aim to make voice a viable alternative to typing for everyday computer tasks. The key difference from earlier iterations of tools is the use of AI models to edit text in near-real-time, removing disfluencies such as “umms,” “ahhs” and filler words to create a polished sentence. </p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/07/Snippets.png?w=1024" alt="Whispr Flow snippets" class="wp-image-4193385" width="1024" height="674" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption"><p>Whispr Flow offers shortcuts, or “snippets” with its voice tool.</p>
</figcaption></figure><p class="imageCredit">Whispr Flow snippets</p></div>



<p>In most cases, users can invoke an AI dictation tool across mobile and desktop applications with a text field – whether that’s a document editor, email client, a vibe-coding app or anything else – by pressing and holding a designated key or button while talking. Users can add words to the app’s dictionary so it can pick up on uncommon names, abbreviations, and industry jargon.</p>



<p>“The technology itself has improved dramatically” compared to previous tools that sought to transcribe speech verbatim and could be frustratingly inaccurate, said <a href="https://uk.linkedin.com/in/mariabell" target="_blank" rel="noreferrer noopener">Maria Bell</a>, senior research analyst at CCS Insight.  </p>



<p>“These modern systems are much more contextual; they understand your intent, they can help structure your thoughts and rewrite while you speak. They function more like writing assistants rather than just dictation.”</p>



<p>Wispr is among the best-funded startups in the market, having raised $81 million to date.<em> </em><a href="https://www.bloomberg.com/news/articles/2026-05-12/ai-dictation-startup-wispr-in-funding-talks-at-2-billion-value" target="_blank" rel="noreferrer noopener">Bloomberg reported in May</a> that the company was in talks to raise a further $260 million at a $2 billion valuation. Other vendors have also attracted investor backing, with Willow Voice <a href="https://x.com/_allanguo/status/1945185671054024828" target="_blank" rel="noreferrer noopener">announcing a $4.2 million funding round</a> last year.</p>



<p>The software is typically available via a freemium model, with a free tier offering basic functionality and usage limits alongside paid premium versions. Superwhisper Pro is $8.49 per user each month; Willow Voice’s Team Pro and Individual Pro are $10 and $12 per user each month, respectively; and Wispr Flow Pro costs $12 per user each month. Enterprise pricing is not publicly available from these vendors.</p>



<p>Larger tech firms have also invested in AI-assisted voice functionality. Apple, for instance, <a href="https://www.apple.com/newsroom/2026/06/apple-introduces-siri-ai-a-profoundly-more-capable-and-personal-assistant/%23:~:text=Users%2520have%2520the%2520ability%2520to%2520customize%2520the%2520expressiveness%2520and%2520pace%2520of%2520Siri%25E2%2580%2599s%2520voice,accurately,%2520and%2520as%2520intended." target="_blank" rel="noreferrer noopener">recently announced</a> AI-powered dictation for its <a href="https://www.computerworld.com/article/4184484/siri-ai-is-all-apple-it-just-needed-google-to-get-there.html">revamped Siri AI assistant</a>, while Google is building in <a href="https://blog.google/products-and-platforms/platforms/android/gemini-intelligence/%23:~:text=Turn%2520spoken%2520thoughts%2520into%2520polished%2520text" target="_blank" rel="noreferrer noopener">similar functionality</a> for the <a href="https://www.computerworld.com/article/4026831/android-voice-typing.html">Gboard keyboard</a> on Android devices. Google is also developing a standalone AI dictation tool – <a href="https://www.computerworld.com/article/4156760/googles-new-ai-app-is-a-glimpse-of-the-future.html">Edge Eloquent</a> – although its approach differs from that of startups in the space because the tool is not available across separate applications.</p>



<h2 class="wp-block-heading">Why use AI dictation?</h2>



<p>The key promise of AI dictation is that it can increase a knowledge worker’s words-per-minute (wpm) output versus typing. </p>



<p><a href="https://superwhisper.com/typing-speed-test" target="_blank" rel="noreferrer noopener">According to Superwhisper</a>, most office workers can knock out between 40 and 70 words a minute on a  keyboard, though some can be much faster. (<em>New York Times</em> reporters vary from 36 to 134 wpm, according to a <em>Times</em> <a href="https://www.nytimes.com/2026/03/25/insider/how-fast-journalists-type.html" target="_blank" rel="noreferrer noopener">article earlier this year</a>.) People talk much faster, at a rate of 160 to 180 wpm, and AI dictation app vendors promise low latency processing to turn speech into edited text (usually less than a second; some claim under 200 milliseconds).</p>



<p>It’s not just about speed: Willow Voice, for instance, claims its app is three times more accurate than dictation tools built into other applications. </p>



<p>The prospect of accelerating routine writing and communication tasks has obvious appeal, particularly as AI threatens to increase rather than reduce the burden on office workers. “We all feel like we’re working faster – we have to do more with less time,” said Bell. </p>



<p>“Employees are overloaded with communication work, and they’re spending huge amounts of time every day writing emails, messaging colleagues, using generative AI,” she said. “Voice tools are appealing because some feel they can do wor] faster. It reduces friction around all the tasks they’re being asked to do.”</p>



<p>The technology is potentially suited to a variety of jobs, said Cowan — not only those that require dictation — helping with tasks such as writing to-do lists and documents, or sending messages and emails. </p>



<p>Accessibility is important, too. “These dictation tools also mean that people who find it hard to type or cannot type now have much better apps to help them with writing,” said Cowan. </p>



<h2 class="wp-block-heading">What’s holding the technology back?</h2>



<p>Despite these potential benefits, the idea of talking to a laptop or smartphone throughout the day might not be appealing for a lot of people, particularly those in a busy office. </p>



<p>“Some might find it embarrassing or uncomfortable, they’ll be worried about distracting colleagues or creating a disruption,” said Bell. “That’s still a major behavioral barrier that you have to overcome. </p>



<p>“The technology is ready, but maybe workplace etiquette and culture is not necessarily there yet,” she said.</p>



<p>Working remotely, Patalano said he and his team can side-step some of this awkwardness. But it still took time to adjust to voice inputs.<em> </em></p>



<p>“Because we’re fully remote, we don’t have the challenge of everybody sitting side by side in an office talking into their computers, which would be more challenging, I suspect. But even getting comfortable with talking out loud alone in a room took a minute,” he said. </p>



<p>As with any AI tool, there’s also the question of accuracy. </p>



<p>Even if vendors promise a low error rate, LLM outputs can still have errors, requiring users to check the results. “They can still mis-recognize what’s being said,” said Cowan. Those in high-risk sectors such as healthcare still need to go through the AI-edited text and “double- and triple-check” the dictation. </p>



<p>This friction means extra steps for a user working with the technology. </p>



<p>It doesn’t take much to dissuade workers from adopting a new tool, said <a href="https://www.jarnoldassociates.com/about/jon-arnold" target="_blank" rel="noreferrer noopener">Jon Arnold</a>, research analyst at J Arnold &amp; Associates. “There’s definitely a lot of use cases where it would have a lot of value, but you’ve got to trust it — if it’s not giving what you think it will, you’re either going to fine tune it or go back to the keyboard and do it the old-fashioned way,” he said.</p>



<p>There are also privacy concerns. Because some tools send voice data to the cloud for processing, organizations in heavily regulated industries such as finance, healthcare and government might move cautiously.</p>



<p>Bell points to two types of privacy: social, such as “having colleagues overhear what you’re saying,” and digital privacy, which relates to who else can access the conversation data. </p>



<p>App providers take different approaches; some process voice data on device, others send it to the cloud. That’s an important distinction for organizations with strict data protection requirements, said Bell. </p>



<p>“Where’s the voice data processed? Where is it stored? How can it be accessed? Enterprises are very, very focused on governance and data security and data privacy,” she said.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/05/evan-yang-LPAYmP4KSrg-unsplash.jpg?quality=50&amp;strip=all&amp;w=1024" alt="Rusty keyboard on the ground" class="wp-image-4175785" width="1024" height="683" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><a href="https://unsplash.com/@__evanyang__" target="_blank" class="imageCredit" rel="noopener">Evan Yang</a></div>



<h2 class="wp-block-heading">Too soon to ditch the keyboard?</h2>



<p>Despite growing interest in the technology, it’s still unclear whether a large number of workers will choose talking over typing. And remains to be seen whether startups that offer a best-of-breed AI dictation app can gain traction, or fade if the technology simply becomes embedded within the software ecosystems of larger tech firms.  </p>



<p>Workers are more familiar with voice technology, thanks to AI assistants in smartphones and smart speakers at home. That, said Bell, could improve the prospects of wider use in business settings. </p>



<p>“Voice interaction feels less niche than it did about five years ago,” she said. “Overall, the technology is improving quickly…, but how we’re really going to determine success is whether we can change human behavior.”</p>



<p>Arnold is bullish about the use of voice technology in the workplace: “Five or 10 years [from now], we won’t think twice about it. It’ll just be the norm.”</p>



<p>Bell is more cautious.She sees potential for AI dictation as a supplementary tool for communication-heavy work. “I don’t think it’s going to replace the keyboard, but I do think it could become a secondary interface,” she said.</p>



<p>Even Patalano doesn’t expect AI-assisted voice dictation to entirely replace typing “Your speaking voice and your written voice will always, to some degree, be different, and that’s okay: we should probably lean into that,” he said.</p>



<p>“I think there will always be a place for wordsmithing, crafting, writing – and the same with coding, too. There’s going to be lots of cases where every single word matters.”</p>



<p>He plans to continue using AI dictation, whether with Wispr Flow or other similar tools that might emerge in the future.  </p>



<p>While a lack of accuracy slowed adoption in the past, continued advances could open the door to wider workplace uptake.  </p>



<p>“When I try to use a voice tool and it misses even once, you kind of throw up your hands and walk away, because the cost of having to correct it is way more than the benefit of using it versus typing,” Patalano said. “But, especially with the improvements in LLMs and AI models generally, the accuracy of these is going to keep getting better and better. </p>



<p>“I’m already looking for more and more opportunities to use voice instead of having to type.” </p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[HPR4677: UNIX Curio #10 - Checksums and Hashes]]></title>
<description><![CDATA[This show has been flagged as Clean by the host.


This series is dedicated to exploring little-known—and occasionally useful—trinkets lurking in the dusty corners of UNIX-like operating systems.


In UNIX Curio #8 (
HPR episode 4657
), I talked about using standard utilities to compare files. L...]]></description>
<link>https://tsecurity.de/de/3650156/podcasts/hpr4677-unix-curio-10-checksums-and-hashes/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3650156/podcasts/hpr4677-unix-curio-10-checksums-and-hashes/</guid>
<pubDate>Tue, 07 Jul 2026 02:04:13 +0200</pubDate>
<category>🎥 Podcasts</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>This show has been flagged as Clean by the host.</p>

<blockquote>
This series is dedicated to exploring little-known—and occasionally useful—trinkets lurking in the dusty corners of UNIX-like operating systems.</blockquote>

<p>
In UNIX Curio #8 (<a href="https://hackerpublicradio.org/eps/hpr4657/" rel="noopener noreferrer" target="_blank">
HPR episode 4657</a>
), I talked about using standard utilities to compare files. Left unmentioned, however, was a method commonly used today—the hash function.</p>

<p>
As I've stated in previous entries, while I am an engineer, I don't have a background in computer science, so my understanding of the mathematics is limited. But I can give a practical description of what a hash function does. It takes an input, performs a set of calculations on it, and produces an output. As hash functions are practically used, the input is a set of bytes, such as a file or another piece of data like a password. The output is a numerical value in a fixed range—most often, expressed as hexadecimal characters. Because this "hash value" can always be represented in a certain number of bytes, its length as printed is usually a constant number of characters, padded with leading zeros if necessary. This episode will not cover the use of hashes in programming, focusing instead on using them to validate data.</p>

<p>
A hash function, or more specifically, a cryptographic hash function, has an additional property. It should be very difficult to predict what changes to the input would be required to produce a specific change in the output.</p>

<p>
An older, related concept is called a "checksum". While these are designed to vary when the input data is damaged or digits are transposed, they do not necessarily have that last property mentioned for cryptographic hashes. You have probably already encountered a checksum, even if you didn't recognize it. On a <a href="https://en.wikipedia.org/wiki/Payment_card_number" rel="noopener noreferrer" target="_blank">
16-digit number assigned to a Mastercard or Visa</a>

<sup>
1</sup>
 credit or debit card, the first six digits identify the card issuer (such as a bank), the next nine digits are assigned to you by the issuer, and the last digit is a check digit. The check digit is calculated using the values of the previous 15 digits, and it is a simple way to avoid typos in entering a card number.</p>

<p>
In another example, every <a href="https://en.wikipedia.org/wiki/Ethernet_frame#Frame_check_sequence" rel="noopener noreferrer" target="_blank">
Ethernet frame that your devices send or receive includes a checksum</a>

<sup>
2</sup>
 to help ensure that the contents weren't scrambled in transit. This is 32 bits long and is called a cyclical redundancy check, commonly referred to as a CRC. A CRC is also used in many other places—for example, the .zip file format includes one for each archive member, and this allows a program extracting files from the archive to identify if any were damaged.</p>

<p>
Our UNIX Curio for today is another example, <a href="https://pubs.opengroup.org/onlinepubs/009695399/utilities/cksum.html" rel="noopener noreferrer" target="_blank">
the </a>

<code>

<a href="https://pubs.opengroup.org/onlinepubs/009695399/utilities/cksum.html" rel="noopener noreferrer" target="_blank">
cksum</a>

</code>

<a href="https://pubs.opengroup.org/onlinepubs/009695399/utilities/cksum.html" rel="noopener noreferrer" target="_blank">
 utility</a>

<sup>
3</sup>
. It generates a 32-bit CRC based on the Ethernet algorithm. It operates on either a named file or standard input and outputs the CRC value, the length of the input, and the pathname if a file was given as an argument. Unlike most modern hashing programs, the checksum is printed as a decimal integer and is not padded, so it can be anywhere from one to ten digits long. The length value is the number of bytes in the input (actually specified as the number of <em>
octets</em>
, as systems could potentially use a byte that isn't eight bits long), also expressed as a decimal integer.</p>

<p>
There are two major ways that one could use <code>
cksum</code>
 to check the validity of a file. First, if you are transferring a file from one UNIX-like system to another, you could run <code>
cksum</code>
 against it on both systems and check that the CRC and length are the same. The utility can also be given multiple filenames as arguments, which would generate a list that can then be compared. The second way would be for someone publishing a file or set of files to also publish the CRC values, lengths, and names so that people downloading them could verify that they match. However, I don't think the practice of publishing lists like this really started until more recent hash functions like MD5 and SHA-1 came about so it is unlikely that anyone would publish CRC values instead.</p>

<p>
The advantage of these tools should be pretty obvious in comparison to <code>
cmp</code>
, one of the utilities discussed in UNIX Curio #8. To verify a file using <code>
cmp</code>
, you need two files to compare—if you're trying to check a large file you downloaded, you would need to spend the time and bandwidth to download a second copy. And if they didn't match, you would have no idea which of the two, if either, was correct. By contrast, <code>
cksum</code>
 is quicker to run, doesn't require downloading a massive amount of excess data, and if run against the original file, makes clear what the correct value is.</p>

<p>
This utility is a follow-on from a program called <code>
sum</code>
, which operated very much the same. I had a bit of trouble tracking down the exact development history, but what seems clear is that <a href="https://www.gnu.org/software/coreutils/manual/html_node/sum-invocation.html" rel="noopener noreferrer" target="_blank">
two different variants</a>

<sup>
4</sup>
 were popular: a BSD version and a System V version. Both output 16-bit checksums, but used different algorithms so they didn't give the same results. Also, the BSD version printed the length of the input data as the number of 1,024-byte blocks, while the System V version instead gave a count of 512-byte blocks. (Some sources <a href="https://man.freebsd.org/cgi/man.cgi?query=sum&amp;sektion=1&amp;manpath=FreeBSD+15.0-RELEASE+and+Ports" rel="noopener noreferrer" target="_blank">
claim that System V </a>

<code>

<a href="https://man.freebsd.org/cgi/man.cgi?query=sum&amp;sektion=1&amp;manpath=FreeBSD+15.0-RELEASE+and+Ports" rel="noopener noreferrer" target="_blank">
sum</a>

</code>

<a href="https://man.freebsd.org/cgi/man.cgi?query=sum&amp;sektion=1&amp;manpath=FreeBSD+15.0-RELEASE+and+Ports" rel="noopener noreferrer" target="_blank">
 generates a 32-bit checksum</a>

<sup>
5</sup>
, which could possibly be true internal to the algorithm, but I have tested several independent implementations of the utility and all of them output a 16-bit value for both the System V and BSD algorithms.)</p>

<p>
From what I can tell, <a href="https://www.tuhs.org/cgi-bin/utree.pl?file=3BSD/usr/src/cmd/sum.c" rel="noopener noreferrer" target="_blank">
the BSD version</a>

<sup>
6,7</sup>
 came first; it was in 3BSD but probably appeared even earlier. An identical <a href="https://www.tuhs.org/cgi-bin/utree.pl?file=32V/usr/src/cmd/sum.c" rel="noopener noreferrer" target="_blank">
copy of BSD's </a>

<code>

<a href="https://www.tuhs.org/cgi-bin/utree.pl?file=32V/usr/src/cmd/sum.c" rel="noopener noreferrer" target="_blank">
sum</a>

</code>

<a href="https://www.tuhs.org/cgi-bin/utree.pl?file=32V/usr/src/cmd/sum.c" rel="noopener noreferrer" target="_blank">
 was included with UNIX/32V</a>

<sup>
8,9</sup>
, which was AT&amp;T's 1979 port of Seventh Edition UNIX to the VAX and became one of the ancestors of System III. The divergence seems to have started with System III, released in 1980; <a href="https://www.tuhs.org/cgi-bin/utree.pl?file=SysIII/usr/src/cmd/sum.c" rel="noopener noreferrer" target="_blank">
its version of the </a>

<code>

<a href="https://www.tuhs.org/cgi-bin/utree.pl?file=SysIII/usr/src/cmd/sum.c" rel="noopener noreferrer" target="_blank">
sum</a>

</code>

<a href="https://www.tuhs.org/cgi-bin/utree.pl?file=SysIII/usr/src/cmd/sum.c" rel="noopener noreferrer" target="_blank">
 utility</a>

<sup>
10,11</sup>
 changed to a new default algorithm, though it could be made to use the BSD algorithm via the <code>
-r</code>
 option. System V looks to have kept the same behavior as System III. It's not clear to me why this algorithm is universally called the "System V algorithm" rather than the "System III algorithm"; perhaps it is because System V saw much more widespread use.</p>

<p>
Instead of trying to reconcile these differences, the POSIX committee decided to create a new utility with a unique name, use a separate algorithm entirely, and avoid the block-length dispute by printing the length in octets instead of blocks. I should point out that POSIX states that the CRC algorithm for <code>
cksum</code>
 does not strictly meet the mathematical definition of a "checksum". I don't know enough to say exactly <em>
why</em>
 it doesn't qualify or to say whether either of the <code>
sum</code>
 algorithms do. However, in less-formal usage the term "checksum" has gathered the meaning of any value used to represent or validate a set of data, so I am fine with using it no matter the technical details of the algorithm.</p>

<p>
When two different inputs produce the same checksum or hash value, this is called a "collision". Because the output value has a limited range, there are an infinite number of possible inputs that could produce a collision. From a practical standpoint the possibilities are more limited—the majority of these inputs are larger than the number of atoms in the universe, which can't fit on any machine. Unlike a cryptographic hash algorithm, the CRC is not specifically designed to resist an attacker crafting a malicious input that would cause a collision. However, it should be sufficient to detect accidental damage.</p>

<p>
Programs implementing more modern cryptographic hash algorithms are superior to the checksum utilities in avoiding collisions (whether malicious or accidental), but there are still three advantages that the older programs have. First, a system running a historical operating system might not have the hash programs available, but is more likely to have <code>
cksum</code>
 or <code>
sum</code>
 already included. Second, the checksum values are much shorter than the hashes output by the newer programs, making them easier for a user to compare by looking at them. This advantage is not as great as it might appear at first, because a common way to check a hash these days is to save a list of hashes and filenames—the hash programs can use that and do the comparison themselves, sparing the user from having to validate it character by character. The third advantage is that <code>
cksum</code>
 prints the input length in bytes. This greatly limits the number of inputs that could be maliciously crafted to create a collision.</p>

<p>
I did a moderate amount of research on implementations of modern cryptographic hash algorithms and found that some, such as MD5, SHA-1, and SHA-2, do use the length of the input (often termed "message length" in the literature) as part of the material fed in to the algorithm, but none of the hashing utilities present this length to the user as part of its output. There are two possible reasons for this that seem evident to me. First, if one is hashing a password, you would certainly not want to give a clear indication of its length—that would give any attacker a massive head start on guessing the password. However, that doesn't explain why one would avoid printing the input length for a file that is made publicly available. Second, it is convenient in many contexts, such as database entries or in software (such as <code>
git</code>
), for the hash to be a fixed length. Including an extra value that can be of variable length would complicate those use cases. However, the length value could simply be dropped and they would be no worse off than they are currently.</p>

<p>
Historically on UNIX, password hashing was treated differently from checksumming files—<a href="https://pubs.opengroup.org/onlinepubs/009695399/functions/crypt.html" rel="noopener noreferrer" target="_blank">
the </a>

<code>

<a href="https://pubs.opengroup.org/onlinepubs/009695399/functions/crypt.html" rel="noopener noreferrer" target="_blank">
crypt()</a>

</code>

<a href="https://pubs.opengroup.org/onlinepubs/009695399/functions/crypt.html" rel="noopener noreferrer" target="_blank">
 function</a>

<sup>
12</sup>
 was used for passwords while <code>
sum</code>
 and later <code>
cksum</code>
 were used to confirm a file's integrity. So even rather early on, these two use cases employed algorithms with different properties, but I haven't dived into the history deeply enough to know how intentional this was. My discussion in this episode focuses on the file use case, so understand that I'm largely avoiding the topic of password hashing. Digital signatures are yet another use case, one that I'm ignoring entirely.</p>

<p>
Every few years, some security researcher declares a particular hash algorithm to be "broken" and that everyone should move over to a new one, which generally has a longer hash. While the larger hash space certainly reduces the opportunity for collisions, this disrupts workflows, such as publishing information about software releases by e-mail, which still tends to observe a <a href="https://datatracker.ietf.org/doc/html/rfc2822#section-2.1.1" rel="noopener noreferrer" target="_blank">
78-character limit on each line</a>

<sup>
13</sup>
, making it harder to include a list of hashes with filenames next to them. This is in addition to the work of modifying software and scripts to use the new algorithm and managing how to treat past data. It seems to me that publishing the input length along with the hash would make it far more difficult to craft a malicious input that matches both, but I haven't found discussion of that during my investigation. (See the Appendix for a possible implementation.) Perhaps someone listening can record a response episode for HPR explaining that.</p>

<p>
References:</p>

<ol>

<li>

<a href="https://en.wikipedia.org/wiki/Payment_card_number" rel="noopener noreferrer" target="_blank">
Payment card number</a>
 https://en.wikipedia.org/wiki/Payment_card_number</li>

<li>

<a href="https://en.wikipedia.org/wiki/Ethernet_frame#Frame_check_sequence" rel="noopener noreferrer" target="_blank">
Ethernet frame: Frame check sequence</a>
 https://en.wikipedia.org/wiki/Ethernet_frame#Frame_check_sequence</li>

<li>

<a href="https://pubs.opengroup.org/onlinepubs/009695399/utilities/cksum.html" rel="noopener noreferrer" target="_blank">
Cksum specification</a>
 https://pubs.opengroup.org/onlinepubs/009695399/utilities/cksum.html</li>

<li>

<a href="https://www.gnu.org/software/coreutils/manual/html_node/sum-invocation.html" rel="noopener noreferrer" target="_blank">
GNU coreutils manual: sum</a>
 https://www.gnu.org/software/coreutils/manual/html_node/sum-invocation.html</li>

<li>

<a href="https://man.freebsd.org/cgi/man.cgi?query=sum&amp;sektion=1&amp;manpath=FreeBSD+15.0-RELEASE+and+Ports" rel="noopener noreferrer" target="_blank">
FreeBSD 15.0 sum manual page</a>
 https://man.freebsd.org/cgi/man.cgi?query=sum&amp;sektion=1&amp;manpath=FreeBSD+15.0-RELEASE+and+Ports</li>

<li>

<a href="https://www.tuhs.org/cgi-bin/utree.pl?file=3BSD/usr/man/man1/sum.1" rel="noopener noreferrer" target="_blank">
3BSD sum manual page</a>
 https://www.tuhs.org/cgi-bin/utree.pl?file=3BSD/usr/man/man1/sum.1</li>

<li>

<a href="https://www.tuhs.org/cgi-bin/utree.pl?file=3BSD/usr/src/cmd/sum.c" rel="noopener noreferrer" target="_blank">
3BSD sum source</a>
 https://www.tuhs.org/cgi-bin/utree.pl?file=3BSD/usr/src/cmd/sum.c</li>

<li>

<a href="https://www.tuhs.org/cgi-bin/utree.pl?file=32V/usr/man/man1/sum.1" rel="noopener noreferrer" target="_blank">
UNIX/32V sum manual page</a>
 https://www.tuhs.org/cgi-bin/utree.pl?file=32V/usr/man/man1/sum.1</li>

<li>

<a href="https://www.tuhs.org/cgi-bin/utree.pl?file=32V/usr/src/cmd/sum.c" rel="noopener noreferrer" target="_blank">
UNIX/32V sum source</a>
 https://www.tuhs.org/cgi-bin/utree.pl?file=32V/usr/src/cmd/sum.c</li>

<li>

<a href="https://www.tuhs.org/cgi-bin/utree.pl?file=SysIII/usr/src/man/man1/sum.1" rel="noopener noreferrer" target="_blank">
System III sum manual page</a>
 https://www.tuhs.org/cgi-bin/utree.pl?file=SysIII/usr/src/man/man1/sum.1</li>

<li>

<a href="https://www.tuhs.org/cgi-bin/utree.pl?file=SysIII/usr/src/cmd/sum.c" rel="noopener noreferrer" target="_blank">
System III sum source</a>
 https://www.tuhs.org/cgi-bin/utree.pl?file=SysIII/usr/src/cmd/sum.c</li>

<li>

<a href="https://pubs.opengroup.org/onlinepubs/009695399/functions/crypt.html" rel="noopener noreferrer" target="_blank">
Crypt specification</a>
 https://pubs.opengroup.org/onlinepubs/009695399/functions/crypt.html</li>

<li>

<a href="https://datatracker.ietf.org/doc/html/rfc2822#section-2.1.1" rel="noopener noreferrer" target="_blank">
RFC 2822: Internet Message Format: Line Length Limits</a>
 https://datatracker.ietf.org/doc/html/rfc2822#section-2.1.1</li>

<li>

<a href="https://lwn.net/ml/all/dd12623ae86aa5eb@cvs.openbsd.org/" rel="noopener noreferrer" target="_blank">
OpenSSH 10.1 released</a>
 https://lwn.net/ml/all/dd12623ae86aa5eb@cvs.openbsd.org/</li>

</ol>

<p>

<strong>
Appendix</strong>

</p>

<p>
The MD5 hash algorithm was (and still is) widely used, but many people characterize it as being "broken" and discourage its use. Let us imagine a variant of this, called MD5.L, where the normal MD5 hash is followed by a "." character and the input length expressed as a hexadecimal number.</p>

<p>
Take, for example, the <a href="https://lwn.net/ml/all/dd12623ae86aa5eb@cvs.openbsd.org/" rel="noopener noreferrer" target="_blank">
e-mail message announcing the release of OpenSSH 10.1</a>

<sup>
14</sup>
. At the bottom, it includes an SHA-1 hash and an SHA-2 256-bit hash for the available gzipped <code>
tar</code>
 files. That longer hash is encoded with Base64 because if it were given as a hexadecimal number, it would make the line longer than 78 bytes. The MD5.L hash of the file would be one character shorter than the SHA-1 hash, as shown below. (The extra length of the <em>
name</em>
 makes them both consume the same number of characters. The hashes shown are for the "portable" version of OpenSSH.)</p>

<p>
Some people claim SHA-1 is also broken, seeking to have people use newer and longer hash functions. For an attacker to compromise MD5.L in this example, they would not only have to create a valid <code>
tar</code>
 file compressed with <code>
gzip</code>
 containing a malicious payload having the right MD5 hash, that file would have to be exactly 1,972,831 bytes long (the decimal equivalent of 1e1a5f). While there are still many possible inputs that could be tried (256<sup>
1972831</sup>
, to be exact*), this is far fewer than the infinite possibilities for plain MD5, SHA-1, or SHA-2.</p>

<p>
If for some reason it is super important to have a fixed hash length, let's imagine another variation called MD5+L. In this one, instead of L being the input length, it is the input length <a href="https://www.mathwords.com/m/modulo.htm" rel="noopener noreferrer" target="_blank">
modulo</a>
 one terabyte (2<sup>
40</sup>
 bytes), which can be represented by 10 hexadecimal characters, left-padded with zeros. While this approach substantially increases the number of possible inputs an attacker could try, it is likely that an intended victim would notice that the file they downloaded is larger (or smaller) than expected by that much. The MD5+L hash is longer than a SHA-1 hash, but still shorter than a 256-bit SHA-2 hash.</p>

<pre data-language="plain">
SHA1 (openssh-10.1p1.tar.gz) = 7fd17b99d1beffb47cd380d64079e920bb0bd91f
SHA256 (openssh-10.1p1.tar.gz) = ufx6K4JXlGem8vQ+SoHI4d/aYU3bT5slWq/XAgu/B1g=
MD5.L (openssh-10.1p1.tar.gz) = 80dd9bb00a86519934710d05903fdf07.1e1a5f
MD5+L (openssh-10.1p1.tar.gz) = 80dd9bb00a86519934710d05903fdf07+00001e1a5f
</pre>

<p>
Of course, if MD5 is considered to be too weak even with the inclusion of the length, one could produce a ".L" or "+L" version of any hash function. However, longer hashes <em>
will</em>
 end up running into the 78-character limit.</p>

<p>

<em>
*This is a number with 4.75 million digits that the </em>

<code>

<em>
bc</em>

</code>

<em>
 utility on my laptop took almost 5 minutes to calculate.</em>

</p>


<p><a href="https://hackerpublicradio.org/eps/hpr4677/index.html#comments">Provide <strong>feedback</strong> on this episode</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Announcing new builds for July 6 2026]]></title>
<description><![CDATA[Hello Windows Insiders,
We have new releases today with builds across Beta and Experimental.
New builds this week
Today we are releasing new Windows 11 Insider Preview Builds. As a reminder, all Insiders can find the rel
The post Announcing new builds for July 6 2026 appeared first on Windows Ins...]]></description>
<link>https://tsecurity.de/de/3649878/windows-tipps/announcing-new-builds-for-july-6-2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3649878/windows-tipps/announcing-new-builds-for-july-6-2026/</guid>
<pubDate>Mon, 06 Jul 2026 23:11:57 +0200</pubDate>
<category>🪟 Windows Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Hello Windows Insiders,</p>
<p>We have new releases today with builds across Beta and Experimental.</p>
<p><strong>New builds this week</strong></p>
<p>Today we are releasing new Windows 11 Insider Preview Builds. As a reminder<strong>, all Insiders can find the rel</strong></p>
<p>The post <a href="https://blogs.windows.com/windows-insider/2026/07/06/announcing-new-builds-for-july-6-2026/">Announcing new builds for July 6 2026</a> appeared first on <a href="https://blogs.windows.com/windows-insider">Windows Insider Blog</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Apple Watch Ultra 3 drops to $699 with $100 Amazon discount]]></title>
<description><![CDATA[Amazon has knocked $100 off the Apple Watch Ultra 3, dropping Apple's premium smartwatch to $699.99 for a limited time.Save $100 on the Apple Watch Ultra 3 at Amazon - Image credit: AppleAmazon has cut the price of the Apple Watch Ultra 3 to $699.99, delivering a solid $100 discount on Apple's pr...]]></description>
<link>https://tsecurity.de/de/3649128/ios-mac-os/apple-watch-ultra-3-drops-to-699-with-100-amazon-discount/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3649128/ios-mac-os/apple-watch-ultra-3-drops-to-699-with-100-amazon-discount/</guid>
<pubDate>Mon, 06 Jul 2026 16:56:04 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Amazon has knocked $100 off the Apple Watch Ultra 3, dropping Apple's premium smartwatch to $699.99 for a limited time.<br><br><div><img src="https://photos5.appleinsider.com/gallery/68168-143696-apple-watch-ultra-3-100-off-sale-xl.jpg" alt="Promotional graphic showing a black Apple Watch Ultra 3 with detailed watch face, bold text announcing BEST PRICE and Apple Watch Ultra 3 100 dollars off on dark geometric background" height="720"><br><span>Save $100 on the Apple Watch Ultra 3 at Amazon - Image credit: Apple</span></div><br>Amazon has cut the price of the Apple Watch Ultra 3 to <a href="https://www.amazon.com/dp/B0FQFHVZYL?th=1&amp;tag=apinsiderdeals-20" rel="nofollow" target="_blank"><strong>$699.99</strong></a>, delivering a solid $100 discount on Apple's premium smartwatch. While we've seen the wearable dip to as low as $649 this year, today's offer remains one of the best widely available deals on the current-generation model.<br><br><a href="https://www.amazon.com/dp/B0FQFHVZYL?th=1&amp;tag=apinsiderdeals-20" rel="nofollow" class="deal-highlight">Buy Apple Watch Ultra 3 for $699.99</a><br><br><br> <a href="https://appleinsider.com/articles/26/07/06/apple-watch-ultra-3-drops-to-699-with-100-amazon-discount?utm_source=rss">Continue Reading on AppleInsider</a> | <a href="https://forums.appleinsider.com/discussion/244879?urm_source=rss">Discuss on our Forums</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Protocols and Servers 2 TryHackMe Writeup]]></title>
<description><![CDATA[Somewhere on a network right now, a username and password are crossing the wire in plain, readable text — and someone could be quietly reading them.No exploit. No zero-day. Just a protocol that was never built to keep a secret.That’s the uncomfortable little truth this room is built around. So le...]]></description>
<link>https://tsecurity.de/de/3646317/hacking/protocols-and-servers-2-tryhackme-writeup/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3646317/hacking/protocols-and-servers-2-tryhackme-writeup/</guid>
<pubDate>Sun, 05 Jul 2026 08:39:11 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><em>Somewhere on a network right now, a username and password are crossing the wire in plain, readable text — and someone could be quietly reading them.</em></p><figure><img alt="" src="https://cdn-images-1.medium.com/max/900/1*7OqFQcrh6OcgOZyqGjAyqw.png"></figure><p>No exploit. No zero-day. Just a protocol that was never built to keep a secret.</p><p>That’s the uncomfortable little truth this room is built around. So let’s pull it apart.</p><p>Most of the internet’s classic protocols were designed in a more trusting era. It was a time when the people sharing a network mostly knew each other, and “someone might be listening” wasn’t the default assumption.</p><p>Those protocols still run everywhere. And many of them still send your credentials across the wire in plain text.</p><p><strong>Protocols and Servers 2</strong> on TryHackMe is about exactly that gap, and what closes it. It walks through three foundational attacks against network protocols, then the defenses that neutralize each one:</p><ul><li>Sniffing — quietly reading traffic off the wire</li><li>Man-in-the-Middle (MITM) — sitting between two parties and tampering</li><li>Password attacks — guessing or cracking the credentials themselves</li></ul><p>This is a writeup of the whole room: the concepts in plain language, the commands that matter, and the task answers explained. If you’re working through it yourself, follow along.</p><blockquote>One idea ties the entire room together: cleartext protocols are insecure by design. Everything else is a consequence of that single fact.</blockquote><h3>Part 1 — Sniffing Attacks</h3><figure><img alt="" src="https://cdn-images-1.medium.com/max/911/1*mxa7u-z6cA7UEL5f8tjJQg.png"></figure><p>A <strong>sniffing attack</strong> is the simplest idea in the room: use a packet-capture tool to grab traffic as it crosses the network, then read it.</p><p>If a protocol talks in cleartext, anyone positioned to see that traffic can pull out private messages or login credentials. Nothing is encrypted before it leaves your machine.</p><pre>"Isn't everything encrypted now?"</pre><p>It’s tempting to think sniffing is a solved, retro problem now that TLS is everywhere. It isn’t. It stays dangerous wherever cleartext still lives:</p><ul><li><strong>Internal corporate networks</strong>, where machine-to-machine traffic is often left unencrypted</li><li><strong>Legacy systems </strong>like old mail servers, embedded devices, and industrial control systems</li><li><strong>Misconfigured services</strong> where TLS is available but not strictly enforced</li><li><strong>IoT devices</strong> that habitually use plain protocols</li><li><strong>Wireless networks</strong>, where anyone in range can listen</li><li>After a MITM attack that has successfully downgraded or stripped encryption</li></ul><blockquote>In real internal pentests and red-team work, sniffing is still one of the most reliable ways to harvest credentials and learn how systems actually talk to each other.</blockquote><h3>The tools</h3><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*xBxcZK8PVBApVtltOosP4Q.jpeg"><figcaption>Wireshark</figcaption></figure><p>Capturing packets needs a network card and the right privileges (root on Linux, administrator on Windows). Here are the staples:</p><ul><li><strong>tcpdump</strong> — lightweight open-source CLI capture tool, preinstalled on most Linux systems.</li><li><strong>Wireshark</strong> — the GUI standard, with powerful filtering, protocol dissection, and visualization.</li><li><strong>tshark</strong> — Wireshark’s command-line sibling, great for scripting.</li></ul><blockquote>Worth knowing too: <strong>tcpflow</strong> (reassembles TCP streams), <strong>ngrep</strong> (pattern-matching in traffic), and <strong>NetworkMiner</strong> (extracts files from captures).</blockquote><blockquote>Specialized credential-grabbers exist, but tcpdump and Wireshark can do the job with a little effort.</blockquote><h3>Capturing POP3 credentials with tcpdump</h3><p>The classic demo: a user checks email over POP3 (port 110, cleartext).</p><p>With access to the traffic — via a wiretap, a switch’s port mirroring, ARP spoofing, a compromised host, or a successful MITM — you run this command:</p><pre>sudo tcpdump port 110 -A</pre><p>Breaking that down:</p><ul><li>sudo — packet capture needs root privileges.</li><li>port 110 — only keep traffic to or from the POP3 server.</li><li>-A — print packet contents as ASCII, so cleartext is human-readable.</li></ul><p>In the capture, the login arrives across two packets and reads straight out:</p><pre>… USER frank … PASS D2xc9CgD</pre><p>Username frank, password D2xc9CgD, handed over in plain sight.</p><blockquote>Wireshark gets you there even faster: type “pop” in the display filter, and only POP3 traffic remains, credentials included.</blockquote><h4>Handy tcpdump filters</h4><pre>+------------------------------------+-----------------------------------------------------------+<br>| Command                            | Purpose                                                   |<br>+------------------------------------+-----------------------------------------------------------+<br>| sudo tcpdump port 110 -A           | Capture traffic on port 110 (POP3) in readable ASCII      |<br>| sudo tcpdump host 10.20.30.148 -A  | Capture ASCII traffic to/from a specific host IP          |<br>| sudo tcpdump port 80 -A            | Capture HTTP traffic (credentials in POST data)           |<br>| sudo tcpdump port 21 -A            | Capture FTP traffic (cleartext credentials)               |<br>| sudo tcpdump -w capture.pcap       | Save raw network packets to a file for later analysis     |<br>| tcpdump -r capture.pcap -A         | Read and display a saved capture file in ASCII text       |<br>+------------------------------------+-----------------------------------------------------------+</pre><h4>Mitigation</h4><p>Any cleartext protocol is exposed. The only requirement for the attack is a vantage point between the two parties or on the same network segment.</p><p>The core fix is encryption. This means wrapping the protocol in TLS (like HTTP to HTTPS, FTP to FTPS, or POP3 to POP3S) and replacing Telnet with SSH.</p><p>Layered on top of that:</p><ul><li>Network segmentation to limit who can see whose traffic</li><li>Encrypted VLANs or tunnels for sensitive internal traffic</li><li>802.1X port-based authentication so unknown devices can’t connect</li><li>Zero-trust thinking: treat every network as hostile and encrypt everything</li><li>Monitoring for ARP spoofing and other redirection to catch sniffing in progress</li></ul><p>Question: How do you capture only Telnet traffic with tcpdump? Answer: Telnet runs on port 23, so you add “port 23”.</p><p>Question: What is the simplest Wireshark display filter for IMAP? Answer: “imap”.</p><h3>Part 2 — Man-in-the-Middle (MITM) Attacks</h3><figure><img alt="" src="https://cdn-images-1.medium.com/max/678/1*uImWCNSpEizR46XoZzoc7g.png"><figcaption>Man-in-the-Middle Attack</figcaption></figure><p>Sniffing is passive listening. A <strong>MITM attack</strong> is active.</p><p>The attacker slips between two parties (A and B) so that A thinks it’s talking to B, while everything actually flows through the attacker. They can read and completely alter the data.</p><p>The room’s example says it best: A asks to transfer $20, the attacker rewrites the amount mid-flight, and B acts on the tampered message.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*C0zge6WQ4_HZjbPjnt1i0g.png"><figcaption>Image 1 from the room</figcaption></figure><p>It works whenever the protocol doesn’t verify the authenticity and integrity of each message.</p><h4>Getting into the middle</h4><p>To sit between two parties, an attacker has to redirect traffic through their own machine. Common routes include:</p><ul><li><strong>ARP spoofing</strong> — on a local network, the attacker sends forged ARP messages tying their own MAC address to the gateway’s IP, routing traffic directly to them.</li><li><strong>DNS spoofing </strong>— feeding false DNS answers to send victims to attacker-controlled servers.</li><li><strong>Rogue access points </strong>— fake Wi-Fi setups (like “Airport_WiFi_Free”) that route every connected victim’s traffic through the attacker.</li><li><strong>BGP hijacking </strong>— announcing false routes at the internet’s routing layer to reroute traffic for whole organizations or regions.</li></ul><h4>The tooling</h4><ul><li><strong>Bettercap </strong>— the modern, actively maintained successor to Ettercap. Handles ARP/DNS spoofing, HTTP/HTTPS proxying, and is modular.</li><li><strong>Ettercap</strong> — the classic LAN MITM tool. It still works, but Bettercap is generally preferred today.</li><li><strong>mitmproxy </strong>— an interactive HTTPS proxy used for inspecting and modifying web traffic on the fly.</li><li><strong>Responder </strong>—<strong> </strong>Windows-focused<strong>.</strong> Abuses fallback name-resolution protocols (LLMNR, NBT-NS) that kick in when DNS fails, answering with its own IP to capture authentication hashes. A staple of internal Active Directory pentests.</li></ul><h4>MITM against encrypted traffic</h4><p>Encryption raises the bar, but it isn’t a magic shield:</p><ul><li><strong>SSL stripping</strong> — quietly downgrade the victim’s connection to plain HTTP while the attacker keeps an HTTPS link to the real server. This is easy to miss if the user never typed <em>“https://”</em> or didn’t check for the padlock icon.</li><li><strong>Fake certificates</strong> — present your own certificate and run two separate encrypted legs. This works if the victim blindly clicks through the browser warning or if a Certificate Authority is compromised.</li><li><strong>Compromised or rogue CAs </strong>— the most serious case. If an attacker controls a trusted CA, they can mint valid-looking certificates for absolutely any domain.</li></ul><h4>Modern defenses</h4><p>A decade of security hardening makes MITM much harder now:</p><ul><li><strong>HTTPS by default</strong> (browsers flag plain HTTP as “Not Secure”)</li><li><strong>HSTS</strong> (forces HTTPS and blocks stripping attacks)</li><li><strong>Certificate Transparency</strong> (public, auditable logs of all issued certificates)</li><li><strong>Certificate pinning</strong> (apps accept only specific, hardcoded keys)</li><li><strong>DANE</strong> (publishing certificate info in DNSSEC-signed DNS)</li></ul><p>MITM still succeeds when users ignore certificate warnings, apps validate keys poorly, the target speaks cleartext, or legacy gear lacks modern features.</p><p>The fundamental fix remains the same: cryptography. You need authentication plus encryption/signing, which is exactly what properly implemented TLS provides.</p><p><strong>Question 1:</strong> How many interfaces does Ettercap offer?</p><pre>Answer: 3</pre><p><strong>Question 2:</strong> How many ways can you invoke Bettercap?</p><pre>Answer: 3</pre><h3>Part 3 — TLS: The Fix for Both Attacks</h3><figure><img alt="" src="https://cdn-images-1.medium.com/max/622/1*3Qn-dR4Ps9kwTxZGqRBBHw.jpeg"></figure><p>Both sniffing and MITM share one cure: TLS (Transport Layer Security). This part of the room is the solution chapter.</p><h4>A quick history</h4><p>SSL appeared in 1994 via Netscape, with SSL 3.0 dropping in 1996 as the web grew into shopping and payments. TLS succeeded it in 1999.</p><p>Where things stand now:</p><ul><li>SSL 2.0 and 3.0 are deprecated and highly insecure. Never use them.</li><li>TLS 1.0 and 1.1 were officially deprecated in 2021 and dropped by major browsers.</li><li>TLS 1.2 (from 2008) is still widely used and secure when configured with modern ciphers.</li><li>TLS 1.3 (from 2018) is the current standard. It features fewer algorithms, a faster handshake, and forward secrecy by default.</li></ul><p>People still say “SSL certificate” out of habit, but in practice, everything modern uses TLS.</p><h4>Where TLS sits</h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*Q9wEkyyAKPn28lVN9bDX2Q.png"><figcaption>Image 2 from the room</figcaption></figure><p>Cleartext application-layer protocols send data entirely in the open.</p><p>TLS adds encryption just below the application protocol, wrapping its data before it hits the network card. On the OSI model, it lives right between the transport and application layers.</p><h4>Upgrading protocols with TLS</h4><ul><li>HTTP (Port 80) upgrades to HTTPS (Port 443)</li><li>FTP (Port 21) upgrades to FTPS (Port 990)</li><li>SMTP (Port 25) upgrades to SMTPS (Port 465)</li><li>POP3 (Port 110) upgrades to POP3S (Port 995)</li><li>IMAP (Port 143) upgrades to IMAPS (Port 993)</li></ul><p>It’s not just web and mail. DNS can be wrapped too via DoT (DNS over TLS) on port 853, or DoH (DNS over HTTPS) on port 443. Both stop eavesdroppers from seeing which sites you look up.</p><h4>Implicit TLS vs STARTTLS</h4><ul><li>Implicit TLS uses a dedicated port that is fully encrypted from the very first byte (like 443 or 993).</li><li>STARTTLS connects in cleartext on the normal port, then issues a “STARTTLS” command to upgrade the connection in place. This is common for email setup.</li></ul><blockquote>Both offer encryption, but implicit TLS is highly preferred.</blockquote><p>A MITM attacker can easily strip the STARTTLS command during negotiation and force the session to stay in cleartext if the client isn’t configured to require it.</p><h4>How HTTPS works</h4><p>Plain HTTP takes two steps: open a TCP connection, then send requests. HTTPS inserts a step in between:</p><ol><li>Establish a standard TCP connection.</li><li>Establish a TLS connection (the handshake).</li><li>Send the HTTP requests, which are now fully encrypted.</li></ol><p>A simplified TLS 1.2 handshake goes like this:</p><blockquote><strong>ClientHello</strong> (client offers its TLS versions and cipher suites) <strong>→</strong> <strong>ServerHello</strong> (server picks the parameters and sends its certificate) <strong>→ Key Exchange</strong> (both derive a shared secret)<strong> →</strong> <strong>Finished</strong> (both confirm and switch to encrypted communication):</blockquote><pre>ClientHello → ServerHello → Key Exchange → Finished</pre><h4>Certificates and trust</h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/980/1*-10wNzrM0tEpRINoAqc5mQ.png"><figcaption>Certificate Authority (CA)</figcaption></figure><p>HTTPS leans on certificates signed by trusted Certificate Authorities (CAs). Your browser expects a valid certificate from a trusted CA, which proves you’re talking to the real server and blocks easy MITM attempts.</p><p>A certificate shows who it was issued to, who issued it, and its validity period. An expired certificate should never be trusted.</p><p>The modern ecosystem made this nearly universal thanks to automated platforms like <a href="https://letsencrypt.org/"><em>Let’s Encrypt</em></a>, which pushed global HTTPS traffic past 95%.</p><p><strong>Question:</strong> What is the three-letter acronym for the DNS protocol that uses TLS?</p><pre>Answer: DoT (DNS over TLS)</pre><h3>Part 4 — SSH: Secure Remote Administration</h3><figure><img alt="" src="https://cdn-images-1.medium.com/max/920/1*EidIDqyfQGBr2l3Y-KLmog.png"><figcaption>SSH</figcaption></figure><p>SSH (Secure Shell) is the secure replacement for Telnet. It is the universal way to administer servers, network gear, and cloud infrastructure.</p><p>The “S” means you can confirm the server’s identity, your messages are encrypted for the intended recipient only, and any data tampering is instantly detectable.</p><blockquote>It handles confidentiality and integrity seamlessly over port 22.</blockquote><h4>Authentication methods</h4><ul><li><strong>Password </strong>— The simplest method. The password rides the encrypted channel, but weak choices can still fall to brute-force attacks.</li><li><strong>Public key (recommended) </strong>— A private key stays on your machine, while the public key goes on the server. The server challenges you to prove you hold the private key without ever transmitting it.</li><li><strong>Certificate-based </strong>— An SSH CA signs user and host keys. This scales incredibly well because you don’t have to manually distribute public keys to every single server.</li><li><strong>MFA </strong>— Combines a traditional key or password with a one-time code for high-security environments.</li></ul><h4>Connecting</h4><ul><li>To connect, you run:</li></ul><pre>ssh mark@MACHINE_IP</pre><p>Enter the password or let your key authenticate, and you are on the remote terminal. Every single command you send runs over an encrypted channel.</p><p><strong>Question:</strong> Connect as mark (password XBtc49AB) and find the kernel release with uname -r.</p><pre>Commands: ssh mark@MACHINE_IP uname -r</pre><pre>Answer: 5.15.0–119-generic</pre><h4>Host key verification</h4><p>On your very first connection, SSH shows the server’s key fingerprint and asks if you want to continue.</p><p>Ideally, you verify this fingerprint through an admin or config management before typing “yes”. It is then saved in your local known_hosts file.</p><p>If that key ever changes unexpectedly in the future, SSH throws a massive warning, a major indicator of a potential MITM attack or a reinstalled server.</p><h4>Generating keys</h4><ul><li>To create a new key pair, run:</li></ul><pre>ssh-keygen -t ed25519 -C "your_email@example.com"</pre><p>The private key stays strictly on your machine and should be passphrase-protected. The public key (.pub) is safe to share. You can push it to a remote server easily using:</p><pre>ssh-copy-id mark@MACHINE_IP</pre><h4>Useful options</h4><pre>+--------------------------------------------+------------------------------------------------------------+<br>| Command                                    | Purpose                                                    |<br>+--------------------------------------------+------------------------------------------------------------+<br>| ssh -p 2222 mark@MACHINE_IP                | Connect to a remote server running on a non-standard port   |<br>| ssh -i ~/.ssh/custom_key mark@MACHINE_IP   | Specify a specific private key file to use for login       |<br>| ssh -J bastion.example.com mark@internal   | Jump through a secure bastion host to reach an internal IP |<br>| ssh -L 8080:localhost:80 mark@MACHINE_IP   | Set up a local port forward to tunnel traffic through SSH  |<br>| ssh -D 9050 mark@MACHINE_IP                | Create a dynamic SOCKS proxy forward for traffic routing   |<br>| ssh mark@MACHINE_IP "cat /etc/passwd"      | Run a single, one-off command without opening a full shell |<br>+--------------------------------------------+------------------------------------------------------------+</pre><h4>Secure file transfer</h4><ul><li><strong>SFTP</strong> — Interactive, FTP-like file management running completely over SSH. This is the recommended choice today.</li><li><strong>SCP </strong>— Simple file copies over SSH. This is now deprecated by OpenSSH in favor of SFTP, though it still works on most systems.</li><li><strong>rsync over SSH </strong>— The best option for large or repeated transfers because it only copies the specific parts of files that changed.</li></ul><p>To copy files via SCP:</p><pre>scp mark@MACHINE_IP:/home/mark/archive.tar.gz ~/ (remote to local)</pre><pre>scp backup.tar.bz2 mark@MACHINE_IP:/home/mark/ (local to remote)</pre><p><strong>Quick clarifier:</strong></p><blockquote>SFTP runs over SSH (port 22).</blockquote><blockquote>FTPS is FTP-over-TLS (port 990).</blockquote><p>They are entirely different protocols despite having similar names.</p><p><strong>Question:</strong> Download book.txt from the remote system; what download size did scp display in KB?</p><pre>Command: scp mark@MACHINE_IP:/home/mark/book.txt ~/</pre><pre>Answer: 415</pre><h4>Hardening SSH</h4><p>To protect a server, you can modify its config file <em>(/etc/ssh/sshd_config)</em>:</p><ul><li>Set PasswordAuthentication to “no” once public keys are established.</li><li>Set PermitRootLogin to “no” to force users to log in with regular accounts first.</li><li>Use AllowUsers or AllowGroups to create an explicit access whitelist.</li><li>Change the default port to reduce automated log noise.</li><li>Deploy fail2ban to automatically block IPs with repeated failed login attempts.</li></ul><h3>Part 5 — Password Attacks</h3><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*6_lWVwmNlB93-2JkYWo8Og.png"></figure><p>Even with a network fully encrypted, authentication remains a primary target. Authentication is simply the act of proving your identity, like entering a password to access a service.</p><p>The three factors:</p><ul><li><strong>Something you know </strong>— a password or PIN</li><li><strong>Something you have </strong>— a phone, hardware security key, or smart card</li><li><strong>Something you are </strong>— a fingerprint or facial scan</li></ul><p>This section focuses entirely on attacking “something you know.”</p><h4>Why weak passwords persist</h4><p>Massive historic breaches show that old habits die hard.</p><p>The most common passwords found in modern breaches still include variations like 123456, password, qwerty, Password1, and seasonal choices like Summer2024.</p><p>Because people constantly reuse passwords across multiple sites, a single leak frequently gives attackers access to entirely unrelated corporate or personal accounts.</p><h4>Types of attacks</h4><ul><li><strong>Guessing </strong>— using personal info like a target’s pet, birth year, or favorite sports team harvested from social media.</li><li><strong>Dictionary</strong>— automatically trying lists of real words and common variations.</li><li><strong>Brute force </strong>— systematically trying every possible characters combination. This is exhaustive, which is why password length matters so much.</li><li><strong>Credential stuffing</strong> — taking leaked username/password pairs from old breaches and automatically testing them against other web services.</li><li><strong>Password spraying </strong>— testing one or two incredibly common passwords against a massive list of user accounts to dodge lockout policies.</li><li><strong>Hybrid</strong> — combining dictionary words with systematic patterns, like capitalizing the first letter and adding a year to the end.</li></ul><h4>Wordlists</h4><ul><li>The classic go-to wordlist is RockYou, located on the TryHackMe AttackBox at:</li></ul><pre>/usr/share/wordlists/rockyou.txt</pre><blockquote>Beyond that, security professionals use collections like SecLists, CrackStation lists, or custom-generated lists tailored specifically to the target’s language, region, or industry habits.</blockquote><h4>THC Hydra</h4><p>Hydra is a fast network login cracker that throws wordlists at live services like FTP, POP3, IMAP, SSH, and HTTP.</p><p>The basic syntax looks like this:</p><pre>hydra -l username -P wordlist.txt server service</pre><ul><li>-l specifies a single username (-L for a text file of names)</li><li>-P specifies a password wordlist (-p for a single password)</li><li>server is the target IP or hostname</li><li>service is the protocol you are targeting</li></ul><p>Examples:</p><pre>hydra -l mark -P /usr/share/wordlists/rockyou.txt MACHINE_IP ftp<br>hydra -l frank -P /usr/share/wordlists/rockyou.txt MACHINE_IP ssh<br>hydra -l lazie -P /usr/share/wordlists/rockyou.txt MACHINE_IP imap</pre><p>Handy options include -s to target a non-default port, -vV for detailed verbosity, -t to adjust parallel attack threads, and -f to immediately stop execution when the first valid password is found.</p><h4>Other tools</h4><p>Alternative online crackers include <strong>Medusa</strong> and <strong>Ncrack</strong>.</p><p>For Windows and Active Directory environments, tools like <strong>NetExec</strong> excel at spraying credentials over SMB and LDAP.</p><p>If you manage to dump password hashes from a database, offline tools like <strong>Hashcat</strong> or <strong>John the Ripper </strong>are used because they can guess millions of combinations per second without worrying about network lag or lockouts.</p><h4>Mitigation</h4><p>Defending against password attacks requires a modern approach to identity management:</p><ul><li>Enforce <strong>length-first password policies</strong> based on NIST guidelines. Favor overall length over complex character rotation, and check new passwords against lists of known compromised credentials.</li><li>Implement <strong>strict account lockout</strong> or <strong>throttling mechanisms</strong> to kill automated automated guessing, while remaining aware of password spraying patterns.</li><li>Use <strong>CAPTCHAs</strong> to prevent basic bot execution on login forms.</li><li>Deploy <strong>Multi-Factor Authentication (MFA)</strong> across all external endpoints.</li><li>Transition toward <strong>passwordless ecosystems</strong>, utilizing passkeys (FIDO2/WebAuthn), hardware keys, or verified magic links.</li></ul><p><strong>Question: </strong>One email account is lazie; what password accesses the IMAP service?</p><pre>Command: hydra -l lazie -P /usr/share/wordlists/rockyou.txt MACHINE_IP imap</pre><pre>Answer: butterfly</pre><h3>Key Takeaways</h3><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*35eDunQG0NLCy_K2XVOvtA.jpeg"></figure><p>The fundamental rule of network security is simple:</p><blockquote>Cleartext protocols are inherently insecure.</blockquote><p>Anything sent without encryption can be effortlessly intercepted by sniffing or manipulated via a Man-in-the-Middle attack.</p><p>The security path forward is uniform across all services:</p><ul><li>Use HTTPS instead of HTTP</li><li>Use SSH instead of Telnet</li><li>Use SFTP or FTPS instead of basic FTP</li><li>Use IMAPS, POP3S, and SMTPS instead of their legacy cleartext variants</li></ul><p>Even when a connection is perfectly encrypted, weak passwords remain a glaring vulnerability.</p><p>Secure the protocol with robust encryption, then secure the account with long passwords, rate limiting, and multi-factor authentication.</p><h4>Quick Port Reference Guide</h4><pre>+-------------------+------+----------------+<br>| Protocol          | Port | Security       |<br>+-------------------+------+----------------+<br>| FTP               | 21   | Cleartext      |<br>| FTPS              | 990  | TLS (implicit) |<br>| HTTP              | 80   | Cleartext      |<br>| HTTPS             | 443  | TLS (implicit) |<br>| IMAP              | 143  | Cleartext      |<br>| IMAPS             | 993  | TLS (implicit) |<br>| POP3              | 110  | Cleartext      |<br>| POP3S             | 995  | TLS (implicit) |<br>| SMTP              | 25   | Cleartext      |<br>| SMTP submission   | 587  | STARTTLS       |<br>| SMTPS             | 465  | TLS (implicit) |<br>| SSH / SFTP        | 22   | Encrypted (SSH)|<br>| Telnet            | 23   | Cleartext      |<br>+-------------------+------+----------------+</pre><p><em>Room: Protocols and Servers 2 — TryHackMe (</em><a href="https://tryhackme.com/room/protocolsandservers2"><em>https://tryhackme.com/room/protocolsandservers2</em></a><em>). This writeup is for educational purposes; only test systems you’re authorized to. Have fun!</em></p><p><em>This article was written by Pop123 as a walkthrough for the TryHackMe lab. I am as always open to further discussing the topic.</em></p><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=42c2d01f5c6c" width="1" height="1" alt=""><hr><p><a href="https://infosecwriteups.com/protocols-and-servers-2-tryhackme-writeup-42c2d01f5c6c">Protocols and Servers 2 TryHackMe Writeup</a> was originally published in <a href="https://infosecwriteups.com/">InfoSec Write-ups</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[kernel.org listing strange releases (super old versions appearing as current)]]></title>
<description><![CDATA[Update It's back to normal regarding the website display, but the links for the releases might not work (404 error). This could depend on your location though. Be patient. :-)  Just a heads-up: Seems like something or someone is re-ordering the entries, which currently results in 6.16 receiving t...]]></description>
<link>https://tsecurity.de/de/3646098/linux-tipps/kernelorg-listing-strange-releases-super-old-versions-appearing-as-current/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3646098/linux-tipps/kernelorg-listing-strange-releases-super-old-versions-appearing-as-current/</guid>
<pubDate>Sun, 05 Jul 2026 04:09:29 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><hr> <h4>Update</h4> <p>It's back to normal regarding the website display, but the links for the releases might not work (404 error). This could depend on your location though. Be patient. :-)</p> <hr> <p>Just a heads-up:</p> <p>Seems like something or someone is re-ordering the entries, which currently results in 6.16 receiving the "Latest release" label.</p> <p>Let's hope it's a minor issue and gets fixed soon.</p> <hr> <p><strong>Live link</strong>: <a href="https://www.kernel.org/">https://www.kernel.org/</a> <em>(now states <code>6.19.14</code> and LTS kernels look normal, seems to be coming back again)</em></p> <p><strong>Status link</strong> (thanks <a href="https://www.reddit.com/u/tfks">u/tfks</a>): <a href="https://status.linuxfoundation.org/">https://status.linuxfoundation.org/</a></p> <blockquote> <p>Kernel Mirrors Sync Issues</p> <p>Update - The recovery process is still in progress. ETA to full restoration is another 12 hours. Affected files are available as they are synced. Jul 03, 2026 - 06:23 UTC</p> </blockquote> <hr> <p>[unavoidable joke about AI and local agents here] /s</p> <hr> <p>PS: The last proper reading I received came from the <strong>RSS feed</strong> announcing "next-20260703"</p> <p>Also: Greetings to all you folks self-compiling your kernels :-)</p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/28874559260134F"> /u/28874559260134F </a> <br> <span><a href="https://i.redd.it/wfnjt56ub8bh1.png">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/1unblw6/kernelorg_listing_strange_releases_super_old/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[Breaking: Sony is launching a new RX10 bridge camera next week! Here's what we can learn from the shock teaser]]></title>
<description><![CDATA[Sony just teased a new RX10 camera, announcing: 'The wait is over'. For clarity, its most recent bridge camera was the RX10 IV, which landed in 2017 and is now discontinued]]></description>
<link>https://tsecurity.de/de/3644075/it-nachrichten/breaking-sony-is-launching-a-new-rx10-bridge-camera-next-week-heres-what-we-can-learn-from-the-shock-teaser/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3644075/it-nachrichten/breaking-sony-is-launching-a-new-rx10-bridge-camera-next-week-heres-what-we-can-learn-from-the-shock-teaser/</guid>
<pubDate>Fri, 03 Jul 2026 18:49:25 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Sony just teased a new RX10 camera, announcing: 'The wait is over'. For clarity, its most recent bridge camera was the RX10 IV, which landed in 2017 and is now discontinued]]></content:encoded>
</item>
<item>
<title><![CDATA[Microsoft launches AI engineering company]]></title>
<description><![CDATA[Microsoft has unveiled the Microsoft Frontier Company, a new operating business focused on delivering “frontier transformation” through AI for Microsoft’s customers around the world. Microsoft Frontier Company launches with a $2.5 billion investment from Microsoft and 6,000 industry and engineeri...]]></description>
<link>https://tsecurity.de/de/3642552/ai-nachrichten/microsoft-launches-ai-engineering-company/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3642552/ai-nachrichten/microsoft-launches-ai-engineering-company/</guid>
<pubDate>Fri, 03 Jul 2026 03:48:02 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Microsoft has unveiled the Microsoft Frontier Company, a new operating business focused on delivering “frontier transformation” through AI for Microsoft’s customers around the world. Microsoft Frontier Company launches with a $2.5 billion investment from Microsoft and 6,000 industry and engineering experts who will be embedded with customers to co-design, co-innovate, deploy, and continuously improve their AI systems, Judson Althoff, CEO of Microsoft Commercial Business, said in a <a href="https://blogs.microsoft.com/blog/2026/07/02/microsoft-frontier-company-ai-engineering-that-amplifies-and-protects-your-intelligence/" data-type="link" data-id="https://blogs.microsoft.com/blog/2026/07/02/microsoft-frontier-company-ai-engineering-that-amplifies-and-protects-your-intelligence/">July 2 blog post</a> announcing the new company.</p>



<p>Microsoft Frontier Company will provide a unique combination of skills that include deep industry knowledge, change management and continuous improvement experience, and enterprise-grade AI engineering expertise, Althoff said. Companies as part of the effort are being encouraged to establish an intelligence platform so their “unique IQ” — their proprietary data, expertise, workflows, and decision-making processes — compounds over time from within, using their choice of models to build AI solutions and workflows. At the same time, they need a trusted platform that allows them to observe, govern, manage, and secure AI solutions across every layer of the technology stack, Althoff said.</p>



<p>AI engineering expertise and deep industry knowledge are required to build a system that acts as a continuous loop of improvement between these two platforms. This is what Microsoft Frontier Company was built to do, Althoff said. </p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Celebrating 1 Million Subscribers on July 8th!]]></title>
<description><![CDATA[Author: The Cyber Mentor - Bewertung: 0x - Views:2 https://www.tcm.rocks/youtube-party - Join our YouTube livestream party on July 8th at 12 PM ET! Heath Adams makes his grand return, Alex Olsen and Andrew Bellini get in on the fun, we'll be giving away 1 (one) ticket to DEF CON plus travel costs...]]></description>
<link>https://tsecurity.de/de/3641443/it-security-video/celebrating-1-million-subscribers-on-july-8th/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3641443/it-security-video/celebrating-1-million-subscribers-on-july-8th/</guid>
<pubDate>Thu, 02 Jul 2026 16:18:16 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: The Cyber Mentor - Bewertung: 0x - Views:2 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/LNcrqBRvRb0?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>https://www.tcm.rocks/youtube-party - Join our YouTube livestream party on July 8th at 12 PM ET! Heath Adams makes his grand return, Alex Olsen and Andrew Bellini get in on the fun, we'll be giving away 1 (one) ticket to DEF CON plus travel costs, and we'll also be announcing the 15 lucky winners who will be part of our mentorship program later this summer.<br />
<br />
Make sure you sign up for the DEF CON and mentorship giveaways ahead of time! https://www.tcm.rocks/youtube-party<br />
<br />
We're also in the thick of our Summer Sale! Get 20% off certs and live trainings in addition to 50% off your first payment to the TCM Security Academy when you purchase an All-Access Membership (use code CAMPTCM to redeem.) <br />
<br />
See you soon!<br />
<br />
#tcmsecurity #shorts #shortsfeed #cybersecurity #defcon <br />
<br />
<br />
Sponsor a Video: https://www.tcm.rocks/Sponsors<br />
Pentests & Security Consulting: https://tcm-sec.com<br />
Get Trained: https://www.tcm.rocks/acad-y<br />
Get Certified: http://www.tcm.rocks/certs-y<br />
Merch: https://www.bonfire.com/store/tcm-security/<br />
<br />
📱Social Media📱<br />
___________________________________________<br />
X: https://x.com/TCMSecurity<br />
Twitch: https://www.twitch.tv/thecybermentor<br />
Instagram: https://www.instagram.com/tcmsecurity/<br />
LinkedIn: https://www.linkedin.com/company/tcm-security-inc/<br />
TikTok: https://www.tiktok.com/@tcmsecurity<br />
Discord: https://discord.gg/tcm<br />
Facebook: https://www.facebook.com/tcmsecure<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[This Week In Rust: This Week in Rust 658]]></title>
<description><![CDATA[Hello and welcome to another issue of This Week in Rust!
Rust is a programming language empowering everyone to build reliable and efficient software.
This is a weekly summary of its progress and community.
Want something mentioned? Tag us at
@thisweekinrust.bsky.social on Bluesky or
@ThisWeekinRu...]]></description>
<link>https://tsecurity.de/de/3640170/tools/this-week-in-rust-this-week-in-rust-658/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3640170/tools/this-week-in-rust-this-week-in-rust-658/</guid>
<pubDate>Thu, 02 Jul 2026 07:10:00 +0200</pubDate>
<category>💾  Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Hello and welcome to another issue of <em>This Week in Rust</em>!
<a href="https://www.rust-lang.org/">Rust</a> is a programming language empowering everyone to build reliable and efficient software.
This is a weekly summary of its progress and community.
Want something mentioned? Tag us at
<a href="https://bsky.app/profile/thisweekinrust.bsky.social">@thisweekinrust.bsky.social</a> on Bluesky or
<a href="https://mastodon.social/@thisweekinrust">@ThisWeekinRust</a> on mastodon.social, or
<a href="https://github.com/rust-lang/this-week-in-rust">send us a pull request</a>.
Want to get involved? <a href="https://github.com/rust-lang/rust/blob/main/CONTRIBUTING.md">We love contributions</a>.</p>
<p><em>This Week in Rust</em> is openly developed <a href="https://github.com/rust-lang/this-week-in-rust">on GitHub</a> and archives can be viewed at <a href="https://this-week-in-rust.org/">this-week-in-rust.org</a>.
If you find any errors in this week's issue, <a href="https://github.com/rust-lang/this-week-in-rust/pulls">please submit a PR</a>.</p>
<p>Want TWIR in your inbox? <a href="https://this-week-in-rust.us11.list-manage.com/subscribe?u=fd84c1c757e02889a9b08d289&amp;id=0ed8b72485">Subscribe here</a>.</p>
<h4><a class="toclink" href="https://this-week-in-rust.org/atom.xml#updates-from-rust-community">Updates from Rust Community</a></h4>


<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#official">Official</a></h5>
<ul>
<li><a href="https://blog.rust-lang.org/2026/06/30/Rust-1.96.1/">Announcing Rust 1.96.1 | Rust Blog</a></li>
<li><a href="https://blog.rust-lang.org/2026/06/25/vision-doc-journeys-to-learning-rust/">The many journeys of learning Rust | Rust Blog</a></li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#foundation">Foundation</a></h5>
<ul>
<li><a href="https://rustfoundation.org/media/rust-foundation-trusted-training-program-launches-giving-learners-a-mark-of-quality-to-trust/">Rust Foundation Trusted Training Program Launches, Giving Learners a Mark of Quality to Trust</a></li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#newsletters">Newsletters</a></h5>
<ul>
<li><a href="https://scientificcomputing.rs/monthly/2026-06">Scientific Computing in Rust #19 (June 2026)</a></li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#projecttooling-updates">Project/Tooling Updates</a></h5>
<ul>
<li><a href="https://slint.dev/blog/slint-1.17-released">Slint 1.17 Released</a></li>
<li><a href="https://blog.antoyo.xyz/rustc_codegen_gcc-progress-report-42">rustc_codegen_gcc: Progress Report #42</a></li>
<li><a href="https://hovinen.me/announcements/2026/06/24/introducing-test-that.html">Introducing Test That!</a></li>
<li><a href="https://hovinen.me/announcements/2026/06/24/introducing-test-that.html">Introducing Test That!: A rich test assertion library for Rust from the original author of GoogleTest Rust</a></li>
<li><a href="https://github.com/shihuili1218/rssh/blob/main/docs/article_arch_en.md">Inside RSSH: one Rust crate, three binaries, and the Tauri lessons along the way</a></li>
<li><a href="https://github.com/Aleixenandros/Rustty/releases/tag/v1.38.0">Rustty 1.38 – accessibility &amp; keyboard nav</a></li>
<li><a href="https://www.willsearch.com.br/blog/2026/06/25/guardiandb-0-17-0-secure-namespaces-iroh-1-0-and-the-arrival-of-the-odm/">GuardianDB 0.17.0: Secure namespaces, Iroh 1.0, and the arrival of the ODM</a></li>
<li><a href="https://dev.to/iam_suriyan_b9078a5b3a553/building-a-real-time-voice-agent-runtime-in-rust-no-gil-one-binary-2000-calls-a-box-12ko">Building a real-time voice-agent runtime in Rust: no GIL, one binary, 2,000 calls a box</a></li>
<li><a href="https://aimdb.dev/blog/aimdb-bring-your-own-connector">AimDB: Bring Your Own Connector</a></li>
<li><a href="https://github.com/kunobi-ninja/kache/releases/tag/v0.8.0">kache 0.8.0: zero-copy restores on Windows (ReFS)</a></li>
<li><a href="https://miskibin.github.io/warbell/">Warbell — a castle-defense action-RPG built with Bevy 0.19</a></li>
<li><a href="https://dev.to/gregorymc86/i-built-a-macos-ftp-client-entirely-in-rust-no-electron-no-webview-2a8i">I built a macOS FTP client entirely in Rust - no Electron, no webview</a></li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#observationsthoughts">Observations/Thoughts</a></h5>
<ul>
<li><a href="https://blog.yoshuawuyts.com/hoisting-expressions">Hoisting Expressions</a></li>
<li><a href="https://blog.jetbrains.com/rust/2026/06/25/rust-web-development-2026/">The Unglamorous Side of Rust Web Development</a></li>
<li><a href="https://dev.to/ernesto_arias_148b35bc25d/-how-i-found-out-52-of-my-knowledge-graph-was-duplicates-and-what-i-did-about-it-3coh">How I Found Out 52% of My Knowledge Graph Was Duplicates (and What I Did About It)</a></li>
<li><a href="https://jtjlehi.github.io/2026/06/25/novel-rust-error-handling.html">A Novel Approach to Rust Error Handling</a></li>
<li><a href="https://encore.dev/blog/redis-runtime">We put a Redis server inside our runtime</a></li>
<li><a href="https://kerkour.com/rust-high-performance-memory-fragmentation-allocations">High-performance Rust: Understanding and eliminating memory fragmentation</a></li>
<li><a href="https://kunobi.ninja/blog/kache-storage-worktrees">AI and worktrees are filling our disks: kache storage, measured</a></li>
<li><a href="https://dev.to/sicklefire/designing-a-cross-platform-terminal-memory-visualizer-in-rust-2365">Designing a cross-platform terminal memory visualizer in Rust</a></li>
<li><a href="https://pranitha.dev/posts/rust-and-memory-allocators">Your Rust Service Isn't Leaking — It Could Be the Allocator</a></li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#rust-walkthroughs">Rust Walkthroughs</a></h5>
<ul>
<li><a href="https://medium.com/@vbasky/measure-dont-guess-building-viser-a-content-adaptive-video-encoding-optimizer-in-rust-7675edd6943a">Measure, Don't Guess: Building viser, a Content-Adaptive Video Encoding Optimizer in Rust</a></li>
<li><a href="https://blog.sheerluck.dev/posts/learn-sql-and-sqlx-by-building-a-book-library-cli-in-rust/">Learn SQL and SQLx by Building a Book Library CLI in Rust</a></li>
<li>[series] <a href="https://aibodh.com/posts/async-rust-chapter-2-what-async-fn-compiles-into/">Reasoning About Async Rust with State Machines</a></li>
<li><a href="https://mainmatter.com/c-to-rust-migration-book/">The C to Rust Migration Book</a></li>
</ul>
<h4><a class="toclink" href="https://this-week-in-rust.org/atom.xml#crate-of-the-week">Crate of the Week</a></h4>
<p>This week's crate is <a href="https://github.com/pbkx/deconvolution">deconvolution</a>, a image deconvolution and restoration library.</p>
<p>Thanks to <a href="https://users.rust-lang.org/t/crate-of-the-week/2704/1621">pbkx</a> for the self-suggestion!</p>
<p><a href="https://users.rust-lang.org/t/crate-of-the-week/2704">Please submit your suggestions and votes for next week</a>!</p>
<h4><a class="toclink" href="https://this-week-in-rust.org/atom.xml#calls-for-testing">Calls for Testing</a></h4>
<p>An important step for RFC implementation is for people to experiment with the
implementation and give feedback, especially before stabilization.</p>
<p>If you are a feature implementer and would like your RFC to appear in this list, add a
<code>call-for-testing</code> label to your RFC along with a comment providing testing instructions and/or
guidance on which aspect(s) of the feature need testing.</p>
<p><em>No calls for testing were issued this week by
<a href="https://github.com/rust-lang/rust/issues?q=state%3Aopen%20label%3Acall-for-testing%20state%3Aopen">Rust</a>,
<a href="https://github.com/rust-lang/cargo/issues?q=state%3Aopen%20label%3Acall-for-testing%20state%3Aopen">Cargo</a>,
<a href="https://github.com/rust-lang/rustup/issues?q=state%3Aopen%20label%3Acall-for-testing%20state%3Aopen">Rustup</a> or
<a href="https://github.com/rust-lang/rfcs/issues?q=label%3Acall-for-testing%20state%3Aopen">Rust language RFCs</a>.</em></p>
<p><a href="https://github.com/rust-lang/this-week-in-rust/issues">Let us know</a> if you would like your feature to be tracked as a part of this list.</p>
<h4><a class="toclink" href="https://this-week-in-rust.org/atom.xml#call-for-participation-projects-and-speakers">Call for Participation; projects and speakers</a></h4>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#cfp-projects">CFP - Projects</a></h5>
<p>Always wanted to contribute to open-source projects but did not know where to start?
Every week we highlight some tasks from the Rust community for you to pick and get started!</p>
<p>Some of these tasks may also have mentors available, visit the task page for more information.</p>
<p><a href="https://github.com/kmolan/multicalc-rust/issues?q=is%3Aissue+is%3Aopen+label%3A%22good+first+issue%22">multicalc - good first issues</a></p>



<ul>
<li><a href="https://github.com/aimdb-dev/aimdb/issues/93">AimDB - Add minimal example: hello-single-latest</a></li>
<li><a href="https://github.com/aimdb-dev/aimdb/issues/109">AimDB - Wire <code>.transform()</code> and <code>.transform_join()</code> into stage profiling</a></li>
<li><a href="https://github.com/SzilvasiPeter/edid-info/issues/1">edid-info - Increase test coverage with real EDID data</a></li>
<li><a href="https://github.com/SzilvasiPeter/edid-info/issues/2">edid-info - Finalize CTA-861 extension implementation</a></li>
<li><a href="https://github.com/SzilvasiPeter/edid-info/issues/3">edid-info - Support additional EDID extension block types</a></li>
</ul>
<p>If you are a Rust project owner and are looking for contributors, please submit tasks <a href="https://github.com/rust-lang/this-week-in-rust?tab=readme-ov-file#call-for-participation-guidelines">here</a> or through a <a href="https://github.com/rust-lang/this-week-in-rust">PR to TWiR</a> or by reaching out on <a href="https://bsky.app/profile/thisweekinrust.bsky.social">Bluesky</a> or <a href="https://mastodon.social/@thisweekinrust">Mastodon</a>!</p>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#cfp-events">CFP - Events</a></h5>
<p>Are you a new or experienced speaker looking for a place to share something cool? This section highlights events that are being planned and are accepting submissions to join their event as a speaker.</p>



<p>If you are an event organizer hoping to expand the reach of your event, please submit a link to the website through a <a href="https://github.com/rust-lang/this-week-in-rust">PR to TWiR</a> or by reaching out on <a href="https://bsky.app/profile/thisweekinrust.bsky.social">Bluesky</a> or <a href="https://mastodon.social/@thisweekinrust">Mastodon</a>!</p>
<h4><a class="toclink" href="https://this-week-in-rust.org/atom.xml#updates-from-the-rust-project">Updates from the Rust Project</a></h4>
<p>426 pull requests were <a href="https://github.com/search?q=is%3Apr+org%3Arust-lang+is%3Amerged+merged%3A2026-06-23..2026-06-30">merged in the last week</a></p>
<h6><a class="toclink" href="https://this-week-in-rust.org/atom.xml#compiler">Compiler</a></h6>
<ul>
<li><a href="https://github.com/rust-lang/rust/pull/157996">drop the full-crate AST walk in <code>check_unused</code></a></li>
<li><a href="https://github.com/rust-lang/rust/pull/158185">make <code>stable_crate_ids</code> reads lock-free after crate loading</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/158239">rework lint pass running</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/157271">simplify some <code>proc_macro</code> things</a></li>
</ul>
<h6><a class="toclink" href="https://this-week-in-rust.org/atom.xml#library">Library</a></h6>
<ul>
<li><a href="https://github.com/rust-lang/rust/pull/158326">add <code>io::ErrorKind::TooManyOpenFiles</code></a></li>
<li><a href="https://github.com/rust-lang/rust/pull/153097">expand <code>OptionFlatten</code>'s iterator methods</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/155625">move <code>std::io::Error</code> into <code>core</code></a></li>
<li><a href="https://github.com/rust-lang/rust/pull/158053">optimize network address parser</a></li>
</ul>
<h6><a class="toclink" href="https://this-week-in-rust.org/atom.xml#cargo">Cargo</a></h6>
<ul>
<li><a href="https://github.com/rust-lang/cargo/pull/17106">add <code>-Zhint-msrv</code> flag</a></li>
</ul>
<h6><a class="toclink" href="https://this-week-in-rust.org/atom.xml#clippy">Clippy</a></h6>
<ul>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17237"><code>filter_map_next</code>: clean-up, overhaul suggestions</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17318"><code>chunks_exact_to_as_chunks</code>: Prevent syntactically invalid suggestions</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17317"><code>chunks_exact_to_as_chunks</code>: Use correct method name in message</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17316"><code>chunks_exact_to_as_chunks</code>: Pick iter method depending on mut-ness</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17302"><code>non_ascii_literal</code>, <code>invisible_characters</code>: don't suggest a fix on raw strings</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17228">create a single <code>ConstEvalCtxt</code> in <code>expr_eagerness</code></a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17299">detect new range types in <code>higher::Range</code></a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17270">do not trigger <code>manual_option_zip</code> when map receiver is a lazy evaluated expression</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/16746">enhance <code>needless_late_init</code> to cover grouped assignments</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17257">fix: <code>borrow_as_ptr</code> is triggered on generated code</a></li>
</ul>
<h6><a class="toclink" href="https://this-week-in-rust.org/atom.xml#rust-analyzer">Rust-Analyzer</a></h6>
<ul>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22466">add diagnostic for E0596</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22645">add fixes add '.await' for <code>type_mismatch</code></a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22646">crash on lowering consts with associated types</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22640">crash when hovering on anonymous consts</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22582">only run <code>Drop::drop</code> when implemented</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22633">mark <code>inline_convert_while_ascii()</code> as <code>unsafe</code></a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22115">switch out lsp-types for gen-lsp-types</a></li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#rust-compiler-performance-triage">Rust Compiler Performance Triage</a></h5>
<p>Overall, the week was fairly neutral, with no meaningful shift on most benchmarks on any of our statistics.</p>
<p>Triage done by <strong>@simulacrum</strong>.
Revision range: <a href="https://perf.rust-lang.org/?start=8b6558a02b2774acfb25cf15e199467c37ba7490&amp;end=7dc2c162b9c197aaa76a6f9e7534569537830a01&amp;absolute=false&amp;stat=instructions%3Au">8b6558a0..7dc2c162</a></p>
<p>2 Regressions, 1 Improvement, 7 Mixed; 5 of them in rollups
34 artifact comparisons made in total</p>
<p><a href="https://github.com/rust-lang/rustc-perf/blob/master/triage/2026/2026-06-29.md">Full report here</a></p>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#approved-rfcs"></a><a href="https://github.com/rust-lang/rfcs/commits/master">Approved RFCs</a></h5>
<p>Changes to Rust follow the Rust <a href="https://github.com/rust-lang/rfcs#rust-rfcs">RFC (request for comments) process</a>. These
are the RFCs that were approved for implementation this week:</p>
<ul>
<li><em>No RFCs were approved this week.</em></li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#final-comment-period">Final Comment Period</a></h5>
<p>Every week, <a href="https://www.rust-lang.org/team.html">the team</a> announces the 'final comment period' for RFCs and key PRs
which are reaching a decision. Express your opinions now.</p>
<h6><a class="toclink" href="https://this-week-in-rust.org/atom.xml#tracking-issues-prs">Tracking Issues &amp; PRs</a></h6>
<a class="toclink" href="https://this-week-in-rust.org/atom.xml#rust"></a><a href="https://github.com/rust-lang/rust/issues?q=is%3Aopen%20label%3Afinal-comment-period%20sort%3Aupdated-desc%20state%3Aopen">Rust</a>
<ul>
<li><a href="https://github.com/rust-lang/rust/issues/143989">Tracking Issue for LocalKey/Cell::update</a></li>
<li><a href="https://github.com/rust-lang/rust/issues/142312">Tracking Issue for <code>{str, [T], Path}::trim_prefix</code> and <code>{str, [T]}::trim_suffix</code></a></li>
<li><a href="https://github.com/rust-lang/rust/pull/155697">Stabilize c-variadic function definitions</a></li>
<li><a href="https://github.com/rust-lang/rust/issues/69835">Tracking Issue for layout information behind pointers</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/158523">Fix feature gate for <code>repr(simd)</code></a></li>
<li><a href="https://github.com/rust-lang/rust/pull/154585">reat no_mangle_generic_items as hard error instead of lint warning</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/158522">Lint against invalid POSIX symbol definitions</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/158302">Fix <code>overflowing_literals</code> lint with repeated negation</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/158504">stabilize <code>extern "custom"</code></a></li>
<li><a href="https://github.com/rust-lang/rust/pull/158057">Don't escape U+FF9E and U+FF9F in <code>escape_debug_ext</code></a></li>
</ul>
<a class="toclink" href="https://this-week-in-rust.org/atom.xml#compiler-team-mcps-only"></a><a href="https://github.com/rust-lang/compiler-team/issues?q=label%3Amajor-change%20label%3Afinal-comment-period%20state%3Aopen">Compiler Team</a> <a href="https://forge.rust-lang.org/compiler/mcp.html">(MCPs only)</a>
<ul>
<li><a href="https://github.com/rust-lang/compiler-team/issues/1007">Decouple <code>BackendRepr</code> from ABI alignment</a></li>
<li><a href="https://github.com/rust-lang/compiler-team/issues/1005">MCP: Stabilization strategy for rustc parallel frontend</a></li>
</ul>
<a class="toclink" href="https://this-week-in-rust.org/atom.xml#language-reference"></a><a href="https://github.com/rust-lang/reference/issues?q=is%3Aopen%20label%3Afinal-comment-period%20sort%3Aupdated-desc%20state%3Aopen">Language Reference</a>
<ul>
<li><a href="https://github.com/rust-lang/reference/pull/2166">Fields must fit in the type, even for repr(Rust)</a></li>
</ul>
<a class="toclink" href="https://this-week-in-rust.org/atom.xml#rust-rfcs"></a><a href="https://github.com/rust-lang/rfcs/issues?q=state%3Aopen%20label%3Afinal-comment-period%20state%3Aopen">Rust RFCs</a>
<ul>
<li><a href="https://github.com/rust-lang/rfcs/pull/3527">RFC: Associated const underscore</a></li>
<li><a href="https://github.com/rust-lang/rfcs/pull/3980">Add <code>extern "custom"</code></a></li>
</ul>
<a class="toclink" href="https://this-week-in-rust.org/atom.xml#unsafe-code-guidelines"></a><a href="https://github.com/rust-lang/unsafe-code-guidelines/issues?q=is%3Aopen%20label%3Afinal-comment-period%20sort%3Aupdated-desc%20state%3Aopen">Unsafe Code Guidelines</a>
<ul>
<li><a href="https://github.com/rust-lang/unsafe-code-guidelines/issues/615">Opsem extension proposal: atomic volatile accesses</a></li>
</ul>
<p><em>No Items entered Final Comment Period this week for
<a href="https://github.com/rust-lang/cargo/issues?q=is%3Aopen%20label%3Afinal-comment-period%20sort%3Aupdated-desc%20state%3Aopen">Cargo</a>,
<a href="https://github.com/rust-lang/lang-team/issues?q=is%3Aopen%20label%3Afinal-comment-period%20sort%3Aupdated-desc%20state%3Aopen">Language Team</a> or
<a href="https://github.com/rust-lang/leadership-council/issues?q=state%3Aopen%20label%3Afinal-comment-period%20state%3Aopen">Leadership Council</a>.</em></p>
<p>Let us know if you would like your PRs, Tracking Issues or RFCs to be tracked as a part of this list.</p>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#new-and-updated-rfcs"></a><a href="https://github.com/rust-lang/rfcs/pulls">New and Updated RFCs</a></h5>
<ul>
<li><a href="https://github.com/rust-lang/rfcs/pull/3977">Method chain as item</a></li>
<li><a href="https://github.com/rust-lang/rfcs/pull/3980">Add <code>extern "custom"</code></a></li>
</ul>
<h4><a class="toclink" href="https://this-week-in-rust.org/atom.xml#upcoming-events">Upcoming Events</a></h4>
<p>Rusty Events between 2026-07-01 - 2026-07-29 🦀</p>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#virtual">Virtual</a></h5>
<ul>
<li>2026-07-01 | Virtual (Indianapolis, IN, US) | <a href="https://www.meetup.com/indyrs">Indy Rust</a><ul>
<li><a href="https://www.meetup.com/indyrs/events/315210366/"><strong>Indy.rs - with Social Distancing</strong></a></li>
</ul>
</li>
<li>2026-07-02 | Virtual (Berlin, DE) | <a href="https://www.meetup.com/rust-berlin">Rust Berlin</a><ul>
<li><a href="https://www.meetup.com/rust-berlin/events/308455932/"><strong>Rust Hack and Learn</strong></a></li>
</ul>
</li>
<li>2026-07-02 | Virtual (Charlottesville, VA, US) | <a href="https://www.meetup.com/charlottesville-rust-meetup">Charlottesville Rust Meetup</a><ul>
<li><a href="https://www.meetup.com/charlottesville-rust-meetup/events/315211402/"><strong>Learning Game Development the Hard Way with Rust and Bevy</strong></a></li>
</ul>
</li>
<li>2026-07-02 | Virtual (Nürnberg, DE) | <a href="https://www.meetup.com/rust-noris">Rust Nuremberg</a><ul>
<li><a href="https://www.meetup.com/rust-noris/events/313345243/"><strong>Rust Nürnberg online</strong></a></li>
</ul>
</li>
<li>2026-07-04 | Virtual (Kampala, UG) | <a href="https://www.eventbrite.com/e/rust-circle-meetup-tickets-628763176587">Rust Circle Meetup</a><ul>
<li><a href="https://www.eventbrite.com/e/rust-circle-meetup-tickets-628763176587"><strong>Rust Circle Meetup</strong></a></li>
</ul>
</li>
<li>2026-07-05 | Virtual (Dallas, TX, US) | <a href="https://www.meetup.com/dallasrust">Dallas Rust User Meetup</a><ul>
<li><a href="https://www.meetup.com/dallasrust/events/314095287/"><strong>Rust Deep Learning: First Sunday</strong></a></li>
</ul>
</li>
<li>2026-07-07 | Virtual (London, UK) | <a href="https://www.meetup.com/women-in-rust">Women in Rust</a><ul>
<li><a href="https://www.meetup.com/women-in-rust/events/315060981/"><strong>👋 Community Catch Up</strong></a></li>
</ul>
</li>
<li>2026-07-14 | Virtual (Dallas, TX, US) | <a href="https://www.meetup.com/dallasrust">Dallas Rust User Meetup</a><ul>
<li><a href="https://www.meetup.com/dallasrust/events/310254778/"><strong>Second Tuesday</strong></a></li>
</ul>
</li>
<li>2026-07-15 | Hybrid (Vancouver, BC, CA) | <a href="https://www.meetup.com/vancouver-rust">Vancouver Rust</a><ul>
<li><a href="https://www.meetup.com/vancouver-rust/events/314233743/"><strong>Jiff</strong></a></li>
</ul>
</li>
<li>2026-07-16 | Hybrid (Seattle, WA, US) | <a href="https://www.meetup.com/join-srug">Seattle Rust User Group</a><ul>
<li><a href="https://www.meetup.com/seattle-rust-user-group/events/314520812/"><strong>July, 2026 SRUG (Seattle Rust User Group) Meetup</strong></a></li>
</ul>
</li>
<li>2026-07-16 | Virtual (Berlin, DE) | <a href="https://www.meetup.com/rust-berlin">Rust Berlin</a><ul>
<li><a href="https://www.meetup.com/rust-berlin/events/312045926/"><strong>Rust Hack and Learn</strong></a></li>
</ul>
</li>
<li>2026-07-19 | Virtual (Dallas, TX, US) | <a href="https://www.meetup.com/dallasrust">Dallas Rust User Meetup</a><ul>
<li><a href="https://www.meetup.com/dallasrust/events/314329045/"><strong>Rust Deep Learning: Third Sunday</strong></a></li>
</ul>
</li>
<li>2026-07-21 | Virtual (London, UK) | <a href="https://www.meetup.com/women-in-rust">Women in Rust</a><ul>
<li><a href="https://www.meetup.com/women-in-rust/events/315102297/"><strong>Lunch &amp; Learn: Learning Rust as First Programming Language</strong></a></li>
</ul>
</li>
<li>2026-07-21 | Virtual (Washington, DC, US) | <a href="https://www.meetup.com/rustdc">Rust DC</a><ul>
<li><a href="https://www.meetup.com/rustdc/events/315279653/"><strong>Mid-month Rustful</strong></a></li>
</ul>
</li>
<li>2026-07-28 | Virtual (Dallas, TX, US) | <a href="https://www.meetup.com/dallasrust">Dallas Rust User Meetup</a><ul>
<li><a href="https://www.meetup.com/dallasrust/events/310254777/"><strong>Fourth Tuesday</strong></a></li>
</ul>
</li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#asia">Asia</a></h5>
<ul>
<li>2026-07-18 | Bangalore, IN | <a href="https://hasgeek.com/rustbangalore">Rust Bangalore</a><ul>
<li><a href="https://hasgeek.com/rustbangalore/july-2026-rustacean-meetup/"><strong>July 2026 Rustacean Meetup</strong></a></li>
</ul>
</li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#europe">Europe</a></h5>
<ul>
<li>2026-07-01 | Köln, DE | <a href="https://www.meetup.com/rust-cologne-bonn">Rust Cologne</a><ul>
<li><a href="https://www.meetup.com/rustcologne/events/315404678/"><strong>Rust in July: Vecs and Strings and Slices, Oh My!</strong></a></li>
</ul>
</li>
<li>2026-07-01 | Manchester, UK | <a href="https://www.meetup.com/rust-manchester">Rust Manchester</a><ul>
<li><a href="https://www.meetup.com/rust-manchester/events/315200163/"><strong>Rust Manchester June Talks</strong></a></li>
</ul>
</li>
<li>2026-07-01 | Oxford, UK | <a href="https://www.meetup.com/oxford-rust-meetup-group">Oxford ACCU/Rust Meetup.</a><ul>
<li><a href="https://www.meetup.com/oxford-rust-meetup-group/events/315409335/"><strong>Building a file system from scratch</strong></a></li>
</ul>
</li>
<li>2026-07-02 | Edinburgh, UK | <a href="https://www.meetup.com/rust-edi">Rust and Friends</a><ul>
<li><a href="https://www.meetup.com/rust-and-friends/events/314941098/"><strong>Bevy, Bits, &amp; Cats (Rust July Talks)</strong></a></li>
</ul>
</li>
<li>2026-07-02 | Enschede, NL | <a href="https://www.meetup.com/dutch-rust-meetup">Baseflow Tech Meetups</a><ul>
<li><a href="https://www.meetup.com/baseflow-tech-meetups/events/315099547/"><strong>AI Summit</strong></a></li>
</ul>
</li>
<li>2026-07-08 | Dublin, IE | <a href="https://www.meetup.com/rust-dublin">Rust Dublin</a><ul>
<li><a href="https://www.meetup.com/rust-dublin/events/315150327/"><strong>Join us live and INPERSON for Rust 262</strong></a></li>
</ul>
</li>
<li>2026-07-09 | Switzerland, CH | <a href="https://www.posttenebraslab.ch/wiki/events/start">PostTenebrasLab</a><ul>
<li><a href="https://www.posttenebraslab.ch/wiki/events/monthly_meeting/rust_meetup"><strong>Rust Meetup Geneva</strong></a></li>
</ul>
</li>
<li>2026-07-21 | Leipzig, DE | <a href="https://www.meetup.com/rust-modern-systems-programming-in-leipzig">Rust - Modern Systems Programming in Leipzig</a><ul>
<li><a href="https://www.meetup.com/rust-modern-systems-programming-in-leipzig/events/313816470/"><strong>Supercharge Rust funcs with implicit arguments and context-generic programming</strong></a></li>
</ul>
</li>
<li>2026-07-23 | Berlin, DE | <a href="https://www.meetup.com/rust-berlin">Rust Berlin</a><ul>
<li><a href="https://www.meetup.com/rust-berlin/events/315484101/"><strong>Rust Berlin Talks: The next generation</strong></a></li>
</ul>
</li>
<li>2026-07-23 | London, UK | <a href="https://www.meetup.com/london-rust-project-group">London Rust Project Group</a><ul>
<li><a href="https://www.meetup.com/london-rust-project-group/events/315366453/"><strong>Rama modular service framework for Rust</strong></a></li>
</ul>
</li>
<li>2026-07-23 | Paris, FR | <a href="https://www.meetup.com/rust-paris">Rust Paris</a><ul>
<li><a href="https://www.meetup.com/rust-paris/events/315309633/"><strong>Rust meetup #87</strong></a></li>
</ul>
</li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#north-america">North America</a></h5>
<ul>
<li>2026-07-02 | Saint Louis, MO, US | <a href="https://www.meetup.com/stl-rust">STL Rust</a><ul>
<li><a href="https://www.meetup.com/stl-rust/events/315103359/"><strong>Git is easy?</strong></a></li>
</ul>
</li>
<li>2026-07-04 | Boston, MA, US | <a href="https://www.meetup.com/bostonrust">Boston Rust Meetup</a><ul>
<li><a href="https://www.meetup.com/bostonrust/events/315225861/"><strong>Boston University Rust Lunch, July 4</strong></a></li>
</ul>
</li>
<li>2026-07-09 | Lehi, UT, US | <a href="https://www.meetup.com/utah-rust">Utah Rust</a><ul>
<li><a href="https://www.meetup.com/utah-rust/events/314696647/"><strong>Utah Rust July Meetup</strong></a></li>
</ul>
</li>
<li>2026-07-11 | Boston, MA, US | <a href="https://www.meetup.com/bostonrust">Boston Rust Meetup</a><ul>
<li><a href="https://www.meetup.com/bostonrust/events/315225865/"><strong>MIT Rust Lunch, July 11</strong></a></li>
</ul>
</li>
<li>2026-07-15 | Hybrid (Vancouver, BC, CA) | <a href="https://www.meetup.com/vancouver-rust">Vancouver Rust</a><ul>
<li><a href="https://www.meetup.com/vancouver-rust/events/314233743/"><strong>Jiff</strong></a></li>
</ul>
</li>
<li>2026-07-16 | Hybrid (Seattle, WA, US) | <a href="https://www.meetup.com/join-srug">Seattle Rust User Group</a><ul>
<li><a href="https://www.meetup.com/seattle-rust-user-group/events/314520812/"><strong>July, 2026 SRUG (Seattle Rust User Group) Meetup</strong></a></li>
</ul>
</li>
<li>2026-07-18 | Boston, MA, US | <a href="https://www.meetup.com/bostonrust">Boston Rust Meetup</a><ul>
<li><a href="https://www.meetup.com/bostonrust/events/315225872/"><strong>North End Rust Lunch, July 18</strong></a></li>
</ul>
</li>
<li>2026-07-21 | San Francisco, CA, US | <a href="https://www.meetup.com/san-francisco-rust-study-group">San Francisco Rust Study Group</a><ul>
<li><a href="https://www.meetup.com/san-francisco-rust-study-group/events/314997214/"><strong>Rust Hacking in Person</strong></a></li>
</ul>
</li>
<li>2026-07-22 | Austin, TX, US | <a href="https://www.meetup.com/rust-atx">Rust ATX</a><ul>
<li><a href="https://www.meetup.com/rust-atx/events/xvkdgtyjckbdc/"><strong>Rust Lunch - Fareground</strong></a></li>
</ul>
</li>
<li>2026-07-22 | Los Angeles, CA, US | <a href="https://www.meetup.com/rust-los-angeles">Rust Los Angeles</a><ul>
<li><a href="https://www.meetup.com/rust-los-angeles/events/315376271/"><strong>Rust LA: Rust in Distributed Systems with Flight Science!</strong></a></li>
</ul>
</li>
<li>2026-07-25 | Brooklyn, NY, US | <a href="https://flowercomputer.com/">Flower</a><ul>
<li><a href="https://partiful.com/e/Vq9fyDNCMSO7ia4ulK5b"><strong>BOG-A-THON 2</strong></a></li>
</ul>
</li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#oceania">Oceania</a></h5>
<ul>
<li>2026-07-21 | Barton, AU | <a href="https://www.meetup.com/rust-canberra">Canberra Rust User Group</a><ul>
<li><a href="https://www.meetup.com/rust-canberra/events/315307280/"><strong>July Meetup</strong></a></li>
</ul>
</li>
<li>2026-07-23 | Perth, AU | <a href="https://www.meetup.com/perth-rust-meetup-group">Rust Perth Meetup Group</a><ul>
<li><a href="https://www.meetup.com/perth-rust-meetup-group/events/315451138/"><strong>Rust Perth: July Meetup!</strong></a></li>
</ul>
</li>
</ul>
<p>If you are running a Rust event please add it to the <a href="https://www.google.com/calendar/embed?src=apd9vmbc22egenmtu5l6c5jbfc%40group.calendar.google.com">calendar</a> to get
it mentioned here. Please remember to add a link to the event too.
Email the <a href="mailto:community-team@rust-lang.org">Rust Community Team</a> for access.</p>
<h4><a class="toclink" href="https://this-week-in-rust.org/atom.xml#jobs">Jobs</a></h4>
<p>Please see the latest <a href="https://www.reddit.com/r/rust/comments/1ttbtf5/official_rrust_whos_hiring_thread_for_jobseekers/">Who's Hiring thread on r/rust</a></p>
<h3><a class="toclink" href="https://this-week-in-rust.org/atom.xml#quote-of-the-week">Quote of the Week</a></h3>
<blockquote>
<p>I <em>do</em> rather hope anyone using <code>-Zllvm-target-features</code> or any stabilized form thereof would know that they are getting a conversation with the dragon directly and they should mind their words carefully if they do not wish to be barbecued by it and served over a nice plate of iron filings.</p>
</blockquote>
<p>– <a href="https://rust-lang.zulipchat.com/#narrow/channel/233931-t-compiler.2Fmajor-changes/topic/Add.20.60-Zllvm-target-feature.60.20target.20.2Amodif.E2.80.A6.20compiler-team.23994/near/606147265">workingjubilee on rust zulip</a></p>
<p>Thanks to <a href="https://users.rust-lang.org/t/twir-quote-of-the-week/328/1784">Tomáš Šedovič</a> for the suggestion!</p>
<p><a href="https://users.rust-lang.org/t/twir-quote-of-the-week/328">Please submit quotes and vote for next week!</a></p>
<p>This Week in Rust is edited by:</p>
<ul>
<li><a href="https://github.com/nellshamrell">nellshamrell</a></li>
<li><a href="https://github.com/llogiq">llogiq</a></li>
<li><a href="https://github.com/ericseppanen">ericseppanen</a></li>
<li><a href="https://github.com/extrawurst">extrawurst</a></li>
<li><a href="https://github.com/U007D">U007D</a></li>
<li><a href="https://github.com/mariannegoldin">mariannegoldin</a></li>
<li><a href="https://github.com/bdillo">bdillo</a></li>
<li><a href="https://github.com/opeolluwa">opeolluwa</a></li>
<li><a href="https://github.com/bnchi">bnchi</a></li>
<li><a href="https://github.com/KannanPalani57">KannanPalani57</a></li>
<li><a href="https://github.com/tzilist">tzilist</a></li>
</ul>
<p><em>Email list hosting is sponsored by <a href="https://foundation.rust-lang.org/">The Rust Foundation</a></em></p>
<p><small><a href="https://www.reddit.com/r/rust/comments/1ul6xfl/this_week_in_rust_658/">Discuss on r/rust</a></small></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[End of support looms for .NET 8 and .NET 9]]></title>
<description><![CDATA[Microsoft will end support for its .NET 8 and .NET 9 platforms on November 10, 2026. The company advises current users of those platforms to upgrade to .NET 10. 



After November 10, Microsoft will no longer provide servicing updates, security fixes, or technical support for .NET 8 and .NET 9. “...]]></description>
<link>https://tsecurity.de/de/3639202/ai-nachrichten/end-of-support-looms-for-net-8-and-net-9/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3639202/ai-nachrichten/end-of-support-looms-for-net-8-and-net-9/</guid>
<pubDate>Wed, 01 Jul 2026 18:49:49 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Microsoft will end support for its .NET 8 and .NET 9 platforms on <a href="https://github.com/dotnet/core/blob/main/release-notes/README.md">November 10</a>, 2026. The company advises current users of those platforms to upgrade to <a href="https://www.infoworld.com/article/4087667/microsofts-net-10-arrives-with-ai-runtime-and-language-improvements.html">.NET 10</a>. </p>



<p>After November 10, Microsoft will no longer provide servicing updates, security fixes, or technical support for .NET 8 and .NET 9. “We recommend upgrading to <a href="https://devblogs.microsoft.com/dotnet/announcing-dotnet-10/">.NET 10</a>, which is an LTS (long term support) release supported through November 2028,” said Rahul Bhandari, Microsoft senior program manager in a June 29 <a href="https://devblogs.microsoft.com/dotnet/dotnet-8-9-end-of-support/">blog post</a>. “By upgrading, you will continue receiving security updates and servicing fixes to keep your applications protected.”</p>



<p>Apps can be upgraded to .NET 10 by changing the value of the <code>TargetFramework</code> property in a project file to <code>net10.0</code>. Development and hosting environments will need to be updated. This process is covered in detail in Microsoft’s article, “<a href="https://learn.microsoft.com/dotnet/core/install/upgrade" target="_blank" rel="noreferrer noopener">Upgrade to a new .NET version</a>.” .NET 10 can be downloaded from <a href="https://dotnet.microsoft.com/en-us/download/dotnet/10.0">dotnet.microsoft.com</a>.</p>



<p><a href="https://www.infoworld.com/article/2335555/the-best-new-features-in-microsoft-net-8.html"> .NET 8</a> was released November 14, 2023, and <a href="https://www.infoworld.com/article/3603700/microsofts-net-9-arrives-with-performance-cloud-and-ai-boosts.html">.NET 9</a> was released November 12, 2024. <a href="https://www.infoworld.com/article/3839444/the-key-new-features-in-net-10.html" data-type="link" data-id="https://www.infoworld.com/article/3839444/the-key-new-features-in-net-10.html">.NET 10</a> became available November 11, 2025. </p>



<p>Microsoft said users of .NET 8 and .NET 9 could expect the following after November 10:</p>



<ul class="wp-block-list">
<li>Applications built on .NET 8 or .NET 9 will continue to run.</li>



<li>No new security updates will be issued for either version.</li>



<li>Staying on an unsupported version means exposure to security vulnerabilities that will not be patched.</li>



<li>Technical support will no longer be available for .NET 8 or .NET 9 applications.</li>
</ul>



<p>Also, beginning with a future servicing update for <a href="https://www.infoworld.com/article/2270802/microsoft-visual-studio-2022-arrives.html">Visual Studio 2022</a>, the .NET 8 and .NET 9 components will be marked as out of support. The arrival of the production release of <a href="https://www.infoworld.com/article/4138881/under-the-hood-with-net-11-preview-1.html">.NET 11</a>, meanwhile, is expected this November.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[NASA Wants To Send Spare Nuclear-Powered Mars Rover To the Moon]]></title>
<description><![CDATA[An anonymous reader quotes a report from Space.com: NASA provided an Artemis update today (June 30), announcing new lunar landing contracts for its Moon Base initiative and a surprise new possible rover mission that could be headed to the moon's south pole. During the second monthly update that N...]]></description>
<link>https://tsecurity.de/de/3639064/it-security-nachrichten/nasa-wants-to-send-spare-nuclear-powered-mars-rover-to-the-moon/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3639064/it-security-nachrichten/nasa-wants-to-send-spare-nuclear-powered-mars-rover-to-the-moon/</guid>
<pubDate>Wed, 01 Jul 2026 18:10:24 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[An anonymous reader quotes a report from Space.com: NASA provided an Artemis update today (June 30), announcing new lunar landing contracts for its Moon Base initiative and a surprise new possible rover mission that could be headed to the moon's south pole. During the second monthly update that NASA has provided for its moon base plans, the agency named Astrobotic, Firefly Aerospace and Intuitive Machines as the providers of four robotic landers that will deliver scientific payloads to the surface of the moon, as NASA tests and expands the technologies needed for a permanent human outpost. "This is this drawing on the playbook that worked very well for NASA during the 1960s," NASA Administrator Jared Isaacman said during the livestreamed update, explaining the experiential approach to a crewed lunar return. "We didn't just jump right to Apollo 11."
 
Isaacman also announced the potential repurposing of an engineering development model built to mirror the agency's Perseverance and Curiosity rovers on Mars. "There is another," Isaacman said, quoting Yoda's line from "Star Wars: The Empire Strikes Back." That test rover is called PROMISE, short for "Polar Rover for Observation, Mapping, and In-Situ Exploration" (though it was formerly known as Optimism). PROMISE was developed at NASA's Jet Propulsion Laboratory (JPL) in Southern California, where it has been used as a test platform for fixes or commands that engineers want to try on the ground before permanently sending them to Perseverance and Curiosity. Now, NASA wants to send PROMISE on a mission of its own. Though sending PROMISE to the moon would leave Perseverance and Curiosity -- both of which remain active on Mars -- without an Earth-based testbed, Isaacman thinks it would be worth it. "We've had years now of experience operating the two rovers on the surface of Mars, and we've got this hardware that the taxpayers have invested a lot in," he said. "So the question was posed: 'What if we send it to the moon?'"
 
With a little refurbishment, PROMISE would help advance NASA's lunar plans, Isaacman added. Like Perseverance and Curiosity, the test rover is powered by a radioisotope thermoelectric generator (RTG), which converts heat from naturally decaying radioactive material into electricity. So it wouldn't require sunlight to operate -- a real benefit on the moon, where most locations experience long stretches of darkness. (NASA plans to build its Artemis base near the moon's south pole, which is thought to harbor an abundance of water ice and also has a relatively complex lighting environment.) The other robots currently in the works to launch on future missions to the moon, including the landers announced during today's update, are all solar powered. Through 2029, NASA hopes to launch up to 20 such missions as part of the CLPS (Commercial Lunar Payload Services) initiative to support the first phase of the agency's moon base plans, and the landers announced today will be some of the first in that lineup.<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=NASA+Wants+To+Send+Spare+Nuclear-Powered+Mars+Rover+To+the+Moon%3A+https%3A%2F%2Fscience.slashdot.org%2Fstory%2F26%2F07%2F01%2F0613245%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fscience.slashdot.org%2Fstory%2F26%2F07%2F01%2F0613245%2Fnasa-wants-to-send-spare-nuclear-powered-mars-rover-to-the-moon%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://science.slashdot.org/story/26/07/01/0613245/nasa-wants-to-send-spare-nuclear-powered-mars-rover-to-the-moon?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Announcing the General Availability of Holodeck 9.1]]></title>
<description><![CDATA[We’re thrilled to announce the General Availability of Holodeck 9.1, a major release that brings significant new capabilities to your nested VMware Cloud Foundation (VCF) toolkit! Today’s infrastructure teams face increasing pressure to validate new capabilities quickly, reliably, and at scale, w...]]></description>
<link>https://tsecurity.de/de/3638765/downloads/announcing-the-general-availability-of-holodeck-91/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3638765/downloads/announcing-the-general-availability-of-holodeck-91/</guid>
<pubDate>Wed, 01 Jul 2026 16:17:02 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div><img width="300" height="291" src="https://blogs.vmware.com/cloud-foundation/wp-content/uploads/sites/75/2025/10/holodeck9.0.1_98a0a8.png?w=300" class="attachment-medium size-medium wp-post-image" alt="Dhruv Tyagi - Holodeck 9.1" decoding="async" fetchpriority="high" srcset="https://blogs.vmware.com/cloud-foundation/wp-content/uploads/sites/75/2025/10/holodeck9.0.1_98a0a8.png 539w, https://blogs.vmware.com/cloud-foundation/wp-content/uploads/sites/75/2025/10/holodeck9.0.1_98a0a8.png?resize=300,291 300w" sizes="(max-width: 300px) 100vw, 300px"></div>
<p>We’re thrilled to announce the General Availability of Holodeck 9.1, a major release that brings significant new capabilities to your nested VMware Cloud Foundation (VCF) toolkit! Today’s infrastructure teams face increasing pressure to validate new capabilities quickly, reliably, and at scale, without monopolizing precious production hardware. Holodeck has always been the answer to that challenge, … <a href="https://blogs.vmware.com/cloud-foundation/2026/07/01/announcing-the-general-availability-of-holodeck-9-1/">Continued</a></p>
<p>The post <a href="https://blogs.vmware.com/cloud-foundation/2026/07/01/announcing-the-general-availability-of-holodeck-9-1/">Announcing the General Availability of Holodeck 9.1</a> appeared first on <a href="https://blogs.vmware.com/cloud-foundation">VMware Cloud Foundation (VCF) Blog</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[In a huge blow to game ownership, PlayStation confirms end of physical games — mere days after GTA 6's disc-less pre-orders]]></title>
<description><![CDATA[PlayStation sets out its stall for a digital-only future by announcing that no new games from 2028 will be on disc.]]></description>
<link>https://tsecurity.de/de/3638565/it-nachrichten/in-a-huge-blow-to-game-ownership-playstation-confirms-end-of-physical-games-mere-days-after-gta-6s-disc-less-pre-orders/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3638565/it-nachrichten/in-a-huge-blow-to-game-ownership-playstation-confirms-end-of-physical-games-mere-days-after-gta-6s-disc-less-pre-orders/</guid>
<pubDate>Wed, 01 Jul 2026 14:47:47 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[PlayStation sets out its stall for a digital-only future by announcing that no new games from 2028 will be on disc.]]></content:encoded>
</item>
<item>
<title><![CDATA[US reverses export restrictions on Anthropic’s Fable 5, Mythos 5 AI models]]></title>
<description><![CDATA[The US government has reversed export restrictions on Anthropic’s frontier AI models Fable 5 and Mythos 5, allowing the company to resume global access after nearly three weeks of disruption triggered by concerns over the models’ cybersecurity capabilities.



“As of today, June 30, the export co...]]></description>
<link>https://tsecurity.de/de/3638243/it-nachrichten/us-reverses-export-restrictions-on-anthropics-fable-5-mythos-5-ai-models/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3638243/it-nachrichten/us-reverses-export-restrictions-on-anthropics-fable-5-mythos-5-ai-models/</guid>
<pubDate>Wed, 01 Jul 2026 13:18:17 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>The US government has reversed export restrictions on Anthropic’s frontier AI models Fable 5 and Mythos 5, allowing the company to resume global access after nearly three weeks of disruption triggered by concerns over the models’ cybersecurity capabilities.</p>



<p>“As of today, June 30, the export controls on Fable 5 and Mythos 5 have been lifted,” Anthropic said in a <a href="https://www.anthropic.com/news/redeploying-fable-5" target="_blank" rel="nofollow">blog post</a>. The company said Fable 5 will begin rolling out globally on July 1 across Claude Platform, Claude.ai, Claude Code and Claude Cowork, while access on Amazon Web Services, Google Cloud, and Microsoft Foundry will be restored “as quickly as possible.”</p>



<p>Commerce Secretary Howard Lutnick said the administration had worked with Anthropic before reversing the restrictions.</p>



<p>“Over the past two weeks, we have worked closely with Anthropic to analyze and approve Fable 5 to ensure alignment across the US Government and strengthen America’s leadership in AI,” <a href="https://x.com/howardlutnick/status/2072100729603452965" target="_blank" rel="nofollow">Lutnick wrote</a> in a post on X.</p>



<p>Anthropic had <a href="https://www.csoonline.com/article/4183094/anthropic-releases-mythos-class-fable-5-model-with-safeguards-for-cyber-risks.html">launched</a> Fable 5 and Mythos 5 on June 9, and the US authorities restricted their export on June 12.</p>



<p>The Anthropic decision comes as other frontier AI developers are also operating under closer government scrutiny.</p>



<p>In announcing GPT-5.6 Sol, Terra, and Luna last week, <a href="https://openai.com/index/previewing-gpt-5-6-sol/" target="_blank" rel="nofollow">OpenAI said</a> it had previewed both its rollout plans and the model’s capabilities to the US government before launch and, “at their request,” was initially making the model available only to “a small group of trusted partners” whose participation had been shared with the government.</p>



<p>OpenAI said it would continue coordinating with government partners before expanding availability, but added that it did not believe “this kind of government access process should become the long-term default” because it keeps advanced AI tools from “users, developers, enterprises, cyber defenders, and global partners who need them.”</p>



<p>Analysts say the Anthropic decision reflects a broader shift in how frontier AI models are governed.</p>



<p>“The reversal is not the story; the instrument beneath it is,” said Sanchit Vir Gogia, chief analyst at Greyhound Research. Washington, he said, has applied the long-standing “deemed export” doctrine to frontier AI models, signalling “negotiated oversight, conditional and monitored, rather than blanket prohibition.”</p>



<h2 class="wp-block-heading">Immediate order created global disruption</h2>



<p>Anthropic said the <a href="https://www.cio.com/article/4185175/anthropic-locks-enterprises-out-of-fable-and-mythos-following-government-order.html">June 12 export controls</a> required it to restrict access to foreign nationals.</p>



<p>“Because the order took effect immediately and we had no reliable way to verify nationality in real-time, we suspended access to both models for all users,” it added. The company partially restored Mythos 5 last week for a limited group of US organizations.</p>



<p>Anthropic said the restrictions followed a report from Amazon researchers describing a technique that bypassed one of Fable 5’s cybersecurity safeguards. After reviewing the findings with Amazon and the US government, the company concluded the technique “did not expose any unique Mythos-level cyber capabilities” and instead represented “a borderline case for Fable 5’s safeguards.”</p>



<p>It subsequently retrained its safety classifier, saying the reported technique is now blocked in more than 99% of cases, while acknowledging that the stronger protections would increase false positives for some legitimate coding requests. Researchers at the US Department of Commerce’s Center for AI Standards and Innovation also evaluated the updated safeguards, Anthropic said.</p>



<h2 class="wp-block-heading">Enterprises face a new continuity risk</h2>



<p>Experts say the episode demonstrates that frontier AI’s availability can now be shaped by policy decisions as much as technical capability.</p>



<p>“Frontier access has become conditional infrastructure,” Gogia said. “The models went dark globally because nationality could not be verified in real time, so a control aimed at foreign nationals became an outage for everyone.”</p>



<p>He said enterprises should also not assume that deploying models across multiple cloud providers insulates them from regulatory actions affecting the underlying model provider.</p>



<p>According to Gogia, organizations should begin evaluating frontier AI platforms for regulatory interruption, cross-border identity restrictions, channel restoration delays, and trusted-partner eligibility alongside traditional security, commercial, and technical considerations.</p>



<h2 class="wp-block-heading">Anthropic proposes a common jailbreak framework</h2>



<p>Anthropic used the announcement to call for an industry-wide framework to assess AI jailbreaks, saying developers and governments currently lack a common standard for evaluating newly discovered techniques.</p>



<p>“There’s currently no consensus in the AI industry on how to describe, in objective terms, the severity of an AI jailbreak,” the company said. Anthropic said it is working with Amazon, Microsoft, Google, and other Project Glasswing partners on a framework for evaluating jailbreaks, while also expanding collaboration with the US government through pre-release testing of future frontier models, information sharing, and joint AI security research.</p>



<p>“Government involvement in AI releases requires a durable, transparent process that gives cyber defenders and others the certainty they need about access to powerful models,” Anthropic said. “These rules should be codified in strong regulation and applied equally across frontier model developers.”</p>



<p>Gogia said the broader lesson extends beyond Anthropic’s restored access. “Restored access is not restored certainty,” Gogia said. “Build for the detour, because the road now runs through policy.”</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[US reverses export restrictions on Anthropic’s Fable 5, Mythos 5 AI models]]></title>
<description><![CDATA[The US government has reversed export restrictions on Anthropic’s frontier AI models Fable 5 and Mythos 5, allowing the company to resume global access after nearly three weeks of disruption triggered by concerns over the models’ cybersecurity capabilities.



“As of today, June 30, the export co...]]></description>
<link>https://tsecurity.de/de/3638240/it-nachrichten/us-reverses-export-restrictions-on-anthropics-fable-5-mythos-5-ai-models/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3638240/it-nachrichten/us-reverses-export-restrictions-on-anthropics-fable-5-mythos-5-ai-models/</guid>
<pubDate>Wed, 01 Jul 2026 13:18:13 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>The US government has reversed export restrictions on Anthropic’s frontier AI models Fable 5 and Mythos 5, allowing the company to resume global access after nearly three weeks of disruption triggered by concerns over the models’ cybersecurity capabilities.</p>



<p>“As of today, June 30, the export controls on Fable 5 and Mythos 5 have been lifted,” Anthropic said in a <a href="https://www.anthropic.com/news/redeploying-fable-5" target="_blank" rel="noreferrer noopener">blog post</a>. The company said Fable 5 will begin rolling out globally on July 1 across Claude Platform, Claude.ai, Claude Code and Claude Cowork, while access on Amazon Web Services, Google Cloud, and Microsoft Foundry will be restored “as quickly as possible.”</p>



<p>Commerce Secretary Howard Lutnick said the administration had worked with Anthropic before reversing the restrictions.</p>



<p>“Over the past two weeks, we have worked closely with Anthropic to analyze and approve Fable 5 to ensure alignment across the US Government and strengthen America’s leadership in AI,” <a href="https://x.com/howardlutnick/status/2072100729603452965" target="_blank" rel="noreferrer noopener">Lutnick wrote</a> in a post on X.</p>



<p>Anthropic had <a href="https://www.csoonline.com/article/4183094/anthropic-releases-mythos-class-fable-5-model-with-safeguards-for-cyber-risks.html">launched</a> Fable 5 and Mythos 5 on June 9, and the US authorities restricted their export on June 12.</p>



<p>The Anthropic decision comes as other frontier AI developers are also operating under closer government scrutiny.</p>



<p>In announcing GPT-5.6 Sol, Terra, and Luna last week, <a href="https://openai.com/index/previewing-gpt-5-6-sol/" target="_blank" rel="noreferrer noopener">OpenAI said</a> it had previewed both its rollout plans and the model’s capabilities to the US government before launch and, “at their request,” was initially making the model available only to “a small group of trusted partners” whose participation had been shared with the government.</p>



<p>OpenAI said it would continue coordinating with government partners before expanding availability, but added that it did not believe “this kind of government access process should become the long-term default” because it keeps advanced AI tools from “users, developers, enterprises, cyber defenders, and global partners who need them.”</p>



<p>Analysts say the Anthropic decision reflects a broader shift in how frontier AI models are governed.</p>



<p>“The reversal is not the story; the instrument beneath it is,” said Sanchit Vir Gogia, chief analyst at Greyhound Research. Washington, he said, has applied the long-standing “deemed export” doctrine to frontier AI models, signalling “negotiated oversight, conditional and monitored, rather than blanket prohibition.”</p>



<h2 class="wp-block-heading">Immediate order created global disruption</h2>



<p>Anthropic said the <a href="https://www.cio.com/article/4185175/anthropic-locks-enterprises-out-of-fable-and-mythos-following-government-order.html">June 12 export controls</a> required it to restrict access to foreign nationals.</p>



<p>“Because the order took effect immediately and we had no reliable way to verify nationality in real-time, we suspended access to both models for all users,” it added. The company partially restored Mythos 5 last week for a limited group of US organizations.</p>



<p>Anthropic said the restrictions followed a report from Amazon researchers describing a technique that bypassed one of Fable 5’s cybersecurity safeguards. After reviewing the findings with Amazon and the US government, the company concluded the technique “did not expose any unique Mythos-level cyber capabilities” and instead represented “a borderline case for Fable 5’s safeguards.”</p>



<p>It subsequently retrained its safety classifier, saying the reported technique is now blocked in more than 99% of cases, while acknowledging that the stronger protections would increase false positives for some legitimate coding requests. Researchers at the US Department of Commerce’s Center for AI Standards and Innovation also evaluated the updated safeguards, Anthropic said.</p>



<h2 class="wp-block-heading">Enterprises face a new continuity risk</h2>



<p>Experts say the episode demonstrates that frontier AI’s availability can now be shaped by policy decisions as much as technical capability.</p>



<p>“Frontier access has become conditional infrastructure,” Gogia said. “The models went dark globally because nationality could not be verified in real time, so a control aimed at foreign nationals became an outage for everyone.”</p>



<p>He said enterprises should also not assume that deploying models across multiple cloud providers insulates them from regulatory actions affecting the underlying model provider.</p>



<p>According to Gogia, organizations should begin evaluating frontier AI platforms for regulatory interruption, cross-border identity restrictions, channel restoration delays, and trusted-partner eligibility alongside traditional security, commercial, and technical considerations.</p>



<h2 class="wp-block-heading">Anthropic proposes a common jailbreak framework</h2>



<p>Anthropic used the announcement to call for an industry-wide framework to assess AI jailbreaks, saying developers and governments currently lack a common standard for evaluating newly discovered techniques.</p>



<p>“There’s currently no consensus in the AI industry on how to describe, in objective terms, the severity of an AI jailbreak,” the company said. Anthropic said it is working with Amazon, Microsoft, Google, and other Project Glasswing partners on a framework for evaluating jailbreaks, while also expanding collaboration with the US government through pre-release testing of future frontier models, information sharing, and joint AI security research.</p>



<p>“Government involvement in AI releases requires a durable, transparent process that gives cyber defenders and others the certainty they need about access to powerful models,” Anthropic said. “These rules should be codified in strong regulation and applied equally across frontier model developers.”</p>



<p>Gogia said the broader lesson extends beyond Anthropic’s restored access. “Restored access is not restored certainty,” Gogia said. “Build for the detour, because the road now runs through policy.”</p>



<p><em>The article originally appeared on <a href="https://www.cio.com/article/4191550/us-reverses-export-restrictions-on-anthropics-fable-5-mythos-5-ai-models.html">CIO</a>.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Trump raked in more than $1bn from crypto businesses in 2025, filing shows]]></title>
<description><![CDATA[President’s crypto ventures have eclipsed in revenue much of his property portfolio that took decades to accumulateDonald Trump raked in more than $1bn from his crypto businesses last year, a federal filing released Monday shows, giving a substantial boost to his annual income.In his second term,...]]></description>
<link>https://tsecurity.de/de/3637787/it-nachrichten/trump-raked-in-more-than-1bn-from-crypto-businesses-in-2025-filing-shows/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3637787/it-nachrichten/trump-raked-in-more-than-1bn-from-crypto-businesses-in-2025-filing-shows/</guid>
<pubDate>Wed, 01 Jul 2026 10:03:18 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>President’s crypto ventures have eclipsed in revenue much of his property portfolio that took decades to accumulate</p><p><a href="https://www.theguardian.com/us-news/donaldtrump">Donald Trump</a> raked in more than $1bn from his crypto businesses last year, a federal filing released Monday shows, giving a substantial boost to his annual income.</p><p>In his second term, the president and his family have heavily invested in digital money and various crypto businesses with Trump <a href="https://www.theguardian.com/technology/2025/mar/07/trump-crypto-leaders-meeting">announcing at the start of 2025</a> that he wanted the US to be the “crypto capital of the world”. Trump’s crypto earnings are in addition to profit from his legal settlements, real estate and royalty deals.</p> <a href="https://www.theguardian.com/us-news/2026/jun/30/trump-1bn-crypto-businesses-2025">Continue reading...</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[MIRI Newsletter #126]]></title>
<description><![CDATA[Announcing: AI StopWatch In our last update, we mentioned we had something new in the works: a dedicated channel for news and analysis about AI.  Subscribe to AI StopWatch  An experiment from the writers and analysts at MIRI, AI StopWatch posts news and commentary seven days a week. You can read ...]]></description>
<link>https://tsecurity.de/de/3636817/ai-nachrichten/miri-newsletter-126/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3636817/ai-nachrichten/miri-newsletter-126/</guid>
<pubDate>Tue, 30 Jun 2026 22:33:48 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Announcing: AI StopWatch In our last update, we mentioned we had something new in the works: a dedicated channel for news and analysis about AI.  Subscribe to AI StopWatch  An experiment from the writers and analysts at MIRI, AI StopWatch posts news and commentary seven days a week. You can read our commentary as it’s […]</p>
<p>The post <a rel="nofollow" href="https://intelligence.org/2026/06/30/miri-newsletter-126/">MIRI Newsletter #126</a> appeared first on <a rel="nofollow" href="https://intelligence.org/">Machine Intelligence Research Institute</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Improving Transparency and Assurance in the Web PKI: Mozilla Root Store Policy v3.1]]></title>
<description><![CDATA[Mozilla remains committed to maintaining a secure, trustworthy, and transparent Web PKI. Today we are announcing the publication of Mozilla Root Store Policy (MRSP) version 3.1, effective July 1, 2026. … Read more
The post Improving Transparency and Assurance in the Web PKI: Mozilla Root Store Po...]]></description>
<link>https://tsecurity.de/de/3632784/it-security-nachrichten/improving-transparency-and-assurance-in-the-web-pki-mozilla-root-store-policy-v31/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3632784/it-security-nachrichten/improving-transparency-and-assurance-in-the-web-pki-mozilla-root-store-policy-v31/</guid>
<pubDate>Mon, 29 Jun 2026 13:53:31 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Mozilla remains committed to maintaining a secure, trustworthy, and transparent Web PKI. Today we are announcing the publication of Mozilla Root Store Policy (MRSP) version 3.1, effective July 1, 2026. … <a class="go" href="https://blog.mozilla.org/security/2026/06/29/improving-transparency-and-assurance-in-the-web-pki-mozilla-root-store-policy-v3-1/">Read more</a></p>
<p>The post <a href="https://blog.mozilla.org/security/2026/06/29/improving-transparency-and-assurance-in-the-web-pki-mozilla-root-store-policy-v3-1/">Improving Transparency and Assurance in the Web PKI: Mozilla Root Store Policy v3.1</a> appeared first on <a href="https://blog.mozilla.org/security">Mozilla Security Blog</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Distribution Release: AnduinOS 2.0.0]]></title>
<description><![CDATA[The DistroWatch news feed is brought to you by TUXEDO COMPUTERS.  AnduinOS 2.0.0 has been released. AnduinOS is an Ubuntu-based Linux distribution featuring a GNOME desktop customised with a variety of extensions. This major new release brings extensive under-the-hood changes while maintaining th...]]></description>
<link>https://tsecurity.de/de/3631506/unix-server/distribution-release-anduinos-200/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3631506/unix-server/distribution-release-anduinos-200/</guid>
<pubDate>Sun, 28 Jun 2026 22:01:00 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The DistroWatch news feed is brought to you by <a href="https://www.tuxedocomputers.com/">TUXEDO COMPUTERS</a>.  AnduinOS 2.0.0 has been released. AnduinOS is an Ubuntu-based Linux distribution featuring a GNOME desktop customised with a variety of extensions. This major new release brings extensive under-the-hood changes while maintaining the usability and customisability of the desktop. "Today, AIURSOFT Limited is announcing the general availability of AnduinOS....]]></content:encoded>
</item>
<item>
<title><![CDATA[Micron Exec Claims Apple Caused The Current Memory Chip Shortage]]></title>
<description><![CDATA[The ongoing memory chip shortage has forced the tech industry to raise prices, and one major supplier is pointing the finger at Apple. After announcing a massive jump in revenue this week, a top executive at Micron suggested that the aggressive buying tactics used by the smartphone maker during t...]]></description>
<link>https://tsecurity.de/de/3628499/ios-mac-os/micron-exec-claims-apple-caused-the-current-memory-chip-shortage/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3628499/ios-mac-os/micron-exec-claims-apple-caused-the-current-memory-chip-shortage/</guid>
<pubDate>Fri, 26 Jun 2026 22:10:50 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The ongoing memory chip shortage has forced the tech industry to raise prices, and one major supplier is pointing the finger at Apple. After announcing a massive jump in revenue this week, a top executive at Micron suggested that the aggressive buying tactics used by the smartphone maker during the last market downturn are partly to blame for the current lack of supply.



The comments arrive just after the tech giant bumped up the cost of several devices to offset rising component expenses.



Micron says cheap deals stopped it from funding new factories



Micron Chief Business Officer Sumit Sadana explained to The Wall Street Journal that the supplier could not invest in new production capacity a few years ago. During the last big slump in the memory market, certain buyers pushed hard for rock-bottom prices. This move caused Micron to lose money and forced it to halt investments in 2023. While the executive did not mention the brand by name, the timing and context clearly point toward the creator of the iPhone.



The tech giant is well known for driving a hard bargain with suppliers to keep costs low. Those long-term contracts helped it delay price hikes longer than competitors. However, the supplier claims those same deals created a bad environment for the whole industry. Because the memory sector was not making enough money, it could not afford to build out the extra capacity needed to meet demand today.



The situation came to a head recently when the tech giant announced sweeping price increases across the Mac and iPad lineups, along with the Apple TV and Vision Pro. CEO Tim Cook called the current component crunch a hundred-year flood, noting that the memory sector was passing along huge cost increases. Cook said the company had to raise shelf prices because the situation was no longer sustainable.



This back and forth shows how deeply connected the supply chain really is. While squeezing suppliers for better deals helps profit margins in the short term, it can clearly backfire when demand spikes. With memory costs expected to stay high for the foreseeable future, everyday buyers will be the ones footing the bill for this ongoing standoff.]]></content:encoded>
</item>
<item>
<title><![CDATA[OpenAI unveils GPT-5.6 Sol, Terra and Luna models — but only accessible to limited preview partners for now, per US Gov]]></title>
<description><![CDATA[OpenAI is announcing a limited preview of its next-generation GPT-5.6 model series today, introducing three distinct, capability-tiered models—Sol, Terra, and Luna—designed to re-engineer developer and enterprise workflows. The initial rollout is available through the API and Codex to a narrow se...]]></description>
<link>https://tsecurity.de/de/3628259/it-nachrichten/openai-unveils-gpt-56-sol-terra-and-luna-models-but-only-accessible-to-limited-preview-partners-for-now-per-us-gov/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3628259/it-nachrichten/openai-unveils-gpt-56-sol-terra-and-luna-models-but-only-accessible-to-limited-preview-partners-for-now-per-us-gov/</guid>
<pubDate>Fri, 26 Jun 2026 20:03:23 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>OpenAI is <a href="https://openai.com/index/previewing-gpt-5-6-sol/">announcing</a> a limited preview of its next-generation GPT-5.6 model series today, introducing three distinct, capability-tiered models—Sol, Terra, and Luna—designed to re-engineer developer and enterprise workflows. </p><p>The initial rollout is available through the API and Codex to a narrow set of approximately 20 total organizations after OpenAI shared the models and release plans with the U.S. government, following an <a href="https://www.whitehouse.gov/presidential-actions/2026/06/promoting-advanced-artificial-intelligence-innovation-and-security/">executive order issued by President Donald J. Trump earlier this month on June 2, 2026</a>, which calls upon various federal agencies to collaborate on a process for benchmarking and assessing capabilities of new AI models to ensure they are safe and appropriate for wide release. </p><p>While this process remains underway (it was said in the order to take 30 days, so July 2), OpenAI says in its release blog post that it "previewed our plans and the models’ capabilities ahead of today’s launch. At [the U.S. government's] request, we are starting with a limited preview for a small group of trusted partners." </p><p>OpenAI's limited preview release strategy also follows the drastic step taken by he<a href="https://venturebeat.com/technology/anthropic-blocks-all-public-access-to-claude-fable-5-mythos-5-following-us-government-order-what-enterprises-should-do"> U.S. government to issue an export control order against Anthropic</a>, OpenAI's top U.S. competitor, over jailbreaks found in its most powerful generally released model, Claude Fable 5, to which Anthropic responded by removing any access to the model and its cybersecurity focused counterpart Claude Mythos 5 by public or private parties. </p><p>Because OpenAI is coordinating its release framework with the White House ahead of a broader public launch, enterprise buyers must navigate a novel landscape of real-time safety interventions, mandatory compliance parameters, and structured token caching systems. </p><h2><b>How the 3 new GPT-5.6 models differ: Sol vs. Terra vs. Luna</b></h2><p>The three GPT-5.6 models are designed to address different enterprise needs and performance profiles. </p><p><b>Sol</b> is the top-tier option, built for the most demanding tasks such as complex reasoning, extended coding sessions, advanced agent-driven workflows, and security-focused applications. It delivers the highest level of capability but comes with the greatest resource requirements.</p><p>It's priced at $5.00 per million input tokens / $30.00 per million output tokens — the same as GPT-5.5 — and OpenAI says it delivers a major performance gain for long-running coding, cybersecurity and agentic tasks. </p><p><b>Terra</b> balances strong performance with efficiency. It is intended for large-scale production environments where organizations need reliable results across high volumes of work without the overhead of the most advanced model. It's available for $2.50/$15 per 1M tokens. </p><p><b>Luna</b> is the most lightweight and cost-efficient option, optimized for speed and everyday use cases. It is well suited for simpler tasks, routine workflows, and applications where responsiveness and scalability are more important than maximum depth of reasoning, and is the most affordably priced at $1/$6 per million tokens in and out, respectively. </p><p>Sources with knowledge of OpenAI's inner workings shared with VentureBeat that the new naming scheme was designed to move away from<a href="https://venturebeat.com/ai/openai-launches-gpt-5-not-agi-but-capable-of-generating-software-on-demand"> the "nano" and "mini" variants of GPT-5</a>, as these models are not so different in terms of size or raw intelligence, but rather, designed for different distinct use cases. </p><p>As OpenAI states in its blog post about the new naming scheme: "In this new naming system introduced with GPT‑5.6, the number identifies a model’s generation, while Sol, Terra, and Luna identify durable capability tiers that can advance on their own cadence. Together, the family gives people and developers clearer choices across intelligence, speed, and cost." </p><p>Also, sources said OpenAI sought to evoke a sense of inspiration by looking to the cosmos and names associated with it. </p><p>Further, Sol fits well alongside OpenAI's Daybreak opt-in program for organizations interested in cyber defense, which is an added bonus. The "Sol" voice style for OpenAI's voice mode on ChatGPT is unrelated, and will likely be renamed. </p><p>Here's how they stack up against the rest of the current leading LLM field in price — note that OpenAI's cheapest option is overall a mid-priced model, and still more expensive than the frontier-level GLM-5.2</p><h1><b>VentureBeat Frontier AI Model API Pricing Snapshot</b></h1><table><tbody><tr><td><p><b>Model</b></p></td><td><p><b>Input</b></p></td><td><p><b>Output</b></p></td><td><p><b>Total Cost</b></p></td><td><p><b>Source</b></p></td></tr><tr><td><p>MiMo-V2.5 Flash</p></td><td><p>$0.10</p></td><td><p>$0.30</p></td><td><p>$0.40</p></td><td><p><a href="https://platform.xiaomimimo.com/docs/en-US/pricing">Xiaomi MiMo</a></p></td></tr><tr><td><p>deepseek-v4-flash</p></td><td><p>$0.14</p></td><td><p>$0.28</p></td><td><p>$0.42</p></td><td><p><a href="https://api-docs.deepseek.com/quick_start/pricing">DeepSeek</a></p></td></tr><tr><td><p>deepseek-v4-pro</p></td><td><p>$0.435</p></td><td><p>$0.87</p></td><td><p>$1.305</p></td><td><p><a href="https://api-docs.deepseek.com/quick_start/pricing">DeepSeek</a></p></td></tr><tr><td><p>MiniMax-M3</p></td><td><p>$0.30</p></td><td><p>$1.20</p></td><td><p>$1.50</p></td><td><p><a href="https://platform.minimax.io/subscribe/token-plan?tab=api-enterprise">MiniMax</a></p></td></tr><tr><td><p>Gemini 3.1 Flash-Lite</p></td><td><p>$0.25</p></td><td><p>$1.50</p></td><td><p>$1.75</p></td><td><p><a href="https://ai.google.dev/gemini-api/docs/pricing">Google</a></p></td></tr><tr><td><p>Qwen3.7-Plus</p></td><td><p>$0.40</p></td><td><p>$1.60</p></td><td><p>$2.00</p></td><td><p><a href="https://modelstudio.console.alibabacloud.com/ap-southeast-1?tab=doc#/doc/?type=model&amp;url=2840914_2&amp;modelId=qwen3.7-plus&amp;serviceSite=international">Alibaba Cloud</a></p></td></tr><tr><td><p>MiMo-V2.5</p></td><td><p>$0.40</p></td><td><p>$2.00</p></td><td><p>$2.40</p></td><td><p><a href="https://platform.xiaomimimo.com/docs/en-US/pricing">Xiaomi MiMo</a></p></td></tr><tr><td><p>Grok 4.3 (low context)</p></td><td><p>$1.25</p></td><td><p>$2.50</p></td><td><p>$3.75</p></td><td><p><a href="https://docs.x.ai/developers/models/grok-4.3">xAI</a></p></td></tr><tr><td><p>MiMo-V2.5 Pro (≤256K)</p></td><td><p>$1.00</p></td><td><p>$3.00</p></td><td><p>$4.00</p></td><td><p><a href="https://platform.xiaomimimo.com/docs/en-US/pricing">Xiaomi MiMo</a></p></td></tr><tr><td><p>Kimi-K2.6</p></td><td><p>$0.95</p></td><td><p>$4.00</p></td><td><p>$4.95</p></td><td><p><a href="https://platform.kimi.ai/docs/pricing/chat-k26">Moonshot/Kimi</a></p></td></tr><tr><td><p>GLM-5.2</p></td><td><p>$1.40</p></td><td><p>$4.40</p></td><td><p>$5.80</p></td><td><p><a href="https://docs.z.ai/guides/overview/pricing">Z.ai</a></p></td></tr><tr><td><p><b>GPT-5.6 Luna</b></p></td><td><p><b>$1.00</b></p></td><td><p><b>$6.00</b></p></td><td><p><b>$7.00</b></p></td><td><p><b></b><a href="https://openai.com/index/previewing-gpt-5-6-sol/"><b>OpenAI</b></a></p></td></tr><tr><td><p>Grok 4.3 (high context)</p></td><td><p>$2.50</p></td><td><p>$5.00</p></td><td><p>$7.50</p></td><td><p><a href="https://docs.x.ai/developers/models/grok-4.3">xAI</a></p></td></tr><tr><td><p>MiMo-V2.5 Pro (&gt;256K)</p></td><td><p>$2.00</p></td><td><p>$6.00</p></td><td><p>$8.00</p></td><td><p><a href="https://platform.xiaomimimo.com/docs/en-US/pricing">Xiaomi MiMo</a></p></td></tr><tr><td><p>Qwen3.7-Max</p></td><td><p>$2.50</p></td><td><p>$7.50</p></td><td><p>$10.00</p></td><td><p><a href="https://modelstudio.console.alibabacloud.com/ap-southeast-1?tab=doc#/doc/?type=model&amp;url=2840914_2&amp;modelId=qwen3.7-max&amp;serviceSite=international">Alibaba Cloud</a></p></td></tr><tr><td><p>Gemini 3.5 Flash</p></td><td><p>$1.50</p></td><td><p>$9.00</p></td><td><p>$10.50</p></td><td><p><a href="https://ai.google.dev/gemini-api/docs/pricing">Google</a></p></td></tr><tr><td><p>Gemini 3.1 Pro Preview (≤200K)</p></td><td><p>$2.00</p></td><td><p>$12.00</p></td><td><p>$14.00</p></td><td><p><a href="https://ai.google.dev/gemini-api/docs/pricing">Google</a></p></td></tr><tr><td><p><b>GPT-5.6 Terra</b></p></td><td><p><b>$2.50</b></p></td><td><p><b>$15.00</b></p></td><td><p><b>$17.50</b></p></td><td><p><b></b><a href="https://openai.com/index/previewing-gpt-5-6-sol/"><b>OpenAI</b></a></p></td></tr><tr><td><p>GPT-5.4</p></td><td><p>$2.50</p></td><td><p>$15.00</p></td><td><p>$17.50</p></td><td><p><a href="https://openai.com/api/pricing/">OpenAI</a></p></td></tr><tr><td><p>Gemini 3.1 Pro Preview (&gt;200K)</p></td><td><p>$4.00</p></td><td><p>$18.00</p></td><td><p>$22.00</p></td><td><p><a href="https://ai.google.dev/gemini-api/docs/pricing">Google</a></p></td></tr><tr><td><p>Claude Opus 4.8</p></td><td><p>$5.00</p></td><td><p>$25.00</p></td><td><p>$30.00</p></td><td><p><a href="https://platform.claude.com/docs/en/about-claude/pricing">Anthropic</a></p></td></tr><tr><td><p>GPT-5.5</p></td><td><p>$5.00</p></td><td><p>$30.00</p></td><td><p>$35.00</p></td><td><p><a href="https://openai.com/api/pricing/">OpenAI</a></p></td></tr><tr><td><p>GPT-5.5 Instant (<code>chat-latest</code>)</p></td><td><p>$5.00</p></td><td><p>$30.00</p></td><td><p>$35.00</p></td><td><p><a href="https://developers.openai.com/api/docs/models/chat-latest">OpenAI</a></p></td></tr><tr><td><p>Sakana Fugu Ultra (≤272K)</p></td><td><p>$5.00</p></td><td><p>$30.00</p></td><td><p>$35.00</p></td><td><p><a href="https://console.sakana.ai/pricing#subscription-plan">Sakana AI</a></p></td></tr><tr><td><p><b>GPT-5.6 Sol</b></p></td><td><p><b>$5.00</b></p></td><td><p><b>$30.00</b></p></td><td><p><b>$35.00</b></p></td><td><p><b></b><a href="https://openai.com/index/previewing-gpt-5-6-sol/"><b>OpenAI</b></a></p></td></tr><tr><td><p>Claude Fable 5 / Claude Mythos 5</p></td><td><p>$10.00</p></td><td><p>$50.00</p></td><td><p>$60.00</p></td><td><p><a href="https://platform.claude.com/docs/en/about-claude/models/overview">Anthropic</a></p></td></tr></tbody></table><h2><b>Technology: Deep Reasoning and the Multi-Agent Paradigm</b></h2><p>The core architectural evolution of the GPT-5.6 series centers on how compute is allocated during inference. Rather than relying on instantaneous token generation, OpenAI introduces a new <code>max</code> reasoning effort mode, which explicitly grants the flagship Sol model extended time to reason through highly complex problems deeply. Compounding this is the debut of an <code>ultra</code> mode. </p><p>This configuration expands past the structural boundaries of a single standalone model, instead deploying specialized "subagents" to divide, conquer, and accelerate multi-step, long-horizon projects. Data from initial evaluations indicates that this subagent coordination shifts the frontier for programmatic execution:</p><ul><li><p><b>Command-Line Automation:</b> On Terminal-Bench 2.1—which evaluates planning, tool usage, and iterative error correction in command-line environments—GPT-5.6 Sol (Ultra) achieves a state-of-the-art score of <b>91.91%</b>. This edges out GPT-5.6 Sol (Max) at <b>88.76%</b> and eclipses Claude Mythos 5 at <b>88%.</b></p></li><li><p><b>Professional Workflows:</b> On Agent's Last Exam, a benchmark spanning 55 professional domains to test long-running workflows, GPT-5.6 Sol is the only model to clear the 50% success threshold, scoring <b>50.9%</b> in code mode while displaying superior token efficiency relative to preceding architectures,.<i> </i></p></li><li><p><b>Quantitative Biology:</b> On GeneBench v1, which measures long-horizon genomics analysis, the flagship model systematically outperforms GPT-5.5 while consuming fewer total tokens across simulated latency periods</p></li></ul><h3><b>Predictable Prompt Caching Mechanics</b></h3><p>To help enterprises control the unpredictable cost curves of running agentic loops, the GPT-5.6 API introduces a revamped prompt caching protocol. </p><p>Developers can now implement explicit cache breakpoints, backed by a guaranteed 30-minute minimum cache lifetime. Under this framework, initial cache writes carry a 1.25x premium over the model's standard uncached input rate, but subsequent cache reads receive a steep <b>90% discount</b>. For systems that routinely pass massive context windows or codebase definitions back into the model, this predictability is a critical financial guardrail. </p><p>Furthermore, for enterprise applications where latency is the primary barrier to adoption, OpenAI is launching GPT-5.6 Sol on Cerebras hardware this July. This infrastructure partnership claims processing speeds of up to <b>750 tokens per second</b>, targeting specialized enterprise applications requiring real-time, frontier-grade reasoning. </p><h2><b>Enterprise Implications: High Security and Algorithmic Friction</b></h2><p>For corporate engineering, information security, and compliance teams, the deployment of GPT-5.6 requires a meticulous look at its security architecture. The models are accessible under a commercial enterprise API license, with open-source options completely off the table due to the dual-use risks inherent to its cyber capabilities. </p><p>To achieve clearance for release, OpenAI dedicated roughly <b>700,000 A100e GPU hours</b> solely to automated red-teaming. This compute was allocated to discovering "universal jailbreaks"—systemic attack vectors designed to bypass safeguards across varied contexts, rather than single-prompt workarounds.</p><p>This massive testing phase feeds directly into a highly strict, multi-layered safeguard stack that operates in real time: </p><ol><li><p><b>Model-Level Refusals:</b> Hardcoded boundaries trained directly into the base weights to resist masked intent or adversarial obfuscation. </p></li><li><p><b>Real-Time Classifiers:</b> Auxiliary systems that evaluate cyber and biological output token-by-token as it is generated. </p></li><li><p><b>Reasoning Review Pauses:</b> If a potential high-risk violation is flagged mid-generation, the pipeline automatically pauses. A secondary, larger reasoning model reviews the context of the conversation; if verified as malicious, the output is withheld before it reaches the user endpoint. </p></li></ol><h2><b>Operational Friction for Dual-Use Security Work</b></h2><p>This real-time safety stack introduces distinct operational hurdles for enterprise security teams. </p><p>Because legitimate defensive work—such as code reviews, vulnerability discovery, patch engineering, and defensive testing—frequently utilizes the exact same code primitives as offensive exploits, OpenAI admits that its classifiers may regularly trigger false positives. During this preview period, enterprise developers should expect localized latency spikes, paused API generations, and intermittent request refusals. </p><p>Persistent flagging can trigger automated account-level reviews across historical conversations to evaluate if an enterprise client is engaging in malicious behavior or standard security research. OpenAI is currently negotiating longer-term enterprise safety compliance controls, including customer-operated safety overrides and privacy-preserving detection mechanisms, to insulate corporate data from manual review pipelines. </p><p>Importantly, OpenAI notes that under testing, Sol remains optimized for defensive containment rather than offensive deployment. In evaluations running against the Chromium and Firefox codebases, the model successfully isolated bugs and exploitation primitives but was unable to autonomously engineer a functional, full-chain exploit, keeping it safely below the organization's "Cyber Critical" alert threshold. </p><h2><b>The Geopolitics of the Phased Release</b></h2><p>The broader rollout of the GPT-5.6 series reflects an escalating entanglement between frontier AI labs and national security protocols. The decision to limit initial access to a small circle of vetted partners whose details are shared with the U.S. government stems from direct coordination regarding the developing cyber Executive Order framework. OpenAI has taken the unusual step of publicly critiquing this sovereign gatekeeping within its official product announcement documentation. The company states plainly: </p><blockquote><p>"We don’t believe this kind of government access process should become the long-term default. It keeps the best tools from users, developers, enterprises, cyber defenders, and global partners who need them." </p></blockquote><p>This tension highlights the precarious position of modern tech enterprises. While organizations can leverage unprecedented agentic efficiency and robust defensive patching capabilities via benchmarks like ExploitGym  and ExploitBench, they must also accept that access to premier tools remains subject to diplomatic and regulatory authorization. General availability across ChatGPT and the wider public API is expected to roll out incrementally over the coming weeks. </p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Announcing new builds for 26 June 2026, retail launch of new WIP improvements]]></title>
<description><![CDATA[Hello Windows Insiders,
We have new releases today with builds across Beta and Experimental, and are excited to begin rolling out the new Windows Insider experience to retail Windows 11 builds this week!
New Windows Insider Program changes 
The post Announcing new builds for 26 June 2026, retail ...]]></description>
<link>https://tsecurity.de/de/3628135/windows-tipps/announcing-new-builds-for-26-june-2026-retail-launch-of-new-wip-improvements/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3628135/windows-tipps/announcing-new-builds-for-26-june-2026-retail-launch-of-new-wip-improvements/</guid>
<pubDate>Fri, 26 Jun 2026 19:11:59 +0200</pubDate>
<category>🪟 Windows Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Hello Windows Insiders,</p>
<p>We have new releases today with builds across Beta and Experimental, and are excited to begin rolling out the new Windows Insider experience to retail Windows 11 builds this week!</p>
<p><strong>New Windows Insider Program changes </strong></p>
<p>The post <a href="https://blogs.windows.com/windows-insider/2026/06/26/announcing-new-builds-for-26-june-2026-retail-launch-of-new-wip-improvements/">Announcing new builds for 26 June 2026, retail launch of new WIP improvements</a> appeared first on <a href="https://blogs.windows.com/windows-insider">Windows Insider Blog</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Ubuntu 26.10 Snapshot 2 is out (with a ‘breaking change’)]]></title>
<description><![CDATA[Ubuntu 26.10 Snapshot 2 is available to download, the second of four snapshots planned for the ‘Stonking Stingray’ development cycle ahead of a stable release in October. As with the first snapshot, there’s not a lot “new” stuff to see or test out, so unless you’re a developer or an avid bug hunt...]]></description>
<link>https://tsecurity.de/de/3627989/linux-tipps/ubuntu-2610-snapshot-2-is-out-with-a-breaking-change/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3627989/linux-tipps/ubuntu-2610-snapshot-2-is-out-with-a-breaking-change/</guid>
<pubDate>Fri, 26 Jun 2026 18:10:22 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="406" height="232" src="https://i0.wp.com/www.omgubuntu.co.uk/wp-content/uploads/2026/04/stonking-stingray-ubuntu.webp?resize=406%2C232&amp;ssl=1" class="attachment-post-list size-post-list wp-post-image" alt="Ubuntu logo behind stingray in the ocean." decoding="async" fetchpriority="high" srcset="https://i0.wp.com/www.omgubuntu.co.uk/wp-content/uploads/2026/04/stonking-stingray-ubuntu.webp?resize=350%2C200&amp;ssl=1 350w, https://i0.wp.com/www.omgubuntu.co.uk/wp-content/uploads/2026/04/stonking-stingray-ubuntu.webp?resize=406%2C232&amp;ssl=1 406w, https://i0.wp.com/www.omgubuntu.co.uk/wp-content/uploads/2026/04/stonking-stingray-ubuntu.webp?resize=840%2C480&amp;ssl=1 840w, https://i0.wp.com/www.omgubuntu.co.uk/wp-content/uploads/2026/04/stonking-stingray-ubuntu.webp?zoom=3&amp;resize=406%2C232&amp;ssl=1 1218w" sizes="(max-width: 406px) 100vw, 406px">Ubuntu 26.10 Snapshot 2 is available to download, the second of four snapshots planned for the ‘Stonking Stingray’ development cycle ahead of a stable release in October. As with the first snapshot, there’s not a lot “new” stuff to see or test out, so unless you’re a developer or an avid bug hunter there’s little reason to rush off and try it. Canonical’s Utkarsh Gupta, announcing the release on Ubuntu’s developer mailing list, warns of a “breaking change” – don’t panic: it’s not in the image itself, but the URL it’s accessed from. Over the past few weeks the Ubuntu […]</p>
<p>You're reading <a href="https://www.omgubuntu.co.uk/2026/06/ubuntu-26-10-snapshot-2-released">Ubuntu 26.10 Snapshot 2 is out (with a ‘breaking change’)</a>, a blog post from <a href="https://www.omgubuntu.co.uk/">OMG! Ubuntu</a>. Do not reproduce elsewhere without permission.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Proposed US law would make AI risk reporting a legal obligation]]></title>
<description><![CDATA[US lawmakers on Thursday introduced a bill that would require developers of advanced AI models to report major safety and security incidents to the Commerce Department, establishing a federal oversight framework for high-risk AI systems.



The proposed AI Incident Reporting Act would mandate tha...]]></description>
<link>https://tsecurity.de/de/3627000/it-security-nachrichten/proposed-us-law-would-make-ai-risk-reporting-a-legal-obligation/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3627000/it-security-nachrichten/proposed-us-law-would-make-ai-risk-reporting-a-legal-obligation/</guid>
<pubDate>Fri, 26 Jun 2026 12:09:09 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>US lawmakers on Thursday introduced a bill that would require developers of advanced AI models to report major safety and security incidents to the Commerce Department, establishing a federal oversight framework for high-risk AI systems.</p>



<p>The proposed AI Incident Reporting Act would mandate that developers of designated “covered models” disclose incidents within seven days of knowing, or reasonably believing, that one has occurred. For incidents posing an imminent or ongoing risk of serious harm, the Commerce Department would have to notify congressional leadership and the chairs of relevant House and Senate committees within 48 hours after receiving the report.</p>



<p>The bill directs the Secretary of Commerce to establish capability thresholds to determine which AI models and developers are subject to the reporting requirements.</p>



<p>“AI is a powerful engine of innovation, and I want to see it flourish, but not without accountability and not without human oversight,” Moran said in a <a href="https://moran.house.gov/news/documentsingle.aspx?DocumentID=2785" target="_blank" rel="noreferrer noopener">statement</a> announcing the legislation. “The rule of law should apply to this new frontier. This legislation ensures that when something goes wrong with a high-capability AI system, the US Government has the information needed to act quickly.”</p>



<h2 class="wp-block-heading">Broad range of reportable incidents</h2>



<p>The proposal identifies a broad set of incidents that would require disclosure to the Commerce Department.</p>



<p><a href="https://moran.house.gov/uploadedfiles/moratx_051_xml-_final_-_ai_incident_reporting_act.pdf" target="_blank" rel="noreferrer noopener">According to the bill</a>, developers would have to report attempts by covered AI models to evade human oversight, deceive operators, circumvent safeguards, resist shutdown, or obtain unauthorized access to systems or privileges.</p>



<p>The reporting requirement would also apply to theft or attempted theft of model weights, capabilities that could materially enable offensive cyber operations against important software or critical infrastructure, autonomous development of more capable AI systems, and capabilities that could accelerate the development or use of chemical, biological, radiological, nuclear, or explosive weapons.</p>



<p>The legislation also directs the Commerce Department to develop the capability thresholds in consultation with AI developers, academic researchers, cybersecurity experts, national security officials, and other stakeholders before issuing implementation guidance.</p>



<p>Sanchit Vir Gogia, chief analyst at Greyhound Research, said the proposal would make reporting serious AI incidents a legal obligation rather than a voluntary practice for developers of frontier AI models.</p>



<p>“The serious frontier developers already run the evaluations, the red-teaming and the escalation drills,” Gogia said. “What they have never faced at the federal level is a legal obligation to tell the government, on the clock, when a model behaves dangerously.”</p>



<h2 class="wp-block-heading">Reporting timelines and enforcement</h2>



<p>The bill requires covered developers to submit an initial report within seven days of discovering a reportable incident and supplemental reports as additional information becomes available. </p>



<p>The legislation also authorizes the Commerce Department to investigate compliance, issue subpoenas, require corrective action, and impose civil penalties of up to $2 million for violations. Each day of a continuing violation would constitute a separate violation, the bill states.</p>



<p>Gogia said implementation could hinge on how regulators define reporting triggers.</p>



<p>“Capability thresholds are the visible difficulty, and not the deepest one. Thresholds decide which models enter the regime. Discovery decides whether the regime ever sees the fire,” he said.</p>



<p>Drawing a comparison with cybersecurity regulations, he said reporting requirements should clearly define when an incident becomes reportable.</p>



<p>“Cyber reporting has already taught the lesson. A vague trigger produces either silence or noise: firms stay quiet until they are certain, or they file everything and bury the signal,” Gogia said.</p>



<h2 class="wp-block-heading">Filling a gap, a recent dispute exposed</h2>



<p>The bill follows a US government action that exposed the absence of any such process. On June 12, the Commerce Department took action against the latest models from Anthropic, a US AI developer, on national security grounds, prompting the company to <a href="https://www.computerworld.com/article/4186538/anthropic-fable-dispute-suggests-export-no-longer-means-what-it-used-to-2.html">disable global access to those models</a>.</p>



<p>“Export control was the sledgehammer. This proposal is the search for a scalpel,” Gogia noted. The measure is a narrower alternative to the <a href="https://obernolte.house.gov/sites/evo-subsites/obernolte.house.gov/files/evo-media-document/the-great-american-ai-act-discussion-draft-website-compressed-compressed.pdf" target="_blank" rel="noreferrer noopener">Great American Artificial Intelligence Act</a>, a broader discussion draft released earlier in June that also routes critical safety incidents to Commerce.</p>



<p>The Commerce Department’s Center for AI Standards and Innovation has separately signed agreements to <a href="https://www.csoonline.com/article/4168135/us-government-agency-to-safety-test-frontier-ai-models-before-release-2.html">evaluate leading models before deployment</a>.</p>



<h2 class="wp-block-heading">Compliance burden falls on enterprises</h2>



<p>Gogia said the legal duty falls on the developer, but the operational cost reaches the customers. “Regulation may name the lab, but the bill for poor visibility is settled downstream,” he said.</p>



<p>He said the hardest question is not which models qualify but when a reporting clock starts. “Thresholds decide which models enter the regime. Discovery decides whether the regime ever sees the fire,” he said, adding that a model can pass laboratory tests yet behave differently once connected to live tools and enterprise data.</p>



<p>The bill exempts submitted reports from public disclosure requirements and states that submitting a report would not waive trade secret protections or attorney-client privilege.</p>



<p>“The instinct behind this bill is sound, but the balance cannot be scored from a press release,” Gogia said. “The wording will decide everything.”</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Proposed US law would make AI risk reporting a legal obligation]]></title>
<description><![CDATA[US lawmakers on Thursday introduced a bill that would require developers of advanced AI models to report major safety and security incidents to the Commerce Department, establishing a federal oversight framework for high-risk AI systems.



The proposed AI Incident Reporting Act would mandate tha...]]></description>
<link>https://tsecurity.de/de/3626980/it-nachrichten/proposed-us-law-would-make-ai-risk-reporting-a-legal-obligation/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3626980/it-nachrichten/proposed-us-law-would-make-ai-risk-reporting-a-legal-obligation/</guid>
<pubDate>Fri, 26 Jun 2026 12:03:04 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>US lawmakers on Thursday introduced a bill that would require developers of advanced AI models to report major safety and security incidents to the Commerce Department, establishing a federal oversight framework for high-risk AI systems.</p>



<p>The proposed AI Incident Reporting Act would mandate that developers of designated “covered models” disclose incidents within seven days of knowing, or reasonably believing, that one has occurred. For incidents posing an imminent or ongoing risk of serious harm, the Commerce Department would have to notify congressional leadership and the chairs of relevant House and Senate committees within 48 hours after receiving the report.</p>



<p>The bill directs the Secretary of Commerce to establish capability thresholds to determine which AI models and developers are subject to the reporting requirements.</p>



<p>“AI is a powerful engine of innovation, and I want to see it flourish, but not without accountability and not without human oversight,” Moran said in a <a href="https://moran.house.gov/news/documentsingle.aspx?DocumentID=2785" target="_blank" rel="nofollow">statement</a> announcing the legislation. “The rule of law should apply to this new frontier. This legislation ensures that when something goes wrong with a high-capability AI system, the US Government has the information needed to act quickly.”</p>



<h2 class="wp-block-heading">Broad range of reportable incidents</h2>



<p>The proposal identifies a broad set of incidents that would require disclosure to the Commerce Department.</p>



<p><a href="https://moran.house.gov/uploadedfiles/moratx_051_xml-_final_-_ai_incident_reporting_act.pdf" target="_blank" rel="nofollow">According to the bill</a>, developers would have to report attempts by covered AI models to evade human oversight, deceive operators, circumvent safeguards, resist shutdown, or obtain unauthorized access to systems or privileges.</p>



<p>The reporting requirement would also apply to theft or attempted theft of model weights, capabilities that could materially enable offensive cyber operations against important software or critical infrastructure, autonomous development of more capable AI systems, and capabilities that could accelerate the development or use of chemical, biological, radiological, nuclear, or explosive weapons.</p>



<p>The legislation also directs the Commerce Department to develop the capability thresholds in consultation with AI developers, academic researchers, cybersecurity experts, national security officials, and other stakeholders before issuing implementation guidance.</p>



<p>Sanchit Vir Gogia, chief analyst at Greyhound Research, said the proposal would make reporting serious AI incidents a legal obligation rather than a voluntary practice for developers of frontier AI models.</p>



<p>“The serious frontier developers already run the evaluations, the red-teaming and the escalation drills,” Gogia said. “What they have never faced at the federal level is a legal obligation to tell the government, on the clock, when a model behaves dangerously.”</p>



<h2 class="wp-block-heading">Reporting timelines and enforcement</h2>



<p>The bill requires covered developers to submit an initial report within seven days of discovering a reportable incident and supplemental reports as additional information becomes available.</p>



<p>The legislation also authorizes the Commerce Department to investigate compliance, issue subpoenas, require corrective action, and impose civil penalties of up to $2 million for violations. Each day of a continuing violation would constitute a separate violation, the bill states.</p>



<p>Gogia said implementation could hinge on how regulators define reporting triggers.</p>



<p>“Capability thresholds are the visible difficulty, and not the deepest one. Thresholds decide which models enter the regime. Discovery decides whether the regime ever sees the fire,” he said.</p>



<p>Drawing a comparison with cybersecurity regulations, he said reporting requirements should clearly define when an incident becomes reportable.</p>



<p>“Cyber reporting has already taught the lesson. A vague trigger produces either silence or noise: firms stay quiet until they are certain, or they file everything and bury the signal,” Gogia said.</p>



<h2 class="wp-block-heading">Filling a gap, a recent dispute exposed</h2>



<p>The bill follows a US government action that exposed the absence of any such process. On June 12, the Commerce Department took action against the latest models from Anthropic, a US AI developer, on national security grounds, prompting the company to <a href="https://www.computerworld.com/article/4186538/anthropic-fable-dispute-suggests-export-no-longer-means-what-it-used-to-2.html">disable global access to those models</a>.</p>



<p>“Export control was the sledgehammer. This proposal is the search for a scalpel,” Gogia noted. The measure is a narrower alternative to the <a href="https://obernolte.house.gov/sites/evo-subsites/obernolte.house.gov/files/evo-media-document/the-great-american-ai-act-discussion-draft-website-compressed-compressed.pdf" target="_blank" rel="nofollow">Great American Artificial Intelligence Act</a>, a broader discussion draft released earlier in June that also routes critical safety incidents to Commerce.</p>



<p>The Commerce Department’s Center for AI Standards and Innovation has separately signed agreements to <a href="https://www.csoonline.com/article/4168135/us-government-agency-to-safety-test-frontier-ai-models-before-release-2.html">evaluate leading models before deployment</a>.</p>



<h2 class="wp-block-heading">Compliance burden falls on enterprises</h2>



<p>Gogia said the legal duty falls on the developer, but the operational cost reaches the customers. “Regulation may name the lab, but the bill for poor visibility is settled downstream,” he said.</p>



<p>He said the hardest question is not which models qualify but when a reporting clock starts. “Thresholds decide which models enter the regime. Discovery decides whether the regime ever sees the fire,” he said, adding that a model can pass laboratory tests yet behave differently once connected to live tools and enterprise data.</p>



<p>The bill exempts submitted reports from public disclosure requirements and states that submitting a report would not waive trade secret protections or attorney-client privilege.</p>



<p>“The instinct behind this bill is sound, but the balance cannot be scored from a press release,” Gogia said. “The wording will decide everything.”</p>



<p><em>The article originally appeared on <a href="https://www.csoonline.com/article/4189908/proposed-us-law-would-make-ai-risk-reporting-a-legal-obligation.html">CSO</a>.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[26H2: So winzig wird das nächste ‘große’ Windows-11-Update]]></title>
<description><![CDATA[Microsoft hat bereits vor einigen Tagen alle Spekulationen beendet und klargestellt, dass im Herbst 2026 das nächste große Update für Windows 11 kommt. Dabei handelt es sich um Windows 11 26H2 (Auf diese Neuerungen dürfen Sie sich freuen). Was dabei besonders erstaunlich ist: Das Upgrade ist nur ...]]></description>
<link>https://tsecurity.de/de/3626809/it-nachrichten/26h2-so-winzig-wird-das-naechste-grosse-windows-11-update/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3626809/it-nachrichten/26h2-so-winzig-wird-das-naechste-grosse-windows-11-update/</guid>
<pubDate>Fri, 26 Jun 2026 10:48:14 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Microsoft hat bereits vor einigen Tagen alle Spekulationen beendet und klargestellt, dass im Herbst 2026 das nächste große Update für Windows 11 kommt. Dabei handelt es sich um Windows 11 26H2 (<a href="https://www.pcwelt.de/article/3057061/windows-11-26h2-auf-diese-neuerungen-durfen-sie-sich-freuen.html" target="_blank" rel="noreferrer noopener">Auf diese Neuerungen dürfen Sie sich freuen)</a>. Was dabei besonders erstaunlich ist: Das Upgrade ist nur 174 KB klein!</p>



<p>Microsoft wird Windows 11 26H2 nämlich über ein Aktivierungspaket (Enablement Package) bereitstellen. Das bedeutet, dass der Code für diese Windows-Version bereits auf den Windows-Rechnern heruntergeladen wurde und Microsoft dann die einzelnen Funktionen serverseitig aktivieren wird, sobald Microsoft die Rechner für bereit hält. </p>



<p>Mit anderen Worten: Windows 11 26H2 kommt nicht als riesiger Download, sondern als geradezu winziges Paket, das die bereits in Windows 11 24H2 oder 25H2 vorhandenen, aber noch nicht aktivierten Funktionen nur noch freischaltet. Windowslatest <a href="https://www.windowslatest.com/2026/06/26/windows-11-26h2-is-just-174kb-which-is-0-003-of-24h2s-size/">zufolge</a> ist der Download für 26H2 sage und schreibe<strong> nur 174 KB groß.</strong> Sofern Sie vorher 25H2 installiert haben. <a href="https://www.pcwelt.de/article/3172810/windows-zwingt-jetzt-jeden-rechner-zum-upgrade-auf-25h2.html" target="_blank" rel="noreferrer noopener">Dessen Installation erzwingt Microsoft derzeit.</a></p>



<p>Anders sah die Sache beim Upgrade von 23H2 auf 24H2 aus. Damals ersetzte das Upgrade die vorhandene Windows-11-Installation komplett. Dementsprechend groß war die Download-Datei, nämlich 5,3 GB. Dazu kommen dann noch einmal 887 MB für das kumulative Update, das Windows 11 auf das 25H2-Niveau bringt. Wer also von Windows 11 23H2 auf 26H2 aktualisiert, muss fast 6,5 GB herunterladen, wie Windowslatest ausrechnet.</p>



<p>Microsoft <a href="https://techcommunity.microsoft.com/blog/windows-itpro-blog/get-ready-for-windows-11-version-26h2/4529367">schreibt</a>:</p>



<blockquote class="wp-block-quote is-layout-flow wp-block-quote-is-layout-flow">
<p>Das nächste jährliche Update für Windows 11 steht kurz bevor und ist für Windows Insider bereits verfügbar! Mit Windows 11, Version 26H2, setzen wir unseren Fokus darauf fort, Unternehmen und IT-Fachleuten ein vorhersehbares Update-Erlebnis mit minimalen Unterbrechungen zu bieten.</p>



<p>Für Geräte, auf denen bereits aktuelle Versionen von Windows 11 laufen, sollte die Umstellung auf diese Version problemlos möglich sein. Sie baut auf derselben Plattform und demselben Wartungskonzept auf, die bereits in früheren Versionen eingeführt wurden, und verbessert gleichzeitig weiterhin die Art und Weise, wie Updates bereitgestellt, getestet und implementiert werden.</p>
</blockquote>



<p>Microsoft verspricht zudem folgende Vorteile für Rechner, auf denen derzeit Windows 11 24H2 oder 25H2 läuft:</p>



<ul class="wp-block-list">
<li>eine kleine, schnelle Installation</li>



<li>minimale Beeinträchtigungen für die Benutzer</li>



<li>keine vollständige Neuinstallation oder komplexe Bereitstellungsmaßnahmen erforderlich</li>



<li>dieselbe Quellcodebasis</li>



<li>dieselben Sicherheits- und Qualitätsupdates</li>



<li>dieselbe Kompatibilitätsprüfung</li>
</ul>



<p><em>Übrigens: Sollten Sie Windows 11 Home im Einsatz haben, dann entgehen Ihnen die vielen Vorteile der Pro-Version, die wir Ihnen <a href="https://www.pcwelt.de/article/1203134/windows-11-unterschiede-zwischen-home-und-pro-version.html" target="_blank" rel="noreferrer noopener">hier vorstellen.</a> Im PC-WELT Software-Shop ist das Windows-11-Upgrade <a href="https://software.pcwelt.de/offer/windows_11_professional_upgrade/44487?x-source=rss" target="_blank" rel="noreferrer noopener">für günstige 59,99 Euro statt 145 Euro</a> erhältlich.</em></p>



<p>Microsoft hebt besonders hervor, dass Windows 11 26H2 zukünftige Updates und die Wartung von Windows vereinfachen soll.</p>



<h2 class="wp-block-heading">Wann erscheint 26H2?</h2>



<p>Ein konkretes Datum für das Erscheinen von Windows 11 26H2 nennt Microsoft nicht, sondern spricht nur von der <strong>zweiten Jahreshälfte 2026.</strong></p>



<p>Vor allem Unternehmen sollen davon profitieren und ihre Windows-11-Rechner so leichter und mit weniger Aufwand aktualisieren können. Für Unternehmenskunden gibt Microsoft <a href="https://techcommunity.microsoft.com/blog/windows-itpro-blog/get-ready-for-windows-11-version-26h2/4529367">hier</a> Ratschläge, wie sich diese auf Windows 11 26H2 vorbereiten können. Die entsprechende <a href="https://www.pcwelt.de/article/3048851/microsoft-liefert-windows-26h2-erstmals-aus-nur-diese-nutzer-bekommen-es-jetzt.html" target="_blank" rel="noreferrer noopener">Windows-Insider-Version</a> des kommenden Windows 11 26H2 stellt Microsoft <a href="https://blogs.windows.com/windows-insider/2026/06/19/announcing-new-builds-for-19-june-2026-26h2-for-experimental/">hier</a> vor.</p>



<p>Windows 11 26H2 Home, Pro, Pro EDU und Pro for Workstations bekommen bis Oktober 2028 Updates, wie Windowslatest <a href="https://www.windowslatest.com/2026/06/20/microsoft-confirms-windows-11-26h2-for-fall-2026-release-reveals-supported-pcs-and-other-details/">berichtet</a>. Windows 11 Enterprise, Education und IoT Enterprise bekommen bis Oktober 2029 Updates.</p>



<p>Die <a href="https://www.pcwelt.de/article/1196400/windows-11-hardware-voraussetzungen-und-pruef-tool.html" target="_blank" rel="noreferrer noopener">Hardware-Voraussetzungen</a> für Windows 11 26H2 bleiben unverändert bei mindestens 4 GB RAM, 64 GB Speicher und 1-GHz-64-Bit-Dual-Core-Prozessor.</p>

</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Microsoft and Xbox announce another console price hike, and this one is steep — things may get even worse in 2027, all thanks to AI and memory shortages]]></title>
<description><![CDATA[The cost of Xbox Series X|S consoles is about to climb by $100 or more, with Microsoft announcing new price hikes amid tech's ongoing hardware crisis.]]></description>
<link>https://tsecurity.de/de/3625491/windows-tipps/microsoft-and-xbox-announce-another-console-price-hike-and-this-one-is-steep-things-may-get-even-worse-in-2027-all-thanks-to-ai-and-memory-shortages/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3625491/windows-tipps/microsoft-and-xbox-announce-another-console-price-hike-and-this-one-is-steep-things-may-get-even-worse-in-2027-all-thanks-to-ai-and-memory-shortages/</guid>
<pubDate>Thu, 25 Jun 2026 19:41:43 +0200</pubDate>
<category>🪟 Windows Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The cost of Xbox Series X|S consoles is about to climb by $100 or more, with Microsoft announcing new price hikes amid tech's ongoing hardware crisis.]]></content:encoded>
</item>
<item>
<title><![CDATA[Google.org is funding two long-term partners on education and AI.]]></title>
<description><![CDATA[We are announcing new funding at the 2026 ISTE conference to support two long-term partners.]]></description>
<link>https://tsecurity.de/de/3625163/it-nachrichten/googleorg-is-funding-two-long-term-partners-on-education-and-ai/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3625163/it-nachrichten/googleorg-is-funding-two-long-term-partners-on-education-and-ai/</guid>
<pubDate>Thu, 25 Jun 2026 18:03:48 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[We are announcing new funding at the 2026 ISTE conference to support two long-term partners.]]></content:encoded>
</item>
<item>
<title><![CDATA[Supporting students with connected AI tools for more personalized learning]]></title>
<description><![CDATA[Announcing connected AI tools for students, including study notebooks and no-cost practice ACT and GRE tests.]]></description>
<link>https://tsecurity.de/de/3625150/it-nachrichten/supporting-students-with-connected-ai-tools-for-more-personalized-learning/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3625150/it-nachrichten/supporting-students-with-connected-ai-tools-for-more-personalized-learning/</guid>
<pubDate>Thu, 25 Jun 2026 18:03:31 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<img src="https://storage.googleapis.com/gweb-uniblog-publish-prod/images/ISTE_2026_Student_Blog_Header.max-600x600.format-webp.webp">Announcing connected AI tools for students, including study notebooks and no-cost practice ACT and GRE tests.]]></content:encoded>
</item>
<item>
<title><![CDATA[Bungie hit with ‘significant’ layoffs after ending Destiny 2]]></title>
<description><![CDATA[Now that Bungie has moved on from Destiny 2, the game studio is being hit with its latest round of layoffs. In a statement posted on X, the studio said that "we are announcing a reduction in force as we reorganize Bungie." No specific numbers were revealed. But in a separate statement, Hermen Hul...]]></description>
<link>https://tsecurity.de/de/3625016/it-nachrichten/bungie-hit-with-significant-layoffs-after-ending-destiny-2/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3625016/it-nachrichten/bungie-hit-with-significant-layoffs-after-ending-destiny-2/</guid>
<pubDate>Thu, 25 Jun 2026 17:05:44 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Now that Bungie has moved on from Destiny 2, the game studio is being hit with its latest round of layoffs. In a statement posted on X, the studio said that "we are announcing a reduction in force as we reorganize Bungie." No specific numbers were revealed. But in a separate statement, Hermen Hulst, CEO […]]]></content:encoded>
</item>
<item>
<title><![CDATA[Meta Pauses Employee-Tracking Program Following Internal Data Leak]]></title>
<description><![CDATA[Meta has paused its Model Compatibility Initiative that tracked employee mouse movements, clicks, keystrokes, and screen content to train AI agents, after some of its collected data became accessible to more employees than intended. Meta says it has no evidence the information was improperly acce...]]></description>
<link>https://tsecurity.de/de/3622955/it-security-nachrichten/meta-pauses-employee-tracking-program-following-internal-data-leak/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3622955/it-security-nachrichten/meta-pauses-employee-tracking-program-following-internal-data-leak/</guid>
<pubDate>Thu, 25 Jun 2026 00:08:10 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Meta has paused its Model Compatibility Initiative that tracked employee mouse movements, clicks, keystrokes, and screen content to train AI agents, after some of its collected data became accessible to more employees than intended. Meta says it has no evidence the information was improperly accessed and will not restart the program until it is confident in its safeguards. Wired reports: Meta rolled out the Model Compatibility Initiative (MCI) tool in April to US employees. The tool "collects computer inputs such as mouse movements, click locations and keystrokes, as well as screen content," according to workers who have been petitioning against it over privacy, security, and personal liberty concerns. When MCI launched, employees couldn't opt out, but that changed to a limited degree after workers protested. Meta executives have repeatedly defended the data-gathering project, saying it was necessary to train AI systems to operate computer software the way humans do and that employees were the best examples for the artificial intelligence to learn from.
 
On Monday, a Meta engineer issued an internal security notice stating that databases filled with information gathered by MCI had been exposed to anyone inside the company. A former employee actively involved in pushing back against MCI describes the lapse as "a mess" -- and one that employees had expected would occur. "When workers raised concerns, leadership doubled down and failed to acknowledge the risks workers raised about the safety and privacy of worker and customer data," the person says. "Leadership has clearly created an authoritarian environment where workers are no longer respected or heard."
 
But after critical comments poured into internal forums on Monday expressing frustration about the security issue, Meta shocked some of its staff by pausing MCI altogether, telling WIRED about the development several hours before announcing it to employees. A few workers told WIRED they were confused in the meantime because the tool was continuing to run on their laptops. Late on Monday, Stephane Kasriel, a Meta vice president overseeing AI research, announced the pause and told staff that the security issue had been discovered on June 18 and addressed within four hours. But the initial fix didn't stick and access to the data had to be further locked down. The issue made "some MCI-derived data" accessible to more people than intended, he wrote, without elaborating.<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=Meta+Pauses+Employee-Tracking+Program+Following+Internal+Data+Leak%3A+https%3A%2F%2Fyro.slashdot.org%2Fstory%2F26%2F06%2F24%2F216239%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fyro.slashdot.org%2Fstory%2F26%2F06%2F24%2F216239%2Fmeta-pauses-employee-tracking-program-following-internal-data-leak%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://yro.slashdot.org/story/26/06/24/216239/meta-pauses-employee-tracking-program-following-internal-data-leak?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Mistral launches OCR 4, turning document extraction into a full enterprise AI play]]></title>
<description><![CDATA[Mistral AI on Tuesday released OCR 4, a document intelligence model that moves beyond raw text extraction to return structured representations of entire documents — complete with bounding boxes, block-type classification, and per-word confidence scores. The release marks Mistral's fourth generati...]]></description>
<link>https://tsecurity.de/de/3622912/it-nachrichten/mistral-launches-ocr-4-turning-document-extraction-into-a-full-enterprise-ai-play/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3622912/it-nachrichten/mistral-launches-ocr-4-turning-document-extraction-into-a-full-enterprise-ai-play/</guid>
<pubDate>Wed, 24 Jun 2026 23:48:27 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><a href="https://mistral.ai/">Mistral AI</a> on Tuesday released <a href="https://mistral.ai/news/ocr-4/">OCR 4</a>, a document intelligence model that moves beyond raw text extraction to return structured representations of entire documents — complete with bounding boxes, block-type classification, and per-word confidence scores. The release marks Mistral's fourth generation of optical character recognition technology in roughly 15 months and lands at a moment when the company's pitch for European AI sovereignty has never been more commercially relevant.</p><p>The model supports 170 languages across 10 language groups, accepts PDF, DOC, PPT, and OpenDocument formats, and can be deployed as a single container on an organization's own infrastructure — a capability Mistral is positioning directly at enterprises in regulated industries that cannot route sensitive documents through U.S.-jurisdiction cloud APIs.</p><p>"Mistral OCR 4 extracts and structures content from a wide range of documents," the company said in its announcement. "Where previous generations focused on converting a page into clean text and tables, OCR 4 returns a structured representation of the document."</p><p>The model is <a href="https://docs.mistral.ai/resources/cookbooks?useCase=OCR">available immediately</a> through the <a href="https://mistral.ai/pricing/">Mistral API</a>, Document AI in <a href="https://mistral.ai/products/studio/">Mistral Studio</a>, <a href="https://aws.amazon.com/sagemaker/ai/">Amazon SageMaker</a>, and <a href="https://azure.microsoft.com/en-us/products/ai-foundry">Microsoft Foundry</a>, with <a href="https://www.snowflake.com/en/blog/engineering/enterprise-scale-document-ai/">Snowflake Parse Document</a> support coming soon. Pricing starts at $4 per 1,000 pages, dropping to $2 per 1,000 pages through a batch API discount.</p><div></div><h2><b>OCR 4 treats every document as a semantic map, not a wall of text</b></h2><p>The central engineering shift in <a href="https://mistral.ai/news/ocr-4/">OCR 4</a> is structural. Rather than outputting a flat stream of extracted text — the paradigm that has defined OCR for decades — the model returns a layered representation in which every block is localized with a bounding box, classified by type (title, table, equation, signature, and others), and scored for confidence at both the page and word level.</p><p>Mistral says bounding boxes were its most-requested capability. The reason is straightforward: without location data, downstream systems cannot trace an extracted fact back to its source on a specific page. That traceability gap has been a persistent friction point for enterprises building retrieval-augmented generation (RAG) pipelines, compliance workflows, or any application where "where did this number come from?" is a question that needs an auditable answer.</p><p>Block classification addresses a related problem. A paragraph tagged as a "title" can segment a document into hierarchical chunks for semantic search. A block tagged as a "table" can be routed to a structured-data pipeline rather than a text summarizer. A block tagged as a "signature" can trigger a redaction workflow in a compliance system.</p><p>These are not novel ideas in isolation, but packaging them as first-class outputs of the OCR model itself — rather than requiring a separate layout-analysis stage — removes an integration layer that enterprise teams have historically had to build and maintain themselves.</p><p>The confidence scores serve a dual purpose. At scale, they allow organizations to programmatically route low-confidence regions to human reviewers and auto-approve high-confidence extractions, building what the industry calls human-in-the-loop verification without requiring a person to review every page of every document. In production systems, OCR is rarely the end goal — it is the first step in a larger pipeline.</p><p>Developers building RAG systems, agent workflows, or document automation often spend more time reconstructing layout and structure than on the downstream AI logic itself. OCR 4 aims to eliminate that reconstruction step, and if it delivers on that promise, the value accrues not just in OCR cost savings but in reduced engineering hours across the entire document pipeline.</p><h2><b>Independent reviewers preferred Mistral's output 72 percent of the time, but benchmarks tell a complicated story</b></h2><p>Mistral reports that <a href="https://mistral.ai/news/ocr-4/">OCR 4</a> achieved a 72% average win rate in a head-to-head human evaluation against leading competitors, conducted by independent annotators across more than 600 real-world documents in over 12 languages. The model also achieved the top overall score on <a href="https://huggingface.co/datasets/allenai/olmOCR-bench">OlmOCRBench</a> at 85.20 and scored 93.07 on <a href="https://github.com/opendatalab/OmniDocBench">OmniDocBench</a>.</p><p>But the company itself urges caution in interpreting those numbers. In its release, Mistral took the unusual step of auditing and publicly disclosing the specific types of scoring artifacts it encountered, including ground-truth errors in the reference annotations, equivalent LaTeX notation scored as mismatches, column-reading-order assumptions, and header/footer attribution issues. "We therefore treat the aggregate score as directional rather than definitive," the company said — a notably transparent stance from a vendor announcing a product.</p><p>That transparency is well-timed. On the public <a href="https://huggingface.co/datasets/allenai/olmOCR-bench">OlmOCRBench leaderboard</a>, some researchers have noted that OCR 4 currently ranks third, behind open models like Chandra OCR 2. And some open-weight models self-report higher OmniDocBench composite scores — <a href="https://huggingface.co/PaddlePaddle/PaddleOCR-VL-1.6">PaddleOCR-VL-1.6</a> claims 96.33 — though those results have not been independently reproduced on the public leaderboard.</p><p>Early enterprise feedback has been favorable nonetheless. Aidan Donohue, an AI engineer at financial AI firm Rogo, said the company benchmarked OCR 4 against leading agentic document parsers on a chart-dense financial QA dataset and "reached equivalent accuracy at roughly 8x lower cost and 17x lower latency." Ivan Mihailov, an AI engineer at intellectual property management firm Anaqua, said OCR 4 is "roughly 4x faster per page than our incumbent provider." </p><p>Enterprise buyers, however, should run their own evaluations rather than relying on any vendor's benchmark numbers. The practical question is not which model scores highest on a leaderboard, but which model produces the fewest errors on your specific documents, in your specific languages, at a price and latency that fit your workflow.</p><h2><b>The Anthropic export ban gave Mistral's sovereignty pitch the proof point it needed</b></h2><p>Mistral's release lands in a geopolitical context that could hardly be more favorable for its strategic positioning.</p><p>On June 12, <a href="https://www.anthropic.com/news/fable-mythos-access">Anthropic was forced to disable all access to its newest AI models</a>, Fable 5 and Mythos 5, after the U.S. Commerce Department used national security export controls to bar the company from distributing the models to any foreign national. Enterprise clients in finance, healthcare, SaaS, and critical infrastructure found their core intelligence services abruptly disabled, without prior warning or effective recourse. As of June 24, both models remain offline, with <a href="https://kalshi.com/markets/kxfablerestore/fable-restored/kxfablerestore-27">prediction markets giving only 57% odds of restoration</a> before July 1.</p><p>That episode validated a warning Mistral CEO Arthur Mensch has been sounding for over a year. As Business Insider reported, <a href="https://www.businessinsider.com/anthropic-model-access-mistral-opportunity-ai-sovereignty-2026-6">Mensch warned at London Tech Week</a> in June 2025 about American AI companies "having the keys" for their models, calling it a scenario where European companies are "giving leverage to their providers." He added: "At some point, you need to be able to turn it off or turn it on, and you don't want to leave it to another country."</p><p>The argument gained further urgency as Mensch's broader sovereignty pitch escalated in recent months. As reported by CNBC in late May, <a href="https://www.cnbc.com/2026/05/28/mistral-arthur-mensch-design-chips-ai-data-centers.html">Mensch told the outlet</a>: "Europe is lagging behind when it comes to [the] buildout of infrastructure, and so we are investing to close that gap." </p><p>At the same time, <a href="https://www.reuters.com/business/media-telecom/mistral-defends-ai-use-warfare-rebuts-pope-criticism-2026-05-28/">Mensch pushed back against Pope Leo XIV's call for AI to be "disarmed,"</a> arguing that Europe cannot afford to fall behind U.S. tech giants. "We're all for ​peace, but if you look at our rivals and adversaries in the world, they're using artificial ​intelligence … we do need to have our own capabilities," Mensch told reporters.</p><p>OCR 4's single-container, self-hosted deployment model is the product-level expression of that argument. A U.S.-headquartered provider offering EU data residency means documents are stored in Frankfurt but governed by U.S. law. Mistral, incorporated in France and operating under EU jurisdiction, offering on-premise containerized deployment, means documents never leave the customer's infrastructure at all. The <a href="https://artificialintelligenceact.eu/article/99/">EU AI Act's fine enforcement provisions</a> take effect August 2, adding regulatory pressure to the compliance calculus for European enterprises evaluating document AI vendors.</p><h2><b>Baidu's free, open-weight OCR model arrived one day earlier — and the contrast is revealing</b></h2><p>Mistral's release did not arrive in isolation. Just one day before <a href="https://mistral.ai/news/ocr-4/">OCR 4</a> launched, Baidu shipped <a href="https://huggingface.co/baidu/Unlimited-OCR">Unlimited-OCR</a> on June 22 — a 3-billion-parameter MIT-licensed model that tackles one of the most persistent pain points in document AI: parsing entire PDFs and multi-page scans in a single forward pass, without chunking the input or stitching the output back together afterward.</p><p>Baidu's model uses a technique called <a href="https://arxiv.org/html/2606.23050v1">Reference Sliding Window Attention (R-SWA)</a> that, as a top <a href="https://news.ycombinator.com/item?id=48643426">Hacker News commenter explained</a>, splits the AI's focus into two paths: maintaining full attention on the original document image while restricting memory of generated text to a tight, moving window. The result is constant KV cache size and the ability to transcribe 40-plus pages in a single forward pass. The model gathered <a href="https://github.com/baidu/Unlimited-OCR">1,800 GitHub stars</a> in its first 24 hours and racked up more than <a href="https://news.ycombinator.com/item?id=48643426">479 upvotes on Hacker News</a>, where the discussion thread ran to 109 comments.</p><p>The two releases frame what some analysts are calling the June 2026 document-AI split: self-hosted long-horizon parsing with open weights versus structured managed extraction with enterprise features.</p><p><a href="https://github.com/baidu/Unlimited-OCR">Baidu's model</a> is free under an MIT license, runs on standard GPU hardware, and has no managed API or enterprise SLA. <a href="https://mistral.ai/news/ocr-4/">Mistral's model</a> is a commercial product with per-page pricing, bounding boxes, confidence scores, block classification, multi-platform distribution, and self-hosted deployment options for enterprise customers. </p><p><a href="https://huggingface.co/baidu/Unlimited-OCR">Unlimited-OCR</a> may be the better tool for a research team digitizing scanned dissertations on a single GPU. <a href="https://mistral.ai/news/ocr-4/">OCR 4</a> is built for the IT procurement process — the world of SLAs, data processing agreements, and compliance audits.</p><p>Beyond Baidu, the broader OCR competitive field includes <a href="https://cloud.google.com/document-ai">Google Document AI</a>, <a href="https://aws.amazon.com/textract/">Amazon Textract</a>, <a href="https://azure.microsoft.com/en-us/products/ai-foundry/tools/document-intelligence">Azure Document Intelligence</a>, <a href="https://www.abbyy.com/vantage/">ABBYY Vantage</a>, and a growing number of open-weight models. </p><p>On the <a href="https://news.ycombinator.com/item?id=48643426">Hacker News thread</a> for Unlimited-OCR, practitioners offered a candid assessment of the state of the art. Joss82, who has worked on document parsing for 10 years, wrote bluntly: "OCR still sucks in 2026." Meanwhile, one user named SyneRyder reported success with Claude for OCR of hundreds of pages of handwritten documents, noting the model delivered results with "no corrections required" and even pointed out a continuity error in the source text. These practitioner reports underscore a key tension in the market: performance varies wildly depending on the specific document type, language, and quality of the source material.</p><h2><b>The real play is not OCR — it is an enterprise AI stack with document intelligence as the on-ramp</b></h2><p>Step back far enough, and <a href="https://mistral.ai/news/ocr-4/">Mistral's OCR 4 release</a> is not really an OCR story. It is an enterprise go-to-market story built on top of a $4.4 billion global intelligent document processing market that is forecast to grow at a 33.1% compound annual growth rate through 2030, according to <a href="https://www.grandviewresearch.com/industry-analysis/intelligent-document-processing-market-report">Grand View Research</a>.</p><p>For Mistral, OCR is a wedge into enterprise AI budgets. The model feeds directly into Mistral's <a href="https://mistral.ai/news/search-toolkit/">Search Toolkit</a>, the company's open-source composable search framework announced at the AI Now Summit. In that architecture, <a href="https://mistral.ai/news/ocr-4/">OCR 4</a> serves as the ingestion layer for retrieval-augmented generation and enterprise search pipelines, converting raw documents into citation-ready, structurally classified input. The logic is clear: once an enterprise adopts OCR 4 for document extraction, Mistral's broader model suite — including Medium 3.5 for reasoning and the Vibe agentic platform for task execution — becomes the natural next step in the stack. </p><p>That pipeline ambition is critical context for understanding Mistral's current fundraising trajectory. Bloomberg recently reported that the company is in early discussions to <a href="https://www.bloomberg.com/news/articles/2026-06-12/france-s-mistral-in-funding-talks-at-about-20-billion-valuation">raise about €3 billion ($3.5 billion)</a> at a valuation of roughly €20 billion — nearly double the €11.7 billion valuation from its September Series C round. To date, Mistral has raised only about $4 billion, a fraction of what its largest U.S. rivals have taken in. OCR 4 and its associated enterprise revenue pipeline are part of how the company plans to justify that higher valuation, with Mistral targeting <a href="https://www.lemonde.fr/en/economy/article/2026/01/22/french-ai-firm-mistral-predicts-revenue-of-1-billion-in-2026_6749706_19.htm">€1 billion in revenue</a> for 2026, up from €200 million in 2025, according to Le Monde.</p><p>Mistral is a company with roughly 1,000 employees and ambitions to compete with labs that have raised 40 times as much capital. It cannot win a general-purpose model arms race against OpenAI and Anthropic. What it can do is build a differentiated enterprise stack around sovereignty, <a href="https://mistral.ai/news/ocr-4/">structured document intelligence</a>, and agentic workflows — and use that stack to capture European enterprise budgets that are increasingly wary of U.S. provider dependency. </p><p>The pricing structure reinforces that strategy: at $2 per 1,000 pages in batch mode, the cost of processing a 100,000-page corporate archive falls to $200, making large-scale digitization projects economically viable in ways they may not have been with token-based vision-language model pricing.</p><p>Whether Mistral can execute that vision at scale — against Google, Amazon, Microsoft, and a surging open-source ecosystem — remains an open question. But the Anthropic export control crisis is still unresolved, European data sovereignty regulations are tightening, and a potential €20 billion funding round is on the horizon. The company is holding an <a href="https://learn.mistral.ai/public/events/ocr4-webinar">OCR 4 production webinar on July 7 at 6:00 PM CET</a>.</p><p>Two weeks ago, the argument for building AI infrastructure outside the reach of U.S. export controls was theoretical. Then the U.S. government flipped a switch, and Anthropic's most advanced models went dark for every non-American on the planet. Mistral did not cause that crisis — but it spent the last year building the product that makes it matter.</p><p>
</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[GTA VI is a worrying sign for the future of physical games]]></title>
<description><![CDATA[Rockstar Games has finally given Grand Theft Auto VI a price ahead of the game's November 19th launch. But while announcing that the game would cost $79.99, Rockstar also confirmed that the physical versions of GTA VI won't include a disc, and instead will only contain a download code inside the ...]]></description>
<link>https://tsecurity.de/de/3622470/it-nachrichten/gta-vi-is-a-worrying-sign-for-the-future-of-physical-games/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3622470/it-nachrichten/gta-vi-is-a-worrying-sign-for-the-future-of-physical-games/</guid>
<pubDate>Wed, 24 Jun 2026 20:48:00 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Rockstar Games has finally given Grand Theft Auto VI a price ahead of the game's November 19th launch. But while announcing that the game would cost $79.99, Rockstar also confirmed that the physical versions of GTA VI won't include a disc, and instead will only contain a download code inside the box. Not only is […]]]></content:encoded>
</item>
<item>
<title><![CDATA[US Authorities Seize Infrastructure Tied to Huione Fraud Network]]></title>
<description><![CDATA[The U.S. government has taken another step in its ongoing campaign against large-scale cyber fraud operations, announcing the seizure of online infrastructure allegedly used to support one of the world’s most active criminal marketplaces while simultaneously expanding financial restrictions again...]]></description>
<link>https://tsecurity.de/de/3621904/it-security-nachrichten/us-authorities-seize-infrastructure-tied-to-huione-fraud-network/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3621904/it-security-nachrichten/us-authorities-seize-infrastructure-tied-to-huione-fraud-network/</guid>
<pubDate>Wed, 24 Jun 2026 17:38:48 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>The U.S. government has taken another step in its ongoing campaign against large-scale cyber fraud operations, announcing the seizure of online infrastructure allegedly used to support one of the world’s most active criminal marketplaces while simultaneously expanding financial restrictions against…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/us-authorities-seize-infrastructure-tied-to-huione-fraud-network/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/us-authorities-seize-infrastructure-tied-to-huione-fraud-network/">US Authorities Seize Infrastructure Tied to Huione Fraud Network</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[The web is evolving. So are we.]]></title>
<description><![CDATA[Earlier this month, we officially stood up Mozilla.org: a new 501(c)(3) nonprofit created to steward the long term success of the Mozilla Project.  Over the last year or so, I’ve said a lot about how AI is reshaping the web — and how we need to simultaneously stand up for the open internet Mozill...]]></description>
<link>https://tsecurity.de/de/3619238/tools/the-web-is-evolving-so-are-we/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3619238/tools/the-web-is-evolving-so-are-we/</guid>
<pubDate>Tue, 23 Jun 2026 20:08:37 +0200</pubDate>
<category>💾  Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Earlier this month, we officially stood up Mozilla.org: a new 501(c)(3) nonprofit created to steward the long term success of the Mozilla Project.  Over the last year or so, I’ve said a lot about how AI is reshaping the web — and how we need to simultaneously stand up for the open internet Mozilla helped build […]</p>
<p>The post <a href="https://blog.mozilla.org/en/mozilla/news/announcing-mozilla-org-new-non-profit/">The web is evolving. So are we.</a> appeared first on <a href="https://blog.mozilla.org/en/">The Mozilla Blog</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Apple Watch Ultra models plunge to as low as $499 for Prime Day]]></title>
<description><![CDATA[Steep Prime Day discounts have driven Apple Watch Ultra models down to as low as $499 as the mega shopping event kicks off.Pick up an Apple Watch Ultra for $499 this Prime Day - Image credit: AppleDeals are plentiful on both current and closeout Apple Watch Ultra models, with the 2nd generation d...]]></description>
<link>https://tsecurity.de/de/3617471/ios-mac-os/apple-watch-ultra-models-plunge-to-as-low-as-499-for-prime-day/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3617471/ios-mac-os/apple-watch-ultra-models-plunge-to-as-low-as-499-for-prime-day/</guid>
<pubDate>Tue, 23 Jun 2026 09:23:45 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Steep <a href="https://appleinsider.com/deals/amazon-prime-day">Prime Day discounts</a> have driven Apple Watch Ultra models down to as low as $499 as the mega shopping event kicks off.<br><br><div><img src="https://photos5.appleinsider.com/gallery/68027-143405-prime-day-apple-watch-ultra-deals-499-xl.jpg" alt="Apple Watch Ultra with colorful display on a blue background, alongside promotional text announcing Prime Day Apple Watch Ultra deals starting from $499 with lowest prices ever for Prime Day" height="720"><br><span>Pick up an Apple Watch Ultra for $499 this Prime Day - Image credit: Apple</span></div><br>Deals are plentiful on both current and closeout Apple Watch Ultra models, with the 2nd generation <a href="https://www.amazon.com/dp/B0CSTGJVKF/?th=1&amp;tag=apinsiderdeals-20" rel="nofollow" target="_blank">dipping to $499</a> and the 3rd generation <a href="https://www.amazon.com/dp/B0FQFHVZYL/?th=1&amp;tag=apinsiderdeals-20" rel="nofollow" target="_blank">on sale from $649</a>.<br><br><br> <a href="https://appleinsider.com/articles/26/06/23/apple-watch-ultra-models-plunge-to-as-low-as-499-for-prime-day?utm_source=rss">Continue Reading on AppleInsider</a> | <a href="https://forums.appleinsider.com/discussion/244736?urm_source=rss">Discuss on our Forums</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Google DeepMind and A24 announce first-of-its-kind research partnership]]></title>
<description><![CDATA[Today, Google DeepMind and A24 are announcing a first-of-its-kind partnership focused on research. The collaboration pairs a world-leading research lab with the industry…]]></description>
<link>https://tsecurity.de/de/3615811/it-nachrichten/google-deepmind-and-a24-announce-first-of-its-kind-research-partnership/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3615811/it-nachrichten/google-deepmind-and-a24-announce-first-of-its-kind-research-partnership/</guid>
<pubDate>Mon, 22 Jun 2026 16:49:12 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<img src="https://storage.googleapis.com/gweb-uniblog-publish-prod/images/3_SocialShare_gradient.max-600x600.format-webp.webp">Today, Google DeepMind and A24 are announcing a first-of-its-kind partnership focused on research. The collaboration pairs a world-leading research lab with the industry…]]></content:encoded>
</item>
<item>
<title><![CDATA[26H2: So kommt das nächste große Windows-11-Update auf Ihren PC]]></title>
<description><![CDATA[Microsoft beendet alle Spekulationen und hat jetzt klargestellt, dass im Herbst 2026 das nächste große Update für Windows 11 kommt. Dabei handelt es sich um Windows 11 26H2. Microsoft hebt besonders hervor, dass Windows 11 26H2 zukünftige Updates und die Wartung von Windows vereinfachen soll.



...]]></description>
<link>https://tsecurity.de/de/3614752/it-nachrichten/26h2-so-kommt-das-naechste-grosse-windows-11-update-auf-ihren-pc/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3614752/it-nachrichten/26h2-so-kommt-das-naechste-grosse-windows-11-update-auf-ihren-pc/</guid>
<pubDate>Mon, 22 Jun 2026 09:17:55 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Microsoft beendet alle Spekulationen und hat jetzt klargestellt, dass im Herbst 2026 das nächste große Update für Windows 11 kommt. Dabei handelt es sich um Windows 11 26H2. Microsoft hebt besonders hervor, dass Windows 11 26H2 zukünftige Updates und die Wartung von Windows vereinfachen soll.</p>



<p>Microsoft wird Windows 11 26H2 über ein Aktivierungspaket (Enablement Package) bereitstellen. Das bedeutet, dass der Code für diese Windows-Version bereits auf die Windows-Rechner heruntergeladen wurde und Microsoft dann die einzelnen Funktionen serverseitig aktivieren wird, sobald Microsoft die Rechner für bereit hält. Mit anderen Worten: Windows 11 26H2 kommt nicht als riesiger Download, sondern als vergleichsweise kleines Paket, das die bereits in Windows 11 24H2 oder 25H2 vorhandenen, aber noch nicht aktivierten Funktionen nur noch freischaltet. Microsoft <a href="https://techcommunity.microsoft.com/blog/windows-itpro-blog/get-ready-for-windows-11-version-26h2/4529367">schreibt</a>:</p>



<blockquote class="wp-block-quote is-layout-flow wp-block-quote-is-layout-flow">
<p>Das nächste jährliche Update für Windows 11 steht kurz bevor und ist für Windows Insider bereits verfügbar! Mit Windows 11, Version 26H2, setzen wir unseren Fokus darauf fort, Unternehmen und IT-Fachleuten ein vorhersehbares Update-Erlebnis mit minimalen Unterbrechungen zu bieten.</p>



<p>Für Geräte, auf denen bereits aktuelle Versionen von Windows 11 laufen, sollte die Umstellung auf diese Version problemlos möglich sein. Sie baut auf derselben Plattform und demselben Wartungskonzept auf, die bereits in früheren Versionen eingeführt wurden, und verbessert gleichzeitig weiterhin die Art und Weise, wie Updates bereitgestellt, getestet und implementiert werden.</p>
</blockquote>



<p>Microsoft verspricht zudem folgende Vorteile für Rechner, auf denen derzeit Windows 11 24H2 oder 25H2 läuft:</p>



<ul class="wp-block-list">
<li>Eine kleine, schnelle Installation</li>



<li>Minimale Beeinträchtigungen für die Benutzer</li>



<li>Keine vollständige Neuinstallation oder komplexe Bereitstellungsmaßnahmen erforderlich</li>



<li>Dieselbe Quellcodebasis</li>



<li>Dieselben Sicherheits- und Qualitätsupdates</li>



<li>Dieselbe Kompatibilitätsprüfung</li>
</ul>



<p><em>Übrigens: Sollten Sie Windows 11 Home im Einsatz haben, dann entgehen Ihnen die vielen Vorteile der Pro-Version, die wir Ihnen <a href="https://www.pcwelt.de/article/1203134/windows-11-unterschiede-zwischen-home-und-pro-version.html" target="_blank" rel="noreferrer noopener">hier vorstellen.</a> Im PC-WELT Software-Shop ist das Windows-11-Upgrade <a href="https://software.pcwelt.de/offer/windows_11_professional_upgrade/44487?x-source=rss" target="_blank" rel="noreferrer noopener">für günstige 59,99 Euro statt 145 Euro</a> erhältlich.</em></p>



<p>Ein konkretes Datum für das Erscheinen von Windows 11 26H2 nennt Microsoft nicht, sondern spricht nur von der zweiten Jahreshälfte 2026.</p>



<p>Vor allem Unternehmen sollen davon profitieren und ihre Windows-11-Rechner so leichter und mit weniger Aufwand aktualisieren können. Für Unternehmenskunden gibt Microsoft <a href="https://techcommunity.microsoft.com/blog/windows-itpro-blog/get-ready-for-windows-11-version-26h2/4529367">hier</a> Ratschläge, wie sich diese auf Windows 11 26H2 vorbereiten können. Die entsprechende Windows-Insider-Version des kommenden Windows 11 26H2 stellt Microsoft <a href="https://blogs.windows.com/windows-insider/2026/06/19/announcing-new-builds-for-19-june-2026-26h2-for-experimental/">hier</a> vor.</p>



<p>Windows 11 26H2 Home, Pro, Pro EDU und Pro for Workstations bekommen bis Oktober 2028 Updates, wie Windowslatest <a href="https://www.windowslatest.com/2026/06/20/microsoft-confirms-windows-11-26h2-for-fall-2026-release-reveals-supported-pcs-and-other-details/">berichtet</a>. Windows 11 Enterprise, Education und IoT Enterprise bekommen bis Oktober 2029 Updates.</p>



<p>Die Hardware-Voraussetzungen für Windows 11 26H2 bleiben unverändert bei mindestens 4 GB RAM, 64 GB Speicher und 1-GHz-64-Bit-Dual-Core-Prozessor.</p>

</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Microsoft buried its best Surface hardware in years through a quiet series of press releases]]></title>
<description><![CDATA[By quietly announcing six Surface devices through a trickle of press releases, Microsoft starved its innovative new PCs of any buzz.]]></description>
<link>https://tsecurity.de/de/3613627/windows-tipps/microsoft-buried-its-best-surface-hardware-in-years-through-a-quiet-series-of-press-releases/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3613627/windows-tipps/microsoft-buried-its-best-surface-hardware-in-years-through-a-quiet-series-of-press-releases/</guid>
<pubDate>Sun, 21 Jun 2026 15:09:57 +0200</pubDate>
<category>🪟 Windows Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[By quietly announcing six Surface devices through a trickle of press releases, Microsoft starved its innovative new PCs of any buzz.]]></content:encoded>
</item>
<item>
<title><![CDATA[Amazon Drops Sam Altman Movie After Announcing OpenAI Partnership]]></title>
<description><![CDATA[Amazon MGM has dropped Luca Guadagnino's nearly completed Sam Altman biopic Artificial and is seeking another distributor for the film. The move comes months after Amazon expanded its multibillion-dollar partnership with OpenAI, fueling speculation about a potential conflict given the movie's rep...]]></description>
<link>https://tsecurity.de/de/3611431/it-security-nachrichten/amazon-drops-sam-altman-movie-after-announcing-openai-partnership/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3611431/it-security-nachrichten/amazon-drops-sam-altman-movie-after-announcing-openai-partnership/</guid>
<pubDate>Sat, 20 Jun 2026 01:08:29 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Amazon MGM has dropped Luca Guadagnino's nearly completed Sam Altman biopic Artificial and is seeking another distributor for the film. The move comes months after Amazon expanded its multibillion-dollar partnership with OpenAI, fueling speculation about a potential conflict given the movie's reportedly unflattering portrayal of Altman. The Independent reports: Artificial would have marked the Oscar-nominated Call Me By Your Name director's third Amazon film, following the critically acclaimed Zendaya-led tennis romance Challengers (2024) and the academic scandal drama After the Hunt (2025), starring Julia Roberts. The new movie is said to chronicle the brief period when Altman was abruptly ousted as OpenAI's CEO in 2023 and subsequently rehired. Monica Barbaro and Ike Barinholtz star alongside Garfield as former OpenAI CTO Mira Murati and SpaceX founder Elon Musk, while Yura Borisov, Cooper Hoffman, Jason Schwartzman, Cooper Koch, Billie Lourd, Zosia Mamet, Angus Imrie, Chris O'Dowd, Mark Rylance and Margo's Got Money Troubles breakout Thaddea Graham round out the cast.
 
It is unclear exactly why the film was dropped, but according to Variety, the news came after it had already undergone positive screen tests. An early viewer told the publication that the film's portrayals of Altman and newly minted trillionaire Musk are the two characters audiences would "like the least." It was also reported that Amazon had already seen every early iteration of the script before Guadagnino was hired to direct. Altman and Amazon founder Jeff Bezos have developed a high-profile friendship over the years. In fact, the former was in attendance at Bezos's wedding to Lauren Sanchez, which took place in Venice, Italy, in 2025. In recent months, the two have continued to deepen their professional partnership that began in 2015, when Amazon became one of OpenAI's first investors. Ten years later, the companies closed their first major deal in November 2025, allowing the ChatGPT maker to run its systems on Amazon's U.S. data centers.<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=Amazon+Drops+Sam+Altman+Movie+After+Announcing+OpenAI+Partnership%3A+https%3A%2F%2Fentertainment.slashdot.org%2Fstory%2F26%2F06%2F19%2F2146253%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fentertainment.slashdot.org%2Fstory%2F26%2F06%2F19%2F2146253%2Famazon-drops-sam-altman-movie-after-announcing-openai-partnership%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://entertainment.slashdot.org/story/26/06/19/2146253/amazon-drops-sam-altman-movie-after-announcing-openai-partnership?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Announcing new builds for 19 June 2026, version 26H2 for Experimental]]></title>
<description><![CDATA[Hello Windows Insiders,
We have new releases today with builds across Beta and Experimental, including Windows 11, version 26H2 for Experimental.
Windows 11, version 26H2
Windows 11, version 26H2 represents our yearly second half 
The post Announcing new builds for 19 June 2026, version 26H2 for ...]]></description>
<link>https://tsecurity.de/de/3610989/windows-tipps/announcing-new-builds-for-19-june-2026-version-26h2-for-experimental/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3610989/windows-tipps/announcing-new-builds-for-19-june-2026-version-26h2-for-experimental/</guid>
<pubDate>Fri, 19 Jun 2026 19:09:29 +0200</pubDate>
<category>🪟 Windows Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Hello Windows Insiders,</p>
<p>We have new releases today with builds across Beta and Experimental, including Windows 11, version 26H2 for Experimental.</p>
<p><strong>Windows 11, version 26H2</strong></p>
<p>Windows 11, version 26H2 represents our yearly second half </p>
<p>The post <a href="https://blogs.windows.com/windows-insider/2026/06/19/announcing-new-builds-for-19-june-2026-26h2-for-experimental/">Announcing new builds for 19 June 2026, version 26H2 for Experimental</a> appeared first on <a href="https://blogs.windows.com/windows-insider">Windows Insider Blog</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[AWS enters the context layer race with a graph that learns from agents, not manual curation]]></title>
<description><![CDATA[Building a context layer between enterprise data stores and AI agents is bespoke work, with no standard service to automate or maintain the graphs over time. Amazon is making a direct play to change that.Amazon on Wednesday entered the space, announcing a series of three products it's positioning...]]></description>
<link>https://tsecurity.de/de/3606395/it-nachrichten/aws-enters-the-context-layer-race-with-a-graph-that-learns-from-agents-not-manual-curation/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3606395/it-nachrichten/aws-enters-the-context-layer-race-with-a-graph-that-learns-from-agents-not-manual-curation/</guid>
<pubDate>Thu, 18 Jun 2026 02:17:28 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Building a context layer between enterprise data stores and AI agents is bespoke work, with no standard service to automate or maintain the graphs over time. Amazon is making a direct play to change that.</p><p>Amazon on Wednesday entered the space, announcing a series of three products it's positioning as a context intelligence stack for AI agents. The centerpiece is AWS Context, a new knowledge graph service that gets smarter through agent usage over time. AWS also announced the general availability of Amazon S3 Annotations and a preview of skill assets in AWS Glue Data Catalog.</p><p>The context layer is now a contested architectural category with no shortage of options from different vendors. AWS is entering that market with a different architectural premise: that the graph should learn from how agents use it automatically, without human re-curation.</p><p>"Your agents now get smarter without you having to rebuild anything from scratch," said Swami Sivasubramanian, vice president of Agentic AI at AWS, during his AWS Summit NYC keynote. </p><p>"This service automatically builds a knowledge graph from all your existing data," he said. "This service infers relationships across your data sets, business rules, and domain knowledge, and makes all of it available to your agents and your organization at runtime."  </p><h2>AWS Context builds a self-learning knowledge graph from existing data</h2><p>It's a problem AWS says it has seen repeatedly in customer deployments. </p><p>AWS Context maps relationships across existing data automatically: what tables exist, what columns mean, how sources relate and which sources are authoritative. It combines semantic search with graph-level reasoning and infers relationships across datasets, business rules and domain knowledge, making all of it available to agents at runtime.</p><p>"The knowledge graph improves itself over time as it learns which sources produce correct results and which parts get used," Sivasubramanian said. </p><p>Data stewards manage the graph through the AWS Management Console, reviewing inferred relationships, promoting them to production and attaching business definitions and usage rules. Every query inherits the calling user's IAM and Lake Formation permissions, making agent data access auditable by identity through controls enterprises already rely on.</p><p>All metadata is published in Apache Iceberg format to Amazon S3 Tables, queryable via Athena, Redshift, Spark or any Iceberg-compatible engine, with no proprietary APIs. Third-party catalog connections are supported, so context from systems outside AWS can be pulled into the same graph. Agents query through agentic search APIs and MCP tools across Bedrock AgentCore, EKS or any MCP-compatible framework.</p><h2>Context is more than just a single service</h2><p>Context is a complicated space and AWS is layering multiple services to help enterprises build context across the data stack.</p><p><b>Amazon S3 Annotations.</b> This service enables users to attach rich business context at the storage layer, directly to individual S3 objects. </p><p><b>AWS Glue Data Catalog skill assets</b>. Glue skill assets attach domain knowledge at the catalog layer, linking runbooks, query patterns and usage rules to data assets across the estate. </p><p>AWS Context then synthesizes both into the knowledge graph that agents query at runtime, combining semantic search with graph-level reasoning across structured and unstructured sources. Each layer feeds the next.</p><h2>AWS is entering a highly competitive context space</h2><p><a href="https://venturebeat.com/data/ai-agents-keep-giving-confident-wrong-answers-the-context-layer-is-enterprise-ais-next-production-problem">Snowflake announced</a> its context approach earlier this month with its Horizon Context and Cortex Sense services. Microsoft is providing context via its<a href="https://venturebeat.com/data/enterprise-ai-agents-keep-operating-from-different-versions-of-reality?_gl=1*b66y4g*_up*MQ..*_ga*MTM4OTgwNTA2LjE3ODE3MzAyNTk.*_ga_SCH1J7LNKY*czE3ODE3MzAyNTgkbzEkZzAkdDE3ODE3MzAyNTgkajYwJGwwJGgw*_ga_B8TDS1LEXQ*czE3ODE3MzAyNTgkbzEkZzEkdDE3ODE3MzAyNTgkajYwJGwwJGgw"> Fabric IQ platform</a> that provides a semantic ontology for data. Redis has developed a<a href="https://venturebeat.com/data/context-architecture-is-replacing-rag-as-agentic-ai-pushes-enterprise-retrieval-to-its-limits?_gl=1*i19buu*_up*MQ..*_ga*MTM4OTgwNTA2LjE3ODE3MzAyNTk.*_ga_SCH1J7LNKY*czE3ODE3MzAyNTgkbzEkZzAkdDE3ODE3MzAyNTgkajYwJGwwJGgw*_ga_B8TDS1LEXQ*czE3ODE3MzAyNTgkbzEkZzEkdDE3ODE3MzAyNTgkajYwJGwwJGgw"> context platform</a> that optimizes data for retrieval. Vector database vendor Pinecone has its<a href="https://venturebeat.com/data/the-rag-era-is-ending-for-agentic-ai-a-new-compilation-stage-knowledge-layer-is-what-comes-next?_gl=1*klgyi3*_up*MQ..*_ga*MTM4OTgwNTA2LjE3ODE3MzAyNTk.*_ga_SCH1J7LNKY*czE3ODE3MzAyNTgkbzEkZzAkdDE3ODE3MzAyNTgkajYwJGwwJGgw*_ga_B8TDS1LEXQ*czE3ODE3MzAyNTgkbzEkZzEkdDE3ODE3MzAyNTgkajYwJGwwJGgw"> Nexus context offering</a> that compiles enterprise data into task-specific artifacts before agents ever query them.</p><p>AWS's structural argument is straightforward: for enterprises already running S3, Glue and Lake Formation, AWS Context extends an existing identity model with no data movement required. The pitch is zero-integration friction — not just cost consolidation.</p><p>"Context makes agents more powerful and as the whole world is building agents, every agentic platform vendor needs a context capability," Holger Mueller, VP and Principal analyst at Constellation Research, told VentureBeat.</p><p>Mueller noted that AWS is no exception. "The concern — as with all context offerings — is going to be performance, especially for transactional data,  we will see," he said.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Amazon SageMaker AI Async Inference now supports inline request payloads]]></title>
<description><![CDATA[Today, we’re announcing inline payload support for Amazon SageMaker AI Async Inference. Customers can now send inference payloads directly in the request body of the InvokeEndpointAsync API, removing the need to upload input data to Amazon Simple Storage Service (Amazon S3) before each invocation.]]></description>
<link>https://tsecurity.de/de/3606088/ai-nachrichten/amazon-sagemaker-ai-async-inference-now-supports-inline-request-payloads/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3606088/ai-nachrichten/amazon-sagemaker-ai-async-inference-now-supports-inline-request-payloads/</guid>
<pubDate>Wed, 17 Jun 2026 23:03:56 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Today, we’re announcing inline payload support for Amazon SageMaker AI Async Inference. Customers can now send inference payloads directly in the request body of the InvokeEndpointAsync API, removing the need to upload input data to Amazon Simple Storage Service (Amazon S3) before each invocation.]]></content:encoded>
</item>
<item>
<title><![CDATA[Context intelligence for your data and AI agents at scale]]></title>
<description><![CDATA[Agents are only as intelligent as the context they can reason over. Today, that context is scattered across data lakes, data warehouses, lakehouses, databases, and streams, and in institutional knowledge that has never been written down. You want to trust the decisions made by your AI agents, but...]]></description>
<link>https://tsecurity.de/de/3605634/ai-nachrichten/context-intelligence-for-your-data-and-ai-agents-at-scale/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3605634/ai-nachrichten/context-intelligence-for-your-data-and-ai-agents-at-scale/</guid>
<pubDate>Wed, 17 Jun 2026 19:18:55 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Agents are only as intelligent as the context they can reason over. Today, that context is scattered across data lakes, data warehouses, lakehouses, databases, and streams, and in institutional knowledge that has never been written down. You want to trust the decisions made by your AI agents, but that can't happen until agents have context. Imagine what becomes possible when we give agents a safe way to access the context they need to deliver trusted decisions. This is why at the AWS Summit New York City, we’re announcing a series of innovations that deliver intelligence for your data and AI agents at scale.]]></content:encoded>
</item>
<item>
<title><![CDATA[Announcing Web Search on Amazon Bedrock AgentCore: Ground your AI agents in current, accurate web knowledge]]></title>
<description><![CDATA[AWS introduces Web Search on Amazon Bedrock AgentCore, a fully managed tool that enables agents to ground responses in current, cited web knowledge with zero data egress from customer's secured AWS environment. You can focus on building agents instead of manually adding web search to agents on Be...]]></description>
<link>https://tsecurity.de/de/3605340/ai-nachrichten/announcing-web-search-on-amazon-bedrock-agentcore-ground-your-ai-agents-in-current-accurate-web-knowledge/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3605340/ai-nachrichten/announcing-web-search-on-amazon-bedrock-agentcore-ground-your-ai-agents-in-current-accurate-web-knowledge/</guid>
<pubDate>Wed, 17 Jun 2026 17:38:12 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[AWS introduces Web Search on Amazon Bedrock AgentCore, a fully managed tool that enables agents to ground responses in current, cited web knowledge with zero data egress from customer's secured AWS environment. You can focus on building agents instead of manually adding web search to agents on Bedrock AgentCore and managing its infrastructure.]]></content:encoded>
</item>
<item>
<title><![CDATA[AMD acquires MEXT to add predictive memory optimization to its AI stack]]></title>
<description><![CDATA[AMD has acquired memory optimization startup MEXT, bringing predictive memory optimization software into its AI infrastructure portfolio as enterprises look for ways to manage increasingly memory-intensive AI workloads without continually expanding expensive DRAM capacity.



The technology uses ...]]></description>
<link>https://tsecurity.de/de/3604788/it-security-nachrichten/amd-acquires-mext-to-add-predictive-memory-optimization-to-its-ai-stack/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3604788/it-security-nachrichten/amd-acquires-mext-to-add-predictive-memory-optimization-to-its-ai-stack/</guid>
<pubDate>Wed, 17 Jun 2026 14:36:05 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>AMD has acquired memory optimization startup MEXT, bringing predictive memory optimization software into its AI infrastructure portfolio as enterprises look for ways to manage increasingly memory-intensive AI workloads without continually expanding expensive DRAM capacity.</p>



<p>The technology uses AI to intelligently move frequently accessed data between flash storage and DRAM, enabling organizations to increase effective memory capacity while reducing infrastructure cost and power consumption, according to AMD.</p>



<p>“Memory has become a critical constraint across cloud and enterprise environments,” <a href="https://www.amd.com/en/blogs/2026/amd-acquires-mext-for-memory-optimization.html" target="_blank" rel="noreferrer noopener">AMD said in a blog</a> announcing the acquisition, adding that traditional approaches of simply adding more DRAM are becoming increasingly costly and power-intensive.</p>



<p>Financial terms of the acquisition were not disclosed. AMD did not immediately respond to a request for additional comment.</p>



<h2 class="wp-block-heading">AI boom reshapes memory economics</h2>



<p>AMD’s move comes as AI infrastructure demand is reshaping the memory market and forcing enterprises to rethink how they scale AI deployments.</p>



<p>According to<a href="https://www.idc.com/resource-center/blog/global-memory-shortage-crisis-market-analysis-and-the-potential-impact-on-the-smartphone-and-pc-markets-in-2026/?utm_source=chatgpt.com" target="_blank"> IDC</a>, AI infrastructure is driving a strategic reallocation of memory production toward enterprise-grade components, with 2026 DRAM supply growth expected to remain below historical norms at 16% year over year, creating pricing pressure across the market.</p>



<p><a href="https://www.gartner.com/en/newsroom/press-releases/2026-02-26-gartner-says-surging-memory-costs-will-reduce-global-pc-and-smartphone-shipments-in-2026?utm_source=chatgpt.com" target="_blank" rel="noreferrer noopener">Gartner has separately</a> forecast a 130% increase in combined DRAM and SSD prices by the end of 2026, warning that higher memory costs will increasingly influence enterprise technology investment decisions.</p>



<p>Against that backdrop, MEXT’s software is designed to address a growing enterprise challenge by using predictive algorithms to identify frequently accessed data and proactively move it between flash storage and DRAM, extending usable memory capacity without requiring proportional hardware expansion, the blog added.</p>



<p>“Memory prices have seen an unprecedented growth, nearly going 4x since 3Q25, making memory one of the most contested chips in the AI infrastructure story,” said Shrish Pant, director analyst at Gartner.</p>



<p>Pant said higher prices and constrained supply are reviving interest in software-driven memory optimization strategies that received little attention when memory was abundant and inexpensive.</p>



<h2 class="wp-block-heading">AI infra competition moves up the stack</h2>



<p>The acquisition also reflects a broader shift in how AI vendors are competing for enterprise workloads.</p>



<p>While the first phase of the AI race centered on securing GPUs and compute capacity, vendors are increasingly investing across networking, software, and infrastructure optimization to improve overall system efficiency.</p>



<p>“We can safely say that we are beyond ‘chips wars’ and have already entered into an ‘Infrastructure optimization war’, and software-based memory optimization is just one of many moving pieces which will determine winners for the AI race,” Pant said.</p>



<p>AMD’s acquisition expands its AI infrastructure portfolio beyond processors into software that optimizes memory utilization, mirroring a broader industry trend toward integrated hardware and software stacks rather than standalone silicon performance.</p>



<p>Manish Rawat, semiconductor analyst at TechInsights, said memory is increasingly becoming a strategic constraint for enterprise AI deployments.</p>



<p>“As enterprises deploy larger models and scale user workloads, memory limitations often constrain performance and GPU utilization before compute resources are fully exhausted,” Rawat said.</p>



<p>Memory is evolving from a supporting hardware component into a strategic enabler of AI scalability, performance, and cost optimization, he added.</p>



<h2 class="wp-block-heading">Software aims to delay expensive DRAM upgrades</h2>



<p>AMD said MEXT’s predictive memory tiering technology intelligently places frequently accessed data in high-speed memory while shifting less active data to lower-cost flash storage.</p>



<p>That approach is intended to increase infrastructure efficiency and reduce the need for continual DRAM expansion as enterprise AI workloads grow, analysts said.</p>



<p>Rawat said software-based memory optimization offers enterprises a practical way to delay expensive hardware upgrades rather than eliminate the need for DRAM.</p>



<p>Although the technology cannot replace high-performance DRAM for latency-sensitive applications, it can improve data center efficiency, lower total cost of ownership, and help organizations maximize returns from existing infrastructure investments, he said.</p>



<p>Sanchit Vir Gogia, chief analyst at Greyhound Research, said the industry is entering a phase where infrastructure orchestration will matter as much as compute performance.</p>



<p>“The GPU is the engine. Memory is the road, the fuel line, and occasionally the traffic jam,” Gogia said.</p>



<p>Production AI workloads place sustained demands on parameters, embeddings, and cached context, making memory performance a business issue rather than simply a hardware specification.</p>



<p>Gogia said predictive memory tiering addresses inefficiencies that often leave expensive DRAM underutilized, but cautioned that optimization should complement, rather than replace, sound infrastructure design.</p>



<p>“Predictive tiering attacks the waste inside that reflex,” he said, referring to the tendency to address performance challenges by purchasing more memory instead of improving utilization.</p>



<p>Rawat said organizations that optimize compute, memory, storage, and software together are likely to scale AI deployments faster, lower operating costs, and generate stronger returns on AI investments than those relying primarily on increasing hardware capacity.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Safeguard your agentic AI applications with the Amazon Bedrock Guardrails InvokeGuardrailChecks API]]></title>
<description><![CDATA[Today, we’re announcing a new API with Amazon Bedrock Guardrails. With this API, you can apply individual safeguards, also referred to as safety checks, at any point in your agentic AI applications without creating guardrail resources. In this post, we walk through how the InvokeGuardrailChecks A...]]></description>
<link>https://tsecurity.de/de/3603313/ai-nachrichten/safeguard-your-agentic-ai-applications-with-the-amazon-bedrock-guardrails-invokeguardrailchecks-api/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3603313/ai-nachrichten/safeguard-your-agentic-ai-applications-with-the-amazon-bedrock-guardrails-invokeguardrailchecks-api/</guid>
<pubDate>Wed, 17 Jun 2026 00:48:32 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Today, we’re announcing a new API with Amazon Bedrock Guardrails. With this API, you can apply individual safeguards, also referred to as safety checks, at any point in your agentic AI applications without creating guardrail resources. In this post, we walk through how the InvokeGuardrailChecks API works and how to use it to build safe, multi-turn agentic AI applications.]]></content:encoded>
</item>
<item>
<title><![CDATA[SpaceX’s planned $60 billion deal for Cursor raises questions for CIOs]]></title>
<description><![CDATA[When SpaceX on Tuesday officially announced its plan to purchase AI coding startup Cursor for $60 billion in stock, as it had predicted it would do in April, it presented CIOs and developers with a little good news, a little bad news and a massive pile of uncertainty. 



The details of the propo...]]></description>
<link>https://tsecurity.de/de/3603083/it-nachrichten/spacexs-planned-60-billion-deal-for-cursor-raises-questions-for-cios/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3603083/it-nachrichten/spacexs-planned-60-billion-deal-for-cursor-raises-questions-for-cios/</guid>
<pubDate>Tue, 16 Jun 2026 22:17:59 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>When SpaceX on Tuesday officially announced its plan to purchase AI coding startup Cursor for $60 billion in stock, as it had <a href="https://www.infoworld.com/article/4161997/spacex-secures-option-to-acquire-ai-coding-startup-cursor-for-60b.html" target="_blank">predicted it would do in April</a>, it presented CIOs and developers with a little good news, a little bad news and a massive pile of uncertainty. </p>



<p>The <a href="https://d18rn0p25nwr6d.cloudfront.net/CIK-0001181412/06fd909f-8de8-4960-aa6e-6b8cd3da6c9e.pdf" target="_blank" rel="nofollow">details of the proposed acquisition</a> were virtually identical to the terms announced in April, even retaining the $10 billion consolation prize for Cursor should SpaceX back out of the deal.  </p>



<p>But for CIOs and developers, the increasing probability of the deal happening is forcing them to make long-term decisions without many long-term answers about what is likely to happen to Cursor, which says its coding agents are used by 64% of Fortune 500 companies.</p>



<p>But whether the deal is good news for Cursor’s customers, or even those of its rivals, is an open question.</p>



<p><a href="https://my.idc.com/getdoc.jsp?containerId=PRF004946" target="_blank" rel="nofollow">Arnal Dayaratna</a>, research VP for software development at IDC, is firmly in the good news camp. He argued that the main element holding back the company, which he estimated brings in about $2 billion in annual revenue, was access to GPUs. And, he said, SpaceX’s xAI has the ability to resolve that problem.</p>



<h2 class="wp-block-heading">It’s all about the GPUs</h2>



<p>“The implication is that Cursor can get better because it will get better access to more compute, in the form of GPUs. That was what Cursor was struggling to obtain,” Dayaratna said, adding that Cursor joins both Anthropic and Google in aligning with xAI. </p>



<p>“It is bad news for Anthropic,” he said, pointing out, “[Elon] Musk figured out that GPUs were the limiters, the bottleneck. Not human talent: compute. And it’s not only about GPUs. It’s about the data centers,” as well as the mechanisms needed to support data centers, including electricity access, cooling apparatus, and zoning rights.</p>



<p>“Zoning rights are very difficult to obtain in the United States, and Elon has been able to leverage his political capital” to obtain those rights, Dayaratna said. </p>



<p>Dayaratna also commented on the highly unusual tactic of a company pre-announcing an acquisition and then announcing it “officially” two months later. The reason, he suggested, is that Musk didn’t want the acquisition to delay the SpaceX IPO, but he <em>did </em>want potential investors to know about it. “It gave the IPO more legs, even though it was not formally a part of the IPO. He wanted to socialize it before it happened,” he said.</p>



<p><a href="https://moorinsightsstrategy.com/team/jason-andersen/" target="_blank" rel="nofollow">Jason Andersen</a>, principal analyst at Moor Insights &amp; Strategy, took a far more cautious approach and predicted, “enterprise customers will be very concerned.”</p>



<h2 class="wp-block-heading">Time for CIO due diligence</h2>



<p>“xAI’s models and treatment of guardrails are very different than what Cursor has stood for,” Andersen said, and the key issue involves model choice. “Will Cursor be able to point at models other than Grok? If that is the case, it could go towards helping customers be OK with things for a while,” he said. </p>



<p>But Andersen stressed the words “for a while.” He argued that Cursor rivals have gotten more sophisticated, which could give enterprise CIOs more alternatives.</p>



<p>“The tooling options from the classic enterprise vendors have gotten really good, and also have a number of features that enable better governance and teaming. For example, Kiro from AWS is already a worthy competitor to Cursor, but there have also been major improvements from Google and Microsoft this year,” Andersen said. “I’d venture to say that Cursor was already facing a substantial competitive challenge in the enterprise, especially as the vibe coding movement lost some steam towards agents that enable so much more developer capability.”</p>



<p>Andersen added, “A <em>lot</em> of SpaceX’s valuation is pinned to xAI and there wasn’t enough IP there for it to be long-term competitive with Anthropic or OpenAI without rapidly injecting new technology.”</p>



<p><a href="https://www.infotech.com/profiles/shashi-bellamkonda" target="_blank" rel="nofollow">Shashi Bellamkonda</a>, principal research director at Info-Tech Research Group, said the current period of due diligence gives CIOs opportunities to ask difficult questions.</p>



<p>“I do believe that enterprise customers will start to ask harder questions now, especially if more of the processing starts moving through Grok or xAI infrastructure,” Bellamkonda said, but he stressed that he does see a SpaceX deal helping Cursor.</p>



<p>“Cursor is already carrying a lot of LLM cost and if SpaceX and xAI can give it access to more compute and a faster, improved Grok model, customers could eventually get better performance at a lower cost. Grok is getting faster and more accurate, and under SpaceX there may be more enterprise appetite for xAI than xAI had on its own,” Bellamkonda said.</p>



<h2 class="wp-block-heading">Questions about data privacy</h2>



<p>But Bellamkonda also pointed to the trust issue, specifically asking whether Cursor would be allowed to continue its zero-data-retention policy under the new ownership.</p>



<p>“Enterprise users with sensitive codebases will want to understand exactly where their data is going, who has access to it, and whether any prompts, code, metadata, or embeddings are touching SpaceX or xAI systems,” Bellamkonda said. “Zero data retention is only valuable if customers believe the controls still apply across the new infrastructure. If they can preserve Cursor’s privacy posture while using xAI and SpaceX compute to improve the product, this could be a very strong outcome for customers. If the data governance is unclear, enterprise buyers will hesitate.”</p>



<p><a href="https://acceligence.com/talent/profiles/justin-greis/" target="_blank" rel="nofollow">Justin Greis</a>, CEO of consulting firm Acceligence, echoed Bellamkonda’s concerns.</p>



<p>“For many enterprise customers, Cursor’s zero-data-retention policy was not simply a security feature. It was a foundational part of the procurement and approval process,” Greis said, pointing out that security teams, legal departments, compliance officers, and executive leadership all became more comfortable adopting AI-assisted development because they believed their source code, prompts, and proprietary intellectual property would not be retained, stored, or repurposed.</p>



<p>“Whenever ownership changes, customers naturally revisit those assumptions,” he said. “I would expect enterprise customers to immediately seek clarity on whether existing zero-data-retention commitments remain unchanged, whether those commitments continue to be contractually enforceable, and whether any future modifications could be introduced through changes to terms of service or product strategy.”</p>



<h2 class="wp-block-heading">Reassessing platform risk</h2>



<p>Another concern is whether the move will create greater vendor concentration, and whether that will increase risk exposure. </p>



<p>“Many organizations are already concerned about becoming overly dependent on a small number of AI providers. If Cursor becomes more tightly integrated into a broader SpaceX technology ecosystem, some enterprises may worry about reduced flexibility and fewer alternatives. I suspect this will be a continued question with SpaceX’s recent IPO and growth plans,” Greis said. </p>



<p>Additionally, he pointed out, “AI coding platforms are rapidly becoming part of critical software delivery infrastructure. When organizations standardize on these tools, they are making a long-term platform decision that influences developer productivity, software quality, security processes, and engineering workflows. A change in ownership naturally prompts a reassessment of platform risk, roadmap alignment, and long-term strategic direction.”</p>



<p>As well, <a href="https://greyhoundresearch.com/svg/" target="_blank" rel="nofollow">Sanchit Vir Gogia</a>, chief analyst at Greyhound Research, noted, “zero data retention survives only where it stays contractual, auditable, enforceable and fenced from affiliate use. The deeper point is what Cursor has become. It is no longer a developer convenience. It sits inside the act of software creation, close to the intellectual-property bloodstream of the enterprise. That is a control plane, and control planes change hands rarely and consequentially.”</p>



<p>Gogia added that even before an acquisition, Cursor was already weakening its data guarantee. “Even now the promise is layered. Cursor’s own disclosures show that standard Privacy Mode still permits some code data to be stored for product features, while only the stricter legacy setting retains nothing. Zero is the exception, not the default.”</p>



<p><em>This article originally appeared on <a href="https://www.infoworld.com/article/4185844/spacexs-planned-60-billion-deal-for-cursor-raises-questions-for-cios.html" target="_blank">InfoWorld</a>.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[SpaceX’s planned $60 billion deal for Cursor raises questions for CIOs]]></title>
<description><![CDATA[When SpaceX on Tuesday officially announced its plan to purchase AI coding startup Cursor for $60 billion in stock, as it had predicted it would do in April, it presented CIOs and developers with a little good news, a little bad news and a massive pile of uncertainty. 



The details of the propo...]]></description>
<link>https://tsecurity.de/de/3603043/ai-nachrichten/spacexs-planned-60-billion-deal-for-cursor-raises-questions-for-cios/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3603043/ai-nachrichten/spacexs-planned-60-billion-deal-for-cursor-raises-questions-for-cios/</guid>
<pubDate>Tue, 16 Jun 2026 22:03:40 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>When SpaceX on Tuesday officially announced its plan to purchase AI coding startup Cursor for $60 billion in stock, as it had <a href="https://www.infoworld.com/article/4161997/spacex-secures-option-to-acquire-ai-coding-startup-cursor-for-60b.html" target="_blank">predicted it would do in April</a>, it presented CIOs and developers with a little good news, a little bad news and a massive pile of uncertainty. </p>



<p>The <a href="https://d18rn0p25nwr6d.cloudfront.net/CIK-0001181412/06fd909f-8de8-4960-aa6e-6b8cd3da6c9e.pdf" target="_blank" rel="noreferrer noopener">details of the proposed acquisition</a> were virtually identical to the terms announced in April, even retaining the $10 billion consolation prize for Cursor should SpaceX back out of the deal.  </p>



<p>But for CIOs and developers, the increasing probability of the deal happening is forcing them to make long-term decisions without many long-term answers about what is likely to happen to Cursor, which says its coding agents are used by 64% of Fortune 500 companies.</p>



<p>But whether the deal is good news for Cursor’s customers, or even those of its rivals, is an open question.</p>



<p><a href="https://my.idc.com/getdoc.jsp?containerId=PRF004946" target="_blank" rel="noreferrer noopener">Arnal Dayaratna</a>, research VP for software development at IDC, is firmly in the good news camp. He argued that the main element holding back the company, which he estimated brings in about $2 billion in annual revenue, was access to GPUs. And, he said, SpaceX’s xAI has the ability to resolve that problem.</p>



<h2 class="wp-block-heading">It’s all about the GPUs</h2>



<p>“The implication is that Cursor can get better because it will get better access to more compute, in the form of GPUs. That was what Cursor was struggling to obtain,” Dayaratna said, adding that Cursor joins both Anthropic and Google in aligning with xAI. </p>



<p>“It is bad news for Anthropic,” he said, pointing out, “[Elon] Musk figured out that GPUs were the limiters, the bottleneck. Not human talent: compute. And it’s not only about GPUs. It’s about the data centers,” as well as the mechanisms needed to support data centers, including electricity access, cooling apparatus, and zoning rights.</p>



<p>“Zoning rights are very difficult to obtain in the United States, and Elon has been able to leverage his political capital” to obtain those rights, Dayaratna said. </p>



<p>Dayaratna also commented on the highly unusual tactic of a company pre-announcing an acquisition and then announcing it “officially” two months later. The reason, he suggested, is that Musk didn’t want the acquisition to delay the SpaceX IPO, but he <em>did </em>want potential investors to know about it. “It gave the IPO more legs, even though it was not formally a part of the IPO. He wanted to socialize it before it happened,” he said.</p>



<p><a href="https://moorinsightsstrategy.com/team/jason-andersen/" target="_blank" rel="noreferrer noopener">Jason Andersen</a>, principal analyst at Moor Insights &amp; Strategy, took a far more cautious approach and predicted, “enterprise customers will be very concerned.”</p>



<h2 class="wp-block-heading">Time for CIO due diligence</h2>



<p>“xAI’s models and treatment of guardrails are very different than what Cursor has stood for,” Andersen said, and the key issue involves model choice. “Will Cursor be able to point at models other than Grok? If that is the case, it could go towards helping customers be OK with things for a while,” he said. </p>



<p>But Andersen stressed the words “for a while.” He argued that Cursor rivals have gotten more sophisticated, which could give enterprise CIOs more alternatives.</p>



<p>“The tooling options from the classic enterprise vendors have gotten really good, and also have a number of features that enable better governance and teaming. For example, Kiro from AWS is already a worthy competitor to Cursor, but there have also been major improvements from Google and Microsoft this year,” Andersen said. “I’d venture to say that Cursor was already facing a substantial competitive challenge in the enterprise, especially as the vibe coding movement lost some steam towards agents that enable so much more developer capability.”</p>



<p>Andersen added, “A <em>lot</em> of SpaceX’s valuation is pinned to xAI and there wasn’t enough IP there for it to be long-term competitive with Anthropic or OpenAI without rapidly injecting new technology.”</p>



<p><a href="https://www.infotech.com/profiles/shashi-bellamkonda" target="_blank" rel="noreferrer noopener">Shashi Bellamkonda</a>, principal research director at Info-Tech Research Group, said the current period of due diligence gives CIOs opportunities to ask difficult questions.</p>



<p>“I do believe that enterprise customers will start to ask harder questions now, especially if more of the processing starts moving through Grok or xAI infrastructure,” Bellamkonda said, but he stressed that he does see a SpaceX deal helping Cursor.</p>



<p>“Cursor is already carrying a lot of LLM cost and if SpaceX and xAI can give it access to more compute and a faster, improved Grok model, customers could eventually get better performance at a lower cost. Grok is getting faster and more accurate, and under SpaceX there may be more enterprise appetite for xAI than xAI had on its own,” Bellamkonda said.</p>



<h2 class="wp-block-heading">Questions about data privacy</h2>



<p>But Bellamkonda also pointed to the trust issue, specifically asking whether Cursor would be allowed to continue its zero-data-retention policy under the new ownership.</p>



<p>“Enterprise users with sensitive codebases will want to understand exactly where their data is going, who has access to it, and whether any prompts, code, metadata, or embeddings are touching SpaceX or xAI systems,” Bellamkonda said. “Zero data retention is only valuable if customers believe the controls still apply across the new infrastructure. If they can preserve Cursor’s privacy posture while using xAI and SpaceX compute to improve the product, this could be a very strong outcome for customers. If the data governance is unclear, enterprise buyers will hesitate.”</p>



<p><a href="https://acceligence.com/talent/profiles/justin-greis/" target="_blank" rel="noreferrer noopener">Justin Greis</a>, CEO of consulting firm Acceligence, echoed Bellamkonda’s concerns.</p>



<p>“For many enterprise customers, Cursor’s zero-data-retention policy was not simply a security feature. It was a foundational part of the procurement and approval process,” Greis said, pointing out that security teams, legal departments, compliance officers, and executive leadership all became more comfortable adopting AI-assisted development because they believed their source code, prompts, and proprietary intellectual property would not be retained, stored, or repurposed.</p>



<p>“Whenever ownership changes, customers naturally revisit those assumptions,” he said. “I would expect enterprise customers to immediately seek clarity on whether existing zero-data-retention commitments remain unchanged, whether those commitments continue to be contractually enforceable, and whether any future modifications could be introduced through changes to terms of service or product strategy.”</p>



<h2 class="wp-block-heading">Reassessing platform risk</h2>



<p>Another concern is whether the move will create greater vendor concentration, and whether that will increase risk exposure. </p>



<p>“Many organizations are already concerned about becoming overly dependent on a small number of AI providers. If Cursor becomes more tightly integrated into a broader SpaceX technology ecosystem, some enterprises may worry about reduced flexibility and fewer alternatives. I suspect this will be a continued question with SpaceX’s recent IPO and growth plans,” Greis said. </p>



<p>Additionally, he pointed out, “AI coding platforms are rapidly becoming part of critical software delivery infrastructure. When organizations standardize on these tools, they are making a long-term platform decision that influences developer productivity, software quality, security processes, and engineering workflows. A change in ownership naturally prompts a reassessment of platform risk, roadmap alignment, and long-term strategic direction.”</p>



<p>As well, <a href="https://greyhoundresearch.com/svg/" target="_blank" rel="noreferrer noopener">Sanchit Vir Gogia</a>, chief analyst at Greyhound Research, noted, “zero data retention survives only where it stays contractual, auditable, enforceable and fenced from affiliate use. The deeper point is what Cursor has become. It is no longer a developer convenience. It sits inside the act of software creation, close to the intellectual-property bloodstream of the enterprise. That is a control plane, and control planes change hands rarely and consequentially.”</p>



<p>Gogia added that even before an acquisition, Cursor was already weakening its data guarantee. “Even now the promise is layered. Cursor’s own disclosures show that standard Privacy Mode still permits some code data to be stored for product features, while only the stricter legacy setting retains nothing. Zero is the exception, not the default.”</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Qualcomm’s latest chip hints that more powerful smart glasses could be on the way]]></title>
<description><![CDATA[Smart glasses are still a nascent category, but chipmaker Qualcomm is hard at work upgrading the silicon to power the next wave of XR devices: the Snapdragon Reality Elite. Although Qualcomm is announcing the chip today at Augmented World Expo, we've technically already gotten a hands-on with a d...]]></description>
<link>https://tsecurity.de/de/3602705/it-nachrichten/qualcomms-latest-chip-hints-that-more-powerful-smart-glasses-could-be-on-the-way/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3602705/it-nachrichten/qualcomms-latest-chip-hints-that-more-powerful-smart-glasses-could-be-on-the-way/</guid>
<pubDate>Tue, 16 Jun 2026 19:17:53 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Smart glasses are still a nascent category, but chipmaker Qualcomm is hard at work upgrading the silicon to power the next wave of XR devices: the Snapdragon Reality Elite. Although Qualcomm is announcing the chip today at Augmented World Expo, we've technically already gotten a hands-on with a device powered by the new chip at […]]]></content:encoded>
</item>
<item>
<title><![CDATA[HPE product barrage targets AI networks, agents, management]]></title>
<description><![CDATA[HPE has rolled out a super-sized package of hardware and software aimed at helping enterprise customers build and manage large AI infrastructures from the data center to the edge.



At its Discover event in Las Vegas this week, the vendor announced HPE Juniper Networking QFX switches aimed at in...]]></description>
<link>https://tsecurity.de/de/3602644/it-security-nachrichten/hpe-product-barrage-targets-ai-networks-agents-management/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3602644/it-security-nachrichten/hpe-product-barrage-targets-ai-networks-agents-management/</guid>
<pubDate>Tue, 16 Jun 2026 19:08:07 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>HPE has rolled out a super-sized package of hardware and software aimed at helping enterprise customers build and manage large AI infrastructures from the data center to the edge.</p>



<p>At its <a href="https://www.hpe.com/us/en/discover/lasvegas.html">Discover</a> event in Las Vegas this week, the vendor announced HPE Juniper Networking QFX switches aimed at inferencing and scale-up architectures. It also deepened integration of its Juniper Networking data center switching and operations into its Mist AI engine and launched a unified, AI-native <a href="https://www.networkworld.com/article/4034500/hpe-unveils-ai-powered-network-security-and-data-protection-technology.html">SASE</a> platform.</p>



<p>“AI requires a solid architectural foundation, and the success of agentic AI in the enterprise depends on a modern networking foundation built for autonomous workflows, where network performance, reliability, and intelligence determine the effectiveness of the entire AI architecture,” Rami Rahim, executive vice president, president and general manager of networking for HPE, told journalists and analysts in a briefing before the event. “HPE is delivering that foundation, letting enterprises deploy agentic AI with greater control, confidence, security, and operational simplicity.”</p>



<p>On the hardware front, the company introduced the HPE Juniper Networking QFX5140 switch, aimed at the booming demand for AI inferencing and edge AI use cases. </p>



<p>The 1RU, 16T QFX5140 fixed-configuration data center switch is designed for AI fabric, spine, leaf, and border leaf deployments. Its port density can be configured to support 24× 400G QSFP112, 8× 800G OSFP800 and 2x SFP28 ports, and it includes support for RDMA over Converged Ethernet (RoCEv2). Additional capabilities include congestion management features such as Priority Flow Control and Explicit Congestion Notification and dynamic load balancing — all features that enable effective GPU-to-GPU communications, according to HPE CTO <a href="https://www.linkedin.com/in/fidelma-russo-202461/">Fidelma Russo</a>.</p>



<p>The box fills out the mid-tier of the HPE Juniper QFX family, which includes the high-end 102T <a href="https://www.networkworld.com/article/4099698/hpe-loads-up-ai-networking-portfolio-strengthens-nvidia-amd-partnerships.html">QFX5240/QFX5250</a> and entry-level 100GBE QFX 5100.</p>



<p>HPE also announced the QFX5252 module for its 72GPU-per-rack <a href="https://www.hpe.com/us/en/newsroom/press-release/2025/12/hpe-accelerates-ai-deployments-with-first-amd-helios-ai-rack-scale-architecture-with-open-scale-up-networking-built-with-broadcom.html">AMD Helios turnkey package</a> aimed AI training and high-volume inferencing. The package combines CPUs, GPUs and open Ethernet networking technology into a unified, high-end AI platform. </p>



<p>The QFX family is part of a significant move aimed at tightening the integration between the <a href="https://www.networkworld.com/article/4099698/hpe-loads-up-ai-networking-portfolio-strengthens-nvidia-amd-partnerships.html">networking gear HPE acquired from Juniper</a> and its existing HPE AI infrastructure offerings. Specifically, HPE’s data center management platform, Data Center Director, now includes the QFX switch portfolio. </p>



<p>The idea is to offer data center customers a more integrated, automated, and centralized view of all their network components to improve network visibility and speed troubleshooting, according to Russo.</p>



<h2 class="wp-block-heading">HPE Mist integration</h2>



<p>Continuing that integration theme, HPE said it will integrate Juniper’s natural language Mist AI into HPE Aruba Central and vice versa, all fed by its core AIOps Marvis AI engine. Marvis collects telemetry and user state data from Juniper’s routers, switches, access points, firewalls, and applications to detect and resolve a broad range of enterprise networking problems. A key part of Marvis is its AI-based Marvis Actions component, which identifies and prioritizes network problem remediation.</p>



<p>Overall, the move integrates AIOps across wired, wireless, and SD-WAN environments to proactively resolve issues, including trusted actions such as wired port remediation, to further extend autonomous operations across the HPE networking portfolio Rami said. He also noted that Marvis Actions will be extended to Aruba Central by the end of the year. </p>



<p>Further, HPE said it will be melding the HPE Aruba CX switching portfolio with HPE Mist, giving CX customers capabilities such as AI-native visibility, zero-touch provisioning, wired assurance for Layer 2 access, service-level insights, and HPE Marvis AI-driven support, Rami said.</p>



<p>HPE also expanded Mist data center capabilities to include predictive analytics for proactive maintenance of network components. For example, Mist can now use AI/ML technology to predict potential optics failures that would cause network outages.</p>



<p>Mist also can now use an advanced reasoning AI agent for high-confidence remediation, Rami said. Agentic AI is used to continuously and autonomously reason across diverse data streams, including millions of TAC cases and a contextual graph database from HPE Networking Data Center Director, to deliver precise root cause analysis inside of the data center. </p>



<p>“So think of this as Marvis AI engine for data center operations. So, here we’re combining telemetry, application flows, operational context, historical knowledge to understand rapidly the root cause and recommend next steps,” Rami said. “So the problems that once took hours if not days to diagnose can now be resolved literally in minutes or even proactively before anybody understands that there is an issue. Together these capabilities bring the self-driving network from where it started inside the campus to now inside the data center.”</p>



<p>The most important takeaway is that there’s real momentum behind HPE’s acquisition strategy to leverage the core of the Mist platform by expanding Marvis as the AI engine across the portfolio, <a href="https://www.linkedin.com/in/mikeleib/">Mike Leibovitz</a>, senior director analyst in Gartner’s business technology and innovation group, told <em>Network World</em>. “They are continuing to innovate while simultaneously integrating that model into Aruba networking, into the data center, and out the branch.”</p>



<p>“Agentic NetOps is the most exciting area of innovation in enterprise networking in more than 20 years, as organizations move toward increasingly hands-off operations. HPE is well aligned with Marvis as the AI engine across its portfolio,” Leibovitz said. “Most enterprises are starting this journey with their existing infrastructure vendors like HPE, Cisco, or Arista, but those with more heterogeneous environments are also investigating a growing set of infrastructure-independent software providers. The space is moving quickly, and leadership is still very much up for grabs.”</p>



<h2 class="wp-block-heading">Unified SASE efforts</h2>



<p>HPE is also trying to simplify WAN access to data center resources. That’s the driving idea behind a new SASE Orchestrator package. It ties together the vendor’s SD-WAN and SSE with cloud security and a unified policy engine that will use AI to manage branch, remote user, and cloud connectivity from one place. With the policy engine, customers can set security policies once, for example, and deploy them across many sites.</p>



<p>“The Orchestrator promises simpler operations with AI operations, faster zero-trust adoption, and a better user experience through intelligent traffic steering and application awareness,” Rami said.</p>



<h2 class="wp-block-heading">Nvidia updates</h2>



<p>Beyond hardware and software enhancements, HPE also tightened its integration with core partner Nvidia, via its <a href="https://www.networkworld.com/article/4145989/hpe-nvidia-expand-ai-partnership.html">HPE Private Cloud AI</a>, a turnkey AI factory co-engineered with the Nvidia.</p>



<p>HPE Private Cloud AI delivers a preconfigured hardware and software stack featuring the latest Nvidia AI Enterprise software and blueprints. The package is being enhanced to help manage AI agent by adding support for Nvidia’s Agent Toolkit software, including Nvidia’s Nemotron open models, NemoClaw, and OpenShell secure runtime, to provide an an agent operating system that reasons, lets customers monitor agent behavior, enforces policies, and reduces deployment risk, according to HPE.</p>



<p>HPE is also bringing <a href="https://www.nvidia.com/en-us/data-center/solutions/confidential-computing/">Nvidia Confidential Computing</a> to the HPE AI Factory through HPE Services. Nvidia Confidential Computing protects models and private data during execution for on-premises or sovereign deployments, according to HPE.</p>



<h2 class="wp-block-heading">HPE Zerto and HPE Morpheus additions</h2>



<p>A new release of <a href="https://www.hpe.com/us/en/zerto-software.html">HPE Zerto Software</a> lets customers identify any rogue agent action and utilizes data protection to rewind to a clean slate. The Private Cloud AI package now also supports secure local agent registration, providing customers with the ability to approve AI models, skills, and tools while adhering to centralized governance and security policies.</p>



<p>Changes are also in store for <a href="https://www.networkworld.com/article/3487156/hpe-buys-morpheus-data-for-multicloud-management.html">HPE Morpheus,</a> which lets enterprises manage virtual machines, containers, and cloud resources across multiple environments from a single control plane. <a href="https://www.networkworld.com/article/3985592/hpe-morphs-private-cloud-portfolio-with-improved-virtualization-storage-and-data-protection.html">Often positioned</a> as an alternative to Broadcom’s VMware, HPE announced if customers own or buy HPE’s VM Essentials package for a year, it won’t charge anything.  </p>



<p>“We are announcing that as a customer goes through this transformation with HPE Morpheus VM Essentials, you don’t pay for the first year of licenses. You will get Zerto migration licenses during that period to help you move. And so what this does is it helps mitigate the double-bubble cost problem that customers see as they are looking to migrate from one platform to another,” Russo said. Zero-interest financing for HPE cloud ops software over three years further supports customer migration, Russo added. “This cost mitigation aims to accelerate customer adoption and ease transitions from legacy platforms,” Russo said.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Hong Kong watchdog launches data privacy academy to develop top talent in sector]]></title>
<description><![CDATA[Hong Kong’s privacy watchdog has launched a data privacy academy as part of efforts to align with the national strategy of developing the city into an international high-calibre talent hub.
Announcing the news at the 30th Anniversary Privacy Protection Summit on Tuesday, Privacy Commissioner for ...]]></description>
<link>https://tsecurity.de/de/3600995/it-security-nachrichten/hong-kong-watchdog-launches-data-privacy-academy-to-develop-top-talent-in-sector/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3600995/it-security-nachrichten/hong-kong-watchdog-launches-data-privacy-academy-to-develop-top-talent-in-sector/</guid>
<pubDate>Tue, 16 Jun 2026 09:53:32 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Hong Kong’s privacy watchdog has launched a data privacy academy as part of efforts to align with the national strategy of developing the city into an international high-calibre talent hub.
Announcing the news at the 30th Anniversary Privacy Protection Summit on Tuesday, Privacy Commissioner for Personal Data Ada Chung Lai-ling said the office would also strive to implement and support the city’s first five-year plan.
“As an educator and reformer, I am delighted to announce the launch of the...]]></content:encoded>
</item>
<item>
<title><![CDATA[Introducing Gemma 4 models on Amazon Bedrock]]></title>
<description><![CDATA[Today, we are announcing the availability of the Gemma 4 family on Amazon Bedrock. Built by Google DeepMind and released under the Apache 2.0 license, Gemma 4 is a family of open-weight models designed with a focus on intelligence-per-parameter across a broad range of deployment scenarios. The fa...]]></description>
<link>https://tsecurity.de/de/3600174/ai-nachrichten/introducing-gemma-4-models-on-amazon-bedrock/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3600174/ai-nachrichten/introducing-gemma-4-models-on-amazon-bedrock/</guid>
<pubDate>Mon, 15 Jun 2026 22:35:32 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Today, we are announcing the availability of the Gemma 4 family on Amazon Bedrock. Built by Google DeepMind and released under the Apache 2.0 license, Gemma 4 is a family of open-weight models designed with a focus on intelligence-per-parameter across a broad range of deployment scenarios. The family includes three instruction-tuned variants: Gemma 4 31B, Gemma 4 26B-A4B, and Gemma 4 E2B. These cover dense and mixture-of-experts (MoE) architectures, where only a fraction of the model’s parameters activate per request. The variants offer built-in reasoning, native function calling, and multimodal input across text and image.]]></content:encoded>
</item>
<item>
<title><![CDATA[Announcing new builds for 12 June 2026]]></title>
<description><![CDATA[Hello Windows Insiders,
We have a number of releases today with new builds across Beta, Experimental and Release Preview.
Release notes for inbox Windows 11 apps
Windows 11 inbox apps are now getting their own release notes sectio
The post Announcing new builds for 12 June 2026 appeared first on ...]]></description>
<link>https://tsecurity.de/de/3594153/windows-tipps/announcing-new-builds-for-12-june-2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3594153/windows-tipps/announcing-new-builds-for-12-june-2026/</guid>
<pubDate>Fri, 12 Jun 2026 19:23:31 +0200</pubDate>
<category>🪟 Windows Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Hello Windows Insiders,</p>
<p>We have a number of releases today with new builds across Beta, Experimental and Release Preview.</p>
<p><strong>Release notes for inbox Windows 11 apps</strong></p>
<p>Windows 11 inbox apps are now getting their own release notes sectio</p>
<p>The post <a href="https://blogs.windows.com/windows-insider/2026/06/12/announcing-new-builds-for-12-june-2026/">Announcing new builds for 12 June 2026</a> appeared first on <a href="https://blogs.windows.com/windows-insider">Windows Insider Blog</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[“500% Less”: How Elon Musk Math Fuels Trump]]></title>
<description><![CDATA[Let’s set aside the fact that what Elon Musk says about cars is a provable lie. Focus on his math here. over 500% *less* That’s Elon Musk math on fire safety. Now look at Trump, November 2025, announcing the GLP-1 deal with “tremendous cuts, 200 percent, 300 percent, 500 percent, 700 percent and ...]]></description>
<link>https://tsecurity.de/de/3592807/it-security-nachrichten/500-less-how-elon-musk-math-fuels-trump/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3592807/it-security-nachrichten/500-less-how-elon-musk-math-fuels-trump/</guid>
<pubDate>Fri, 12 Jun 2026 09:57:11 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Let’s set aside the fact that what Elon Musk says about cars is a provable lie. Focus on his math here. over 500% *less* That’s Elon Musk math on fire safety. Now look at Trump, November 2025, announcing the GLP-1 deal with “tremendous cuts, 200 percent, 300 percent, 500 percent, 700 percent and even more … <a href="https://www.flyingpenguin.com/500-less-how-elon-musk-math-fuels-trump/" class="more-link">Continue reading <span class="screen-reader-text">“500% Less”: How Elon Musk Math Fuels Trump</span> <span class="meta-nav">→</span></a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Opendoor Ends India Operations, Fueling a Bigger Conversation About AI and Outsourcing]]></title>
<description><![CDATA[Opendoor is shutting down its India operations less than two years after opening offices there. Slashdot reader alternative_right shares a post from Opendoor CEO Kaz Nejatian: "I shared this note earlier today with the entire team at Opendoor. Today we began to say goodbye to our colleagues in In...]]></description>
<link>https://tsecurity.de/de/3591380/it-security-nachrichten/opendoor-ends-india-operations-fueling-a-bigger-conversation-about-ai-and-outsourcing/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3591380/it-security-nachrichten/opendoor-ends-india-operations-fueling-a-bigger-conversation-about-ai-and-outsourcing/</guid>
<pubDate>Thu, 11 Jun 2026 19:08:29 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Opendoor is shutting down its India operations less than two years after opening offices there. Slashdot reader alternative_right shares a post from Opendoor CEO Kaz Nejatian: "I shared this note earlier today with the entire team at Opendoor. Today we began to say goodbye to our colleagues in India as we wind down our India operations. Our customers are in America, and that's where our operational work belongs." TechCrunch reports: In announcing the decision on Wednesday, CEO Kaz Nejatian cited a push to bring operational work back to the U.S., where Opendoor's customers are, and a shift toward smaller AI-native teams. The company did not respond to requests for comment on how many employees were affected or how much of the decision was driven by AI efficiency. But the announcement quickly gained traction across Silicon Valley, where founders, investors, and outsourcing experts see it as an early example of how AI is reshaping the economics that made India a global hub for back-office operations.
 
[...] Some investors viewed the decision as a sign of what AI could mean for India's vast outsourcing workforce. "As manual work gets replaced by AI, a lot of jobs will be lost in India," wrote Sheel Mohnot, co-founder of Better Tomorrow Ventures. Others viewed Opendoor as evidence of a larger shift in how companies are organized. Keshav Lohia, a venture capitalist at Emergent Ventures, described the decision as a "watershed moment" for AI-driven operations, arguing that advances in AI are beginning to challenge the cost-arbitrage model that made India a popular offshoring destination.
 
Phil Fersht, chief executive of HFS Research, an advisory firm that tracks the global outsourcing and business services industry, told TechCrunch that the development should not be viewed simply as jobs moving from India to the U.S. The more important shift, he said, is that AI is reducing the amount of operational labor companies require in the first place, allowing firms to run leaner organizations regardless of location. "This is not an isolated restructuring," Fersht said. "It is part of a much broader pattern we are starting to see as companies redesign operations around AI, automation, and much leaner workflows." Fersht argued that the winners would be companies that combine AI, software and human expertise to deliver outcomes without continually adding headcount, a model he described as "Services-as-Software." While Opendoor may be one of the first high-profile examples, he said it is unlikely to be the last.
 
Some investors are already extrapolating beyond individual companies. Varun Rekhi, a venture capitalist at Speedinvest, argued that if AI reduces demand for labor-intensive services, it could eventually pressure one of India's most important export industries, which is built around supplying talent and expertise to global corporations.<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=Opendoor+Ends+India+Operations%2C+Fueling+a+Bigger+Conversation+About+AI+and+Outsourcing%3A+https%3A%2F%2Fslashdot.org%2Fstory%2F26%2F06%2F11%2F070228%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fslashdot.org%2Fstory%2F26%2F06%2F11%2F070228%2Fopendoor-ends-india-operations-fueling-a-bigger-conversation-about-ai-and-outsourcing%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://slashdot.org/story/26/06/11/070228/opendoor-ends-india-operations-fueling-a-bigger-conversation-about-ai-and-outsourcing?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Xbox CEO Says Current Margins 'Cannot Continue']]></title>
<description><![CDATA[Xbox CEO Asha Sharma and Chief Content Officer Matt Booty told staff that Xbox's current economics "cannot continue," citing more than $20 billion in spending over five years, declining revenue outside Activision Blizzard King, console supply constraints tied to RAMaggedon, and an overextended st...]]></description>
<link>https://tsecurity.de/de/3591170/it-security-nachrichten/xbox-ceo-says-current-margins-cannot-continue/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3591170/it-security-nachrichten/xbox-ceo-says-current-margins-cannot-continue/</guid>
<pubDate>Thu, 11 Jun 2026 18:08:14 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Xbox CEO Asha Sharma and Chief Content Officer Matt Booty told staff that Xbox's current economics "cannot continue," citing more than $20 billion in spending over five years, declining revenue outside Activision Blizzard King, console supply constraints tied to RAMaggedon, and an overextended studio portfolio. The memo stops short of announcing layoffs, but a Bloomberg report says substantial Xbox cuts are expected after Microsoft's fiscal year ends on June 30. Engadget reports: The takeaways are pretty grim. For starters, the simple math of Xbox's revenue isn't adding up to success. "Excluding Activision Blizzard King, over the past five years, we have spent over $20 billion on ongoing investments in our content, platform, and hardware subsidy, but our annual revenue has declined nearly half a billion during that time," the execs state. "Going forward, this cannot continue." They also acknowledge the impact of RAMaggedon: "We are currently unable to make as many consoles as players want to buy, and we need a new business model and partnerships for hardware as we remain committed to Helix." (Helix, in this case, is Project Helix, the codename for Xbox's new console.)
 
Then there's the kicker, a renewed admission that Xbox still can't support the many studios it acquired in the late 2010s in an effort to grow its first-party game ambitions. "We have found ourselves over extended as we executed on changing strategies in a landscape of more readily available content," the pair said, noting elsewhere that with so many good games, not to mention the plethora of other forms of entertainment available, "Going forward, our competition is attention."<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=Xbox+CEO+Says+Current+Margins+'Cannot+Continue'%3A+https%3A%2F%2Fgames.slashdot.org%2Fstory%2F26%2F06%2F11%2F0646245%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fgames.slashdot.org%2Fstory%2F26%2F06%2F11%2F0646245%2Fxbox-ceo-says-current-margins-cannot-continue%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://games.slashdot.org/story/26/06/11/0646245/xbox-ceo-says-current-margins-cannot-continue?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Microsoft open sources AI evaluation framework for enterprise agents]]></title>
<description><![CDATA[Microsoft has open-sourced an AI evaluation framework that converts natural-language requirements into executable tests, expanding its push into enterprise AI governance as organizations struggle to validate agent behavior before production deployments systematically.



The framework, called ASS...]]></description>
<link>https://tsecurity.de/de/3590584/ai-nachrichten/microsoft-open-sources-ai-evaluation-framework-for-enterprise-agents/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3590584/ai-nachrichten/microsoft-open-sources-ai-evaluation-framework-for-enterprise-agents/</guid>
<pubDate>Thu, 11 Jun 2026 14:48:56 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Microsoft has open-sourced an AI evaluation framework that converts natural-language requirements into executable tests, expanding its push into enterprise AI governance as organizations struggle to validate agent behavior before production deployments systematically.</p>



<p>The framework, called ASSERT (Adaptive Spec-driven Scoring for Evaluation and Regression Testing), generates evaluation scenarios, datasets, metrics, and scorecards from written specifications, product requirements, and governance documents, <a href="https://commandline.microsoft.com/assert-written-intent-executable-evals/" target="_blank" rel="noreferrer noopener">Microsoft said in a blog post</a> announcing the release.</p>



<p>“Agents fail in ways that are hard to see,” Microsoft wrote in the blog post. “They drift from policy, produce unsafe outputs in edge cases, and behave differently in production than they did in testing. Generic benchmarks do not catch these failures because they are not built around your policies, your agent, or your use case.”</p>



<p>Rather than requiring developers to manually create evaluation suites, ASSERT translates written intent into reusable tests that can be integrated into AI development pipelines, the company said in the blog post.</p>



<p>With ASSERT, Microsoft is entering an increasingly competitive AI evaluation market that already includes platforms such as LangChain’s LangSmith, Braintrust, Patronus AI, Galileo, Arize AI’s Phoenix, and Promptfoo, which help enterprises benchmark, monitor, and validate large language model applications.</p>



<h2 class="wp-block-heading">Behavioral testing remains immature</h2>



<p>The release comes as enterprises rapidly expand AI agent deployments while formal evaluation practices remain the exception rather than the rule.</p>



<p>“Most organizations, in fact, 99% of them, do not evaluate any AI agents pre-production,” said Anushree Verma, senior director analyst at Gartner.</p>



<p>According to Verma, the industry’s next competitive advantage will depend less on advances in reasoning models than on how effectively organizations simulate and stress-test AI agents before deployment.</p>



<p>“The next competitive moat in agentic AI is not about the sophistication of reasoning models or the underlying architecture,” she said. “It will be about the depth and realism of the training environment through agentic simulation, particularly for mission-critical deployments.”</p>



<p>Gartner estimates that by 2029, more than 75% of domain-specific agents designed without agentic simulation in regulated industries will fail to deliver value.</p>



<p>Forrester sees enterprises moving toward behavioral evaluation but says most organizations have yet to make it a formal production requirement.</p>



<p>“Most enterprises are still in an intermediate stage where behavioral evaluation is inconsistently applied rather than treated as a formal production gate,” said Biswajeet Mahapatra, principal analyst at Forrester.</p>



<p>According to Forrester data, more than 45% of organizations are already using AI agents, and another 25% are piloting them, yet many continue to struggle with scaling because of immature governance and limited operational rigor.</p>



<p>“The net is that behavioral evaluation is becoming important, but for most organizations it is still ad hoc or tool-driven rather than a standardized release gate enforced across the lifecycle,” Mahapatra said.</p>



<h2 class="wp-block-heading">AI judges still need human oversight</h2>



<p>Microsoft said ASSERT uses large language models as judges, with model-generated evaluations agreeing with human reviewers 80% to 90% of the time in the company’s internal validation.</p>



<p>That level of agreement can help automate large portions of AI testing, but should not be treated as a standalone governance mechanism, Mahapatra said.</p>



<p>“An 80% to 90% agreement rate with human reviewers indicates strong alignment but is not sufficient as a standalone control for governance or compliance,” he said.</p>



<p>Instead, enterprises should adopt layered oversight where AI evaluates AI at scale while humans retain supervisory accountability for high-risk, regulated, or ambiguous scenarios. Buyers should also watch for bias, consistency issues, and overreliance on a single model acting as both generator and evaluator, he added.</p>



<h2 class="wp-block-heading">Open source reduces lock-in, not governance risk</h2>



<p>Microsoft released ASSERT under the MIT open-source license, allowing organizations to inspect, modify, and integrate the framework into existing AI development workflows.</p>



<p>But open sourcing a framework does not eliminate questions around evaluation neutrality, Mahapatra said.</p>



<p>“Open sourcing under an MIT license reduces lock-in concerns and enables broad interoperability across model ecosystems,” he said. “However, it does not fully eliminate trust or conflict-of-interest questions because the originating vendor still influences how evaluation criteria, scoring logic, and definitions of acceptable behaviour are encoded.”</p>



<p>Instead of relying on a single evaluation framework, enterprises should validate AI systems against multiple evaluation approaches and retain ownership of internal evaluation policies, he said.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[This Week In Rust: This Week in Rust 655]]></title>
<description><![CDATA[Hello and welcome to another issue of This Week in Rust!
Rust is a programming language empowering everyone to build reliable and efficient software.
This is a weekly summary of its progress and community.
Want something mentioned? Tag us at
@thisweekinrust.bsky.social on Bluesky or
@ThisWeekinRu...]]></description>
<link>https://tsecurity.de/de/3589813/tools/this-week-in-rust-this-week-in-rust-655/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3589813/tools/this-week-in-rust-this-week-in-rust-655/</guid>
<pubDate>Thu, 11 Jun 2026 10:13:12 +0200</pubDate>
<category>💾  Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Hello and welcome to another issue of <em>This Week in Rust</em>!
<a href="https://www.rust-lang.org/">Rust</a> is a programming language empowering everyone to build reliable and efficient software.
This is a weekly summary of its progress and community.
Want something mentioned? Tag us at
<a href="https://bsky.app/profile/thisweekinrust.bsky.social">@thisweekinrust.bsky.social</a> on Bluesky or
<a href="https://mastodon.social/@thisweekinrust">@ThisWeekinRust</a> on mastodon.social, or
<a href="https://github.com/rust-lang/this-week-in-rust">send us a pull request</a>.
Want to get involved? <a href="https://github.com/rust-lang/rust/blob/main/CONTRIBUTING.md">We love contributions</a>.</p>
<p><em>This Week in Rust</em> is openly developed <a href="https://github.com/rust-lang/this-week-in-rust">on GitHub</a> and archives can be viewed at <a href="https://this-week-in-rust.org/">this-week-in-rust.org</a>.
If you find any errors in this week's issue, <a href="https://github.com/rust-lang/this-week-in-rust/pulls">please submit a PR</a>.</p>
<p>Want TWIR in your inbox? <a href="https://this-week-in-rust.us11.list-manage.com/subscribe?u=fd84c1c757e02889a9b08d289&amp;id=0ed8b72485">Subscribe here</a>.</p>
<h4><a class="toclink" href="https://this-week-in-rust.org/atom.xml#updates-from-rust-community">Updates from Rust Community</a></h4>


<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#official">Official</a></h5>
<ul>
<li><a href="https://blog.rust-lang.org/inside-rust/2026/06/04/how-josh-helps-rust-manage-code-across-multiple-repositories/">How Josh helps Rust manage code across multiple repositories</a></li>
<li><a href="https://blog.rust-lang.org/inside-rust/2026/06/03/maintainer-spotlight-tiffany-pek-yuan-tiif/">Maintainer spotlight: Tiffany Pek Yuan (@tiif)</a></li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#newsletters">Newsletters</a></h5>
<ul>
<li><a href="https://rust-osdev.com/this-month/2026-05/">This Month in Rust OSDev: May 2026</a></li>
<li><a href="https://www.theembeddedrustacean.com/p/the-embedded-rustacean-issue-73">The Embedded Rustacean Issue #73</a></li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#projecttooling-updates">Project/Tooling Updates</a></h5>
<ul>
<li><a href="https://kerkour.com/stdx">Announcing stdx, Rust's extended standard library</a></li>
<li><a href="https://medium.com/p/dc57a4631f8b?postPublishedType=initial">OmniScope 0.2.0 released:FFI static detection tool based on LLVM IR</a></li>
<li><a href="https://asterinas.github.io/2026/06/04/announcing-asterinas-0.18.0.html">Announcing Asterinas 0.18.0</a></li>
<li><a href="https://github.com/wilsonglasser/oryxis/releases/tag/v0.8.0">Oryxis SSH 0.8: split panes</a></li>
<li><a href="https://ratatui.rs/highlights/v0301/">Ratatui 0.30.1 is released - a Rust library for cooking up terminal user interfaces</a></li>
<li><a href="https://utoo.land/en/docs/blog/utoopack-intro">@utoo/pack: A Next-Generation Build Tool Based on Turbopack</a></li>
<li><a href="https://felipebalbi.github.io/pico-de-gallo/">Pico de Gallo - a USB-attached protocol bridge for developing embedded-hal drivers on your laptop</a></li>
<li><a href="https://kunobi.ninja/blog/kache-v0-5-0">kache 0.5.0: designing a correct compile-cache key</a></li>
<li><a href="https://www.veszelovszki.com/a/smb2/">Announcing smb2: a very fast pure-Rust SMB2/3 client</a></li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#observationsthoughts">Observations/Thoughts</a></h5>
<ul>
<li><a href="https://smallcultfollowing.com/babysteps/blog/2026/06/09/only-bounds/">Only Bounds</a></li>
<li><a href="https://wasmer.io/posts/ported-wasmer-backend-django-to-rust">Porting our Django backend to Rust improved the infra usage by 90%</a></li>
<li><a href="https://wubingzheng.github.io/en/Decimal-Crates-Comparison.html">Decimal Crates Comparison and Benchmark</a> | <a href="https://wubingzheng.github.io/zh/Decimal-Crates-Comparison.html">Chinese version</a></li>
<li><a href="https://teaql.io/blog/robot-task-board-showcase/">TeaQL Robot Task Board: a Rust TUI showcase for auditable business workflows</a></li>
<li>[video] <a href="https://www.youtube.com/watch?v=QFQkqFSg8Z4">Rayon is NOT for games - use this instead</a></li>
<li>[audio] <a href="https://corrode.dev/podcast/s06e05-veo/">Veo with Anders Hellerup Madsen and Gorm Casper</a></li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#rust-walkthroughs">Rust Walkthroughs</a></h5>
<ul>
<li>[series] <a href="https://aibodh.com/posts/async-rust-chapter-1-hands-on-intro-to-async-rust/">Who Runs Your Rust Future? Hands-On Intro to Async Rust</a></li>
<li><a href="https://villagesql.com/blog/rust/">Extend MySQL Using Rust</a></li>
<li><a href="https://blog.sheerluck.dev/posts/learn-rust-smart-pointers-and-interior-mutability-by-building-git-commit-graph-viewer/">Learn Rust Smart Pointers and Interior Mutability by Building Git Commit Graph Viewer</a></li>
<li><a href="https://rustarians.com/heap-underflow/">heap underflow: classic algorithm solutions in idiomatic Rust, runnable in the browser</a></li>
</ul>
<h4><a class="toclink" href="https://this-week-in-rust.org/atom.xml#crate-of-the-week">Crate of the Week</a></h4>
<p>This week's crate is <a href="https://github.com/handewo/rustion">rustion</a>, a SSH bastion server.</p>
<p>Thanks to <a href="https://users.rust-lang.org/t/crate-of-the-week/2704/1610">handewo</a> for the self-suggestion!</p>
<p><a href="https://users.rust-lang.org/t/crate-of-the-week/2704">Please submit your suggestions and votes for next week</a>!</p>
<h4><a class="toclink" href="https://this-week-in-rust.org/atom.xml#calls-for-testing">Calls for Testing</a></h4>
<p>An important step for RFC implementation is for people to experiment with the
implementation and give feedback, especially before stabilization.</p>
<p>If you are a feature implementer and would like your RFC to appear in this list, add a
<code>call-for-testing</code> label to your RFC along with a comment providing testing instructions and/or
guidance on which aspect(s) of the feature need testing.</p>
<p><em>No calls for testing were issued this week by
<a href="https://github.com/rust-lang/rust/issues?q=state%3Aopen%20label%3Acall-for-testing%20state%3Aopen">Rust</a>,
<a href="https://github.com/rust-lang/cargo/issues?q=state%3Aopen%20label%3Acall-for-testing%20state%3Aopen">Cargo</a>,
<a href="https://github.com/rust-lang/rustup/issues?q=state%3Aopen%20label%3Acall-for-testing%20state%3Aopen">Rustup</a> or
<a href="https://github.com/rust-lang/rfcs/issues?q=label%3Acall-for-testing%20state%3Aopen">Rust language RFCs</a>.</em></p>
<p><a href="https://github.com/rust-lang/this-week-in-rust/issues">Let us know</a> if you would like your feature to be tracked as a part of this list.</p>
<h4><a class="toclink" href="https://this-week-in-rust.org/atom.xml#call-for-participation-projects-and-speakers">Call for Participation; projects and speakers</a></h4>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#cfp-projects">CFP - Projects</a></h5>
<p>Always wanted to contribute to open-source projects but did not know where to start?
Every week we highlight some tasks from the Rust community for you to pick and get started!</p>
<p>Some of these tasks may also have mentors available, visit the task page for more information.</p>

<ul>
<li><a href="https://github.com/ansidium/cuda-oxide-windows/issues/1">cuda-oxide Windows fork - test the Windows MSVC release on more CUDA/Windows setups</a></li>
<li><a href="https://github.com/MrSheerluck/openslate/issues/38">openslate - add unit tests for slugify() in api/src/notes.rs</a></li>
<li><a href="https://github.com/MrSheerluck/openslate/issues/70">openslate - add integration tests for notes CRUD in api/src/notes.rs</a></li>
<li><a href="https://github.com/MrSheerluck/openslate/issues/96">openslate - add integration tests for auth flow in api/src/users.rs</a></li>
<li><a href="https://github.com/MrSheerluck/openslate/issues/89">openslate - add unit tests for build_fts_query() in api/src/search.rs</a></li>
<li><a href="https://github.com/MrSheerluck/openslate/issues/106">openslate - add integration tests for auth middleware and logout in api/src/auth.rs</a></li>
<li><a href="https://github.com/MrSheerluck/openslate/issues/85">openslate - add integration tests for media endpoints (DB layer) in api/src/media.rs</a></li>
<li><a href="https://github.com/MrSheerluck/openslate/issues/40">openslate - add unit tests for ext_from_mime() and filename_from_url() in api/src/media.rs</a></li>
<li><a href="https://github.com/satyakwok/reliakit/issues/91">reliakit - add a typed_csv example to the umbrella crate</a></li>
<li><a href="https://github.com/satyakwok/reliakit/issues/92">reliakit - implement CsvField for char</a></li>
<li><a href="https://github.com/satyakwok/reliakit/issues/107">reliakit - implement CsvField for the core::net address types</a></li>
<li><a href="https://github.com/satyakwok/reliakit/issues/95">reliakit - write a short "which resilience block do I use?" guide</a></li>
<li><a href="https://github.com/satyakwok/reliakit/issues/94">reliakit - extract a reusable rolling-window counter from RollingBreaker</a></li>
</ul>



<p>If you are a Rust project owner and are looking for contributors, please submit tasks <a href="https://github.com/rust-lang/this-week-in-rust?tab=readme-ov-file#call-for-participation-guidelines">here</a> or through a <a href="https://github.com/rust-lang/this-week-in-rust">PR to TWiR</a> or by reaching out on <a href="https://bsky.app/profile/thisweekinrust.bsky.social">Bluesky</a> or <a href="https://mastodon.social/@thisweekinrust">Mastodon</a>!</p>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#cfp-events">CFP - Events</a></h5>
<p>Are you a new or experienced speaker looking for a place to share something cool? This section highlights events that are being planned and are accepting submissions to join their event as a speaker.</p>



<p>If you are an event organizer hoping to expand the reach of your event, please submit a link to the website through a <a href="https://github.com/rust-lang/this-week-in-rust">PR to TWiR</a> or by reaching out on <a href="https://bsky.app/profile/thisweekinrust.bsky.social">Bluesky</a> or <a href="https://mastodon.social/@thisweekinrust">Mastodon</a>!</p>
<h4><a class="toclink" href="https://this-week-in-rust.org/atom.xml#updates-from-the-rust-project">Updates from the Rust Project</a></h4>
<p>526 pull requests were <a href="https://github.com/search?q=is%3Apr+org%3Arust-lang+is%3Amerged+merged%3A2026-06-02..2026-06-09">merged in the last week</a></p>
<h6><a class="toclink" href="https://this-week-in-rust.org/atom.xml#compiler">Compiler</a></h6>
<ul>
<li><a href="https://github.com/rust-lang/rust/pull/157016">add <code>extern "tail"</code> calling convention</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/148820">add very basic "comptime" fn implementation</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/157009">avoid <code>unreachable_code</code> on required return values</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/157540">cleanup and optimize <code>render_impls</code></a></li>
<li><a href="https://github.com/rust-lang/rust/pull/156155">macros: report unbound metavariables directly</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/157252">rewrite <code>rustc_span::symbol::Interner</code> to avoid double hashing</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/155338">staticlib hide internal symbols</a></li>
</ul>
<h6><a class="toclink" href="https://this-week-in-rust.org/atom.xml#library">Library</a></h6>
<ul>
<li><a href="https://github.com/rust-lang/rust/pull/154742">add APIs for case folding to the standard library</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/154608">add <code>_value</code> API for number literals in proc-macro</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/156119">further optimize <code>SliceIndex&lt;str&gt;</code> impl for <code>Range&lt;usize&gt;</code></a></li>
<li><a href="https://github.com/rust-lang/rust/pull/143511">improve TLS codegen by marking the panic/init path as cold</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/155607">perf: use <code>get_unchecked</code> for <code>TwoWaySearcher</code></a></li>
<li><a href="https://github.com/rust-lang/rust/pull/156840">stabilize <code>PathBuf::into_string</code></a></li>
<li><a href="https://github.com/rust-lang/rust/pull/156222">stabilize <code>Result::map_or_default</code> and <code>Option::map_or_default</code></a></li>
</ul>
<h6><a class="toclink" href="https://this-week-in-rust.org/atom.xml#cargo">Cargo</a></h6>
<ul>
<li><a href="https://github.com/rust-lang/cargo/pull/17081">strip CR from <code>cargo:token-from-stdout</code></a></li>
</ul>
<h6><a class="toclink" href="https://this-week-in-rust.org/atom.xml#rustdoc">Rustdoc</a></h6>
<ul>
<li><a href="https://github.com/rust-lang/rust/pull/157262">IXCRE: preserve sizedness bounds on type params belonging to the parent item</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/157438">don't link <code>doc(hidden)</code> associated type projections</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/157233">fix trait impl ordering</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/157310">render <code>impl</code> restriction</a></li>
</ul>
<h6><a class="toclink" href="https://this-week-in-rust.org/atom.xml#clippy">Clippy</a></h6>
<ul>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17122">support <code>iter_mut</code> in <code>ITER_NEXT_SLICE</code></a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17173"><code>borrowed_box</code>: clean-up, improve suggestion message</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17144"><code>double_must_use</code>: make the lint machine-applicable in single-attribute case</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17174"><code>iter_cloned_collect</code>: split off the suggestion from the main message</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17037">add <code>manual_isolate_lowest_one</code> lint</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17146">detect more ranges in <code>single_range_in_vec_init</code></a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17131">do not trigger <code>inline_trait_bounds</code> on auto-derived code</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17031">extend <code>extra_unused_lifetimes</code> for spurious <code>for&lt;'a&gt;</code></a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17141"><code>large_const_arrays</code>: check nested large arrays</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17023">fix <code>explicit_counter_loop</code> false positive when the counter is only modified inside the <code>else</code> block of <code>let...else</code> binding</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17130">fix <code>result_large_err</code> and <code>result_unit_err</code> not triggering on async functions</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17181">fix <code>unused_async_trait_impl</code> suggestions with return statements</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17164">fix lints duplications in <code>unknown_attribute</code> and <code>renamed_builtin_attr</code></a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17121">obtaining the metadata of a const pointer is a const operation</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17135">perf: avoid cloning associated items in <code>empty_line_after</code></a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17168">perf: skip the <code>boxed_local</code> walk for functions without a Box parameter</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17137">perf: skip the <code>inline_always</code> relevance walk for items without the attribute</a></li>
</ul>
<h6><a class="toclink" href="https://this-week-in-rust.org/atom.xml#rust-analyzer">Rust-Analyzer</a></h6>
<ul>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22469"><code>feat(diagnostics)</code>: emit error for infer vars in non-inference contexts</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22505">adopt uv's AI policy</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22495">distribute windows builts with mimalloc</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22481">lower field defaults to <code>rustc_type_ir::Const</code>s</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22522"><code>RunnableKind::Test</code> should map to <code>project_json::RunnableKind::TestOne</code></a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22523"><code>extract_function</code> misses <code>&amp;mut</code> for <code>container[i].mut_method()</code></a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22520">do not emit a "type annotations needed" error on <code>include_bytes!()</code> where the array length cannot be inferred</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22519">no generate unused generic params in trait sign</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22524">parse OR pattern types</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22444">rename schema subItems with <code>sub_items</code></a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22448">implement <code>rust-analyzer/evaluatePredicate</code> lsp extension</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22512">parse unnamed <code>enum</code> variants</a></li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#rust-compiler-performance-triage">Rust Compiler Performance Triage</a></h5>
<p>A fairly noisy week, with a bunch of small regressions contained within,
leading to a slight increase on average in instruction counts. This week had a
lot of large rollups, likely due to some CI problems, but thankfully many of
those came with pre-triaged perf results by the time (thank you to those
triagers!). Roughly similar slight regressions for cycles and wall times across
the week.</p>
<p>Triage done by <strong>@simulacrum</strong>.
Revision range: <a href="https://perf.rust-lang.org/?start=4804ad7e93e1b31f4605b7083871d0d3d85a2afe&amp;end=f3ef3bd882dd24a275a60701a67c3bb330edd8c1&amp;absolute=false&amp;stat=instructions%3Au">4804ad7e..f3ef3bd8</a></p>
<p>2 Regressions, 0 Improvements, 10 Mixed; 5 of them in rollups
32 artifact comparisons made in total</p>
<p><a href="https://github.com/rust-lang/rustc-perf/blob/master/triage/2026/2026-06-08.md">Full report here</a></p>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#approved-rfcs"></a><a href="https://github.com/rust-lang/rfcs/commits/master">Approved RFCs</a></h5>
<p>Changes to Rust follow the Rust <a href="https://github.com/rust-lang/rfcs#rust-rfcs">RFC (request for comments) process</a>. These
are the RFCs that were approved for implementation this week:</p>
<ul>
<li><a href="https://github.com/rust-lang/rfcs/pull/3808"><code>#![register_{attribute,lint}_tool]</code></a></li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#final-comment-period">Final Comment Period</a></h5>
<p>Every week, <a href="https://www.rust-lang.org/team.html">the team</a> announces the 'final comment period' for RFCs and key PRs
which are reaching a decision. Express your opinions now.</p>
<h6><a class="toclink" href="https://this-week-in-rust.org/atom.xml#tracking-issues-prs">Tracking Issues &amp; PRs</a></h6>
<a class="toclink" href="https://this-week-in-rust.org/atom.xml#rust"></a><a href="https://github.com/rust-lang/rust/issues?q=is%3Aopen%20label%3Afinal-comment-period%20sort%3Aupdated-desc%20state%3Aopen">Rust</a>
<ul>
<li><a href="https://github.com/rust-lang/rust/pull/155421">Document panic in <code>RangeInclusive::from(legacy::RangeInclusive)</code></a></li>
<li><a href="https://github.com/rust-lang/rust/issues/116258">Tracking Issue for explicit-endian String::from_utf16</a></li>
<li><a href="https://github.com/rust-lang/rust/issues/126769">Tracking Issue for <code>substr_range</code> and related methods</a></li>
<li><a href="https://github.com/rust-lang/rust/issues/153990">Decide and document where stdarch intrinsics are allowed to diverge from asm behavior</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/155750">Document that <code>ManuallyDrop</code>'s Box interaction has been fixed</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/155739">Add temporary scope to assert_eq and assert_ne</a></li>
<li><a href="https://github.com/rust-lang/rust/issues/153863">Clean up crate type names to fix dylib vs staticlib confusion</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/156807">Add <code>T: PartialEq</code> bounds to derived <code>StructuralPartialEq</code> impls.</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/157029">stabilize feature <code>float_algebraic</code></a></li>
</ul>
<a class="toclink" href="https://this-week-in-rust.org/atom.xml#compiler-team-mcps-only"></a><a href="https://github.com/rust-lang/compiler-team/issues?q=label%3Amajor-change%20label%3Afinal-comment-period%20state%3Aopen">Compiler Team</a> <a href="https://forge.rust-lang.org/compiler/mcp.html">(MCPs only)</a>
<ul>
<li><a href="https://github.com/rust-lang/compiler-team/issues/999">Deny todo!() in tidy</a></li>
</ul>
<a class="toclink" href="https://this-week-in-rust.org/atom.xml#leadership-council"></a><a href="https://github.com/rust-lang/leadership-council/issues?q=state%3Aopen%20label%3Afinal-comment-period%20state%3Aopen">Leadership Council</a>
<ul>
<li><a href="https://github.com/rust-lang/leadership-council/issues/300">Rust All Hands 2027</a></li>
</ul>
<p><em>No Items entered Final Comment Period this week for
<a href="https://github.com/rust-lang/rfcs/issues?q=state%3Aopen%20label%3Afinal-comment-period%20state%3Aopen">Rust RFCs</a>,
<a href="https://github.com/rust-lang/cargo/issues?q=is%3Aopen%20label%3Afinal-comment-period%20sort%3Aupdated-desc%20state%3Aopen">Cargo</a>,
<a href="https://github.com/rust-lang/lang-team/issues?q=is%3Aopen%20label%3Afinal-comment-period%20sort%3Aupdated-desc%20state%3Aopen">Language Team</a>,
<a href="https://github.com/rust-lang/reference/issues?q=is%3Aopen%20label%3Afinal-comment-period%20sort%3Aupdated-desc%20state%3Aopen">Language Reference</a> or
<a href="https://github.com/rust-lang/unsafe-code-guidelines/issues?q=is%3Aopen%20label%3Afinal-comment-period%20sort%3Aupdated-desc%20state%3Aopen">Unsafe Code Guidelines</a>.</em></p>
<p>Let us know if you would like your PRs, Tracking Issues or RFCs to be tracked as a part of this list.</p>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#new-and-updated-rfcs"></a><a href="https://github.com/rust-lang/rfcs/pulls">New and Updated RFCs</a></h5>
<ul>
<li><a href="https://github.com/rust-lang/rfcs/pull/3968">RFC for convenient, explicit closure capture using move($expr) expressions</a></li>
</ul>
<h4><a class="toclink" href="https://this-week-in-rust.org/atom.xml#upcoming-events">Upcoming Events</a></h4>
<p>Rusty Events between 2026-06-10 - 2026-07-08 🦀</p>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#virtual">Virtual</a></h5>
<ul>
<li>2026-06-10 | Virtual (Girona, ES) | <a href="https://lu.ma/rust-girona">Rust Girona</a><ul>
<li><a href="https://luma.com/3bcnx1jb"><strong>Weekly coding session</strong></a></li>
</ul>
</li>
<li>2026-06-12 | Virtual (Kenya, KE) | <a href="https://luma.com/user/rustaceanskenya">RustaceansKenya</a><ul>
<li><a href="https://luma.com/vuxir9w8"><strong>RUST FOR CIVIC TECH</strong></a></li>
</ul>
</li>
<li>2026-06-16 | Virtual (Washington, DC, US) | <a href="https://www.meetup.com/rustdc">Rust DC</a><ul>
<li><a href="https://www.meetup.com/rustdc/events/314985751/"><strong>Mid-month Rustful</strong></a></li>
</ul>
</li>
<li>2026-06-17 | Hybrid (Vancouver, BC, CA) | <a href="https://www.meetup.com/vancouver-rust">Vancouver Rust</a><ul>
<li><a href="https://www.meetup.com/vancouver-rust/events/314000478/"><strong>Rust Study/Hack/Hang-out</strong></a></li>
</ul>
</li>
<li>2026-06-17 | Virtual (Girona, ES) | <a href="https://lu.ma/rust-girona">Rust Girona</a><ul>
<li><a href="https://luma.com/ekws5nr4"><strong>Weekly coding session</strong></a></li>
</ul>
</li>
<li>2026-06-18 | Hybrid (Seattle, WA, US) | <a href="https://www.meetup.com/join-srug">Seattle Rust User Group</a><ul>
<li><a href="https://www.meetup.com/seattle-rust-user-group/events/314236370/"><strong>June, 2026 SRUG (Seattle Rust User Group) Meetup</strong></a></li>
</ul>
</li>
<li>2026-06-18 | Virtual (Berlin, DE) | <a href="https://www.meetup.com/rust-berlin">Rust Berlin</a><ul>
<li><a href="https://www.meetup.com/rust-berlin/events/308455931/"><strong>Rust Hack and Learn</strong></a></li>
</ul>
</li>
<li>2026-06-21 | Virtual (Dallas, TX, US) | <a href="https://www.meetup.com/dallasrust">Dallas Rust User Meetup</a><ul>
<li><a href="https://www.meetup.com/dallasrust/events/314329044/"><strong>Rust Deep Learning: Third Sunday</strong></a></li>
</ul>
</li>
<li>2026-06-23 | Virtual (Dallas, TX, US) | <a href="https://www.meetup.com/dallasrust">Dallas Rust User Meetup</a><ul>
<li><a href="https://www.meetup.com/dallasrust/events/310254779/"><strong>Fourth Tuesday</strong></a></li>
</ul>
</li>
<li>2026-06-23 | Virtual (London, UK) | <a href="https://www.meetup.com/women-in-rust">Women in Rust</a><ul>
<li><a href="https://www.meetup.com/women-in-rust/events/313767883/"><strong>Lunch &amp; Learn: What the heck are monads - and how do we fake them in Rust</strong></a></li>
</ul>
</li>
<li>2026-07-01 | Virtual (Indianapolis, IN, US) | <a href="https://www.meetup.com/indyrs">Indy Rust</a><ul>
<li><a href="https://www.meetup.com/indyrs/events/wqzhftyjckbcb/"><strong>Indy.rs - with Social Distancing</strong></a></li>
</ul>
</li>
<li>2026-07-02 | Virtual (Berlin, DE) | <a href="https://www.meetup.com/rust-berlin/events/">Rust Berlin</a><ul>
<li><a href="https://www.meetup.com/rust-berlin/events/308455932/"><strong>Rust Hack and Learn</strong></a></li>
</ul>
</li>
<li>2026-07-02 | Virtual (Nürnberg, DE) | <a href="https://www.meetup.com/rust-noris/events/">Rust Nuremberg</a><ul>
<li><a href="https://www.meetup.com/rust-noris/events/313345243/"><strong>Rust Nürnberg online</strong></a></li>
</ul>
</li>
<li>2026-07-05 | Virtual (Dallas, TX, US) | <a href="https://www.meetup.com/dallasrust/events/">Dallas Rust User Meetup</a><ul>
<li><a href="https://www.meetup.com/dallasrust/events/314095287/"><strong>Rust Deep Learning: First Sunday</strong></a></li>
</ul>
</li>
<li>2026-07-07 | Virtual (London, GB) | <a href="https://www.meetup.com/women-in-rust/events/">Women in Rust</a><ul>
<li><a href="https://www.meetup.com/women-in-rust/events/315060981/"><strong>👋 Community Catch Up</strong></a></li>
</ul>
</li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#europe">Europe</a></h5>
<ul>
<li>2026-06-10 | Köln, DE | <a href="https://www.meetup.com/rust-cologne-bonn/events/">Rust Cologne</a><ul>
<li><a href="https://www.meetup.com/rustcologne/events/315090338/"><strong>Rust in June: Speedy Rust</strong></a></li>
</ul>
</li>
<li>2026-06-10 | München, DE | <a href="https://www.meetup.com/rust-munich">Rust Munich</a><ul>
<li><a href="https://www.meetup.com/rust-munich/events/313791798/"><strong>Rust Munich 2026 / 2 - Hacking Evening</strong></a></li>
</ul>
</li>
<li>2026-06-11 | Berlin, DE | <a href="https://www.meetup.com/rust-berlin/events/">Rust Berlin</a><ul>
<li><a href="https://www.meetup.com/rust-berlin/events/315088919/"><strong>Rust Berlin on location 🏳️‍🌈 - Edition 014</strong></a></li>
</ul>
</li>
<li>2026-06-11 | Switzerland, CH | <a href="https://www.posttenebraslab.ch/wiki/events/start">PostTenebrasLab</a><ul>
<li><a href="https://www.posttenebraslab.ch/wiki/events/monthly_meeting/rust_meetup"><strong>Rust Meetup Geneva</strong></a></li>
</ul>
</li>
<li>2026-06-12 - 2026-06-14 | Kraków, PL | <a href="https://rustmeet.eu/">Rustmeet</a><ul>
<li><a href="https://rustmeet.eu/"><strong>Rustmeet</strong></a></li>
</ul>
</li>
<li>2026-06-16 | Leipzig, DE | <a href="https://www.meetup.com/rust-modern-systems-programming-in-leipzig">Rust - Modern Systems Programming in Leipzig</a><ul>
<li><a href="https://www.meetup.com/rust-modern-systems-programming-in-leipzig/events/313813937/"><strong>Interactive: Everything is Open Source</strong></a></li>
</ul>
</li>
<li>2026-06-16 | Milano, IT | <a href="https://www.meetup.com/rust-language-milano">Rust Language Milan</a><ul>
<li><a href="https://www.meetup.com/rust-language-milan/events/314766950/"><strong>Real-time planning in Rust: SolverForge &amp; SERIO</strong></a></li>
</ul>
</li>
<li>2026-06-18 | Aarhus, DK | <a href="https://www.meetup.com/rust-aarhus">Rust Aarhus</a><ul>
<li><a href="https://www.meetup.com/rust-aarhus/events/314965238/"><strong>Talk Night at Danske Commodities</strong></a></li>
</ul>
</li>
<li>2026-06-18 | Barcelona, ES | <a href="https://www.meetup.com/bcnrust/events/">BcnRust</a><ul>
<li><a href="https://www.meetup.com/bcnrust/events/315094938/"><strong>21st BcnRust Meetup</strong></a></li>
</ul>
</li>
<li>2026-06-19 | Dresden, DE | <a href="https://github.com/rust-dresden">Rust Dresden</a><ul>
<li><a href="https://pretix.eu/rust-dresden/on-location-2"><strong>Second Meetup</strong></a></li>
</ul>
</li>
<li>2026-06-23 | Paris, FR | <a href="https://www.meetup.com/rust-paris">Rust Paris</a><ul>
<li><a href="https://www.meetup.com/rust-paris/events/315040676/"><strong>Rust meetup #86</strong></a></li>
</ul>
</li>
<li>2026-06-23 | Warsaw, PL | <a href="https://luma.com/rust.in.warsaw">Rust Warsaw</a><ul>
<li><a href="https://luma.com/djs7ntfx"><strong>Rust Warsaw Meetup: June 2026</strong></a></li>
</ul>
</li>
<li>2026-06-25 | Berlin, DE | <a href="https://www.meetup.com/rust-berlin">Rust Berlin</a><ul>
<li><a href="https://www.meetup.com/rust-berlin/events/314396600/"><strong>Rust Berlin Talks: The next generation</strong></a></li>
</ul>
</li>
<li>2026-07-02 | Edinburgh, GB | <a href="https://www.meetup.com/rust-edi/events/">Rust and Friends</a><ul>
<li><a href="https://www.meetup.com/rust-and-friends/events/314941098/"><strong>Bevy, Bits, &amp; Cats (Rust July Talks)</strong></a></li>
</ul>
</li>
<li>2026-07-02 | Enschede, OV, NL | <a href="https://www.meetup.com/dutch-rust-meetup/events/">Baseflow Tech Meetups</a><ul>
<li><a href="https://www.meetup.com/baseflow-tech-meetups/events/315099547/"><strong>AI Summit</strong></a></li>
</ul>
</li>
<li>2026-07-08 | Dublin, IE | <a href="https://www.meetup.com/rust-dublin/events/">Rust Dublin</a><ul>
<li><a href="https://www.meetup.com/rust-dublin/events/315150327/"><strong>Join us live and INPERSON for Rust 261</strong></a></li>
</ul>
</li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#north-america">North America</a></h5>
<ul>
<li>2026-06-11 | Lehi, UT, US | <a href="https://www.meetup.com/utah-rust">Utah Rust</a><ul>
<li><a href="https://www.meetup.com/utah-rust/events/314696643/"><strong>Utah Rust June Meetup</strong></a></li>
</ul>
</li>
<li>2026-06-11 | Mountain View, CA, US | <a href="https://www.meetup.com/hackerdojo/events/">Hacker Dojo</a><ul>
<li><a href="https://www.meetup.com/hackerdojo/events/314825006/"><strong>RUST MEETUP at HACKER DOJO</strong></a></li>
</ul>
</li>
<li>2026-06-11 | San Diego, CA, US | <a href="https://www.meetup.com/san-diego-rust">San Diego Rust</a><ul>
<li><a href="https://www.meetup.com/san-diego-rust/events/313721899/"><strong>San Diego Rust June Meetup - Back in person!</strong></a></li>
</ul>
</li>
<li>2026-06-16 | San Francisco, CA, US | <a href="https://www.meetup.com/san-francisco-rust-study-group">San Francisco Rust Study Group</a><ul>
<li><a href="https://www.meetup.com/san-francisco-rust-study-group/events/314989012/"><strong>Rust Hacking in Person</strong></a></li>
</ul>
</li>
<li>2026-06-16 | San Francisco, CA, US | <a href="https://www.meetup.com/san-francisco-rust-study-group">San Francisco Rust Study Group</a><ul>
<li><a href="https://www.meetup.com/san-francisco-rust-study-group/events/ghhwqtyjcjbvb/"><strong>Rust Hacking in Person</strong></a></li>
</ul>
</li>
<li>2026-06-17 | Hybrid (Vancouver, BC, CA) | <a href="https://www.meetup.com/vancouver-rust">Vancouver Rust</a><ul>
<li><a href="https://www.meetup.com/vancouver-rust/events/314000478/"><strong>Rust Study/Hack/Hang-out</strong></a></li>
</ul>
</li>
<li>2026-06-18 | Hybrid (Seattle, WA, US) | <a href="https://www.meetup.com/join-srug">Seattle Rust User Group</a><ul>
<li><a href="https://www.meetup.com/seattle-rust-user-group/events/314236370/"><strong>June, 2026 SRUG (Seattle Rust User Group) Meetup</strong></a></li>
</ul>
</li>
<li>2026-06-24 | Austin, TX, US | <a href="https://www.meetup.com/rust-atx">Rust ATX</a><ul>
<li><a href="https://www.meetup.com/rust-atx/events/xvkdgtyjcjbgc/"><strong>Rust Lunch - Fareground</strong></a></li>
</ul>
</li>
<li>2026-06-24 | Los Angeles, CA, US | <a href="https://www.meetup.com/rust-los-angeles">Rust Los Angeles</a><ul>
<li><a href="https://www.meetup.com/rust-los-angeles/events/314386080/"><strong>Rust LA: Rust-Based Constraint Solvers in 2D Sketching with Zoo Technologies</strong></a></li>
</ul>
</li>
<li>2026-06-25 | Atlanta, GA, US | <a href="https://www.meetup.com/rust-atl">Rust Atlanta</a><ul>
<li><a href="https://www.meetup.com/rust-atl/events/313539326/"><strong>Rust-Atl</strong></a></li>
</ul>
</li>
<li>2026-06-26 | New York, NY, US | <a href="https://www.meetup.com/rust-nyc">Rust NYC</a><ul>
<li><a href="https://www.meetup.com/rust-nyc/events/315014582/"><strong>Rust NYC's Big Summer Social</strong></a></li>
</ul>
</li>
<li>2026-07-02 | Saint Louis, MO, US | <a href="https://www.meetup.com/stl-rust/events/">STL Rust</a><ul>
<li><a href="https://www.meetup.com/stl-rust/events/315103359/"><strong>Git is easy?</strong></a></li>
</ul>
</li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#oceania">Oceania</a></h5>
<ul>
<li>2026-06-11 | Brisbane City, QL, AU | <a href="https://www.meetup.com/rust-brisbane/events/">Rust Brisbane</a><ul>
<li><a href="https://www.meetup.com/rust-brisbane/events/315092980/"><strong>Rust Brisbane • June 2026</strong></a></li>
</ul>
</li>
<li>2026-06-25 | Melbourne, AU | <a href="https://www.meetup.com/rust-melbourne">Rust Melbourne</a><ul>
<li><a href="https://www.meetup.com/rust-melbourne/events/315039461/"><strong>Rust Melbourne June 2026</strong></a></li>
</ul>
</li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#south-america">South America</a></h5>
<ul>
<li>2026-06-18 | Florianópolis, BR | <a href="https://luma.com/rust-sc">Rust SC</a><ul>
<li><a href="https://luma.com/acinctdf"><strong>Rust Floripa</strong></a></li>
</ul>
</li>
</ul>
<p>If you are running a Rust event please add it to the <a href="https://www.google.com/calendar/embed?src=apd9vmbc22egenmtu5l6c5jbfc%40group.calendar.google.com">calendar</a> to get
it mentioned here. Please remember to add a link to the event too.
Email the <a href="mailto:community-team@rust-lang.org">Rust Community Team</a> for access.</p>
<h4><a class="toclink" href="https://this-week-in-rust.org/atom.xml#jobs">Jobs</a></h4>
<p>Please see the latest <a href="https://www.reddit.com/r/rust/comments/1ttbtf5/official_rrust_whos_hiring_thread_for_jobseekers/">Who's Hiring thread on r/rust</a></p>
<h3><a class="toclink" href="https://this-week-in-rust.org/atom.xml#quote-of-the-week">Quote of the Week</a></h3>
<blockquote>
<p>It's a footgun, yes, but it's a sound footgun.</p>
</blockquote>
<p>– <a href="https://github.com/rust-lang/rust/pull/155750#discussion_r3356323620">Prof. Dr. Ralf Jung on github</a></p>
<p>Thanks to <a href="https://users.rust-lang.org/t/twir-quote-of-the-week/328/1779">Theemathas</a> for the suggestion!</p>
<p><a href="https://users.rust-lang.org/t/twir-quote-of-the-week/328">Please submit quotes and vote for next week!</a></p>
<p>This Week in Rust is edited by:</p>
<ul>
<li><a href="https://github.com/nellshamrell">nellshamrell</a></li>
<li><a href="https://github.com/llogiq">llogiq</a></li>
<li><a href="https://github.com/ericseppanen">ericseppanen</a></li>
<li><a href="https://github.com/extrawurst">extrawurst</a></li>
<li><a href="https://github.com/U007D">U007D</a></li>
<li><a href="https://github.com/mariannegoldin">mariannegoldin</a></li>
<li><a href="https://github.com/bdillo">bdillo</a></li>
<li><a href="https://github.com/opeolluwa">opeolluwa</a></li>
<li><a href="https://github.com/bnchi">bnchi</a></li>
<li><a href="https://github.com/KannanPalani57">KannanPalani57</a></li>
<li><a href="https://github.com/tzilist">tzilist</a></li>
</ul>
<p><em>Email list hosting is sponsored by <a href="https://foundation.rust-lang.org/">The Rust Foundation</a></em></p>
<p><small><a href="https://www.reddit.com/r/rust/comments/1u2rz3a/this_week_in_rust_655/">Discuss on r/rust</a></small></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Improvements to Out-of-Domain file-level warnings]]></title>
<description><![CDATA[Today, we’re announcing improvements to our Out-of-Domain file-level warnings. First launched in April 2025, these badges alert users to documents and users outside of their Workspace organization, helping to prevent accidental data exfiltration and potential phishing attacks that spoof internal ...]]></description>
<link>https://tsecurity.de/de/3589223/web-tipps/improvements-to-out-of-domain-file-level-warnings/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3589223/web-tipps/improvements-to-out-of-domain-file-level-warnings/</guid>
<pubDate>Thu, 11 Jun 2026 01:55:01 +0200</pubDate>
<category>Web Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Today, we’re announcing improvements to our Out-of-Domain file-level warnings. First launched in April 2025, these badges alert users to documents and users outside of their Workspace organization, helping to prevent accidental data exfiltration and potential phishing attacks that spoof internal content. We’ve expanded support across devices and sharing types in the following ways:<div><br><div><ul><li>Files in the Android and iOS apps for Drive, Docs, Sheets, and Slides now include external indicators</li><li>Chat Spaces and Google Groups can be configured to allow external users; if they’re given access to a document, that document now shows the external badge</li><li>If a service account has access to a document, and that service account is owned by an external Google Cloud organization, it now triggers the external badge in documents</li><li>Comment email notifications now include badges for external documents and users</li><li>File sharing email notifications now include badges for external documents and users</li></ul></div><div><b><br></b></div><div><b>How Out-of-Domain warnings work</b></div><div><br></div><div>This feature helps users identify potentially risky files and avoid phishing scams when working with files shared from outside your organization.</div><div><br></div><table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container"><tbody><tr><td><a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgQy2JIt2r0a8lr3MNeIuRiSuWjhJ5MfoLAKUis3IGNYLEF9k5OyEXvWJfHHjoYi6MDncizwtrU7UvVqD7UxnQPtpn0RKHWZRMDdIKkzZknCClJXBdvfWhSHDD9fvlQhERRDg5eftlvmJgn7qwhVllnRFFPi6ItEjAf8Ewq6QhWw3ZxwxjNiHm5aL-sXxY/s2048/Improvements%20to%20Out-of-Domain%20file-level%20warnings%20-%201.png"><img border="0" data-original-height="2048" data-original-width="1262" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgQy2JIt2r0a8lr3MNeIuRiSuWjhJ5MfoLAKUis3IGNYLEF9k5OyEXvWJfHHjoYi6MDncizwtrU7UvVqD7UxnQPtpn0RKHWZRMDdIKkzZknCClJXBdvfWhSHDD9fvlQhERRDg5eftlvmJgn7qwhVllnRFFPi6ItEjAf8Ewq6QhWw3ZxwxjNiHm5aL-sXxY/s16000/Improvements%20to%20Out-of-Domain%20file-level%20warnings%20-%201.png"></a></td></tr><tr><td class="tr-caption"><span><span face='"Google Sans Text", sans-serif'>Notification in comments</span></span></td></tr></tbody></table><table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container"><tbody><tr><td><a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj1Xjq4IfzCvgL5np8UW-30Rvcts3_4ly80zvqhEzyAMcHtJEqbN3uy0LkgkdYv6aM0AbgwVwiF_P1R0e2z301tscCd2mviEglB9p5uC-DHaN5iy_qXIDXaEDMVb1ohCQGApWVeHUTFgnycinBy75DBthiebYhKqTdlPtCIRpgoVKrXf_uacwtMs17CekQ/s1924/Improvements%20to%20Out-of-Domain%20file-level%20warnings%20-%202.png"><img border="0" data-original-height="1924" data-original-width="1504" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj1Xjq4IfzCvgL5np8UW-30Rvcts3_4ly80zvqhEzyAMcHtJEqbN3uy0LkgkdYv6aM0AbgwVwiF_P1R0e2z301tscCd2mviEglB9p5uC-DHaN5iy_qXIDXaEDMVb1ohCQGApWVeHUTFgnycinBy75DBthiebYhKqTdlPtCIRpgoVKrXf_uacwtMs17CekQ/s16000/Improvements%20to%20Out-of-Domain%20file-level%20warnings%20-%202.png"></a></td></tr><tr><td class="tr-caption"><span><p dir="ltr"><span face='"Google Sans Text", sans-serif'>Notification in file sharing email</span></p></span></td></tr></tbody></table><table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container"><tbody><tr><td><a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhqHshXomWaOj6QPCMrIba4nSBkHCcN40xQdEQeq0LxhfT4miuI0CexK2rEQ3AzYb4VeHlzamYtBA-RG8pv5AdUfyMFZLQXE3ioAB9wmpZPw7l-RdON11GZ8HUmNZp2Zcs7rxoeZ73DzfsI3hPa-1BqcBU_t8MhmABG475_BSh_RXguPiZJn9z6iiYj42w/s979/Improvements%20to%20Out-of-Domain%20file-level%20warnings%20-%203.png"><img alt='An image showing a Google Doc with the word "External" displayed in a small yellow badge next to the document title. The badge has been clicked, and a pop-up window appears with more information stating that “This document is owned by someone outside your organization. Be cautious about sharing sensitive information.' border="0" data-original-height="350" data-original-width="979" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhqHshXomWaOj6QPCMrIba4nSBkHCcN40xQdEQeq0LxhfT4miuI0CexK2rEQ3AzYb4VeHlzamYtBA-RG8pv5AdUfyMFZLQXE3ioAB9wmpZPw7l-RdON11GZ8HUmNZp2Zcs7rxoeZ73DzfsI3hPa-1BqcBU_t8MhmABG475_BSh_RXguPiZJn9z6iiYj42w/s16000/Improvements%20to%20Out-of-Domain%20file-level%20warnings%20-%203.png"></a></td></tr><tr><td class="tr-caption"><span><span face='"Google Sans Text", sans-serif'>Image of "External" badge displayed in Google Docs</span></span></td></tr></tbody></table><h3>Getting started</h3><div><ul><li><b>Admins: </b>This feature is <b>ON</b> by default and can be disabled at the domain and organizational level. Visit the Help Center to <a href="https://support.google.com/a/answer/60781" target="_blank">learn more about turning Out-of-Domain Warnings on or off for your organization</a>.</li><li><b>End users:</b> This feature is ON by default. There is no end-user setting for this feature. Visit the Help Center to <a href="https://support.google.com/drive/answer/2494822?hl=en#:~:text=Learn%20about%20alerts%20for%20external%20files" target="_blank">learn more about sharing files from Google Drive</a>.</li></ul><table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container"><tbody><tr><td><a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi7mo3hbQeWyBTL9WKeDT_Cz7e3UcbHbs0DHJBK8yTnLOUylNcfS9Z0axncnIjEI0D45CaUu_CYikMbp2FVdjGKj-pQGMYJRORf8CiWlQU1EY-HReZFBUVwjjG-qA2kcv-IR9gLN1aybGnggFH9Z-5fg_pDYn1-1dJtG_-unFRfhv2AD2-uFJETUJqHaMc/s2048/Improvements%20to%20Out-of-Domain%20file-level%20warnings%20-%204.png"><img alt='Screenshot of the Google Workspace Admin console, navigated to Sharing settings. At the bottom of the page, a new section labeled "Highlight external files" is highlighted. The checkbox is checked, and the description reads: "Mark external files shared or owned externally as “external” to flag that content may be viewable outside your organization.' border="0" data-original-height="1427" data-original-width="2048" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi7mo3hbQeWyBTL9WKeDT_Cz7e3UcbHbs0DHJBK8yTnLOUylNcfS9Z0axncnIjEI0D45CaUu_CYikMbp2FVdjGKj-pQGMYJRORf8CiWlQU1EY-HReZFBUVwjjG-qA2kcv-IR9gLN1aybGnggFH9Z-5fg_pDYn1-1dJtG_-unFRfhv2AD2-uFJETUJqHaMc/s16000/Improvements%20to%20Out-of-Domain%20file-level%20warnings%20-%204.png"></a></td></tr><tr><td class="tr-caption"><span><span face='"Google Sans Text", sans-serif'>Image of the Google Workspace Admin console, Sharing settings, showing the "Highlight external files" option enabled</span></span></td></tr></tbody></table></div><h3>Rollout pace</h3><div><ul><li><a href="https://support.google.com/a/answer/172177" target="_blank">Rapid Release and Scheduled Release domains:</a> Available now</li></ul></div><h3>Availability</h3><div><ul><li>Available to all Google Workspace customers</li></ul></div><h3>Resources</h3><div><ul><li>Google Workspace Admin Help: <a href="https://knowledge.workspace.google.com/admin/drive/manage-external-sharing-for-your-organization" target="_blank">Manage external sharing for your organization</a></li><li>Google Drive Help: <a href="https://support.google.com/drive/answer/2494822?hl=en#:~:text=Learn%20about%20alerts%20for%20external%20files" target="_blank">Share files from Google Drive - Android</a></li><li>Google Drive Help: <a href="https://support.google.com/drive/answer/2494893?hl=en#:~:text=Learn%20about%20alerts%20for%20external%20files" target="_blank">Stop, limit, or change sharing</a></li><li>Google Workspace Updates Blog: <a href="https://workspaceupdates.googleblog.com/2025/04/out-of-domain-file-warnings-for-drive-docs-sheets-slides-files.html" target="_blank">Enhance Your Organization’s Security with Out-of-Domain File Warnings in Google Workspace</a></li></ul></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Google Workspace Updates Weekly Recap - May 29, 2026]]></title>
<description><![CDATA[Introducing a fresh visual identity for Google Workspace app iconsWe’re updating icons across Google Workspace to introduce a modern visual design that gives every app a more distinct identity. Over the next several weeks, users will see new icons for Gmail, Calendar, Chat, Meet, Drive, Docs, Sli...]]></description>
<link>https://tsecurity.de/de/3589212/web-tipps/google-workspace-updates-weekly-recap-may-29-2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3589212/web-tipps/google-workspace-updates-weekly-recap-may-29-2026/</guid>
<pubDate>Thu, 11 Jun 2026 01:54:48 +0200</pubDate>
<category>Web Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h3>Introducing a fresh visual identity for Google Workspace app icons</h3><div>We’re updating icons across Google Workspace to introduce a modern visual design that gives every app a more distinct identity. Over the next several weeks, users will see new icons for Gmail, Calendar, Chat, Meet, Drive, Docs, Slides, Sheets, Vids, Keep, Forms, Voice, Sites, and Tasks. | Learn more about <a href="https://workspaceupdates.googleblog.com/2026/05/introducing-fresh-visual-identity-for-Google-Workspace-app-icons.html" target="_blank">the new fresh visual identity for Google Workspace app icons</a>.</div><h3>Simplify decision-making with Polly, now available for Google Chat</h3><div>Making decisions in a fast-paced environment often leads to long, messy threads and lost consensus. Polly helps teams solve this by enabling the creation of interactive polls within existing Chat conversations. | Learn more about <a href="https://workspaceupdates.googleblog.com/2026/05/simplify-decision-making-with-polly-now-available-for-Google-Chat.html" target="_blank">how to Simplify decision-making with Polly, now available for Google Chat</a>.</div><h3>Improvements to Out-of-Domain file-level warnings</h3><div>We’re announcing improvements to our Out-of-Domain file-level warnings. First launched in April 2025, these badges alert users to documents and users outside of their Workspace organization, helping to prevent accidental data exfiltration and potential phishing attacks that spoof internal content. | Learn more about <a href="https://workspaceupdates.googleblog.com/2026/05/improvements-to-out-of-domain-file-level-warnings.html" target="_blank">the improvements to Out-of-Domain file-level warnings</a>.</div><h3>Keep your sources up to date with automatic Drive syncing in NotebookLM</h3><div>We’re making it easier to keep your sources and insights current in NotebookLM by enabling automatic syncing with Google Drive. Previously, if you uploaded a file in Google Docs, Sheets, or Slides, you’d have to manually update it in NotebookLM to see the changes. With this update, as the content in your Drive files evolves, the information within the notebook updates automatically to match. | Learn more about <a href="https://workspaceupdates.googleblog.com/2026/05/keep-your-sources-up-to-date-with-automatic-Drive-syncing-in-NotebookLM.html" target="_blank">how to Keep your sources up to date with automatic Drive syncing in NotebookLM</a>.</div><h3>Gemini LTI Update: Include your LMS sources when using NotebookLM in Powerschool Schoology</h3><div>When creating a notebook in Powerschool Schoology, Gemini LTI users can now add content directly from their course as sources. This integration allows educators and students to seamlessly bridge their course materials with AI-powered research and analysis, and generate Studio artifacts like Audio and Video Overviews, infographics, slide decks, and more based on their Schoology resources. | Learn more about <a href="https://workspaceupdates.googleblog.com/2026/05/gemini-lti-update-include-your-lms-sources-when-using-NotebookLM-in-Powerschool-Schoology.html" target="_blank">how to include your LMS sources when using NotebookLM in Powerschool Schoology</a>.</div><h3>More granular admin controls for Workspace Studio steps and starters</h3><div>We’re introducing more granular admin controls for Workspace Studio steps and starters. With these new controls, admins can define which steps and starters people in their organization can use to create flows, including by Workspace service or individually. | Learn more about <a href="https://workspaceupdates.googleblog.com/2026/05/more-granular-admin-controls-for-Workspace-Studio-steps-and-starters.html" target="_blank">more granular admin controls for Workspace Studio steps and starters</a>.</div><h3>Easily identify data irregularities with anomaly detection in Connected Sheets</h3><div>You can now easily identify critical irregularities and outliers in your time-series data when using Connected Sheets to analyze BigQuery data sets from Google Sheets. Anomaly detection in Connected Sheets allows users to distinguish between expected trends and true outliers without requiring manual model training or complex SQL knowledge. | Learn more about <a href="https://workspaceupdates.googleblog.com/2026/05/easily-identify-data-irregularities-with-anomaly-detection-in-Connected-Sheets.html" target="_blank">how to easily identify data irregularities with anomaly detection in Connected Sheets</a>.</div><h3>Ask Gemini in Google Meet is becoming more easily accessible on web</h3><div>We’re excited to announce that we’re making the feature more easily accessible by moving the Ask Gemini prompt box into the bottom left-hand corner of the Google Meet web interface. | Learn more about <a href="https://workspaceupdates.googleblog.com/2026/05/ask-gemini-in-google-meet-is-becoming-more-easily-accessible-on-web.html" target="_blank">how ask Gemini in Google Meet is becoming more easily accessible on web</a>.</div><h3>Prevent account takeovers with Device Bound Session Credentials (DBSC), now generally available in the Chrome browser for Windows</h3><div>Previously available in beta, Device Bound Session Credentials (DBSC) in the Chrome browser on Windows is now generally available and enabled by default for Google Workspace users. | Learn more about <a href="https://workspaceupdates.googleblog.com/2026/05/prevent-account-takeovers-with-DBSC-now-generally-available-in-the-Chrome-browser-for-Windows.html" target="_blank">how to prevent account takeovers with Device Bound Session Credentials (DBSC), now generally available in the Chrome browser for Windows</a>.</div><h3>Share chats, canvases, and generated media from the Gemini app securely via Google Drive</h3><div>We are introducing the ability for Workspace users on the web to share snapshots of their chats, canvases, and generated media in the Gemini app. | Learn more about <a href="https://workspaceupdates.googleblog.com/2026/04/share-chats-canvases-and-generated-media-from-the-Gemini-app-securely-via-Google-Drive.html" target="_blank">how to share chats, canvases, and generated media from the Gemini app securely via Google Drive</a>.</div><h3>Google Chat external interoperability with Microsoft Teams via NextPlane OpenHub is now available </h3><div>Organizations often need to collaborate with customers, partners, and suppliers who use Microsoft Teams. NextPlane OpenHub was built to bridge this Google Chat and Microsoft Teams divide, and it is now launching external interoperability to allow communication across organizational boundaries. | Learn more about <a href="https://workspaceupdates.googleblog.com/2026/05/google-chat-external-interoperability-with-Microsoft-Teams-via-NextPlane-OpenHub-is-now-available.html" target="_blank">how Google Chat external interoperability with Microsoft Teams via NextPlane OpenHub is now available</a>.</div><div><br></div><h3>Available in beta: Convert your client-side encrypted Slides after a Vault or Takeout export</h3><div>Admins can now bulk export client-side encrypted (CSE) Slides using Vault or Data Export (takeout), and then convert those exports into PowerPoint files. This allows your organization to retain complete ownership, access, and control of sensitive data in a highly portable format. | Learn more about <a href="https://workspaceupdates.googleblog.com/2026/05/available-in-beta-convert-your-client-side-encrypted-Slides-after-a-Vault-or-Takeout-export.html" target="_blank">how to Convert your client-side encrypted Slides after a Vault or Takeout export</a>.</div><div><br></div><h3>Keep track of student progress with learning standards and skills in Google Classroom</h3><div>Google Classroom now allows educators to tag coursework and rubrics with learning goals, including specific learning standards and skills, providing a more structured way to monitor student growth. | Learn more about <a href="https://workspaceupdates.googleblog.com/2026/05/keep-track-of-student-progress-with-learning-standards-and-skills-in-Google-Classroom.html" target="_blank">how to keep track of student progress with learning standards and skills in Google Classroom</a>.</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[TypeScript 5.8]]></title>
<description><![CDATA[For release notes, check out the release announcement.

fixed issues query for Typescript 5.8.0 (Beta).
fixed issues query for Typescript 5.8.1 (RC).
fixed issues query for Typescript 5.8.2 (Stable).

Downloads are available on:

npm]]></description>
<link>https://tsecurity.de/de/3588930/downloads/typescript-58/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3588930/downloads/typescript-58/</guid>
<pubDate>Wed, 10 Jun 2026 23:17:12 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>For release notes, check out the <a href="https://devblogs.microsoft.com/typescript/announcing-typescript-5-8/" rel="nofollow">release announcement</a>.</p>
<ul>
<li><a href="https://github.com/Microsoft/TypeScript/issues?utf8=%E2%9C%93&amp;q=milestone%3A%22TypeScript+5.8.0%22+is%3Aclosed+">fixed issues query for Typescript 5.8.0 (Beta)</a>.</li>
<li><a href="https://github.com/Microsoft/TypeScript/issues?utf8=%E2%9C%93&amp;q=milestone%3A%22TypeScript+5.8.1%22+is%3Aclosed+">fixed issues query for Typescript 5.8.1 (RC)</a>.</li>
<li><a href="https://github.com/Microsoft/TypeScript/issues?utf8=%E2%9C%93&amp;q=milestone%3A%22TypeScript+5.8.2%22+is%3Aclosed+">fixed issues query for Typescript 5.8.2 (Stable)</a>.</li>
</ul>
<p>Downloads are available on:</p>
<ul>
<li><a href="https://www.npmjs.com/package/typescript" rel="nofollow">npm</a></li>
</ul>]]></content:encoded>
</item>
<item>
<title><![CDATA[TypeScript 5.9.3]]></title>
<description><![CDATA[Note: this tag was recreated to point at the correct commit. The npm package contained the correct content.
For release notes, check out the release announcement

fixed issues query for Typescript 5.9.0 (Beta).
fixed issues query for Typescript 5.9.1 (RC).
No specific changes for TypeScript 5.9.2...]]></description>
<link>https://tsecurity.de/de/3588929/downloads/typescript-593/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3588929/downloads/typescript-593/</guid>
<pubDate>Wed, 10 Jun 2026 23:17:11 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Note: this tag was recreated to point at the correct commit. The npm package contained the correct content.</p>
<p>For release notes, check out the <a href="https://devblogs.microsoft.com/typescript/announcing-typescript-5-9/" rel="nofollow">release announcement</a></p>
<ul>
<li><a href="https://github.com/Microsoft/TypeScript/issues?utf8=%E2%9C%93&amp;q=milestone%3A%22TypeScript+5.9.0%22+is%3Aclosed+">fixed issues query for Typescript 5.9.0 (Beta)</a>.</li>
<li><a href="https://github.com/Microsoft/TypeScript/issues?utf8=%E2%9C%93&amp;q=milestone%3A%22TypeScript+5.9.1%22+is%3Aclosed+">fixed issues query for Typescript 5.9.1 (RC)</a>.</li>
<li><em>No specific changes for TypeScript 5.9.2 (Stable)</em></li>
<li><a href="https://github.com/Microsoft/TypeScript/issues?utf8=%E2%9C%93&amp;q=milestone%3A%22TypeScript+5.9.3%22+is%3Aclosed+">fixed issues query for Typescript 5.9.3 (Stable)</a>.</li>
</ul>
<p>Downloads are available on:</p>
<ul>
<li><a href="https://www.npmjs.com/package/typescript" rel="nofollow">npm</a></li>
</ul>]]></content:encoded>
</item>
<item>
<title><![CDATA[TypeScript 5.8.3]]></title>
<description><![CDATA[Note: this tag was recreated to point at the correct commit. The npm package contained the correct content.
For release notes, check out the release announcement.

fixed issues query for Typescript 5.8.0 (Beta).
fixed issues query for Typescript 5.8.1 (RC).
fixed issues query for Typescript 5.8.2...]]></description>
<link>https://tsecurity.de/de/3588928/downloads/typescript-583/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3588928/downloads/typescript-583/</guid>
<pubDate>Wed, 10 Jun 2026 23:17:10 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Note: this tag was recreated to point at the correct commit. The npm package contained the correct content.</p>
<p>For release notes, check out the <a href="https://devblogs.microsoft.com/typescript/announcing-typescript-5-8/" rel="nofollow">release announcement</a>.</p>
<ul>
<li><a href="https://github.com/Microsoft/TypeScript/issues?utf8=%E2%9C%93&amp;q=milestone%3A%22TypeScript+5.8.0%22+is%3Aclosed+">fixed issues query for Typescript 5.8.0 (Beta)</a>.</li>
<li><a href="https://github.com/Microsoft/TypeScript/issues?utf8=%E2%9C%93&amp;q=milestone%3A%22TypeScript+5.8.1%22+is%3Aclosed+">fixed issues query for Typescript 5.8.1 (RC)</a>.</li>
<li><a href="https://github.com/Microsoft/TypeScript/issues?utf8=%E2%9C%93&amp;q=milestone%3A%22TypeScript+5.8.2%22+is%3Aclosed+">fixed issues query for Typescript 5.8.2 (Stable)</a>.</li>
<li><a href="https://github.com/Microsoft/TypeScript/issues?utf8=%E2%9C%93&amp;q=milestone%3A%22TypeScript+5.8.3%22+is%3Aclosed+">fixed issues query for Typescript 5.8.3 (Stable)</a>.</li>
</ul>
<p>Downloads are available on:</p>
<ul>
<li><a href="https://www.npmjs.com/package/typescript" rel="nofollow">npm</a></li>
</ul>]]></content:encoded>
</item>
<item>
<title><![CDATA[TypeScript 5.9 Beta]]></title>
<description><![CDATA[Note: this tag was recreated to point at the correct commit. The npm package contained the correct content.
For release notes, check out the release announcement.

fixed issues query for Typescript 5.9.0 (Beta).

Downloads are available on:

npm]]></description>
<link>https://tsecurity.de/de/3588927/downloads/typescript-59-beta/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3588927/downloads/typescript-59-beta/</guid>
<pubDate>Wed, 10 Jun 2026 23:17:09 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Note: this tag was recreated to point at the correct commit. The npm package contained the correct content.</p>
<p>For release notes, check out the <a href="https://devblogs.microsoft.com/typescript/announcing-typescript-5-9-beta/" rel="nofollow">release announcement</a>.</p>
<ul>
<li><a href="https://github.com/Microsoft/TypeScript/issues?utf8=%E2%9C%93&amp;q=milestone%3A%22TypeScript+5.9.0%22+is%3Aclosed+">fixed issues query for Typescript 5.9.0 (Beta)</a>.</li>
</ul>
<p>Downloads are available on:</p>
<ul>
<li><a href="https://www.npmjs.com/package/typescript" rel="nofollow">npm</a></li>
</ul>]]></content:encoded>
</item>
<item>
<title><![CDATA[TypeScript 5.9 RC]]></title>
<description><![CDATA[Note: this tag was recreated to point at the correct commit. The npm package contained the correct content.
For release notes, check out the release announcement

fixed issues query for Typescript 5.9.0 (Beta).
fixed issues query for Typescript 5.9.1 (RC).

Downloads are available on:

npm]]></description>
<link>https://tsecurity.de/de/3588926/downloads/typescript-59-rc/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3588926/downloads/typescript-59-rc/</guid>
<pubDate>Wed, 10 Jun 2026 23:17:07 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Note: this tag was recreated to point at the correct commit. The npm package contained the correct content.</p>
<p>For release notes, check out the <a href="https://devblogs.microsoft.com/typescript/announcing-typescript-5-9-rc/" rel="nofollow">release announcement</a></p>
<ul>
<li><a href="https://github.com/Microsoft/TypeScript/issues?utf8=%E2%9C%93&amp;q=milestone%3A%22TypeScript+5.9.0%22+is%3Aclosed+">fixed issues query for Typescript 5.9.0 (Beta)</a>.</li>
<li><a href="https://github.com/Microsoft/TypeScript/issues?utf8=%E2%9C%93&amp;q=milestone%3A%22TypeScript+5.9.1%22+is%3Aclosed+">fixed issues query for Typescript 5.9.1 (RC)</a>.</li>
</ul>
<p>Downloads are available on:</p>
<ul>
<li><a href="https://www.npmjs.com/package/typescript" rel="nofollow">npm</a></li>
</ul>]]></content:encoded>
</item>
<item>
<title><![CDATA[TypeScript 5.9]]></title>
<description><![CDATA[Note: this tag was recreated to point at the correct commit. The npm package contained the correct content.
For release notes, check out the release announcement

fixed issues query for Typescript 5.9.0 (Beta).
fixed issues query for Typescript 5.9.1 (RC).
No specific changes for TypeScript 5.9.2...]]></description>
<link>https://tsecurity.de/de/3588925/downloads/typescript-59/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3588925/downloads/typescript-59/</guid>
<pubDate>Wed, 10 Jun 2026 23:17:06 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Note: this tag was recreated to point at the correct commit. The npm package contained the correct content.</p>
<p>For release notes, check out the <a href="https://devblogs.microsoft.com/typescript/announcing-typescript-5-9/" rel="nofollow">release announcement</a></p>
<ul>
<li><a href="https://github.com/Microsoft/TypeScript/issues?utf8=%E2%9C%93&amp;q=milestone%3A%22TypeScript+5.9.0%22+is%3Aclosed+">fixed issues query for Typescript 5.9.0 (Beta)</a>.</li>
<li><a href="https://github.com/Microsoft/TypeScript/issues?utf8=%E2%9C%93&amp;q=milestone%3A%22TypeScript+5.9.1%22+is%3Aclosed+">fixed issues query for Typescript 5.9.1 (RC)</a>.</li>
<li><em>No specific changes for TypeScript 5.9.2 (Stable)</em></li>
</ul>
<p>Downloads are available on:</p>
<ul>
<li><a href="https://www.npmjs.com/package/typescript" rel="nofollow">npm</a></li>
</ul>]]></content:encoded>
</item>
<item>
<title><![CDATA[TypeScript 6.0 Beta]]></title>
<description><![CDATA[For release notes, check out the release announcement.

fixed issues query for Typescript 6.0.0 (Beta).

Downloads are available on:

npm]]></description>
<link>https://tsecurity.de/de/3588924/downloads/typescript-60-beta/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3588924/downloads/typescript-60-beta/</guid>
<pubDate>Wed, 10 Jun 2026 23:17:05 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>For release notes, check out the <a href="https://devblogs.microsoft.com/typescript/announcing-typescript-6-0-beta/" rel="nofollow">release announcement</a>.</p>
<ul>
<li><a href="https://github.com/Microsoft/TypeScript/issues?utf8=%E2%9C%93&amp;q=milestone%3A%22TypeScript+6.0.0%22+is%3Aclosed+">fixed issues query for Typescript 6.0.0 (Beta)</a>.</li>
</ul>
<p>Downloads are available on:</p>
<ul>
<li><a href="https://www.npmjs.com/package/typescript" rel="nofollow">npm</a></li>
</ul>]]></content:encoded>
</item>
<item>
<title><![CDATA[TypeScript 6.0.1 RC]]></title>
<description><![CDATA[For release notes, check out the release announcement blog post.

fixed issues query for TypeScript 6.0.0 (Beta).
fixed issues query for TypeScript 6.0.1 (RC).

Downloads are available on:

npm]]></description>
<link>https://tsecurity.de/de/3588923/downloads/typescript-601-rc/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3588923/downloads/typescript-601-rc/</guid>
<pubDate>Wed, 10 Jun 2026 23:17:04 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>For release notes, check out the <a href="https://devblogs.microsoft.com/typescript/announcing-typescript-6-0-rc/" rel="nofollow">release announcement blog post</a>.</p>
<ul>
<li><a href="https://github.com/Microsoft/TypeScript/issues?utf8=%E2%9C%93&amp;q=milestone%3A%22TypeScript+6.0.0%22">fixed issues query for TypeScript 6.0.0 (Beta)</a>.</li>
<li><a href="https://github.com/Microsoft/TypeScript/issues?utf8=%E2%9C%93&amp;q=milestone%3A%22TypeScript+6.0.1%22">fixed issues query for TypeScript 6.0.1 (RC)</a>.</li>
</ul>
<p>Downloads are available on:</p>
<ul>
<li><a href="https://www.npmjs.com/package/typescript" rel="nofollow">npm</a></li>
</ul>]]></content:encoded>
</item>
<item>
<title><![CDATA[TypeScript 6.0]]></title>
<description><![CDATA[For release notes, check out the release announcement blog post.

fixed issues query for TypeScript 6.0.0 (Beta).
fixed issues query for TypeScript 6.0.1 (RC).
fixed issues query for TypeScript 6.0.2 (Stable).

Downloads are available on:

npm]]></description>
<link>https://tsecurity.de/de/3588922/downloads/typescript-60/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3588922/downloads/typescript-60/</guid>
<pubDate>Wed, 10 Jun 2026 23:17:03 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>For release notes, check out the <a href="https://devblogs.microsoft.com/typescript/announcing-typescript-6-0/" rel="nofollow">release announcement blog post</a>.</p>
<ul>
<li><a href="https://github.com/Microsoft/TypeScript/issues?utf8=%E2%9C%93&amp;q=milestone%3A%22TypeScript+6.0.0%22">fixed issues query for TypeScript 6.0.0 (Beta)</a>.</li>
<li><a href="https://github.com/Microsoft/TypeScript/issues?utf8=%E2%9C%93&amp;q=milestone%3A%22TypeScript+6.0.1%22">fixed issues query for TypeScript 6.0.1 (RC)</a>.</li>
<li><a href="https://github.com/Microsoft/TypeScript/issues?utf8=%E2%9C%93&amp;q=milestone%3A%22TypeScript+6.0.2%22">fixed issues query for TypeScript 6.0.2 (Stable)</a>.</li>
</ul>
<p>Downloads are available on:</p>
<ul>
<li><a href="https://www.npmjs.com/package/typescript" rel="nofollow">npm</a></li>
</ul>]]></content:encoded>
</item>
<item>
<title><![CDATA[TypeScript 6.0.3]]></title>
<description><![CDATA[For release notes, check out the release announcement blog post.

fixed issues query for TypeScript 6.0.0 (Beta).
fixed issues query for TypeScript 6.0.1 (RC).
fixed issues query for TypeScript 6.0.2 (Stable).
fixed issues query for TypeScript 6.0.3 (Stable).

Downloads are available on:

npm]]></description>
<link>https://tsecurity.de/de/3588921/downloads/typescript-603/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3588921/downloads/typescript-603/</guid>
<pubDate>Wed, 10 Jun 2026 23:17:01 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>For release notes, check out the <a href="https://devblogs.microsoft.com/typescript/announcing-typescript-6-0/" rel="nofollow">release announcement blog post</a>.</p>
<ul>
<li><a href="https://github.com/Microsoft/TypeScript/issues?utf8=%E2%9C%93&amp;q=milestone%3A%22TypeScript+6.0.0%22">fixed issues query for TypeScript 6.0.0 (Beta)</a>.</li>
<li><a href="https://github.com/Microsoft/TypeScript/issues?utf8=%E2%9C%93&amp;q=milestone%3A%22TypeScript+6.0.1%22">fixed issues query for TypeScript 6.0.1 (RC)</a>.</li>
<li><a href="https://github.com/Microsoft/TypeScript/issues?utf8=%E2%9C%93&amp;q=milestone%3A%22TypeScript+6.0.2%22">fixed issues query for TypeScript 6.0.2 (Stable)</a>.</li>
<li><a href="https://github.com/Microsoft/TypeScript/issues?utf8=%E2%9C%93&amp;q=milestone%3A%22TypeScript+6.0.3%22">fixed issues query for TypeScript 6.0.3 (Stable)</a>.</li>
</ul>
<p>Downloads are available on:</p>
<ul>
<li><a href="https://www.npmjs.com/package/typescript" rel="nofollow">npm</a></li>
</ul>]]></content:encoded>
</item>
<item>
<title><![CDATA[CISA tells agencies to patch smarter, not harder — foreshadowing broader industry practice]]></title>
<description><![CDATA[Security teams’ patching practices have come under intense pressure over the past year, as active exploitation is up, time-to-exploit windows are accelerating, and vulnerabilities have become attackers’ top initial access vector of choice.



Last year, organizations fully remediated only 26% of ...]]></description>
<link>https://tsecurity.de/de/3588858/it-security-nachrichten/cisa-tells-agencies-to-patch-smarter-not-harder-foreshadowing-broader-industry-practice/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3588858/it-security-nachrichten/cisa-tells-agencies-to-patch-smarter-not-harder-foreshadowing-broader-industry-practice/</guid>
<pubDate>Wed, 10 Jun 2026 22:38:06 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Security teams’ patching practices have come under intense pressure over the past year, as active exploitation is up, time-to-exploit windows are accelerating, and <a href="https://www.csoonline.com/article/4176086/vulnerabilities-have-become-cyber-attackers-no-1-door-to-the-enterprise.html">vulnerabilities have become attackers’ top initial access vector</a> of choice.</p>



<p>Last year, organizations fully remediated only 26% of the vulnerabilities that attackers were actively exploiting in the wild — down from 38% the year before, according to Verizon’s <a href="https://www.csoonline.com/article/4176086/vulnerabilities-have-become-cyber-attackers-no-1-door-to-the-enterprise.html">2026 Data Breach Investigations Report</a>. The median time to close those known dangerous gaps stretched to 43 days, while attackers have trimmed their side of the equation to days, sometimes hours.</p>



<p>That’s the backdrop against which the US Cybersecurity and Infrastructure Security Agency issued <a href="https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk">Binding Operational Directive 26-04</a>. The directive reflects growing recognition that patching based primarily on severity scores is no longer sufficient in an AI-driven environment where defenders face more vulnerabilities than they can realistically remediate at once.</p>



<p>During a media briefing announcing the directive, Chris Butera, acting executive assistant director for cybersecurity at CISA, described the initiative as the culmination of more than a decade of lessons learned from federal vulnerability management programs, adversary activity, and the agency’s growing understanding of AI’s impact on cyber operations.</p>



<p>“Prioritizing IT and security operations attention on the most at-risk assets is particularly important now given advancements in artificial intelligence, which allow threat actors to find and exploit vulnerabilities in these assets,” Butera said. “Defenders cannot afford to take weeks to patch systems that can be autonomously exploited en masse.”</p>



<p>In a companion <a href="https://www.cisa.gov/news-events/news/patch-smarter-not-harder">blog post</a>, Butera and Jonathan Spring, CISA’s senior technical advisor, argue that defenders are struggling to keep pace with a rapidly growing volume of vulnerabilities. AI is assisting researchers and adversaries in identifying flaws in software, vastly increasing the pace at which new vulnerabilities are discovered and forcing organizations to <a href="https://www.csoonline.com/article/4065137/cisos-advised-to-rethink-vulnerability-management-as-exploits-sharply-rise.html">rethink how they prioritize remediation efforts</a>.</p>



<p>Butera and Spring argue that defenders need greater clarity and speed when deciding what to patch. Their prescription: patch smarter, not harder.</p>



<h2 class="wp-block-heading">Beyond CVSS: Why severity scores are no longer enough</h2>



<p>The directive builds on CISA’s <a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog">Known Exploited Vulnerabilities</a> program, which already identifies vulnerabilities actively being abused by attackers. But BOD 26-04 goes further by introducing a decision framework that considers four key factors: whether the vulnerable system is publicly exposed to the internet, whether the vulnerability is listed in the KEV catalog, whether an attacker can automate exploitation, and how much control an attacker would gain after exploitation.</p>



<p>During the briefing, Butera said those four characteristics — public exposure, known exploitation, exploit automation, and post-exploitation impact — represent the conditions most closely associated with meaningful risk to federal systems. Vulnerabilities exhibiting three or more of those attributes must be patched within three days, while lower-risk vulnerabilities can be addressed on longer timelines or, in some cases, deferred until the next major system upgrade.</p>



<p>The change reflects a broader shift in how security practitioners think about vulnerability management. For years, organizations have relied heavily on severity scores such as <a href="https://cyberscoop.com/cvss-criticism-cve-nvd-nist-epss/">CVSS</a> to determine patching priorities. But those scores often fail to predict whether attackers will actually exploit a flaw.</p>



<p>“The directive used to be based on just severity score, which we as an industry have come to find is not a good predictor of exploitation,” <a href="https://www.linkedin.com/in/sasha-romanosky-6093831/">Sasha Romanosky</a>, a senior cybersecurity policy researcher at RAND, tells CSO. “This BoD looks to be updated to account for both impact and exploitation, which I think is the right approach.”</p>



<p><a href="https://www.csoonline.com/article/4183750/%5CUsers%5Ccynth%5COneDrive%5CDocuments%5Clinkedin.com%5Cin%5Cjgamblin">Jerry Gamblin</a>, FIRST EPSS SIG member and founder of RogoLabs, is even more enthusiastic about the BoD. “BOD 26-04 is a massive step in the right direction and validates what data-driven teams already know: Patching every CVSS High or Critical is mathematically impossible,” he tells CSO. “By formalizing the use of the KEV catalog alongside advanced predictive data like EPSS, CISA is helping drive the industry toward practical, risk-based operational maturity.”</p>



<h2 class="wp-block-heading">The operational burden of continuous risk assessment</h2>



<p>Perhaps the most notable operational change is that remediation timelines become dynamic. A vulnerability’s required response time can change as circumstances change, with internet-facing and actively exploited vulnerabilities receiving the highest priority.</p>



<p>During the briefing, Butera said that this flexibility is one of the directive’s greatest strengths. In an analysis of one federal civilian agency, CISA found that only about 1% of vulnerability instances required remediation within three days, while more than 60% could be deferred until the next system update.</p>



<p>That finding highlights the agency’s central argument: Vulnerability management has become a prioritization problem as much as a patching problem.</p>



<p>“We really believe we should be able to free up some time to patch the most urgent vulnerabilities faster while allowing for more regular patch cycles for some of the lower-risk vulnerabilities,” Butera said.</p>



<p>Rather than forcing agencies to expend resources remediating thousands of vulnerabilities of varying importance, the framework concentrates attention on the small subset of flaws most likely to result in compromise.</p>



<h2 class="wp-block-heading">What the directive gets right — and what it leaves out</h2>



<p>Romanosky notes, however, that the directive’s treatment of impact is relatively narrow, focusing largely on whether exploitation grants an attacker partial or complete control of a system.</p>



<p>“What about integrity impacts that change data, or completely deny access to a system, such as a DDoS attack on DNS or wiping out a database?” he says. “Those impacts would also seem important.”</p>



<p>Still, he acknowledges that if policymakers must simplify risk decisions across the federal government, prioritizing vulnerabilities that provide adversaries control over systems is a reasonable place to start.</p>



<p>The directive also places significant emphasis on internet-facing systems, which could raise questions about risks deeper inside enterprise networks. Butera and Spring address that point directly in their blog post, arguing that CISA does not typically observe threat actors compromising core networks through software vulnerabilities alone. Instead, attackers frequently rely on valid credentials, misconfigurations, and other “living off the land” techniques.</p>



<h2 class="wp-block-heading">KEV is useful — but is it enough?</h2>



<p>Cybersecurity professionals outside government should pay close attention because federal vulnerability management often foreshadows broader industry practice. The directive formalizes ideas that many security leaders have advocated for years: CVSS scores alone are insufficient; asset context matters; internet exposure matters; active exploitation matters most.</p>



<p><a href="https://www.csoonline.com/Users/cynth/OneDrive/Documents/csomagazine/linkedin.com/in/michael-roytman">Michael Roytman</a>, co-founder and CTO of Empirical Security, views the directive as a milestone in that evolution.</p>



<p>“The federal government finally retired the ‘patch everything on the list’ mandate and replaced it with risk-based prioritization,” Roytman tells CSO. “Eleven years ago, prioritizing by exploitation probability was a heresy we had to defend in conference hallways. Today, it’s a binding federal directive.”</p>



<p>But he also argues that the framework’s reliance on the KEV catalog highlights one of its limitations.</p>



<p>“KEV lists are binary and retroactive,” Roytman says. “When AI compresses the gap between patch and exploit to hours, waiting for the KEV entry means you find out you were wrong from the incident report.”</p>



<p>Romanosky raises a similar concern, describing KEV as a valuable but inherently backward-looking source of information. “KEV is a great program for DHS and the public, but it is, at best, evidence of past exploitation,” he says.</p>



<p>Both experts suggested that predictive signals deserve a larger role in future vulnerability prioritization efforts. Romanosky points specifically to the <a href="https://www.csoonline.com/article/4161626/anthropic-bets-on-epss-for-the-coming-bug-surge.html">Exploit Prediction Scoring System (EPSS)</a>, which estimates the likelihood that a vulnerability will be exploited in the future.</p>



<p>“The concern, of course, is that vulnerabilities age, and so what may have been exploited last year or last month may no longer be used in active exploitation today,” Romanosky says. “So EPSS would provide a better signal.”</p>



<p>Roytman takes the argument a step further. Drawing on research conducted alongside Verizon’s DBIR team, he said that recency matters enormously when assessing exploitation risk.</p>



<p>According to Roytman, 82% of KEV entries involve vulnerabilities whose exploitation was first reported more than a year ago. “Twelve months of inactivity means the chance of exploitation falls from 99% on the first day down to 5%,” he says.</p>



<p>He also argues that KEV captures only a fraction of observed exploitation activity. “The KEV list covers only about 8% of observed exploitation,” Roytman said. “We’re tracking 17,800 CVEs compared to CISA’s 1,600.”</p>



<h2 class="wp-block-heading">How AI could force another rethink of vulnerability management</h2>



<p>Butera and Spring argue that artificial intelligence is already accelerating vulnerability discovery and increasing pressure on defenders. BOD 26-04 is intended to help agencies automate and scale vulnerability management while focusing scarce resources on the risks that matter most.</p>



<p>But the directive’s four-factor framework was built on the vulnerability landscape as it exists today — and AI may render that landscape unrecognizable relatively quickly.</p>



<p>Romanosky points to a structural gap in the current model: because the framework relies heavily on CVE identifiers, defenders may encounter newly discovered flaws that require urgent attention before they’ve been formally cataloged. “As more vulnerabilities are discovered quicker with AI tools, we might expect a whole set of new vulnerabilities that haven’t yet been assigned CVE IDs that need to be patched super quick,” he says.</p>



<p>That’s not a hypothetical concern. The <a href="https://cyberscoop.com/cve-program-history-mitre-nist-1999-2024/">CVE assignment process</a> — run by MITRE and a network of numbering authorities — was built for a slower discovery cadence. It can take days or weeks for a vulnerability to receive an identifier, go through NVD analysis, and appear in tools that practitioners actually use. If AI compresses the window between discovery and exploitation to hours, that pipeline becomes a liability.</p>



<p>Roytman sees the directive’s four-factor model as a starting point rather than an endpoint — one calibrated to average federal risk rather than the specific conditions of any individual organization. “The risk in CISA’s table is the average risk across the federal enterprise,” he said. “The risk in an enterprise environment is a different number that depends on controls, telemetry, prevalence, and ultimately a local model specific to that enterprise.”</p>



<p>Romanosky agrees that another revision may be inevitable. “I might expect another revised BOD — or some other directive — to account for what may be a new continuous stream of vulnerabilities,” he says.</p>



<p>In that sense, BOD 26-04 may be less a destination than a waypoint: the federal government’s best current answer to a problem that AI is guaranteed to make harder.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[ASUS ROG G1000 20th Anniversary Desktop Has THIS World's First Feature!]]></title>
<description><![CDATA[Author: Shannon Morse - Bewertung: 3x - Views:70 🚀 ASUS brought one of the most epic desktops at Computex 2026. The ROG G1000 20th Anniversary Edition features AniMe Holo, a redesigned Thermal Atrium cooling system, and an AMD Ryzen™ 9 9950X3D processor paired with an RTX 5090. What do you think?...]]></description>
<link>https://tsecurity.de/de/3588690/videos/asus-rog-g1000-20th-anniversary-desktop-has-this-worlds-first-feature/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3588690/videos/asus-rog-g1000-20th-anniversary-desktop-has-this-worlds-first-feature/</guid>
<pubDate>Wed, 10 Jun 2026 21:03:01 +0200</pubDate>
<category>🎥 Videos</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: Shannon Morse - Bewertung: 3x - Views:70 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/UqXoOZi-XDI?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>🚀 ASUS brought one of the most epic desktops at Computex 2026. The ROG G1000 20th Anniversary Edition features AniMe Holo, a redesigned Thermal Atrium cooling system, and an AMD Ryzen™ 9 9950X3D processor paired with an RTX 5090. What do you think? 🔥 @AMD @asusrog <br />
<br />
#Computex2026<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Larson: Are insecure code completions a vulnerability?]]></title>
<description><![CDATA[Seth Larson, the Python Software Foundation's security
developer-in-residence, has written
about the difficulty in classifying insecure code completion in
the PyCharm IDE using
its Full
Line code completion plugin. Larson discovered that the plugin,
which uses a local "deep learning module" to of...]]></description>
<link>https://tsecurity.de/de/3588420/linux-tipps/larson-are-insecure-code-completions-a-vulnerability/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3588420/linux-tipps/larson-are-insecure-code-completions-a-vulnerability/</guid>
<pubDate>Wed, 10 Jun 2026 18:59:26 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Seth Larson, the Python Software Foundation's <a href="https://pyfound.blogspot.com/2023/06/announcing-our-new-security-developer.html">security
developer-in-residence</a>, has <a href="https://sethmlarson.dev/are-insecure-code-completions-a-vulnerability">written
about</a> the difficulty in classifying insecure code completion in
the <a href="https://www.jetbrains.com/pycharm/">PyCharm IDE</a> using
its <a href="https://www.jetbrains.com/help/pycharm/full-line-code-completion.html">Full
Line code completion</a> plugin. Larson discovered that the plugin,
which uses a local "deep learning module" to offer code completions,
suggests code that would lead to severe vulnerabilities. He was unsure
whether it warranted a CVE or not, however:</p>

<blockquote class="bq">
<p>I reported this behavior to JetBrains for "Full Line Code Completion" v253.29346.142
and clearly their support staff weren't certain whether this defect
was a security vulnerability or not either. When I asked to
publish a blog post about this behavior after they confirmed
this report wasn't a "direct security vulnerability" (which
I agree with) but then was asked not to publicize my report and referred to
PyCharm's <a href="https://www.jetbrains.com/legal/docs/terms/coordinated-disclosure/">Coordinated Disclosure Policy</a>
so... which is it? Security vulnerability or not?</p>

<p>I ended up waiting the 90 days anyway and I didn't hear back with
any substantive update from the development team. I double-checked
again today using "Full Line Code Completion" v261.24374.152 and the
behavior is identical, suggesting the same insecure code for both
contexts.</p>

<p>This isn't meant to be a specific dig at PyCharm or JetBrains, I
have no-doubt that examples like this exist in every code generation
model available.</p>
</blockquote>]]></content:encoded>
</item>
<item>
<title><![CDATA[Stop hand-tuning kernels: How Neuron Agentic Development accelerates AWS Trainium optimizations]]></title>
<description><![CDATA[Today, we’re announcing the Neuron Agentic Development capabilities: a collection of AI agents and skills that make this possible for developers building on AWS Trainium and AWS Inferentia. In this post, we explain how the Neuron Agentic Development capabilities accelerate the kernel development ...]]></description>
<link>https://tsecurity.de/de/3588180/ai-nachrichten/stop-hand-tuning-kernels-how-neuron-agentic-development-accelerates-aws-trainium-optimizations/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3588180/ai-nachrichten/stop-hand-tuning-kernels-how-neuron-agentic-development-accelerates-aws-trainium-optimizations/</guid>
<pubDate>Wed, 10 Jun 2026 17:34:06 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Today, we’re announcing the Neuron Agentic Development capabilities: a collection of AI agents and skills that make this possible for developers building on AWS Trainium and AWS Inferentia. In this post, we explain how the Neuron Agentic Development capabilities accelerate the kernel development workflow.]]></content:encoded>
</item>
<item>
<title><![CDATA[Zscaler launches zero trust platform for agentic AI]]></title>
<description><![CDATA[Zscaler announced what it calls the first complete zero trust platform for agentic AI, aimed at securing how AI agents access data and talk to one another.



“Traditional security was never designed for millions of autonomous agents that act and reach sensitive data at machine speed,” said Jay C...]]></description>
<link>https://tsecurity.de/de/3585012/it-security-nachrichten/zscaler-launches-zero-trust-platform-for-agentic-ai/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3585012/it-security-nachrichten/zscaler-launches-zero-trust-platform-for-agentic-ai/</guid>
<pubDate>Tue, 09 Jun 2026 17:39:21 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Zscaler announced what it calls the first complete zero trust platform for agentic AI, aimed at securing how AI agents access data and talk to one another.</p>



<p>“Traditional security was never designed for millions of autonomous agents that act and reach sensitive data at machine speed,” said <a href="https://www.linkedin.com/in/jaychaudhry/">Jay Chaudhry</a>, Zscaler’s chairman and CEO, in the Tuesday <a href="http://zscaler.com/events/zenithlive2026">announcement</a>.</p>



<p>The company will be extending its Zscaler Zero Trust Exchange platform to cover AI agents, including how they connect, how they access data, and how they run on devices.</p>



<p>According to <a href="https://www.linkedin.com/in/christina-m-powers/">Christina Powers</a>, partner and cybersecurity consulting leader at management consulting firm West Monroe Partners, zero trust for agentic systems means treating every AI agent, tool, and action as untrusted until it is explicitly verified and authorized.</p>



<p>“As organizations give agents greater autonomy to access systems and make decisions, zero trust becomes essential because of the risk of unauthorized actions being executed at scale,” she says.</p>



<p>To this end, the new Zscaler AI Broker will secure MCP [Model Context Protocol] and A2A [Agent to Agent] communications. MCP and A2A are the top open standards for how AI agents connect to data and to each other, respectively.</p>



<p>Second, Zscaler Endpoint AI Security will help find and stop AI-related threats on employee devices. It covers browsers, plugins, extensions, and local AI tools — which traditional endpoint security tools can miss.</p>



<p>In addition to these two new security tools, Zscaler is announcing the Zscaler AI Access Graph, which maps how identities, applications, and data sources connect across the enterprise. This new tool is powered by Zscaler’s recent acquisition of Symmetry Systems.</p>



<p>“The integration of this technology with Zscaler’s Zero Trust Exchange enables organizations to understand and then enforce policies, reduce unnecessary access and risk, and track data lineage in real-time across every channel,” the company said in its <a href="https://www.zscaler.com/press/zscaler-unveils-new-product-innovations-secure-agentic-ai">announcement</a>.</p>



<p>Finally, Zscaler is expanding Zscaler AI Protect, which was launched in January 2026. The platform will now include AI asset management, which will identify AI agents and MCP servers, discover embedded AI in SaaS and internet traffic, scan agentic code bases for risks, and provide visibility to AI activity on endpoints.</p>



<p>The platform will also have expanded controls for AI interactions, with prompt extraction, across more than 250 genAI apps. It includes full conversational views, support for Anthropic and OpenAI compliance APIs, and intent-based guardrails for multi-turn conversations.</p>



<p>Zscaler is also introducing AI red teaming for MCP servers, a standalone prompt hardening service, and compliance heat maps to strengthen AI governance.</p>



<p>Zscaler is entering an agentic AI security market that barely existed a year ago.</p>



<p>According to a <a href="https://www.delloro.com/news/ai-systems-security-market-to-rise-from-zero-to-nearly-8-b-by-2030/">report from the Dell’Oro Group</a>, the AI systems security market is projected to grow from “essentially  zero” to $8 billion by 2030 — and there are already nearly 60 vendors active in the space, offering everything from model and component security, to AI validation and red teaming, AI security posture management, runtime guardrails, and agent security.</p>



<p>Zero trust is just one component of the AI security puzzle, says Dell’Oro Group analyst <a href="https://www.linkedin.com/in/mssanche/">Mauricio Sanchez</a>.</p>



<p>At its heart, zero trust for agentic AI extends beyond users and devices to the agents themselves. “An AI agent should not inherit broad access simply because a user launched it or because it runs within a trusted application,” Sanchez says. “It needs its own identity, its own permissions, a clear scope of action, and continuous monitoring of its activities.”</p>



<p>Enterprises need to know who authorized the agent, what it’s allowed to do, what systems it can access — and whether it can be stopped quickly if it starts to misbehave. “This is important because agentic systems can act at machine speed,” he says. “They can call APIs, move data, trigger workflows, create content, and interact with other systems.”</p>



<p>The idea is to protect agents from both adversaries and accidental misconfigurations, says <a href="https://www.linkedin.com/in/michelamenting/">Michela Menting</a>, vice president and analyst at ABI Research.</p>



<p>“I would say this is particularly important as threat actors moving laterally within an organization tend to use other internal assets to escalate privileges and reach corporate crown jewels,” she says. “Agentic systems and agents are a powerful new asset that can be exploited quite easily without such controls, and could lead to catastrophic outcomes.”</p>



<p>According to Eric Syphard, senior vice president of AI at Booz Allen Hamilton, the first step to deploying zero trust for AI agents is to create guardrails that limit what the agents can do. “Second,” he says, “is to utilize additional agents to observe and evaluate compliance.”</p>



<p>With humans in loop, of course, as the final check.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Apple’s best AI idea looks a lot like vibe coding]]></title>
<description><![CDATA[Most of Apple's current AI ideas are roughly the same as everyone else's AI ideas. A chatbot you can ask questions; quick ways to create or summarize text; bizarre, borderline creepy image-generation tools. The company spent most of its WWDC keynote playing catch-up with the state of the AI art, ...]]></description>
<link>https://tsecurity.de/de/3584738/it-nachrichten/apples-best-ai-idea-looks-a-lot-like-vibe-coding/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3584738/it-nachrichten/apples-best-ai-idea-looks-a-lot-like-vibe-coding/</guid>
<pubDate>Tue, 09 Jun 2026 15:47:22 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Most of Apple's current AI ideas are roughly the same as everyone else's AI ideas. A chatbot you can ask questions; quick ways to create or summarize text; bizarre, borderline creepy image-generation tools. The company spent most of its WWDC keynote playing catch-up with the state of the AI art, announcing Siri features you can […]]]></content:encoded>
</item>
<item>
<title><![CDATA[OpenAI files SEC paperwork to go public]]></title>
<description><![CDATA["We expect it to leak so we're just announcing it."]]></description>
<link>https://tsecurity.de/de/3583048/it-nachrichten/openai-files-sec-paperwork-to-go-public/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3583048/it-nachrichten/openai-files-sec-paperwork-to-go-public/</guid>
<pubDate>Tue, 09 Jun 2026 00:02:22 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA["We expect it to leak so we're just announcing it."]]></content:encoded>
</item>
<item>
<title><![CDATA[OpenAI confidentially files for initial public offering on US stock market]]></title>
<description><![CDATA[ChatGPT maker is expected to be valued at more than $850bnOpenAI has filed confidentially to go public on the US stock market, according to a company blog post published Monday. The ChatGPT maker is expected to be valued at more than $850bn.“We recently submitted a confidential S-1. We expect it ...]]></description>
<link>https://tsecurity.de/de/3583017/ai-nachrichten/openai-confidentially-files-for-initial-public-offering-on-us-stock-market/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3583017/ai-nachrichten/openai-confidentially-files-for-initial-public-offering-on-us-stock-market/</guid>
<pubDate>Mon, 08 Jun 2026 23:48:46 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>ChatGPT maker is expected to be valued at more than $850bn</p><p></p><p>OpenAI has filed confidentially to go public on the US stock market, according to a company blog post published Monday. The ChatGPT maker is expected to be valued at more than $850bn.</p><p>“We recently submitted a confidential S-1. We expect it to leak so we’re just announcing it. We have not decided on timing yet; it may be a while because there are things we want to do that are likely easier as a private company. But it’s a complicated set of tradeoffs and this gives us the option to go public sooner if that ends up being best,” the company’s post reads. An S-1 is an investor prospectus submitted to the US Securities and Exchange Commission (SEC) in advance of an initial public offering (IPO).</p> <a href="https://www.theguardian.com/technology/2026/jun/08/openai-ipo-files-for-public-stock-market">Continue reading...</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Announcing new builds 8 June 2026]]></title>
<description><![CDATA[Hello Windows Insiders,  
Announcing several new builds today across Beta and Experimental, including a new build train for 26H1!
The post Announcing new builds 8 June 2026 appeared first on Windows Insider Blog.]]></description>
<link>https://tsecurity.de/de/3582961/windows-tipps/announcing-new-builds-8-june-2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3582961/windows-tipps/announcing-new-builds-8-june-2026/</guid>
<pubDate>Mon, 08 Jun 2026 23:24:09 +0200</pubDate>
<category>🪟 Windows Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><span data-contrast="auto">Hello Windows Insiders, </span><span data-ccp-props="{}"> </span></p>
<p><span data-contrast="auto">Announcing several new builds today across Beta and Experimental, including a new build train for 26H1!</span><span data-ccp->
<p>The post <a href="https://blogs.windows.com/windows-insider/2026/06/08/announcing-new-builds-8-june-2026-2/">Announcing new builds 8 June 2026</a> appeared first on <a href="https://blogs.windows.com/windows-insider">Windows Insider Blog</a>.</p></span></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Announcing major new donations, and recapping the 2025 fundraiser]]></title>
<description><![CDATA[This past December, we ran our first fundraiser in six years, setting an ambitious goal of $6M. We ended up receiving a total of $1.8M from small donors and $1.6M in matching from the Survival and Flourishing Fund (SFF) for a total of $3.4M. We’re incredibly grateful for all this support! In the ...]]></description>
<link>https://tsecurity.de/de/3582193/ai-nachrichten/announcing-major-new-donations-and-recapping-the-2025-fundraiser/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3582193/ai-nachrichten/announcing-major-new-donations-and-recapping-the-2025-fundraiser/</guid>
<pubDate>Mon, 08 Jun 2026 19:04:35 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>This past December, we ran our first fundraiser in six years, setting an ambitious goal of $6M. We ended up receiving a total of $1.8M from small donors and $1.6M in matching from the Survival and Flourishing Fund (SFF) for a total of $3.4M. We’re incredibly grateful for all this support! In the rest of […]</p>
<p>The post <a rel="nofollow" href="https://intelligence.org/2026/06/08/announcing-major-new-donations-and-recapping-the-2025-fundraiser/">Announcing major new donations, and recapping the 2025 fundraiser</a> appeared first on <a rel="nofollow" href="https://intelligence.org/">Machine Intelligence Research Institute</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[7 Big Things to Expect From Today’s WWDC 2026 Keynote]]></title>
<description><![CDATA[Apple's WWDC 2026 keynote is just hours away, and all signs point to one of the company's most important software events in years. The biggest focus will likely be a completely rebuilt Siri powered by Google's Gemini AI, but Apple is also expected to announce major updates for iOS 27, macOS 27, w...]]></description>
<link>https://tsecurity.de/de/3582128/ios-mac-os/7-big-things-to-expect-from-todays-wwdc-2026-keynote/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3582128/ios-mac-os/7-big-things-to-expect-from-todays-wwdc-2026-keynote/</guid>
<pubDate>Mon, 08 Jun 2026 18:39:46 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Apple's WWDC 2026 keynote is just hours away, and all signs point to one of the company's most important software events in years. The biggest focus will likely be a completely rebuilt Siri powered by Google's Gemini AI, but Apple is also expected to announce major updates for iOS 27, macOS 27, watchOS 27, and more.



Here's a look at the biggest things to expect from today's WWDC keynote.



Table of contents1. A Completely New Siri Powered by Gemini2. Shortcuts Gets an AI Upgrade3. iOS 27 Will Focus on AI4. macOS 27 Gets a Refined Liquid Glass Design5. watchOS 27 Could Deliver Better Health Insights6. AI Will Be Everywhere7. Tim Cook's Final WWDC as CEOWill Apple Announce New Hardware?Wrap-Up



1. A Completely New Siri Powered by Gemini



The headline announcement is expected to be Apple's new AI-powered Siri.



According to multiple reports, Apple has rebuilt Siri around Google Gemini models, giving the assistant more natural conversations, better context awareness, and the ability to handle more complex requests. Users may also get a dedicated Siri app that works similarly to ChatGPT and other AI assistants.



Expected features include:




Chat-style conversations



Voice and text interactions



Photo and file uploads



Conversation history



Cross-device syncing




Reports also suggest Apple could launch the new Siri as a beta and require a waitlist for some users when iOS 27 arrives later this year.



2. Shortcuts Gets an AI Upgrade



Apple is also expected to make Shortcuts much easier to use.



Instead of manually building automation workflows, users may simply describe what they want in natural language. The system would then create the shortcut automatically.



For example, users could type:




"Create a morning routine."



"Turn on Focus mode when I arrive at work."



"Save screenshots to a folder and rename them."




Apple has pushed automation for years, but this update could finally make Shortcuts accessible to everyday users.



3. iOS 27 Will Focus on AI



While iOS 27 may not bring a dramatic redesign, it is expected to introduce several AI-focused improvements across the system. Reports describe the update as a refinement release with meaningful quality-of-life changes rather than a major visual overhaul. 



Expected additions include:




Smarter writing tools



Improved Genmoji



Better Image Playground features



Visual Intelligence upgrades



New AI-powered search experiences




Apple needs a strong showing here after facing criticism for announcing AI features in previous years that took much longer to arrive.



4. macOS 27 Gets a Refined Liquid Glass Design



Apple introduced its Liquid Glass design language last year, but many Mac users felt macOS did not receive the same level of attention as iOS.



That could change with macOS 27.



Reports suggest Apple will further refine the visual experience and bring the Mac closer to the design language used across its other platforms. The update is expected to focus on polish and consistency rather than a complete redesign.



There is also speculation that macOS 27 could carry the name Big Bear or Emerald, though Apple has not confirmed anything yet.



Apple Silicon Only



Another important change is compatibility.



macOS 27 is expected to drop support for Intel Macs and become the first major macOS release designed exclusively for Apple silicon Macs.



5. watchOS 27 Could Deliver Better Health Insights



Apple Watch remains one of Apple's most important products, and watchOS 27 is expected to bring new health and fitness features.



Bloomberg reports point to:




Improved heart-rate tracking



Enhanced fitness metrics



New health insights



A new Modular watch face




Apple already collects data such as heart rate and Heart Rate Variability (HRV). The company could now use that information more effectively to provide recovery and wellness insights similar to competitors like Garmin, Fitbit, WHOOP, and Oura.



6. AI Will Be Everywhere



Beyond Siri, AI is expected to appear throughout Apple's software lineup.



Several reports indicate Apple Intelligence will receive major upgrades across:




Writing tools



Image generation



Photo editing



Visual Intelligence



System-wide search



Developer tools




Wall Street analysts and industry watchers view this year's WWDC as a crucial moment for Apple's AI strategy.



7. Tim Cook's Final WWDC as CEO



Today's keynote will also mark the end of an era.



Apple previously announced that John Ternus will become CEO on September 1, while Tim Cook transitions to Executive Chairman. That makes WWDC 2026 likely Cook's final developer conference keynote as Apple's chief executive.



Cook has opened nearly every WWDC keynote for more than a decade, so many Apple fans will be watching closely to see whether the company acknowledges the leadership transition during the presentation.



Will Apple Announce New Hardware?



A hardware surprise cannot be ruled out, but expectations remain low.



Most reports suggest WWDC 2026 will stay focused on software, AI, and Apple Intelligence. Some rumors claim Apple has hardware ready to launch, but the company appears more interested in showcasing its AI roadmap first.



Wrap-Up



The biggest story at WWDC 2026 is simple: Apple needs to show that its AI strategy is finally ready. A Gemini-powered Siri, smarter Apple Intelligence features, AI-powered Shortcuts, and deeper software integration are expected to dominate the keynote. Alongside that, today's event carries extra significance as Tim Cook prepares for his final WWDC appearance as CEO.]]></content:encoded>
</item>
<item>
<title><![CDATA[Life After Death? IO Campaigns Linked to Notorious Russian Businessman Prigozhin Persist After His Political Downfall and Death]]></title>
<description><![CDATA[Written by: Alden Wahlstrom, David Mainor, Daniel Kapellmann Zafra

 
In June 2023, Russian businessman Yevgeniy Prigozhin and his private military company (PMC) “Wagner” carried out an armed mutiny within Russia. The events triggered the meteoric political downfall of Prigozhin, raising question...]]></description>
<link>https://tsecurity.de/de/3578871/it-security-nachrichten/life-after-death-io-campaigns-linked-to-notorious-russian-businessman-prigozhin-persist-after-his-political-downfall-and-death/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3578871/it-security-nachrichten/life-after-death-io-campaigns-linked-to-notorious-russian-businessman-prigozhin-persist-after-his-political-downfall-and-death/</guid>
<pubDate>Sun, 07 Jun 2026 08:22:21 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div class="block-paragraph_advanced"><p>Written by: Alden Wahlstrom, David Mainor, Daniel Kapellmann Zafra</p>
<hr>
<p> </p></div>
<div class="block-paragraph_advanced"><p>In June 2023, Russian businessman Yevgeniy Prigozhin and his private military company (PMC) “Wagner” carried out an armed mutiny within Russia. The events triggered the meteoric political downfall of Prigozhin, raising questions about the future of his various enterprises that were only underscored when he died two months later under <a href="https://thehill.com/policy/international/4374263-putin-confidant-patrushev-plan-kill-prigozhin/" rel="noopener" target="_blank"><u>suspicious circumstances</u></a>. Up to that point, Prigozhin and his enterprises worked to advance the Kremlin’s interests as the manifestation of the thinnest veil of plausible deniability for state-guided actions on multiple continents. Such enterprises included the Wagner PMC; overt influence infrastructure, like his media company Patriot Group that housed his media companies, including the “RIA FAN” Federal News Agency; covert influence infrastructures; and an array of <a href="https://home.treasury.gov/news/press-releases/jy1581" rel="noopener" target="_blank"><u>businesses aimed</u></a> at generating personal wealth and the resourcing necessary to fund his various ventures.</p>
<p>Mandiant has for years tracked and reported on covert information operations (IO) threat activity linked to Prigozhin. His involvement in IO was first widely established in the West as part of the <a href="https://home.treasury.gov/news/press-releases/jy0126" rel="noopener" target="_blank"><u>public exposure</u></a> of Russian-backed interference in the 2016 U.S. presidential election—this included activity conducted by Russia’s Internet Research Agency (IRA), which the U.S. Government <a href="https://home.treasury.gov/news/press-releases/jy0126" rel="noopener" target="_blank"><u>publicly named</u></a> Prigozhin as its financier. Subsequently, Prigozhin was publicly connected to a web of IO activity targeting the U.S., EU, Ukraine, Russian domestic audiences, countries across Africa, and further afield. Such activity has worked not only to advance Russian interests on matters of strategic importance, but also has attempted to exploit existing divisions in societies targeting various subgroups across their population. </p>
<p>Throughout 2023, Mandiant has observed shifts in the activity from multiple IO campaigns linked to Prigozhin, including continued indicators that components of these campaigns have remained viable since his death. This blog post examines a sample of Prigozhin-linked IO campaigns to better understand their outcomes thus far and provide an overview of what can be expected from these activity sets in the future. This is relevant not only because some of the infrastructure of these campaigns remains viable despite Prigozhin’s undoing, but also because we advance into a year in which Ukraine continues to dominate Russia’s strategic priorities and there are multiple global elections that Russia may seek to influence.</p>
<p>Mandiant and Google's Threat Analysis Group (TAG) work together in support of our respective missions at Google. TAG <a href="https://blog.google/threat-analysis-group/ukraine-remains-russias-biggest-cyber-focus-in-2023/" rel="noopener" target="_blank">has likewise been tracking </a>coordinated influence operations <a href="https://blog.google/threat-analysis-group/prigozhin-interests-and-russian-information-operations/" rel="noopener" target="_blank">linked to Prigozhin</a> and the Internet Research Agency (IRA) for years; and in 2023, Google took over 400 enforcement actions to disrupt IO campaigns linked to the IRA, details of which are reported in the quarterly <a href="https://blog.google/threat-analysis-group/tag-bulletin-q3-2023/" rel="noopener" target="_blank">TAG Bulletin</a>. TAG has not observed significant activity from the IRA or other Prigozhin-linked entities specifically on Google platforms since Prigozhin's death, which is in line with Mandiant’s findings that have tracked different aspects of this broader set of threat activity.</p></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/life-after-death-prigozhin-fig1.max-1000x1000.png" alt="Image of Prigozhin delivering an address at the Cyber Front Z headquarters in Saint Petersburg, Russia following a bombing that occurred there in April 2023">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="muos3">Figure 1: Image of Prigozhin delivering an address at the Cyber Front Z headquarters in Saint Petersburg, Russia following a bombing that occurred there in April 2023</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><h2>Prigozhin-linked IO Infrastructure Persists Post-Death</h2>
<p>Mandiant closely tracks multiple IO campaigns that have variously been linked to Prigozhin, and we have observed shifts in these activity sets over the course of 2023, some of which likely were precipitated by Prigozhin’s political downfall and death. We have observed uneven degrees of change between campaigns, which may suggest variances in their original proximity to Prigozhin’s core operations or other campaign differences, such as management models or targeting focus, that have somehow influenced their respective degrees of continued viability thus far. However, we lack the visibility to assess the reason for this.</p>
<p>At least some components of these campaigns’ assets and infrastructure have remained viable since Prigozhin’s death, and we assess with moderate confidence that they will remain operational for the medium-term. These components will likely be leveraged by either their original, or appropriating operators, to influence public opinion on issues including those related to the Russian invasion of Ukraine, U.S. elections and politics, and developments in Africa’s Sahel region. </p>
<ul>
<li>We conducted an analytical review of three significant Prigozhin-linked IO campaigns that we track: the "Newsroom for American and European Based Citizens" (NAEBC) Campaign, Cyber Front Z, and a campaign linked to the Togo-based <em>Groupe Panafricain pour le Commerce et l'Investissement</em> (GPCI). 
<ul>
<li>The campaigns’ targeting aligns with core geographical regions known to be targeted by Prigozhin-linked IO: the U.S., Europe, Ukraine, Russia, and countries in Africa. </li>
</ul>
</li>
<li>Following the June 2023 mutiny, the swift closure of Prigozhin’s overt influence arms such as his <a href="https://www.theguardian.com/world/2023/jul/05/putin-takes-on-yevgeny-prigozhin-business-empire" rel="noopener" target="_blank"><u>Patriot Group</u></a> demonstrated the Russian Government’s intent to publicly dismantle at least components of Prigozhin’s operations. Reports <a href="https://www.reuters.com/world/europe/prigozhin-controlled-russian-media-group-shuts-amid-mutiny-fallout-2023-07-02/" rel="noopener" target="_blank"><u>also indicated</u></a> that Prigozhin’s “troll factory” was likewise closed as a result. 
<ul>
<li>Given the well-established nature of the campaigns detailed in this report, we find it unlikely that they could have been overlooked or that formal or informal Russian Government enforcement measures would have been incapable of stopping them—specifically as regards to Russia-based operations. </li>
<li>We have traditionally prioritized externally focused Prigozhin-linked IO in our tracking and thus lack the visibility to formally assess potential differences in outcomes for domestic Russia focused operations. However, it is plausible that efforts to dismantle Prigozhin’s influence capabilities may have centered on domestically focused operations. </li>
</ul>
</li>
<li>Narratives recently promoted by each of these campaigns largely correspond with the campaigns’ established focuses; this also includes topical overlaps between campaigns’ promoted narratives on general pro-Russia topics and/or narratives that mutually promote Russian interests and those of Prigozhin’s foreign business ventures.
<ul>
<li>Prigozhin’s businesses often served as a mechanism for promoting Russian interests abroad. Also, Prigozhin’s business holdings often appeared to concurrently operate in a target region. For example, Prigozhin-linked IO activity targeted African nations while his Wagner PMC also operated in the region (Figure 2).</li>
</ul>
</li>
</ul></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/life-after-death-prigozhin-fig2.max-1000x1000.png" alt="Cyber Front Z has consistently disseminated content promoting Prigozhin’s interests">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="muos3">Figure 2: Cyber Front Z has consistently disseminated content promoting Prigozhin’s interests. This includes content directly supporting Prigozhin and Wagner during and immediately after the June mutiny, as well as content promoting Wagner’s presence in Africa. These posts have been machine translated from Russian.</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><h2>Three Prigozhin-linked IO Campaigns</h2>
<p>Mandiant reviewed activity associated with assets attributed to the NAEBC, Cyber Front Z, and GPCI campaigns following the political downfall and death of Prigozhin. While our visibility into each campaign is neither equal nor complete, each displays at least continued activity showing how the campaigns and/or the auxiliary infrastructure leveraged to support them have endured. Additionally, each of these three campaigns represents one of a range of models leveraged for covert Prigozhin-linked IO (Figure 3).</p></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/life-after-death-prigozhin-fig3.max-1000x1000.png" alt="Prigozhin-linked IO activity has employed at least three different models for campaigns">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="vmq7r">Figure 3: Prigozhin-linked IO activity has employed at least three different models for campaigns</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><ul>
<li>NAEBC presents as a completely covertly managed campaign.</li>
<li>Cyber Front Z is an overt nominally third-party Russian organization established to obfuscate and administer IO activity.</li>
<li>GPCI is an independent, domestically-focused foreign organization with some reported financial links to Prigozhin. </li>
</ul>
<h3>Covertly Managed Campaign: NAEBC </h3>
<p>Since October 2020, Mandiant has tracked and reported on the NAEBC IO campaign, which has persistently attempted to influence right-leaning U.S. audiences on issues related to U.S. politics and elections, as well as significant geopolitical events. The campaign is named for the now-inaccessible inauthentic news site "Newsroom for American and European Based Citizens'' (NAEBC), which according to an October 2020 <a href="https://www.reuters.com/article/usa-election-russia-disinformation/exclusive-russian-operation-masqueraded-as-right-wing-news-site-to-target-u-s-voters-sources-idUSKBN26M5OP/" rel="noopener" target="_blank"><u>Reuters article</u></a> was attributed by a U.S. Federal Bureau of Investigation investigation as being run by individuals linked to the IRA. NAEBC has evolved and shifted its tactics over time. Its operators have continued to use established campaign infrastructure after repeated public exposure, including the repurposing of social media assets once used to backstop and promote the inauthentic NAEBC news site to form the core of an effort to promote content furthering the campaign’s objectives through coordinated and inauthentic means. </p>
<p>If leveraged to target upcoming U.S. elections, the NAEBC campaign may only be one component of pro-Russia activity collectively targeting the population. Historically, IO campaigns linked to Prigozhin and/or the IRA have targeted all sides of the political spectrum to advance broader foreign influence objectives to sow division. </p>
<ul>
<li>Some previously attributed campaign assets on alternative platforms continue to promote content targeting right-leaning U.S. audiences on a range of issues.</li>
<li>The campaign has a history of fluctuating its activity levels between key events such as U.S. elections. Its current levels appear to be reduced from those during the 2022 U.S. <a href="https://www.mandiant.com/resources/blog/information-operations-2022-midterm-elections" rel="noopener" target="_blank"><u>midterm elections</u></a>, when the campaign had a focused operation, but are similar to what was observed preceding Prigozhin’s downfall. </li>
<li>NAEBC personas recently promoted pro-Russia narratives appear consistent with past activity, including narratives targeting U.S. domestic politics and elections, the Russian invasion of Ukraine, and geopolitical developments, such as the Israel-Hamas conflict (Figure 4). </li>
<li>It is possible that the controversy surrounding Prigozhin has affected the campaign; however, given limitations in our current visibility and the identified consistencies in recent campaign activity, we are currently unable to assess to which degree this may be so.</li>
<li>NAEBC's ongoing activity may be an indicator that the campaign operators intend to leverage campaign assets in the upcoming U.S. election season—the campaign has<a href="https://www.mandiant.com/resources/blog/information-operations-2022-midterm-elections" rel="noopener" target="_blank"><u> previously mobilized</u></a> around such events—even if only as an attempt to bolster the perception that pro-Russia IO is persistently influencing the U.S. electorate.
<ul>
<li>In the 2022 midterm elections, the campaign launched their main operation closer to election day, thus it may be too early to assess this scenario. </li>
</ul>
</li>
<li>Historical activity linked to Prigozhin and/or the IRA show that their tactics often appear foremost intended to exacerbate existing divisions in society, often targeting both sides of the political spectrum. Accordingly, we highlight as context an example of related IO activity that occurred contemporaneous to NAEBC’s emergence in 2020, which illustrates how this dynamic can manifest. 
<ul>
<li>In August 2020, Mandiant identified and reported to customers a website named “Peace Data,” which promoted content that appeared curated to influence left-leaning audiences, including some content related to U.S. domestic political issues and the then-upcoming 2020 presidential election (Figure 5). </li>
<li>Subsequently, Meta <a href="https://about.fb.com/news/2020/09/august-2020-cib-report/" rel="noopener" target="_blank"><u>reported</u></a> publicly in September 2020 that it had removed a network of coordinated and inauthentic accounts promoting Peace Data—it attributed this activity as being run by individuals with links to the IRA. Shortly after public exposure, the Peace Data website posted a message indicating that it was ceasing operations. </li>
<li>The Peace Data comparison with NAEBC likewise provides an example of how even nominally similar IO campaigns can leverage different tactics to target subsets of the same populations. For example, Peace Data reportedly engaged in the paid solicitation of unwitting real individuals to write articles for dissemination.</li>
</ul>
</li>
</ul></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/life-after-death-prigozhin-fig4.max-1000x1000.png" alt="Example post by NAEBC persona that disseminated content">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="vmq7r">Figure 4: Example post by NAEBC persona that disseminated content that promoted commentary from Putin regarding the Israel-Hamas conflict that positively framed Russia’s actions in Ukraine</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/life-after-death-prigozhin-fig5.max-1000x1000.png" alt="Example of article published in 2020 to the “Peace Data” domain">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="vmq7r">Figure 5: Example of article published in 2020 to the “Peace Data” domain, which promoted content on a range of issues including some pertaining to U.S. domestic politics and elections. Notably, its operators leveraged some different tactics than the NAEBC campaign, <a href="https://www.nbcnews.com/tech/tech-news/russian-internet-trolls-hired-u-s-journalists-push-their-news-n1239000">reportedly</a> including the paid soliciting of content from unwitting contributors</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><h3>“Third-Party” Front Organization: Cyber Front Z</h3>
<p>Cyber Front Z first emerged as a Russian-language pro-Russia Telegram channel (Russian: Кибер Фронт Z) in the days following Russia’s launch of its full scale invasion of Ukraine in late February 2022. We first<a href="https://www.mandiant.com/resources/blog/information-operations-surrounding-ukraine" rel="noopener" target="_blank"><u> publicly reported</u></a> on our tracking of Cyber Front Z in May 2022, noting its overt efforts to coordinate the promotion of invasion-related pro-Russia content and that Russian investigative reporting suggested it was linked to individuals from the IRA who were running a troll factory—Meta seemingly confirmed this in <a href="https://about.fb.com/wp-content/uploads/2022/08/Quarterly-Adversarial-Threat-Report-Q2-2022.pdf" rel="noopener" target="_blank"><u>public reporting</u></a> from August 2022. </p>
<p>In an August 2023 update to customers following Prigozhin’s death, we identified expansions in Cyber Front Z’s activity and several indicators that more clearly established Cyber Front Z’s IRA links and suggested the group had plans to expand operations leading up to Prigozhin’s mutiny. This activity has been significantly curtailed since then, though the Telegram channel has remained somewhat active and limited indicators suggest it may still be planning for expanded future activity. </p>
<ul>
<li>In Spring 2023, Prigozhin announced a new head of Cyber Front Z, a woman named Asiya Aminovna Sadrieva who we judge to be a former IRA employee. Prigozhin then directed Sadrieva to register Cyber Front Z as a public organization—business records show this was done in early June—suggesting plans for Cyber Front Z’s continued activity and growth leading up to the mutiny.
<ul>
<li>Throughout this time Cyber Front Z was posting job solicitations including for "activists…who are ready to defend their Motherland in the information field with the help of comments (VKontakte, Telegram)” (translated from Russian) (Figure 6). </li>
</ul>
</li>
<li>Cyber Front Z organized grassroots activity and in-person events, often focused on invasion related topics, that appeared to cease post-mutiny. However, in early December 2023, the group’s VKontakte (VK) page, where they traditionally promoted events, began posting about past events and implying considerations for future organizing (Figure 7).
<ul>
<li>The halting of in-person events indicates that Cyber Front Z was at minimum indirectly hampered in some of its activity by Prigozhin’s political fallout; its nascent reactivation on this front suggests such effects may not be final.</li>
<li>The grassroots activity organized under the Cyber Front Z brand demonstrates how the campaign, which has centered on promoting invasion-related messaging, dually maintained an element focused on domestic Russian populations. </li>
</ul>
</li>
<li>Cyber Front Z’s Telegram channel has remained operational throughout the process of Prigozhin’s undoing and since his death, though it appears less active and is now primarily focused on publishing and cross-promoting content related to developments in Ukraine and other domestic Russian and global developments.
<ul>
<li>Cyber Front Z’s Telegram channel continued to promote content supportive of Prigozhin and Wagner throughout the insurrection and since.</li>
<li>A New Year’s Eve post published to both the Cyber Front Z Telegram channel and VK page reflected on the group’s 2023 activity, including noting that it had organized “raids” on social media pages—likely describing what is known as “brigading”— spotlighting its efforts coordinating online activity as one of the group’s key accomplishments.</li>
<li>We currently lack the visibility to determine if and/or when the coordinated and inauthentic activity previously attributed to the group by Meta ceased. However, this Telegram channel has at least previously served as a component of that activity.</li>
</ul>
</li>
</ul></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/life-after-death-prigozhin-fig6.max-1000x1000.png" alt="Cyber Front Z posted job solicitations in the period preceding Prigozhin’s June mutiny">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="37793">Figure 6: Cyber Front Z posted job solicitations in the period preceding Prigozhin’s June mutiny (these posts have been machine translated from Russian)</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/life-after-death-prigozhin-fig7.max-1000x1000.png" alt="advertisement and post">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="37793">Figure 7: An advertisement for an in-person Cyber Front Z event held at the group's headquarters (left); a December 2023 post to Cyber Front Z VK page announcing interest in resuming in-person events (machine translated from Russian), the text of the included graphic reads “We are with you again!” (right)</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><h3>Likely Paid Partnership: GPCI</h3>
<p>In August 2023, before Prigozhin’s death, we identified, and subsequently reported to customers, recently registered infrastructure and newly created social media accounts that we attributed with high confidence to <em>Groupe Panafricain pour le Commerce et l'Investissement</em> (GPCI), a Togo-based political marketing consultancy <a href="https://about.fb.com/news/2023/05/metas-adversarial-threat-report-first-quarter-2023/" rel="noopener" target="_blank"><u>recently outed</u></a> by Meta for its involvement in continued information operations targeting domestic audiences primarily in the Sahel region of Africa. According to <a href="https://cyber.fsi.stanford.edu/io/news/car-takedown-may-2021" rel="noopener" target="_blank"><u>multiple</u></a> <a href="https://alleyesonwagner.org/2023/02/05/burkina-faso-under-influence/" rel="noopener" target="_blank"><u>sources</u></a>, GPCI and its founder Harouna Douamba allegedly maintain ties to the now-deceased Yevgeniy Prigozhin.</p>
<ul>
<li>The identified websites, which we assessed to be inauthentic, present as media entities targeting different countries in Africa’s Sahel region. Additionally, we identified a number of Facebook pages and accounts leveraged to seed and disseminate content—some pages correspond directly to media outlets attributed to GPCI. 
<ul>
<li>Facebook pages published content and then regularly shared that content across different Facebook groups. </li>
<li>Additionally, the suspected inauthentic Facebook accounts, which most commonly presented as regionally based individuals, inorganically boosted engagement with the GPCI-associated Facebook pages (Figure 8). </li>
</ul>
</li>
<li>Messaging promoted by this network has included narratives related to political dynamics and events within the Sahel region, such as criticizing France’s regional presence.</li>
<li>According to <a href="https://advantage.mandiant.com/reports/23-00039724#:~:text=May%202023%2C%20Meta-,acknowledged,-renewed%20attempts%20by" rel="noopener" target="_blank"><u>public reporting</u></a> by Meta, GPCI is linked to Aimons Notre Afrique (ANA), a non-governmental organization (NGO) based in the Central African Republic (CAR) that has previously been exposed for supporting information operations. Notably, separate <a href="https://alleyesonwagner.org/2023/02/05/burkina-faso-under-influence/" rel="noopener" target="_blank"><u>public reporting</u></a> has indicated that GPCI/ANA, as well as its founder Harouna Douamba, maintain various ties to Prigozhin. These links include alleged financial connections to a company called Lobaye Invest, which the <a href="https://home.treasury.gov/news/press-releases/sm1133" rel="noopener" target="_blank"><u>U.S. Department of Treasury</u></a> previously sanctioned as controlled by Prigozhin and used to consolidate PMC Wagner’s operations in the Central African Republic; and claims that Douamba managed Russian propaganda out of the “Office of Information and Communication in the Central African Republic,” <a href="https://www.lemonde.fr/en/le-monde-africa/article/2023/08/06/the-faces-of-russia-s-influence-across-the-african-continent_6082513_124.html" rel="noopener" target="_blank"><u>a center of influence established by Wagner within the Central African presidency</u></a>.</li>
<li>GPCI exhibited an upward trend in its activity throughout the period of Prigozhin’s downfall and subsequent death, during a time when some other Prigozhin-linked IO activity sets appeared to be at least hampered by the political fallout surrounding him. One possible explanation for this is that GPCI represents a third model for how Prigozhin managed his IO activity. 
<ul>
<li>In addition to being located outside Russia, and thus potentially beyond the reach and care of the Russian Government, GPCI is an organization local to the target region under local management. It is possible that GPCI has conducted influence activity in the pay of Prigozhin-linked entities and also is engaged in separate activity reflecting local initiatives that in instances also has alignments with Russian interests.</li>
<li>We lack the visibility that would confirm this possible dynamic. However, if true, such a paid-local partnership model could explain the resurgence of GPCI activity during this tumultuous period. Likewise, its purported history of partnering with Prigozhin would suggest that it could be leveraged by surviving Prigozhin legacy organizations or other Russian actors in future.</li>
</ul>
</li>
</ul></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/life-after-death-prigozhin-fig8.max-1000x1000.png" alt="Suspected inauthentic account attributed to GPCI">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="37793">Figure 8: Suspected inauthentic account attributed to GPCI engaged in concerted sharing of campaign content while using #Abonnez_Vous_a_la_Page (machine translation: Subscribe to the page) for audience building</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><h2>Promoted Messaging</h2>
<p>The NAEBC, Cyber Front Z, and GPCI campaigns’ recently promoted narratives largely appear to be consistent with past activity. Each campaign has a distinct regional focus that directly corresponds with the majority of its promoted content. However, the campaigns have also promoted messaging targeting other countries or issues, including issues relevant to Russian strategic interests and/or Prigozhin’s diverse business investments. What follows are some examples of narratives promoted by these campaigns organized by some of the regions they have variously targeted. </p>
<h3>The U.S. and Europe</h3>
<p>NAEBC’s central narrative focus remains related to U.S. politics and elections. This includes narratives promoting issues that appear aligned with the Republican Party, specifically supporting former U.S. President Donald Trump and criticizing the current administration and the Democratic Party (Figure 9).</p>
<ul>
<li>Promoted content has supported Trump’s candidacy in the 2024 U.S. presidential election, and it has questioned the 2020 U.S. presidential election results.</li>
<li>Other narratives promoted controversial narratives, such as alleging that the congressional committee established to investigate the events of Jan. 6 was engaged in a cover-up, or promoting narratives related to allegations against President Biden's son Hunter.</li>
<li>Narratives that appeared to criticize the Administration include those that framed Biden as unfit for leadership and those that implied he and other officials are corrupt and ignore the problems facing the American people.</li>
<li>In some instances, NAEBC promoted content more broadly criticizing major institutions, such as NATO or the UN, suggesting they should be dismantled. Such narratives appear to generally support an idea that a Western-led global order should be broken up in favor of a multipolar world where Russia has a larger share of influence.</li>
</ul></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/life-after-death-prigozhin-fig9.max-1000x1000.png" alt="Example NAEBC content that promoted narratives related to U.S. elections (top) and criticizing NATO (bottom)">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="0o9tl">Figure 9: Example NAEBC content that promoted narratives related to U.S. elections (top) and criticizing NATO (bottom)</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><p>Russian-language content published to the Cyber Front Z Telegram channel regularly criticizes “the West” and individual Western countries.</p>
<ul>
<li>Often this is in the context of the Russian invasion of Ukraine, though Western countries also are targeted on unrelated issues. This includes content that is critical of U.S. and European leaders. </li>
<li>Additional narratives critique what are labeled as “Western values,” including the repeated promotion of anti-LGBTQ+ content. </li>
</ul>
<h3>Ukraine and Russia</h3>
<p>Cyber Front Z’s core focus remains the promotion of pro-Russia content related to the Russian invasion of Ukraine, though it does comment on other topics (Figure 10).</p>
<ul>
<li>Promoted narratives support the Russian war effort, including explicit support for Wagner; they also include anti-Ukraine messaging, criticizing Ukraine’s war effort and leadership, as well as disinformation narratives and pro-Russia talking points like falsely calling Ukrainians “nazis” and the war a process of “denazification.” </li>
<li>Additional content has promoted Russia and Russian President Vladimir Putin more generally, such as praising Putin for his purported candor at media events.</li>
</ul></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/life-after-death-prigozhin-fig10.max-1000x1000.png" alt="Example Cyber Front Z content promoting narratives related to the Russian invasion of Ukraine">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="0o9tl">Figure 10: Example Cyber Front Z content promoting narratives related to the Russian invasion of Ukraine (these posts have been machine translated from Russian)</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><p>NAEBC assets have incorporated invasion-related narratives as another core component of its recent activity. Such anti-Ukraine narratives have consistently appeared intended to diminish support among its target audience for foreign aid sent to Ukraine (Figure 11).</p>
<ul>
<li>Promoted narratives criticize U.S. support for Ukraine, alleging the U.S. Government deprioritizes U.S. domestic issues as a result, and they frame Ukraine’s war effort as futile and its leadership as corrupt. </li>
<li>A more limited number of narratives promoted Vladimir Putin, including those that framed him as a force for good working to counter Western values that are presented as detrimental to those living under them.</li>
</ul></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/life-after-death-prigozhin-fig11.max-1000x1000.png" alt="Example NAEBC content that promoted narratives related to the Russian invasion of Ukraine">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="0o9tl">Figure 11: Example NAEBC content that promoted narratives related to the Russian invasion of Ukraine</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><h3>Africa </h3>
<p>GPCI primarily promotes content targeting countries in the Sahel region of Africa, most frequently focusing on domestic audiences in Burkina Faso though sometimes pivoting to target other regional events and issues (Figure 12). </p>
<ul>
<li>Messaging has frequently praised and supported Captain Ibrahim Traoré (the military leader and transitional president of Burkina Faso) and the role of Burkina Faso's Defense and Security Forces (FDS) and the Patriotic Movement for Safeguard and Restoration (MPSR).</li>
<li>Some narratives praised strengthened Russo-Burkinabe relations, such as touting Traoré's involvement in the July 27, 2023, Russia-Africa Summit where he stated that "Russia is a part of the family for Africa." Additional narratives praised Wagner’s involvement throughout the region. </li>
<li>Promoted narratives also included topics such as the July 2023 coup d'état in Niger. Such messaging most frequently supported the coup leader General Abdourahamane Tiani; and it was critical of the role of France in the region and regional bodies like the Economic Community of West African States (ECOWAS).</li>
</ul></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/life-after-death-prigozhin-fig12.max-1000x1000.png" alt="Content promoted by GPCI criticizing ECOWAS (left); and content promoted by in-network GPCI accounts promoting pro-Russia messaging (right)">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="0o9tl">Figure 12: Content promoted by GPCI criticizing ECOWAS (left); and content promoted by in-network GPCI accounts promoting pro-Russia messaging (right)</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><p>Cyber Front Z has also promoted Africa-related narratives via its Telegram channel. Interestingly, in the interlude between the Prigozhin-led mutiny and his death, it promoted content supporting Wagner’s role in several African countries, including content presenting Wagner as important to regional security and defending Russia's interests abroad.</p>
<h2>Outlook and Implications</h2>
<p>Throughout his long tenure as a funder of IO activity, Yevgeniy Prigozhin and his affiliated entities not only established a range of campaigns targeting different geographies but also leveraged multiple models for managing and executing IO as is exemplified by the case studies detailed in this blog post. We currently lack the visibility necessary to assess the total implications of what the differences between Prigozhin-linked IO campaigns may mean for their long-term survivability. Key indicators that we are looking for moving forward include those that might shed light on their future management: indicators suggesting a central connection between any surviving campaigns, or those suggesting that the various Prigozhin-linked activity sets are linked to different actors and thus they have been fragmented under new operators. While the outcome of this process remains unknown, analysis of these three campaigns highlights the potential that this and potentially other IO infrastructure established by Prigozhin-linked initiatives will remain available for pro-Russia threat activity at least in the medium term.</p></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[AWS targets a longtime cloud migration blocker with SQL Server license portability]]></title>
<description><![CDATA[Licensing can be complicated, particularly when enterprises are forced to double-pay because the software they already own is only licensed for a specific environment, and moving it requires a whole different licensing model. Without proper portability rights, they need to make additional financi...]]></description>
<link>https://tsecurity.de/de/3576806/ai-nachrichten/aws-targets-a-longtime-cloud-migration-blocker-with-sql-server-license-portability/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3576806/ai-nachrichten/aws-targets-a-longtime-cloud-migration-blocker-with-sql-server-license-portability/</guid>
<pubDate>Sat, 06 Jun 2026 02:03:18 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Licensing can be complicated, particularly when enterprises are forced to double-pay because the software they already own is only licensed for a specific environment, and moving it requires a whole different licensing model. Without proper portability rights, they need to make additional financial investments to run the same workloads in a different home.</p>



<p>AWS says its new Bring Your Own Media (BYOM) service eliminates this duplication. Customers can now reuse their existing Microsoft SQL Server media and licenses on Amazon Relational Database Service (RDS) with no additional licensing fees.</p>



<p>This means enterprises no longer have to justify workload migrations to the cloud against existing licensing commitments and infrastructure investments, AWS said.</p>



<p>“What used to be a licensing barrier between operational SQL Server data and agentic AI is now gone,” AWS data engineer Srikanth Katakam and product marketing manager Colleen Betik wrote in a <a href="https://aws.amazon.com/blogs/database/unlock-license-mobility-with-bring-your-own-media-on-fully-managed-amazon-rds-for-sql-server/" target="_blank" rel="noreferrer noopener">blog post</a> announcing the service.</p>



<h2 class="wp-block-heading">Avoiding the double-licensing problem</h2>



<p>To drive true value, <a href="https://www.infoworld.com/article/4047863/three-tips-for-building-agentic-ai-systems-on-cloud-platforms.html" target="_blank">agentic AI apps</a> must have access to elastic GPU capacity as well as direct, low-latency access to the data they need to reason and make decisions. But, AWS argued, that can be difficult in self-managed data centers and on premises infrastructure with limited access to agentic AI cloud-native services. But a lot of enterprise data lives in Microsoft SQL Server, and until now customers have had to pay for a second license to use a fully managed cloud service like RDS.</p>



<p>Now, with BYOM on Amazon RDS for SQL Server, enterprises can reuse their existing SQL Server Enterprise Edition or Standard Edition licenses through a “lift-and-shift” model. This brings their data into a fully-managed environment.</p>



<p>According to the licensing distribution terms, enterprises must provide their licensed SQL Server Release to Manufacturing (RTM) media to Amazon RDS. They can then upload that media to <a href="https://www.infoworld.com/article/4155868/aws-turns-its-s3-storage-service-into-a-file-system-for-ai-agents.html" target="_blank">Amazon S3</a> and launch BYOM instances. Enterprises must configure AWS License Manager to perform automatic instance tracking.</p>



<p>From there, RDS automates patching, backups, high availability, and monitoring, while providing direct access to agentic AI and analytics services native to AWS. The platform also reports vCPU usage to provide visibility into SQL Server license usage, Katakam and Betik wrote.</p>



<p>“You do not need to choose between protecting your SQL Server licensing investments and giving your data a path to the AWS analytics and agentic AI services redefining what’s possible in the cloud,” they said. </p>



<p>It’s important to note that this service is only available to enterprises with Microsoft Software Assurance (SA), an add-on which supports mobility and rehosting of existing licenses. Enterprises must verify that their SQL Server licenses comply with Microsoft’s licensing agreement, and that they have a SQL Server License (Standard or Enterprise) with SA. They also must submit a License Mobility Verification Form to Microsoft; it, in turn, will notify AWS once verification is complete.</p>



<p>AWS emphasized that enterprises remain responsible for compliance; it does not block operations if license limits are exceeded.</p>



<h2 class="wp-block-heading">More control over workloads, loosening Microsoft’s grip</h2>



<p>The advantage of this service, explained <a href="https://moorinsightsstrategy.com/team/mike-leone/" target="_blank" rel="noreferrer noopener">Mike Leone</a>, principal analyst at Moor Insights &amp; Strategy, is that enterprises can get a Microsoft SQL Server workload onto a managed AWS service without rewriting it for Aurora or paying for the license twice. This means they can modernize on their own schedule rather than being forced into rewrites before they’re ready.</p>



<p>“For a lot of shops, that control over timing is worth more than the license saving itself,” Leone said.</p>



<p>This also loosens Microsoft’s grip on enterprise workloads, because organizations finally have somewhere else to run SQL Server using licenses they already own, he noted. Realistically, their dependency shifts to AWS rather than disappearing entirely, as their data ends up living next to AWS’s AI services.</p>



<p>“For a lot of teams, that’s a trade they’re glad to make for the managed infrastructure and the AI tooling they get in return,” Leone said.</p>



<p><a href="https://www.infotech.com/profiles/yaz-palanichamy" target="_blank" rel="noreferrer noopener">Yaz Palanichamy</a>, a senior advisory analyst at Info-Tech Research Group, also pointed to significant improvements stemming from the migration. Notably, it allows organizations to transition away from static, linear, or reactive storage capabilities towards more dynamically intelligent environments.</p>



<p>“The key is to balance the unification of transactional data towards managed AI and machine learning pipelines,” he said.</p>



<h2 class="wp-block-heading">Enterprises take on new responsibilities</h2>



<p>The catch? Leone noted that enterprises now own the task of licensing compliance. Staying current on SA, the Microsoft maintenance contract that makes any of this legal, and the license mobility rules, “become your headache instead of something baked into the bill,” he said.</p>



<p>Furthermore, he added, lift-and-shift has a way of turning into “lift-and-forget” when enterprises move SQL Server as-is and never actually modernize, “so you end up carrying all the old baggage onto a shinier platform.”</p>



<p>Palanichamy also pointed to skyrocketing AWS costs, since operationalizing AI agents requires a considerable amount of data ingestion and querying. This can potentially be cost prohibitive on RDS for SQL Server.</p>



<p>“One aspect to consider would be the relative time to production value, so that enterprises can better handle the management of volatile AI workloads,” he said.</p>



<h2 class="wp-block-heading">Just one challenge in the AI race</h2>



<p>Although AWS frames licensing complexity as a roadblock to agentic AI, analysts say it’s really just one piece of the puzzle.</p>



<p>Organizations are not in an AI-ready state due to a number of factors, Palanichamy noted. This could be total cost of ownership (TCO)-related, a lack of appropriate acceptable use policies (AUPs), or concerns around security and compliance.</p>



<p>If and when enterprises are ready to adopt AI, they must perform thorough needs analysis/process optimization benchmarking exercises to determine what workflows could benefit from the technology, he said, and, conversely, flag workflows where AI could prove “an impediment or potential disservice.”</p>



<p>Leone also pointed out that moving SQL Server onto RDS doesn’t “magically make your data agent-ready,” nor does it make it smarter. The data proximity and managed plumbing are what actually support agents. Sitting data next to Bedrock and the rest of <a href="https://www.infoworld.com/article/4143387/running-agents-with-amazon-bedrock-agentcore.html" target="_blank">AWS’s AI services</a> means builders “stop wasting time shipping the data around or building one-off integrations every time an agent needs it.”</p>



<p>Ultimately, though, licensing isn’t the real issue when it comes to AI; it’s more of a migration problem. The real roadblocks are messy data, questionable governance, and teams that aren’t ready to run it in production, and, Leone said, “no change to a license bill touches a single one of them.”</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Microsoft's AI Futurist explains how he uses Copilot — and the real-world problems enterprises are solving with agents]]></title>
<description><![CDATA[Microsoft used its Build 2026 conference this week to push a clear message: agents are rapidly moving into production throughout enterprise systems, and the winning platform will be the one that gives them reliable context, governance, identity, memory — and secure access to enterprise data. The ...]]></description>
<link>https://tsecurity.de/de/3576491/it-nachrichten/microsofts-ai-futurist-explains-how-he-uses-copilot-and-the-real-world-problems-enterprises-are-solving-with-agents/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3576491/it-nachrichten/microsofts-ai-futurist-explains-how-he-uses-copilot-and-the-real-world-problems-enterprises-are-solving-with-agents/</guid>
<pubDate>Fri, 05 Jun 2026 22:17:26 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Microsoft used its <a href="https://news.microsoft.com/build-2026/">Build 2026 conference </a>this week to push a clear message: agents are rapidly moving into production throughout enterprise systems, and the winning platform will be the one that gives them reliable context, governance, identity, memory — and secure access to enterprise data. </p><p>The company <a href="https://venturebeat.com/data/enterprise-ai-agents-keep-creating-data-silos-microsofts-build-answer-is-microsoft-iq-and-rayfin">announced Microsoft IQ</a> as a context layer across GitHub Copilot, Microsoft Foundry and Copilot Studio; Work IQ APIs coming June 16; Fabric IQ for structured business data; Foundry IQ for retrieval across enterprise knowledge and the live web; and Web IQ as a new agent-facing web search stack. </p><p>Microsoft also introduced <a href="https://www.microsoft.com/en-us/microsoft-365/blog/2026/06/02/introducing-microsoft-scout-your-always-on-personal-agent/">Scout</a>, a personal work agent, and a whopping <i>seven </i><a href="https://microsoft.ai/news/building-a-hillclimbing-machine-launching-seven-new-mai-models/">new in-house AI models in its growing MAI family</a> across modalities and use cases, including MAI-Thinking-1.</p><p>Those announcements sit directly in <b>Marco Casalaina</b>’s lane. Casalaina<a href="https://www.linkedin.com/in/marcocasalaina/"> is Microsoft’s VP Products, Core AI and AI Futurist</a>. He leads Microsoft’s AI Futures team and previously led teams across Azure AI, including Azure OpenAI, Vision, Speech, Decision, Language, Responsible AI and AI Studio. </p><p><a href="https://onegiantleap.com/2026-speakers/marco-casalaina?utm_source=direct&amp;utm_medium=direct&amp;utm_campaign=Unspecified">Before Microsoft</a>, he led Salesforce’s Einstein AI team and earned a computer science degree from Cornell University. <a href="https://www.crn.com/slide-shows/channel-programs/30-notable-it-executive-moves-march-2022">CRN reported</a> that he joined Microsoft in early 2022 as vice president of products for Azure Cognitive Services, meaning he has now been at the company for more than four years.</p><p>VentureBeat spoke with Casalaina ahead of Build about Microsoft’s agent strategy, the company’s model-choice philosophy, how Microsoft IQ fits with MCP, and why he believes enterprises need far more than just access to powerful models. The interview below has been edited for clarity and condensed from the transcript.</p><h3><b>VentureBeat (VB): To start, can you explain your role at Microsoft and what “AI Futurist” means in practice?</b></h3><p>Marco Casalaina (MC): I am VP Products of what we call Core AI. Core AI is our set of tools for AI developers, and that includes Foundry, Visual Studio, VS Code, GitHub and GitHub Copilot. That’s our overall group.</p><p>My Silicon Valley title is AI Futurist, and that has a very concrete meaning here. I’ve worked with other folks who are considered futurists, like Peter Schwartz, and that can be a little bit more fuzzy. For me, what it means concretely is that I am the first person to try anything new here.</p><p>I am constantly getting things from all over Microsoft, not even just Foundry, because I work with really everybody across the company. Pretty much everybody sends me the new things at all times. Even today, I got something brand new just before this call. I’m usually the first person to try anything new here, which is pretty cool. I get to see a lot of really cool stuff.</p><p>A friend of mine, who is head of AI at Intuit, calls me an “adjacent possiblist.” I consider my futurist concept to be about a year out from now — the immediate future of what’s about to happen next. That’s what I focus on.</p><h3><b>VB: Where are you looking at the agentic state of things, and in particular Microsoft’s position as enterprises and individuals rush to adopt agentic AI?</b></h3><p>MC: We can look at it from bottom to top. At the very base of the stack is our commitment to model choice. All along, we’ve had the OpenAI GPT frontier models. Now we have a really solid partnership with Anthropic, where we’re offering the Claude models. We just launched Claude Opus 4.8 on Azure — on Foundry, I should say — and at Build, we are introducing our new MAI model.</p><p>The MAI models are a set of frontier models that we’re building in-house. They are made for token efficiency, optimization and customization. We are specifically making them for our customers to customize on their own data sets.</p><p>One level above that, we are announcing hosted agents in Foundry. That is our managed agent capability in Foundry. It automatically handles scaling, containerization and those kinds of things. It is an environment where you can manage agents.</p><p>One level above that is the Foundry control plane. At least for the agents you build, you want to have control over them. This gives you observability into their cost, tokens and correctness. You can do continuous evaluations and sample interactions with those agents, run evals and make sure they are continuing to work and not drifting.</p><p>The big news is going to be the GA of what we call the IQs here at Microsoft. There are currently three, and there will be four. There is Foundry IQ, which is basically for knowledge — largely unstructured knowledge. There is Fabric IQ. We have a ton of customers who have entrusted a lot of data to the Microsoft Cloud in Fabric, Power BI and related technologies. Fabric IQ is about making an agent-facing interface for this data, so agents can get to it without literally going through a Power BI report. That’s ridiculous.</p><p>Work IQ is about the Microsoft ecosystem. You can look at Work IQ as the agentic face of all the Microsoft apps: Outlook, Teams, Word, SharePoint and all those kinds of things. How does an agent interact with those things? That is Work IQ.</p><p>And finally, the fourth IQ is Web IQ. We are releasing our new agent-facing web search capability. It can search the web, search through videos and even do some kinds of browsing tasks automatically. It is super fast, and it kind of has no face. It’s headless. The interface is intended for agents.</p><p>We will also be announcing Agent Optimizer. That includes a new type of evaluation that allows you to evaluate much more granularly whether an agent is actually working and working correctly. The optimization step can go back in and make modifications to the prompt, obviously with your consent, and modify your agent so it works more correctly going forward. Effectively, it creates a feedback loop to make agents work better.</p><h3><b>VB: Microsoft has sometimes been criticized for murky and clunky product naming. Where do these IQ products sit? Are enterprise users supposed to go to IQ first, or is IQ more for developers to connect to?</b></h3><p>MC: All of the IQs are headless. The concept of IQ is that each one provides a different type of context to an agent specifically. Largely, it will be developers interacting with the various IQs — developers and the agents they build.</p><p>The IQ brand is really about agent context. End users largely won’t interact with the IQs. It is true that if you use Microsoft 365 Copilot today, you’ll notice a little thing that says it is using Work IQ. So it is a little bit visible, but the customer or end user doesn’t have to go find the IQ. Their system or developers hook that up.</p><h3><b>VB: Is the IQ family essentially Microsoft’s version of MCP? Is it using MCP, or is it something different?</b></h3><p>MC: All of the IQs are indeed exposed as MCP servers. You have correctly characterized MCP as basically an agent-facing or self-describing API. It’s not that fancy. That’s really what it is, with some authentication layers and capabilities built in, which is super useful.</p><p>Something like Work IQ — really all the IQs — have to be authenticated. In order for Work IQ to see my email, Teams messages, documents and stuff like that, I have to be able to authenticate it on behalf of me.</p><p>That gets us to another core differentiator that we will be announcing at Build, which is agent identity. We have this Entra system, and Entra is, I believe, the world’s largest used identity system for human users. For some time now, you have been able to declare an agent to have an identity in there. Now, agents will be able to have their own identity, their own Teams box, their own email inbox and stuff like that.</p><p>These agents will use Work IQ to check their own email, check their own documents and that sort of thing.</p><h3><b>VB: Enterprises are not one-size-fits-all on models. Microsoft supports many leading models through Foundry and Azure, while also building its own. Is Microsoft a model company, an infrastructure company or a connector between models and work products?</b></h3><p>MC: The answer is yes. We are obviously the hyperscaler. We are absolutely committed to model choice, and we will continue to offer the frontier models from all of the major players: OpenAI, Anthropic, Mistral, Black Forest, xAI — you name it. They are all going to be represented in there.</p><p>At the same time, we have what is now called our Microsoft AI Superintelligence Team, formed by Mustafa Suleyman, and we are building our own frontier models as well. Like I said earlier, we are really gearing these models toward optimization — token efficiency, bang for the buck and customization.</p><p>These are things our customers have been asking for: the ability to more finely customize models, whether that is fine-tuning or continued pre-training. Continued pre-training is literally changing the weights of the model, whereas fine-tuning is adding a little layer on top.</p><p>We have these capabilities in Foundry: fine-tuning, distillation and those kinds of things. I would note, by the way, that our MAI models are not distilled. Some model providers, especially some of the less scrupulous ones, will distill other models into theirs, and that can have unusual effects. We don’t do that. The data provenance of our models is of primary importance to us.</p><p>When we come out with these models, we want our customers to know that the data provenance is clean in terms of the rights to the data, where it came from and all that kind of stuff.</p><p>The choice thing also goes above the model layer. When we talk about Foundry hosted agents, we have the Microsoft Agent Framework. You talk about agent orchestration — how you make agents work together when you have multiple agents — and Microsoft Agent Framework is an excellent framework for that.</p><p>However, I can make a LangGraph or LangChain Foundry hosted agent. I can make a CrewAI Foundry hosted agent. I can use any number of orchestration frameworks and put that up as a Foundry hosted agent, and it becomes a first-class Foundry agent.</p><p>That means I get the observability. It shows up in the Foundry control plane. I can do evaluations on it. I can do traces on it. I can get all those things from the Foundry control plane with an agent built in really any framework I choose.</p><h3><b>VB: Some companies are interested in Chinese and open-source models. How much of Microsoft offering its own models is about giving customers an American version of that?</b></h3><p>MC: I can’t speak to that exactly. Of course, we offer DeepSeek models and Qwen models in Foundry, so we offer all of these choices today, and our customers can make that choice.</p><p>The MAI models are really focused on token efficiency and customizability. That is what our customers are demanding, and that is the gap we are filling.</p><h3><b>VB: As agents take on longer tasks and more specialized work, will enterprises keep expanding the number of models they use, or will there be a winnowing?</b></h3><p>MC: I do see it expanding. We are not just focused on tokens per se. A token is not a token is not a token. One token is not necessarily equivalent across these things. It is all about what you are doing with each token and the efficiency of that. It comes back to what kind of value you are getting for the cost. That is a lot of the rationale behind why we are developing our own MAI models.</p><p>Part of my job is to travel all around the world. I’ve been all over the place. For example, I’ve been working with Bayer. One of the things we are measuring is not just token usage, but number of users — monthly active users and daily active users — because we have a lot of first-party capabilities like Microsoft 365 Copilot. Over the last year, we’ve seen a 6x increase in monthly active users. We have over 20 million users of Microsoft 365 Copilot alone.</p><p>That is on the agents you use. In terms of the agents you build, Bayer put up its own agent system on Foundry, and now it has 20,000 of its own employees on it.</p><p>A few weeks ago, I was in Sydney, Australia, hanging out with AEMO, the Australian Energy Market Operator. They operate the electrical grid of Australia. They showed me that they had built agents to manage grid operations.</p><p>This is a human-centered thing. They have grid operators sitting in centers in West Sydney, Brisbane and places like that, and they are bombarded with alerts. I wouldn’t believe it if I hadn’t seen it myself. The alerts are constant. They built a system to triage those alerts. Is this alert a super major thing, or is it just that a transformer is getting a little hot? It also says, here is when we had this problem last time, and here is how we resolved it last time. Maybe now we need to replace this component, or whatever.</p><p>Ultimately, it is the grid operators making the choice. A lot of our philosophy here is human empowerment. These human-centered agents are the ones that are working best among our customers. What I saw at AEMO and Bayer is this notion of human empowerment: taking away some of the grunt work, or in the case of AEMO, taking billions of alerts and reducing them to something much more manageable and actionable for the people involved.</p><p>We are moving past the era where agents are just answering questions. AI in general is moving past that. We are not just answering questions anymore. We are moving toward a place where AI can really meaningfully help you do your work.</p><h3><b>VB: How do observability, tokenomics, ROI analysis and agent governance fit into Microsoft Foundry?</b></h3><p>MC: That is what the Foundry control plane is all about. We introduced it in November of last year. If you looked at my own Foundry control plane — I’ve built a ton of these agents, and I am a developer by background — you would see all of my agents that are running and the ones that are paused.</p><p>I can see how many tokens they’ve used over the last day, week or month. I can look at trends. I can look at costs, because the cost will be different depending on what underlying model I’m using. If I’m using our model router, it can route to different models depending on the complexity of the inbound prompt.</p><p>We also have Azure cost management overall. Azure has had cost management for over a decade, before the AI thing even happened. This integrates with overall Azure cost management.</p><p>It is not just narrowly about what your AI is doing. Your AI will be using storage resources, data resources and other compute resources around that AI. You can get a complete picture of not just the cost and token usage of the AI itself, but everything around it.</p><p>When you think about governance, that also extends to evaluation. One of the things we are releasing in preview is rubric-based evaluation. Rubric-based evaluation is much more granular.</p><p>Let’s say you have built a restaurant reservation agent. The things you want to test about that agent are not really groundedness. Groundedness is the opposite of hallucination, and that is very question-answering. For a restaurant reservation agent, you want to test very granular things. If you say, “Make me a table for two tomorrow,” did it come back and ask, “What time would you like the table?” Before it gave you a table for two tomorrow at 6 p.m., did it actually check that the table was available, or did it randomly give you a table without checking first?</p><p>There are very granular things you want to test about that specific use case. You don’t just want to test whether the agent works. You want to test whether the agent works right.</p><p>That is what we are approaching with our new rubric-based evaluation system. You will see that in Satya’s keynote. I have been using it myself lately, and I’m very happy about it. I’ve been waiting for this.</p><h3><b>VB: Microsoft is also partnering with companies like Anthropic and allowing Claude to work with Microsoft 365. How important is Copilot to this story? Why would someone turn to Copilot over other options?</b></h3><p>MC: Microsoft 365 Copilot is a huge advantage for us. As I mentioned, we crossed the 20 million user mark on Copilot relatively recently.</p><p>The great thing about that is that it is the face. When you go into Foundry and make an agent, there is a button that says “publish to Copilot” — actually, it says “publish to Copilot in Teams,” because you can put it in Teams too.</p><p>The idea is that you want to put these agents where your users are. A lot of people who use the Microsoft ecosystem are in Teams, or they are using Copilot. I can create a custom agent, as many of my colleagues have, and now it is in Copilot, which I use maybe 50 times a day.</p><p>Since January, Copilot has become more and more capable. I now use it to draft my email. I am not just using it for question answering. I’m starting to use it to manage my calendar and draft emails. I really do this every day now.</p><p>When I want to use a custom agent — for example, to file my expenses, because we have a custom agent for that now — I can access that agent not in some random standalone interface, but in Copilot or Teams, where I already am.</p><p>That surface area that people are already engaging with is a major advantage.</p><h3><b>VB: As people offload more repetitive work to AI, what are they able to spend more time doing?</b></h3><p>MC: Let’s consider something I did yesterday. I got an email from a customer named Frankie, and he asked me a question about Foundry hosted agents. I knew the answer because I had talked to my colleague Jeff Holland, who is the head of our hosted agents product management. I had asked Jeff the same question two weeks ago.</p><p>Where or how I asked him, I don’t remember. Was it in Teams? Was it email? Was it a meeting? I don’t really remember. But I knew the answer to the question Frankie was asking.</p><p>So I went into Copilot and said, “Answer Frankie’s question about how hosted agents scale, and reference the conversation I had with Jeff a couple of weeks ago on this same topic.” And it did it. It drafted the email.</p><p>Over time, I have taught Copilot my style. I don’t do the bold-print thing. I tell it: don’t use em dashes and that kind of stuff. I have a certain style in the way I write emails. It’s a little terse, to be perfectly honest, but I want it to be the way I write.</p><p>It drafted this thing. It searched through my Teams messages, my emails and the transcripts of my meetings with Jeff. It used Work IQ, as a matter of fact. It found the answer, drafted the email and provided a link to the documentation that specifically covered the question Frankie was asking.</p><p>I looked at the draft and thought, yep, that’s it.</p><p>Yes, I could have composed this email myself. I knew the answer to the question. I could have looked up the documentation. If I dug around, I’m sure I could have found the conversation I had with Jeff in whatever medium that was. I could have done that stuff. It probably would have taken me, I don’t know, an hour to find all the information and compose it.</p><p>Instead, I did it in about a minute. I had a draft, I looked at it, I was happy with it, I pressed send, and that was the end of that.</p><p>It really is about giving people time back. It is not even just grunt work. It is all this time you spend looking things up and finding things. Now, I can make it take an action. It didn’t just answer the question. It fully drafted the email and copied Jeff.</p><h3><b>VB: Do you fear for your job? How has AI changed your own work?</b></h3><p>MC: I don’t fear for my job. My job has changed. For one thing, I do a lot more now, both in my business life and personal life.</p><p>This weekend I was using Web IQ, the new Web IQ. I’ve been car shopping. My car’s lease is coming up, and there is a very specific car I’m trying to find, which is hard to find. It’s a Hyundai Ioniq 6, which Hyundai, for whatever reason, has stopped offering in the United States. I’m going to get one, though.</p><p>I set my agent to the task, using Web IQ, of finding all the Hyundai Ioniq 6s available in the entire Bay Area — everywhere, all the way out to Sacramento, all the way as far south as Gilroy. I set it to this task, and then I went on a hike.</p><p>When I got back, I had a big long list of all the Hyundai Ioniq 6s, at least the 2024 and 2025 models, available in the entire Bay Area. From that, I started calling down these dealers.</p><p>Even in my personal life, I’m using it constantly. It saves me a ton of time. That would have taken me hours, to go through every single dealer’s inventory like this. But Web IQ could do that, and it was super quick.</p><h3><b>VB: Any final thought for developers around this news?</b></h3><p>MC: Foundry is really the place. This is the place where you can build your agents, scale your agents, test your agents and improve your agents. That’s what it’s all about, and it’s happening.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[How to Download macOS 27 When Apple Releases It]]></title>
<description><![CDATA[Apple is expected to unveil macOS 27 during WWDC 2026 on June 8, with the first developer beta likely becoming available shortly after the keynote. A public beta is expected to follow in July, while the final stable version should arrive later this year for compatible Macs.



If you're planning ...]]></description>
<link>https://tsecurity.de/de/3575250/ios-mac-os/how-to-download-macos-27-when-apple-releases-it/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3575250/ios-mac-os/how-to-download-macos-27-when-apple-releases-it/</guid>
<pubDate>Fri, 05 Jun 2026 13:54:46 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Apple is expected to unveil macOS 27 during WWDC 2026 on June 8, with the first developer beta likely becoming available shortly after the keynote. A public beta is expected to follow in July, while the final stable version should arrive later this year for compatible Macs.



If you're planning to try macOS 27 as soon as it becomes available, there are several ways to download and install it, depending on whether you want the developer beta, public beta, or the final public release. Here's everything you need to know.



Download macOS 27 Developer Beta



The developer beta is usually the first version Apple releases after announcing a new macOS update. In recent years, Apple has made developer betas available to anyone with an Apple Account enrolled in its developer program.



Developer betas are designed for testing. They often contain bugs, app compatibility issues, and performance problems. It's best to install them on a secondary Mac rather than your primary work machine.




Back up your Mac using Time Machine.



Sign in with your Apple Account.



Open System Settings.



Click General.



Select Software Update.



Click the Beta Updates option.



Choose macOS 27 Developer Beta when it appears.



Click Done.



Select Upgrade Now or Install Now.



Follow the on-screen instructions and restart your Mac when prompted.




The update should then download and install automatically.



Download macOS 27 Public Beta



If you want early access without using the developer version, the public beta is usually the safer option. Apple typically releases public betas after several rounds of developer testing. Reports suggest macOS 27's public beta could arrive sometime in July 2026.



Public betas are generally more stable than developer betas, but they are still unfinished software. You may encounter bugs and unexpected behavior.




Visit Apple's Beta Software Program website.



Sign in with your Apple Account.



Enroll your Mac if it is not already enrolled.



Open System Settings.



Go to General &gt; Software Update.



Click Beta Updates.



Select macOS 27 Public Beta.



Return to Software Update.



Click Upgrade Now when the beta appears.



Complete the installation process.




After restarting, your Mac will boot into the macOS 27 public beta.



Download the Final macOS 27 Release



Most Mac users should wait for the final version. Apple is expected to release macOS 27 to the public in the fall, likely around September, after several months of beta testing.



The final release receives the most testing and typically offers the best performance, battery life, and app compatibility.



Steps to download the stable version




Open System Settings.



Click General.



Select Software Update.



Wait for macOS 27 to appear.



Click Upgrade Now.



Accept Apple's terms and conditions.



Allow the download to complete.



Restart your Mac to finish installation.




How to Check if Your Mac Is Compatible



Apple has not yet published the official compatibility list for macOS 27. That information should become available during WWDC 2026.



To check your Mac model:




Click the Apple logo in the top-left corner.



Select About This Mac.



Note your Mac model and chip.



Compare it with Apple's official compatibility list once released.




Apple continues to prioritize Apple silicon Macs, so older Intel-based models may see reduced support going forward.



FAQs



When will macOS 27 be available to download? The first developer beta is expected shortly after Apple's WWDC 2026 keynote on June 8. The public beta should arrive in July, followed by the final release later in the year.  Is the developer beta free? Yes. Apple no longer requires a paid developer membership for downloading developer betas in most cases. Users can access beta software using their Apple Account.  Should I install macOS 27 beta on my main Mac? It is not recommended. Beta software can contain bugs, performance issues, and app compatibility problems.  Will I lose my files during installation? Normally no, but creating a full backup before installing any major macOS update is strongly recommended.  Can I leave the beta program later? Yes. You can disable beta updates through Software Update settings and move back to stable releases when Apple publishes them.  



Summary




macOS 27 is expected to be announced during WWDC 2026.



The developer beta should arrive shortly after the keynote.



The public beta is expected in July 2026.



The final version will likely launch in the fall.



Always back up your Mac before installing beta software.



Use a secondary Mac for developer beta testing when possible.



Check Apple's official compatibility list before upgrading.




Conclusion



If you want to experience Apple's next-generation Mac software early, the developer and public betas will likely be available within weeks of the WWDC 2026 announcement. For most users, however, waiting for the final public release remains the safest choice. Before installing any version of macOS 27, make sure your Mac is compatible, create a full backup, and choose the release channel that best matches your needs.]]></content:encoded>
</item>
<item>
<title><![CDATA[iOS 27, macOS 27, Siri: What to expect to launch at WWDC 2026]]></title>
<description><![CDATA[WWDC is just around the corner. Here's what to expect from Apple about the future of iOS 27, macOS 27, AI, and Siri.The WWDC 2026 logo - Image Credit: AppleApple's annual Worldwide Developer Conference will be held from June 8 to June 12. As it's big developer event, it is also the main place to ...]]></description>
<link>https://tsecurity.de/de/3575066/ios-mac-os/ios-27-macos-27-siri-what-to-expect-to-launch-at-wwdc-2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3575066/ios-mac-os/ios-27-macos-27-siri-what-to-expect-to-launch-at-wwdc-2026/</guid>
<pubDate>Fri, 05 Jun 2026 12:35:46 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[WWDC is just around the corner. Here's what to expect from Apple about the future of iOS 27, macOS 27, AI, and Siri.<br><br><div><img src="https://photos5.appleinsider.com/gallery/67668-142628-67394-141863-wwdc2026logo-xl-xl.jpg" alt="WWDC26 logo in large bold letters on a black background, with the numbers 26 glowing brightly with a soft white and rainbow light effect"><br><span>The WWDC 2026 logo - Image Credit: Apple</span></div><br>Apple's annual Worldwide Developer Conference will be held from June 8 to June 12. As it's big developer event, it is also the main place to discover the big changes that will be arriving in its operating system updates due this fall.<br><br>Just after the keynote announcing the news, Apple will release its first developer beta builds of iOS 27, iPadOS 27, macOS 27, watchOS 27, tvOS 27, and visionOS 27. These will be a second beta-testing track alongside the <a href="https://appleinsider.com/articles/26/05/26/first-betas-of-ios-266-macos-266-arrive-as-wwdcs-gen-27-draws-near">current-gen 26 versions</a>, though those will be more for performance and bug fixing rather than introducting new features.<br><br><br> <a href="https://appleinsider.com/articles/26/06/05/ios-27-macos-27-siri-what-to-expect-to-launch-at-wwdc-2026?utm_source=rss">Continue Reading on AppleInsider</a> | <a href="https://forums.appleinsider.com/discussion/244542?urm_source=rss">Discuss on our Forums</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Microsoft makes Linux developers feel more at home in Windows with Coreutils release]]></title>
<description><![CDATA[Microsoft has announced Coreutils, a new Windows 11 feature that allows developers to run many popular Linux command line utilities natively on Windows from a single binary.



Revealed at this week’s Build 2026 developer conference in Seattle, Coreutils is about reducing what Microsoft terms the...]]></description>
<link>https://tsecurity.de/de/3573877/ai-nachrichten/microsoft-makes-linux-developers-feel-more-at-home-in-windows-with-coreutils-release/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3573877/ai-nachrichten/microsoft-makes-linux-developers-feel-more-at-home-in-windows-with-coreutils-release/</guid>
<pubDate>Thu, 04 Jun 2026 22:48:07 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Microsoft has announced Coreutils, a new Windows 11 feature that allows developers to run many popular Linux command line utilities natively on Windows from a single binary.</p>



<p>Revealed at this week’s Build 2026 developer conference in Seattle, Coreutils is about reducing what Microsoft terms the “cognitive load” faced by developers when moving between Windows and other platforms.</p>



<p>Currently, accessing the Linux command line utilities that are considered essential in many CI/CD development environments on Windows requires a kludge that involves either opening an emulation such as Git Bash, or a virtualized <a href="https://www.computerworld.com/article/3990866/windows-subsystem-for-linux-becomes-open-source.html" target="_blank">Windows Linux Subsystem (WSL)</a> terminal.</p>



<p>Both are time-consuming and inefficient. As Microsoft’s <a href="https://blogs.windows.com/windowsdeveloper/2026/06/02/build-2026-furthering-windows-as-the-trusted-platform-for-development/#:~:text=Announcing%20general%20availability,for%20Windows" target="_blank" rel="noreferrer noopener">announcement</a> puts it: “Developers constantly move between platforms, but familiar commands don’t work consistently, forcing workarounds, lost speed and context switching.”</p>



<p>Coreutils removes the need for this back and forth, allowing developers to run most Linux commands straight from the Windows CMD command prompt, PowerShell, or Windows Terminal.</p>



<p>“Whether you’re moving between Linux, macOS, WSL, containers or cloud environments, the commands and workflows you’ve built over years just work in your Windows environment,” Microsoft said.</p>



<h2 class="wp-block-heading">Most utilities, but not all</h2>



<p>Installed as a single executable (via WinGet:<em> install Microsoft.Coreutils), </em><a href="https://learn.microsoft.com/en-us/windows/core-utils/overview" target="_blank" rel="noreferrer noopener">Coreutils for Windows</a> itself is a Rust rewrite of the GNU <a href="https://github.com/uutils/coreutils" target="_blank" rel="noreferrer noopener">uutils/coreutils</a> project that provides commands that are universal across Linux distros.</p>



<p>Fundamental to making Coreutils efficient to manage is the fact that individual Linux commands run from a multi-call executable which maps via NTFS hardlinks pointing to each command. The advantage of this approach is that there’s only one binary to install, one binary to sign, and one binary to patch or update.</p>



<p>Microsoft <a href="https://learn.microsoft.com/en-us/windows/core-utils/commands" target="_blank" rel="noreferrer noopener">lists 75 Linux utilities</a> supported by Coreutils, including <a href="https://www.networkworld.com/article/3958246/18-essential-commands-for-new-linux-users.html" target="_blank">commonly-used commands</a> such as <em>ls, cp, find, grep, find, rm, du, hostname, </em>and<em> uptime</em>.</p>



<p>However, some Coreutils commands clash with existing CMD or Powershell commands, or are otherwise not possible to execute; Microsoft provides a <a href="https://github.com/microsoft/coreutils#shell-conflicts" target="_blank" rel="noreferrer noopener">compatibility table</a> listing conflicts. This means that some commands are not available, specifically: <em>dir, expand, kill, more, timeout, </em>and<em> whoami.</em></p>



<p>There are also some commands omitted from Coreutils because a command relies on a POSIX Unix/Linux feature that Windows doesn’t implement in a compatible way; some examples are <em>chmod, chown, id, stty</em>, and <em>chroot.</em></p>



<p>In other cases, the command will execute in one context, CMD, but not in PowerShell. Microsoft explained the complex order of precedence:  “Whether the Coreutils version runs depends on the shell, the PATH order, and (for PowerShell) the alias table.”</p>



<p>As well as Coreutils, the Build 2026 developer conference also saw Microsoft announce <a href="https://blogs.windows.com/windowsdeveloper/2026/06/02/build-2026-furthering-windows-as-the-trusted-platform-for-development/#:~:text=Announcing%20WSL%20containers%2C%20coming%20soon%20to%20public%20preview" target="_blank" rel="noreferrer noopener">WSL containers CLI and API</a> to deploy Linux containers on Windows, a <a href="https://www.csoonline.com/article/4180467/microsoft-wants-to-put-ai-agents-on-a-short-leash.html" target="_blank">new framework for autonomous agents</a> with open source governance tools, and <a href="https://www.computerworld.com/article/4180103/microsoft-unveils-scout-an-autonomous-ai-agent-built-on-openclaw.html" target="_blank">Microsoft Scout</a>, an AI agent designed to automate tasks in Microsoft 365.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Microsoft makes Linux developers feel more at home in Windows with Coreutils release]]></title>
<description><![CDATA[Microsoft has announced Coreutils, a new Windows 11 feature that allows developers to run many popular Linux command line utilities natively on Windows from a single binary.



Revealed at this week’s Build 2026 developer conference in Seattle, Coreutils is about reducing what Microsoft terms the...]]></description>
<link>https://tsecurity.de/de/3573850/it-security-nachrichten/microsoft-makes-linux-developers-feel-more-at-home-in-windows-with-coreutils-release/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3573850/it-security-nachrichten/microsoft-makes-linux-developers-feel-more-at-home-in-windows-with-coreutils-release/</guid>
<pubDate>Thu, 04 Jun 2026 22:38:35 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Microsoft has announced Coreutils, a new Windows 11 feature that allows developers to run many popular Linux command line utilities natively on Windows from a single binary.</p>



<p>Revealed at this week’s Build 2026 developer conference in Seattle, Coreutils is about reducing what Microsoft terms the “cognitive load” faced by developers when moving between Windows and other platforms.</p>



<p>Currently, accessing the Linux command line utilities that are considered essential in many CI/CD development environments on Windows requires a kludge that involves either opening an emulation such as Git Bash, or a virtualized <a href="https://www.computerworld.com/article/3990866/windows-subsystem-for-linux-becomes-open-source.html" target="_blank">Windows Linux Subsystem (WSL)</a> terminal.</p>



<p>Both are time-consuming and inefficient. As Microsoft’s <a href="https://blogs.windows.com/windowsdeveloper/2026/06/02/build-2026-furthering-windows-as-the-trusted-platform-for-development/#:~:text=Announcing%20general%20availability,for%20Windows" target="_blank" rel="noreferrer noopener">announcement</a> puts it: “Developers constantly move between platforms, but familiar commands don’t work consistently, forcing workarounds, lost speed and context switching.”</p>



<p>Coreutils removes the need for this back and forth, allowing developers to run most Linux commands straight from the Windows CMD command prompt, PowerShell, or Windows Terminal.</p>



<p>“Whether you’re moving between Linux, macOS, WSL, containers or cloud environments, the commands and workflows you’ve built over years just work in your Windows environment,” Microsoft said.</p>



<h2 class="wp-block-heading">Most utilities, but not all</h2>



<p>Installed as a single executable (via WinGet:<em> install Microsoft.Coreutils), </em><a href="https://learn.microsoft.com/en-us/windows/core-utils/overview" target="_blank" rel="noreferrer noopener">Coreutils for Windows</a> itself is a Rust rewrite of the GNU <a href="https://github.com/uutils/coreutils" target="_blank" rel="noreferrer noopener">uutils/coreutils</a> project that provides commands that are universal across Linux distros.</p>



<p>Fundamental to making Coreutils efficient to manage is the fact that individual Linux commands run from a multi-call executable which maps via NTFS hardlinks pointing to each command. The advantage of this approach is that there’s only one binary to install, one binary to sign, and one binary to patch or update.</p>



<p>Microsoft <a href="https://learn.microsoft.com/en-us/windows/core-utils/commands" target="_blank" rel="noreferrer noopener">lists 75 Linux utilities</a> supported by Coreutils, including <a href="https://www.networkworld.com/article/3958246/18-essential-commands-for-new-linux-users.html" target="_blank">commonly-used commands</a> such as <em>ls, cp, find, grep, find, rm, du, hostname, </em>and<em> uptime</em>.</p>



<p>However, some Coreutils commands clash with existing CMD or Powershell commands, or are otherwise not possible to execute; Microsoft provides a <a href="https://github.com/microsoft/coreutils#shell-conflicts" target="_blank" rel="noreferrer noopener">compatibility table</a> listing conflicts. This means that some commands are not available, specifically: <em>dir, expand, kill, more, timeout, </em>and<em> whoami.</em></p>



<p>There are also some commands omitted from Coreutils because a command relies on a POSIX Unix/Linux feature that Windows doesn’t implement in a compatible way; some examples are <em>chmod, chown, id, stty</em>, and <em>chroot.</em></p>



<p>In other cases, the command will execute in one context, CMD, but not in PowerShell. Microsoft explained the complex order of precedence:  “Whether the Coreutils version runs depends on the shell, the PATH order, and (for PowerShell) the alias table.”</p>



<p>As well as Coreutils, the Build 2026 developer conference also saw Microsoft announce <a href="https://blogs.windows.com/windowsdeveloper/2026/06/02/build-2026-furthering-windows-as-the-trusted-platform-for-development/#:~:text=Announcing%20WSL%20containers%2C%20coming%20soon%20to%20public%20preview" target="_blank" rel="noreferrer noopener">WSL containers CLI and API</a> to deploy Linux containers on Windows, a <a href="https://www.csoonline.com/article/4180467/microsoft-wants-to-put-ai-agents-on-a-short-leash.html" target="_blank">new framework for autonomous agents</a> with open source governance tools, and <a href="https://www.computerworld.com/article/4180103/microsoft-unveils-scout-an-autonomous-ai-agent-built-on-openclaw.html" target="_blank">Microsoft Scout</a>, an AI agent designed to automate tasks in Microsoft 365.</p>



<p><em>This article originally appeared on <a href="https://www.infoworld.com/article/4181357/microsoft-makes-linux-developers-feel-more-at-home-in-windows-with-coreutils-release.html" target="_blank">InfoWorld</a>.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Microsoft makes Linux developers feel more at home in Windows with Coreutils release]]></title>
<description><![CDATA[Microsoft has announced Coreutils, a new Windows 11 feature that allows developers to run many popular Linux command line utilities natively on Windows from a single binary.



Revealed at this week’s Build 2026 developer conference in Seattle, Coreutils is about reducing what Microsoft terms the...]]></description>
<link>https://tsecurity.de/de/3573838/it-nachrichten/microsoft-makes-linux-developers-feel-more-at-home-in-windows-with-coreutils-release/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3573838/it-nachrichten/microsoft-makes-linux-developers-feel-more-at-home-in-windows-with-coreutils-release/</guid>
<pubDate>Thu, 04 Jun 2026 22:32:34 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Microsoft has announced Coreutils, a new Windows 11 feature that allows developers to run many popular Linux command line utilities natively on Windows from a single binary.</p>



<p>Revealed at this week’s Build 2026 developer conference in Seattle, Coreutils is about reducing what Microsoft terms the “cognitive load” faced by developers when moving between Windows and other platforms.</p>



<p>Currently, accessing the Linux command line utilities that are considered essential in many CI/CD development environments on Windows requires a kludge that involves either opening an emulation such as Git Bash, or a virtualized <a href="https://www.computerworld.com/article/3990866/windows-subsystem-for-linux-becomes-open-source.html" target="_blank">Windows Linux Subsystem (WSL)</a> terminal.</p>



<p>Both are time-consuming and inefficient. As Microsoft’s <a href="https://blogs.windows.com/windowsdeveloper/2026/06/02/build-2026-furthering-windows-as-the-trusted-platform-for-development/#:~:text=Announcing%20general%20availability,for%20Windows" target="_blank" rel="noreferrer noopener">announcement</a> puts it: “Developers constantly move between platforms, but familiar commands don’t work consistently, forcing workarounds, lost speed and context switching.”</p>



<p>Coreutils removes the need for this back and forth, allowing developers to run most Linux commands straight from the Windows CMD command prompt, PowerShell, or Windows Terminal.</p>



<p>“Whether you’re moving between Linux, macOS, WSL, containers or cloud environments, the commands and workflows you’ve built over years just work in your Windows environment,” Microsoft said.</p>



<h2 class="wp-block-heading">Most utilities, but not all</h2>



<p>Installed as a single executable (via WinGet:<em> install Microsoft.Coreutils), </em><a href="https://learn.microsoft.com/en-us/windows/core-utils/overview" target="_blank" rel="noreferrer noopener">Coreutils for Windows</a> itself is a Rust rewrite of the GNU <a href="https://github.com/uutils/coreutils" target="_blank" rel="noreferrer noopener">uutils/coreutils</a> project that provides commands that are universal across Linux distros.</p>



<p>Fundamental to making Coreutils efficient to manage is the fact that individual Linux commands run from a multi-call executable which maps via NTFS hardlinks pointing to each command. The advantage of this approach is that there’s only one binary to install, one binary to sign, and one binary to patch or update.</p>



<p>Microsoft <a href="https://learn.microsoft.com/en-us/windows/core-utils/commands" target="_blank" rel="noreferrer noopener">lists 75 Linux utilities</a> supported by Coreutils, including <a href="https://www.networkworld.com/article/3958246/18-essential-commands-for-new-linux-users.html" target="_blank">commonly-used commands</a> such as <em>ls, cp, find, grep, find, rm, du, hostname, </em>and<em> uptime</em>.</p>



<p>However, some Coreutils commands clash with existing CMD or Powershell commands, or are otherwise not possible to execute; Microsoft provides a <a href="https://github.com/microsoft/coreutils#shell-conflicts" target="_blank" rel="noreferrer noopener">compatibility table</a> listing conflicts. This means that some commands are not available, specifically: <em>dir, expand, kill, more, timeout, </em>and<em> whoami.</em></p>



<p>There are also some commands omitted from Coreutils because a command relies on a POSIX Unix/Linux feature that Windows doesn’t implement in a compatible way; some examples are <em>chmod, chown, id, stty</em>, and <em>chroot.</em></p>



<p>In other cases, the command will execute in one context, CMD, but not in PowerShell. Microsoft explained the complex order of precedence:  “Whether the Coreutils version runs depends on the shell, the PATH order, and (for PowerShell) the alias table.”</p>



<p>As well as Coreutils, the Build 2026 developer conference also saw Microsoft announce <a href="https://blogs.windows.com/windowsdeveloper/2026/06/02/build-2026-furthering-windows-as-the-trusted-platform-for-development/#:~:text=Announcing%20WSL%20containers%2C%20coming%20soon%20to%20public%20preview" target="_blank" rel="noreferrer noopener">WSL containers CLI and API</a> to deploy Linux containers on Windows, a <a href="https://www.csoonline.com/article/4180467/microsoft-wants-to-put-ai-agents-on-a-short-leash.html" target="_blank">new framework for autonomous agents</a> with open source governance tools, and <a href="https://www.computerworld.com/article/4180103/microsoft-unveils-scout-an-autonomous-ai-agent-built-on-openclaw.html" target="_blank">Microsoft Scout</a>, an AI agent designed to automate tasks in Microsoft 365.</p>



<p><em>This article originally appeared on <a href="https://www.infoworld.com/article/4181357/microsoft-makes-linux-developers-feel-more-at-home-in-windows-with-coreutils-release.html" target="_blank">InfoWorld</a>.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Microsoft’s Web IQ aims to give enterprise AI agents real-time web intelligence]]></title>
<description><![CDATA[For the past two years, enterprises have focused on grounding AI systems in internal documents, databases and knowledge repositories. Microsoft now contends that the next challenge is giving those systems reliable access to the outside world as they move into production.



At its ongoing annual ...]]></description>
<link>https://tsecurity.de/de/3573587/ai-nachrichten/microsofts-web-iq-aims-to-give-enterprise-ai-agents-real-time-web-intelligence/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3573587/ai-nachrichten/microsofts-web-iq-aims-to-give-enterprise-ai-agents-real-time-web-intelligence/</guid>
<pubDate>Thu, 04 Jun 2026 20:17:33 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>For the past two years, enterprises have focused on grounding AI systems in internal documents, databases and knowledge repositories. Microsoft now contends that the next challenge is giving those systems reliable access to the outside world as they move into production.</p>



<p>At its ongoing annual Build conference, Microsoft unveiled <a href="https://www.microsoft.com/en-us/webiq" target="_blank" rel="noreferrer noopener">Web IQ</a>, a new suite of AI-native APIs designed to connect AI agents and applications to real-time information from across the web, including web pages, news, images and videos.</p>



<p>The goal is to help developers build more accurate and context-aware AI systems while reducing the complexity of integrating web search, retrieval and grounding capabilities into enterprise applications, the company wrote in a <a href="https://blogs.bing.com/cmsctx/pv/fa68b46d-1542-458e-bf01-f578848fcdef/culture/en-US/wg/c91f7f9f-4e47-41ab-ae48-87b525fd7ea6/h/e144d329decb4b83192eb25076b9661499c79bba09626f7e5f8b228ca5c69db1/-/search/june-2026/announcing-microsoft-web-iq?uh=3e2a1b0378c8adef0ee33a8ee321bba0336fac2ccc08f367795d041252c0d18b" target="_blank" rel="noreferrer noopener">blog post</a>.</p>



<p>The APIs already underpins grounding for Microsoft Copilot and <a href="https://www.computerworld.com/article/3615039/two-years-of-chatgpt-the-conversation-that-never-ends.html">ChatGPT</a>, and unlike traditional search APIs are designed to retrieve highly relevant information while minimizing token consumption, helping reduce both inference costs and response latency, Microsoft said.</p>



<h2 class="wp-block-heading">Reducing the cost and complexity of web grounding</h2>



<p>That focus on reducing inference costs and response latency to deliver Web IQ’s search capabilities will be valuable for CIOs and developers, said <a href="https://www.hfsresearch.com/team/philfersht/" target="_blank" rel="noreferrer noopener">Phil Fersht</a>, chief analyst at HFS Research.</p>



<p>“Developers have typically stitched this together themselves using search APIs, web scraping, retrieval-augmented generation, vector databases, custom ranking logic, crawling tools and separate orchestration layers. That works, but it is messy, brittle and expensive to maintain,” he said.</p>



<p>“The hard part is not just finding a web page. It is retrieving the right evidence, ranking it, selecting useful passages, reducing token waste, respecting publisher controls and doing all this fast enough for multi-step agents,” he added.</p>



<p>An agent running in production will typically run at least five or ten retrieval steps and in such scenarios latency and cost can become “ugly,” said Moor Insights and Strategy principal analyst <a href="https://moorinsightsstrategy.com/team/mike-leone/" target="_blank" rel="noreferrer noopener">Mike Leone</a>.</p>



<p>“I’ve watched plenty of teams handle this by gluing a search API onto a model and hoping the model can sort through whatever HTML comes back, which isn’t ideal,” he said.</p>



<h2 class="wp-block-heading">Simplifying development of applications</h2>



<p>Beyond the infrastructure and cost advantages, Web IQ could also simplify the AI application building process developers, said <a href="https://www.linkedin.com/in/slwalter/" target="_blank" rel="noreferrer noopener">Stephanie Walter</a>, practice lead of the AI stack at HyperFrame Research.</p>



<p>“The value of Web IQ is that Microsoft is trying to make web grounding a reusable, agent-native service rather than a bespoke integration,” Walter said.</p>



<p>That reusability, Fersht said, will matter to CIOs as most enterprises do not want every development team rebuilding its own web grounding stack: “They need a common capability that is governed, scalable, low-latency and economically efficient.”</p>



<p>Still, Microsoft is not entering an untapped market and there are several offerings already available, including OpenAI web search, Google grounding, Perplexity APIs, Bing Search APIs, Azure AI Search, vector databases, and custom <a href="https://www.infoworld.com/article/2335814/what-is-retrieval-augmented-generation-more-accurate-and-reliable-llms.html" target="_blank">RAG</a> pipelines.</p>



<p>However, Microsoft might have an advantage with IQ, despite Google’s strength in search and web-scale knowledge, OpenAI’s tooling push, and AWS’ Bedrock-data-service-partner integrations combo, Fersht said.</p>



<p>“Microsoft’s differentiation is that it can combine Bing’s global web index with Azure AI, Copilot, Foundry, Microsoft 365 and enterprise developer channels,” he said.</p>



<p>The other advantage is the existence of existing IQ offerings, such as Work IQ, <a href="https://www.infoworld.com/article/4093181/microsoft-fabric-iq-adds-semantic-intelligence-layer-to-fabric.html" target="_blank">Fabric IQ</a>, and Foundry IQ, all of which are targeted towards adding more business context for agentic systems, Fersht added.</p>



<p>But uptake, Walter said, will depend on whether these integrations translate into better production outcomes.</p>



<p>Web IQ is currently available in limited access for select Azure customers. Enterprises can request access to Web IQ via their Microsoft account team or submit a <a href="http://aka.ms/webIQ" target="_blank" rel="noreferrer noopener">form</a>.</p>



<p>Beyond direct API access, developers can also configure the model-agnostic Web IQ as an <a href="https://www.infoworld.com/article/4029634/what-is-model-context-protocol-how-mcp-bridges-ai-and-external-services.html" target="_blank">MCP</a> tool within Foundry IQ, a Microsoft spokesperson said.</p>



<p></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[We’re announcing a new data center and energy investments in Gray and Roberts Counties, Texas.]]></title>
<description><![CDATA[Google and Intersect are announcing construction of the Meitner Energy Center, a new data center and new energy generation in Texas.]]></description>
<link>https://tsecurity.de/de/3572651/it-nachrichten/were-announcing-a-new-data-center-and-energy-investments-in-gray-and-roberts-counties-texas/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3572651/it-nachrichten/were-announcing-a-new-data-center-and-energy-investments-in-gray-and-roberts-counties-texas/</guid>
<pubDate>Thu, 04 Jun 2026 15:02:37 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<img src="https://storage.googleapis.com/gweb-uniblog-publish-prod/images/Texas_Social.max-600x600.format-webp.webp">Google and Intersect are announcing construction of the Meitner Energy Center, a new data center and new energy generation in Texas.]]></content:encoded>
</item>
<item>
<title><![CDATA[What Anthropic and OpenAI IPOs spell for CIOs’ AI budgets]]></title>
<description><![CDATA[AI pioneers Anthropic and OpenAI both appear to be headed toward IPOs, leaving IT leaders whose organizations rely on their AI models wondering what might be in store for them.



Top of mind is the possibility of higher costs for enterprise use, especially for frontier models.



By offering sto...]]></description>
<link>https://tsecurity.de/de/3572152/it-nachrichten/what-anthropic-and-openai-ipos-spell-for-cios-ai-budgets/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3572152/it-nachrichten/what-anthropic-and-openai-ipos-spell-for-cios-ai-budgets/</guid>
<pubDate>Thu, 04 Jun 2026 12:17:39 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>AI pioneers Anthropic and OpenAI both appear to be headed toward IPOs, leaving IT leaders whose organizations rely on their AI models wondering what might be in store for them.</p>



<p>Top of mind is the possibility of higher costs for enterprise use, especially for frontier models.</p>



<p>By offering stock for sale, the two AI innovators will likely raise hundreds of millions of dollars to invest in their products and pay their bills. But many observers worry that by shifting their focus from private, research-focused organizations to publicly traded companies, both Anthropic and OpenAI will be under new pressure to turn a profit.</p>



<p>OpenAI’s enterprise customers should expect substantial price increases after an IPO, especially those who are leaning hard on API usage, copilots, agents, and custom deployments, says <a href="https://www.linkedin.com/in/marknvena/" rel="nofollow">Mark Vena</a>, CEO and principal analyst at IT research firm SmartTech Research.</p>



<p>Vena sees an Anthropic IPO landing differently, with the company’s broad focus on AI safety. “It is selling enterprise trust, safety, developer productivity, and a more buttoned-up brand of AI that CFOs and CIOs can actually explain to their boards,” he says. “Frankly, I think OpenAI is the cultural rocket ship, but Anthropic is shaping up as the institutional AI bet.”</p>



<p>Still, there are concerns about Anthropic’s ability to generate profits, he adds.</p>



<p>“Let’s face it: The big question for Anthropic is whether public investors will reward discipline or punish the brutal economics of frontier AI,” he adds. “Training models, renting compute, and keeping pace with OpenAI, Google, Meta, and xAI is insanely expensive, so Anthropic will have to prove it is more than a very elegant cash-burning machine.”</p>



<p>Anthropic <a href="https://www.cnbc.com/2026/06/01/anthropic-ipo-s1-prospectus.html?msockid=2a6c16066e436d7a193b004b6f656c25" rel="nofollow">announced that it had filed</a> for an IPO on June 1 after news reports that OpenAI was also headed in that direction. Though OpenAI declined to comment on a potential IPO, news reports suggest that the company will <a href="https://techcrunch.com/2026/05/20/openai-barrels-toward-ipo-that-may-happen-in-september/" rel="nofollow">announce one within the next few weeks</a>, with the initial stock sale potentially happening in September.</p>



<p>IPOs would bring several other changes, Vena notes, including more transparency, more scrutiny, and more enterprise discipline around governance, uptime, security, and roadmap commitments. But new pricing models are likely as well.</p>



<p>“An OpenAI IPO would turn the company from a fast-moving AI lab into a Wall Street–monitored platform vendor,” Vena says. “Users should expect less ‘move fast and surprise everybody’ energy and more pressure to package, meter, and monetize everything.”</p>



<h2 class="wp-block-heading">End of the research lab model</h2>



<p>Other observers express similar fears about OpenAI’s pricing models after an IPO.</p>



<p><a href="https://www.linkedin.com/in/leoderikiants/" rel="nofollow">Leo Derikiants</a>, CEO and cofounder at AI research firm Mind Simulation Lab, says IT leaders should expect steep API price hikes, the introduction of expensive premium enterprise tiers for basic data privacy, and increasingly opaque billing models.</p>



<p>“An OpenAI IPO signals the end of the ‘research lab’ illusion and the birth of a traditional tech monopoly,” he adds. “Public markets demand predictable, escalating revenue, but OpenAI’s core technology — autoregressive LLMs — is fundamentally unpredictable and probabilistic.”</p>



<p>Anthropic, meanwhile, seems to be headed toward an IPO in a stronger, more defensible position than OpenAI, he says. While both companies rely on similar probabilistic and autoregressive architectures, Anthropic has focused less on consumer-facing toys such as video generation and more on the corporate enterprise market, giving the company a stable revenue foundation, he notes.</p>



<p>The Anthropic IPO announcement, however, also confirms a disappointing truth — that the AI market is driven by herd mentality, Derikiants says.</p>



<p>“The major labs are running in circles, building the exact same probabilistic products with different branding, without questioning the architectural limits or the actual long-term value,” he says. “The industry has completely lost the original plot. The foundational goal used to be achieving true artificial general intelligence (AGI). Today, the only goal is maximizing monthly subscription revenue.”</p>



<p>CIOs should prepare for aggressive vendor lock-in tactics, forced ecosystem bundling, and a shift away from flexible, open-source-friendly initiatives, he predicts. The corporate focus will pivot from creating safe AI to trapping enterprise data within the company’s proprietary API walls to maximize shareholder value, he says.</p>



<p>AI vendors caught in an AI scaling trap, with its architecture requiring exponentially more computing power and energy to yield marginal improvements in reasoning, he adds.</p>



<p>“Operating these models is fundamentally inefficient and heavily subsidized by venture capital,” he notes. “Once public, Wall Street will not tolerate those massive infrastructure losses indefinitely.”</p>



<p>After an IPO, customers of both companies should expect new pricing models to emerge, says <a href="https://www.linkedin.com/in/richardkamos/" rel="nofollow">Richard Amos</a>, CIO at systems integrator and cloud services provider Blue Mantis. An organization’s priorities change when it transitions from a startup to a publicly traded company, he adds.</p>



<p>“Before an IPO, the focus is largely on innovation, growth, and potential,” he says. “Once public, the expectations change and shareholders demand consistent quarterly performance, regulatory compliance, and enterprise-grade reliability.”</p>



<p>Amos expects several positive developments, with a greater emphasis on platform stability, security, compliance, and the development of more industry-specific capabilities after an OpenAI IPO.</p>



<p>At the same time, he expects AI vendors will move away from enterprise-wide licensing toward consumption-based pricing, mirroring trends in the public cloud market.</p>



<p>With many reports suggesting OpenAI is currently operating at a loss, Amos sees the company revamping its pricing models after an IPO. The company could, for example, move to premium pricing for advanced capabilities such as higher-end models, agentic workflows, and advanced orchestration.</p>



<p>In response, some users will adopt <a href="https://www.cio.com/article/3839075/finops-breaks-out-of-the-cloud.html">AI FinOps</a> solutions to balance consumption and business value, Amos predicts. “We will see some price increases, and I believe that we will have new tools or licensing constructs to manage the cost of the ecosystem,” he adds.</p>



<h2 class="wp-block-heading">New pricing model</h2>



<p>Days before announcing its IPO, Anthropic unveiled a <a href="https://www.infoworld.com/article/4171274/anthropic-puts-claude-agents-on-a-meter-across-its-subscriptions.html">new metered pricing model</a> for some of its products.</p>



<p>Meanwhile, OpenAI’s new <a href="https://www.cnbc.com/2026/05/19/openai-announces-new-guaranteed-capacity-offering-for-customers-to-secure-compute.html" rel="nofollow">Guaranteed Capacity subscription model</a> points to a new pricing philosophy that moves the focus away from selling flexible API tokens and toward a predictable, contractually locked enterprise utility requiring companies to make upfront multi-year spending commitments, notes <a href="https://euginajordan.com/" rel="nofollow">Eugina Jordan</a>, CEO and cofounder at unified intelligence provider YOUnifiedAI.</p>



<p>OpenAI also <a href="https://www.cio.com/article/4169759/openais-new-ai-consulting-offering-raises-questions-of-trust-strategy.html?utm=hybrid_search">announced a new consulting company</a> in May.</p>



<p>Becoming a publicly traded company will likely increase pressure to revamp pricing, Jordan says.</p>



<p>“An OpenAI IPO would drastically reshape the landscape for IT leaders, shifting the company from an agile tech pioneer to a public entity tethered to Wall Street’s quarterly earnings demands,” she adds. “While a massive influx of public capital could fund the robust infrastructure needed to stabilize enterprise products, the immediate reality for users is a sharp pivot toward aggressive monetization.”</p>



<p>However, there’s some good news for enterprise AI users as several major competitors have emerged since OpenAI opened the AI floodgates with its release of the first version of ChatGPT in late 2022, Jordan says. Anthropic has rapidly become the default choice for enterprise developers and deep coding, Google’s Gemini has leveraged its unmatched workspace distribution, and Mistral is securing the European open-source stronghold, she notes.</p>



<p>“This push for predictable enterprise revenue comes at a time when OpenAI is facing a fragmented, highly aggressive competitive landscape where being the first mover is no longer a guarantee of winning,” she adds. “Much like the historic shifts where Yahoo lost to Google or MySpace fell to Facebook, OpenAI is finding that pioneering a technology is very different from scaling it, and an IPO will force them to mature rapidly, just as their competitors are successfully chipping away at their enterprise armor.”</p>



<p>SmartTech Research’s Vena also sees several major competitors, including Google, xAl, and Meta.</p>



<p>“From my perspective, OpenAI is still a leader, but it no longer owns the AI narrative uncontested,” he says. “OpenAI still has brand gravity and product momentum, but the next phase will be less about who has the flashiest demo and more about who can deliver durable, secure, cost-effective AI at scale.”</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Demand Is Booming For New No Tech, Repairable Tractor]]></title>
<description><![CDATA[An anonymous reader quotes a report from 404 Media: The secondary market for decades old, low-tech John Deere tractors has been booming for years as farmers have sought reliable tractors that they can actually fix without having to deal with John Deere's repair monopoly. A Canadian company has se...]]></description>
<link>https://tsecurity.de/de/3571357/it-security-nachrichten/demand-is-booming-for-new-no-tech-repairable-tractor/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3571357/it-security-nachrichten/demand-is-booming-for-new-no-tech-repairable-tractor/</guid>
<pubDate>Thu, 04 Jun 2026 05:36:37 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[An anonymous reader quotes a report from 404 Media: The secondary market for decades old, low-tech John Deere tractors has been booming for years as farmers have sought reliable tractors that they can actually fix without having to deal with John Deere's repair monopoly. A Canadian company has seen that demand and came up with a radical thought: What if they made a new, repairable, "no-tech" tractor to solve what has become a gigantic pain point for farmers? Alberta's Ursa Ag says that it has been inundated with demand after announcing its tractor, which costs roughly half as much as a Deere and has the benefit of not being a repair nightmare.
 
[...] Ursa Ag markets its tractors as "no frills" and "built to last." Ursa Ag's Doug Wilson told me that the company designed the tractor because of a need in the marketplace for a new machine that isn't loaded with tech and is easy to maintain. The company follows in the footsteps of consumer electronics companies like Fairphone, which makes a repairable smartphone and Framework, which makes modular, repairable laptops. The demand Ursa Ag has seen is part of the backlash to manufacturer repair monopolies and the injection of technology and internet-connected sensors and terms of use into even the most basic of gadgets. "I talk to farmers every day and I hear from farmers every day about how they went out and bought machinery from 1987 so that it wouldn't have a computer on it," Wilson said. "All of this came from a simple discussion with a customer who wanted to be able to turn [the tractor] on at the start of the day, to use it, and shut it off at the end of the day. It needed to work, so that's what we built."
 
Ursa Ag's tractor has been hyped in agriculture circles after Wilson showed the tractor off at a Canadian farm show and it was featured by Farms.com. Wilson said more than a thousand farmers have contacted him after that show, from roughly 30 countries. "I got a handwritten letter from a farmer in France who doesn't own a computer and wanted us to mail him information about the tractors," he said. He said the company has thus far made a couple fewer than 100 tractors but is working on tripling its production capacity and has seen a lot of demand over the last few months. "Given the number of my customers that carry flip phones, I would say there is consumer pressure to back away from some of the technology that is unnecessary to perform everyday tasks," Wilson said. "So that is definitely transferable to dishwashers and washing machines, refrigerators. Refrigerators that have screens on them that'll tell you what's inside. It's a little crazy."
 
"That high-tech stuff, the million-dollar John Deere tractor has a place. It has technology that is well worth the money," Wilson said. "But that technology is needed for 5 percent of what a farm does. There are so many applications for tractors on farms that don't require technology. The technology that goes into even a calculator is not required for most farming applications."<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=Demand+Is+Booming+For+New+No+Tech%2C+Repairable+Tractor%3A+https%3A%2F%2Ftech.slashdot.org%2Fstory%2F26%2F06%2F04%2F0043253%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Ftech.slashdot.org%2Fstory%2F26%2F06%2F04%2F0043253%2Fdemand-is-booming-for-new-no-tech-repairable-tractor%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://tech.slashdot.org/story/26/06/04/0043253/demand-is-booming-for-new-no-tech-repairable-tractor?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[MacBook Neo is So Popular That Apple Reportedly Doubled Production]]></title>
<description><![CDATA[According to supply chain analyst Ming-Chi Kuo, Apple has reportedly doubled 2026 MacBook Neo production from 5 million to 10 million units after stronger-than-expected demand for its $599 budget laptop. MacRumors reports: On an earnings call in late April, Apple's CEO Tim Cook said that customer...]]></description>
<link>https://tsecurity.de/de/3570825/it-security-nachrichten/macbook-neo-is-so-popular-that-apple-reportedly-doubled-production/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3570825/it-security-nachrichten/macbook-neo-is-so-popular-that-apple-reportedly-doubled-production/</guid>
<pubDate>Wed, 03 Jun 2026 23:07:23 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[According to supply chain analyst Ming-Chi Kuo, Apple has reportedly doubled 2026 MacBook Neo production from 5 million to 10 million units after stronger-than-expected demand for its $599 budget laptop. MacRumors reports: On an earnings call in late April, Apple's CEO Tim Cook said that customer response to the MacBook Neo was "off the charts," and the popularity of the laptop has reportedly led the company to significantly boost production. [...] Apple was very optimistic about the MacBook Neo before announcing it, but the company still "undercalled" the level of enthusiasm that the laptop would generate, according to Cook. He said that MacBook Neo demand exceeded Apple's expectations and helped to drive a record number of first-time Mac buyers last quarter.
 
New figures from market research firm IDC support Apple's claim that the MacBook Neo is selling well, and the Windows PC industry has taken notice. For example, Dell recently introduced a redesigned XPS 13 laptop from $699 and said it has features "you won't find on a MacBook Neo," such as a touch screen and a backlit keyboard. "Apple's MacBook Neo is a capable machine, and its arrival confirms that there's real appetite for premium quality at accessible prices," admitted Dell.<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=MacBook+Neo+is+So+Popular+That+Apple+Reportedly+Doubled+Production%3A+https%3A%2F%2Fhardware.slashdot.org%2Fstory%2F26%2F06%2F03%2F2021221%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fhardware.slashdot.org%2Fstory%2F26%2F06%2F03%2F2021221%2Fmacbook-neo-is-so-popular-that-apple-reportedly-doubled-production%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://hardware.slashdot.org/story/26/06/03/2021221/macbook-neo-is-so-popular-that-apple-reportedly-doubled-production?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Microsoft wants to put AI agents on a short leash]]></title>
<description><![CDATA[As enterprises race to adopt AI agents across software development workflows, Microsoft is rolling out new controls aimed at keeping the transformation from becoming a security headache.



At its annual developer conference, Microsoft Build, the company unveiled a set of initiatives, including a...]]></description>
<link>https://tsecurity.de/de/3569404/it-security-nachrichten/microsoft-wants-to-put-ai-agents-on-a-short-leash/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3569404/it-security-nachrichten/microsoft-wants-to-put-ai-agents-on-a-short-leash/</guid>
<pubDate>Wed, 03 Jun 2026 13:52:32 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>As enterprises race to adopt AI agents across software development workflows, Microsoft is rolling out new controls aimed at keeping the transformation from becoming a security headache.</p>



<p>At its annual developer conference, Microsoft Build, the company unveiled a set of initiatives, including a brand new runtime containment offering, Microsoft Execution Container (MXC), for agentic AI workloads, and improvements to its recently launched multi-agent vulnerability research system MDASH, among others.</p>



<p>“AI is accelerating development and introducing new issues around insecure code, opaque models, data exposure, and compliance,” <a href="https://www.linkedin.com/in/ale%C5%A1-hole%C4%8Dek/" target="_blank" rel="noreferrer noopener">Aleš Holeček</a>, chief architect at Microsoft Security, said in a blog <a href="https://www.microsoft.com/en-us/security/blog/2026/06/02/microsoft-build-2026-securing-code-agents-and-models-across-the-development-lifecycle/" target="_blank" rel="noreferrer noopener">post</a>. The new tools and capabilities will “give developers clear guidance in real time, scale with the complexity of tasks, and provide security teams with a consistent view across the full lifecycle,” he added.</p>



<p>The idea of sandboxing untrusted code is obviously not new. Containers, VMs, browser sandboxes, and GitHub Codespaces all exist. What’s new is that Microsoft is positioning MXC as a dedicated runtime containment environment for agentic AI workloads, where autonomous agents can take actions, invoke tools, modify code, and access resources.</p>



<p>A lot is said and seen about what could happen when these agents have a little too much autonomy. Coding agents today can <a href="https://www.csoonline.com/article/4179309/flowises-mcp-implementation-can-run-ghost-commands.html">access files</a> they shouldn’t, <a href="https://www.csoonline.com/article/3953927/ai-programming-copilots-are-worsening-code-security-and-leaking-more-secrets.html">leak secrets</a>, make unauthorized network calls, and execute other unexpected <a href="https://www.csoonline.com/article/4036868/black-hat-researchers-demonstrate-zero-click-prompt-injection-attacks-in-popular-ai-agents.html">actions</a>.</p>



<h2 class="wp-block-heading"><a></a>Microsoft puts AI agents in a security sandbox</h2>



<p>Microsoft Execution Containers are a new containment technology intended to place guardrails around autonomous AI agents. It is a policy-driven execution workflow that lets developers specify what an AI agent can access, such as files, networks, resources, credentials, and then enforces those boundaries at runtime.</p>



<p>“MXC is a sandboxed code execution system for running untrusted code (model output, plugins, tools) on Windows, Linux, and macOS,” Microsoft’s official <a href="https://github.com/microsoft/mxc" target="_blank" rel="noreferrer noopener">description</a> of the offering reads. “It provides multiple containment backends — from OS-native process sandboxes to full VMs — behind a unified JSON configuration schema and TypeScript SDK.”</p>



<p>Build announcements also included Microsoft’s two new offerings made public in May 2026. These included the <a href="https://github.com/microsoft/agents">Agent 365 SDK</a>, which provides developers with tools to build, deploy, and manage AI agents, and <a href="https://www.microsoft.com/en-us/windows-365/agents" target="_blank" rel="noreferrer noopener">Windows 365 for Agents</a>, a managed environment intended to give autonomous agents dedicated cloud-based workspaces.</p>



<p>Microsoft also <a href="https://blogs.windows.com/windowsdeveloper/2026/06/02/build-2026-furthering-windows-as-the-trusted-platform-for-development" target="_blank" rel="noreferrer noopener">revealed </a>its plans for MXC, serving as a security foundation for several agent platforms. Agent 365 will integrate with the framework to bring controls from Defender, Entra, Intune, and Purview to agent environments, while OpenClaw and NVIDIA’s OpenShell are already adopting MXC to run AI agents within isolated execution containers designed to limit risk and improve runtime security.</p>



<h2 class="wp-block-heading"><a></a>MDASH moves beyond a research project</h2>



<p>While MXC fell under Microsoft’s “secure your agents” initiative at Build, the “secure your code” drive had the company announce updates to its Security Multi-model Agentic Scanning Harness (MDASH). The system claims to use more than 100 specialized AI agents operating across multiple models to identify vulnerabilities, assess exploitability, and reduce false positives before findings reach security teams.</p>



<p>At Build, Microsoft positioned MDASH as part of a broader enterprise security workflow, announcing expanded preview availability and integration with Microsoft Defender.</p>



<p>MDASH was first introduced in May, when it was <a href="https://www.csoonline.com/article/4170785/microsofts-new-ai-system-finds-16-windows-flaws-including-four-critical-rces.html">revealed</a> to have helped uncover multiple Windows vulnerabilities, including critical remote code execution flaws.</p>



<h2 class="wp-block-heading"><a></a>Open-source controls aim to govern agent behavior</h2>



<p>Microsoft also used Build to <a href="https://devblogs.microsoft.com/foundry/build-2026-open-trust-stack-ai-agents/" target="_blank" rel="noreferrer noopener">introduce</a> two open-source initiatives designed to address the governance challenges around AI agents.</p>



<p>The first, Adaptive Spec-driven Scoring for Evaluation and Regression Testing (ASSERT), is intended to help organizations evaluate agent behavior against defined security and operational requirements.</p>



<p>The second, the Agent Control Specifications (ACS), provides an open standard framework for defining and enforcing governance policies in a portable manner, capable of moving with the agent across different frameworks, platforms, and runtimes instead of being tied to a specific vendor’s technology stack. Together, MXC, MDASH, ASSERT, and ACS sum up Microsoft’s attempt at securing AI models’ entire lifecycle, from the code they generate to the actions they take later.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Anthropic grants Project Glasswing access to 150 more companies, with a focus on critical infrastructure]]></title>
<description><![CDATA[Anthropic on Tuesday announced that it was adding 150 more companies to its Project Glasswing AI-based vulnerability hunting initiative, with a particular focus on critical infrastructure companies including those involved in “power, water, healthcare, communications and hardware.”



Analysts an...]]></description>
<link>https://tsecurity.de/de/3567951/it-security-nachrichten/anthropic-grants-project-glasswing-access-to-150-more-companies-with-a-focus-on-critical-infrastructure/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3567951/it-security-nachrichten/anthropic-grants-project-glasswing-access-to-150-more-companies-with-a-focus-on-critical-infrastructure/</guid>
<pubDate>Wed, 03 Jun 2026 02:51:57 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Anthropic on Tuesday announced that it was adding 150 more companies to its Project Glasswing AI-based vulnerability hunting initiative, with a particular focus on critical infrastructure companies including those involved in “power, water, healthcare, communications and hardware.”</p>



<p>Analysts and security vendors agreed that the move is a positive step, noting that the more companies involved in bug identification, the better. But the bigger background issue is a practical one: the bottleneck problem. </p>



<p>If Project Glasswing, and similar projects from other major AI vendors, increase the stream of vulnerability identifications by 10 or more times, will vendors be able to triage and patch them in a timely manner? Vendors have historically been notoriously slow to patch known security issues. Microsoft, for example, <a href="https://www.csoonline.com/article/4178869/microsoft-and-security-researchers-dueling-posts-about-cybersecurity-disclosures-get-nasty.html" target="_blank">recently argued with a security researcher </a>who went public with holes because he felt that Microsoft was too slow in addressing them. </p>



<p>And even if those vendors can keep up, are enterprise SOCs going to be able to keep up with the avalanche of patches? And if extensive automation is deployed to generate those patches, will CISOs trust them enough to let them be deployed without manual verification? Trust is not a common CISO trait.</p>



<p>“What each partner has in common is that a successful attack on their codebase could be catastrophic. For most partners, we estimate that a major attack could affect more than 100 million people, with important ramifications for both global and national security,” <a href="https://www.anthropic.com/news/expanding-project-glasswing" target="_blank" rel="noreferrer noopener">Anthropic said in its blog post</a> announcing the new participants. “This expansion is the next step toward our long-term goals: for AI to make all software more secure, and for us to help the industry adjust to how AI could change many of the core assumptions of cybersecurity.”</p>



<p><a href="https://www.csoonline.com/article/4176865/project-glasswing-has-uncovered-10000-vulnerabilities-anthropic.html" target="_blank">Glasswing </a>was announced on April 7 and was initially supported by AWS, Apple, Broadcom, Cisco, CrowdStrike, Google, JPMorganChase, the Linux Foundation, Microsoft, NVIDIA, and Palo Alto Networks. Okta later confirmed that it was also involved. </p>



<h2 class="wp-block-heading">The patch bottleneck</h2>



<p>The bottleneck problem is a difficult one to solve, given that even the largest vendors can only cost-justify so many resources for patching security holes and distributing those patches.</p>



<p>“The biggest issue is adaptability: once a vulnerability or weakness is found, defenders have to validate it, prioritize it, and fix it before attackers can operationalize the same insight. And that validation step matters,” said <a href="https://www.linkedin.com/in/tomfindling/" target="_blank" rel="noreferrer noopener">Tom Findling</a>, CEO of Conifers.ai. “While testing the tool ourselves, we saw a lot of false positives, which means organizations cannot simply treat every finding as immediately actionable. They need the ability to separate signal from noise quickly, then adapt their processes, engineering workflows, and patching pipelines around the real issues.”</p>



<p>“The most important metric for organizations to track may not just be how many vulnerabilities are found, but how long it takes them to adapt once a credible issue is identified. For some organizations, that adaptation cycle can still take months,” he added. “Reducing that time-to-adapt is what will determine whether AI-assisted vulnerability discovery actually improves defense or just increases the speed and volume of security noise.”</p>



<h2 class="wp-block-heading">A remediation problem</h2>



<p><a href="https://acceligence.com/talent/profiles/justin-greis/" target="_blank" rel="noreferrer noopener">Justin Greis</a>, CEO of consulting firm Acceligence, agreed that the Glasswing expansion may simply demonstrate to CISOs how much the security hole problem is shifting, not shrinking. </p>



<p>“It’s no secret that cybersecurity has been treated as a vulnerability discovery problem. AI is proving that it was really a remediation problem all along. The industry already struggles to validate, prioritize, patch, test, and deploy fixes fast enough. It may even be worse if security teams own the vulnerability identification and the IT teams, or the business teams, own the patching itself,” Greis said. “If AI can identify vulnerabilities 10x or 100x faster than humans, the bottleneck simply moves downstream. Organizations may soon find themselves in the uncomfortable position of knowing about far more vulnerabilities than they can realistically address. AI is turning cybersecurity from a visibility problem into an execution problem.”</p>



<p>Greis added a frightening prediction: “AI could make organizations simultaneously more secure and more overwhelmed, if that’s possible. They’ll have unprecedented visibility into their risk, but they’ll also discover just how large that risk really is.”</p>



<h2 class="wp-block-heading">Trust required</h2>



<p><a href="https://my.idc.com/getdoc.jsp?containerId=PRF005722" target="_blank" rel="noreferrer noopener">Grace Trinidad</a>, research director for AI security at IDC, said the bottleneck problem at the enterprise needs to be addressed via extensive automation. But given the lack of trust by cybersecurity staff, vendors must have a rigorous method for producing a numerical confidence score for every patch. </p>



<p>“Having a confidence score accompanying these patches is a new concept. There must be an ability of the enterprise to identify, triage and address the vulnerabilities that are specific to their environment,” Trinidad said. “We are learning a skillset that we are not ready for: How do we trust automated technologies? Given that we are having to move at this speed, that trust is going to get broken. Confidence scoring is a discipline that needs transparency. Don’t make the confidence [explanation] so complicated that you can’t explain it to a human being.”</p>



<p>Trinidad also noted that the Anthropic announcement pointed out that each of the 150 new participants, in Anthropic’s phrasing, “will need to meet our security requirements before they gain access.”</p>



<p>Trinidad said the security requirement claim doesn’t build confidence, because “nobody knows what those security requirements are.”</p>



<p>One possible solution is for security vendors to use high-trust third parties so that they are not seen as ‘grading their own homework’. Enterprise software vendor Workday is using a similar third-party approach, relying on trusted services that use public standards such as Mitre ATLAS to validate the security and compliance of AI agents using its platform. <a href="https://www.cio.com/article/4179876/workday-launches-agent-passport-to-test-and-monitor-ai-agents-in-the-enterprise.html" target="_blank">Workday’s approach</a> deals with security checks and not reliability scores, but the idea could potentially be tweaked. </p>



<h2 class="wp-block-heading">Expansion creates security concerns</h2>



<p><a href="https://www.linkedin.com/in/carmi/" target="_blank" rel="noreferrer noopener">Carmi Levy</a>, an independent technology analyst, was more skeptical about what Glasswing will ultimately be able to accomplish by adding 150 more participants.</p>



<p>“The entire point of Project Glasswing was to allow Anthropic to work closely with a small, fully vetted group of vendors to develop stronger defenses against the cybersecurity risks posed by what was, and is, an entirely new LLM class that would otherwise pose unacceptable risks to existing protective technologies and protocols,” Levy said. “Expanding access into the hundreds may very well bring in more minds to build better defensive measures, but it simultaneously introduces significant concerns around potential leaks. And this from a company that has already reported two leaks involving this same model.”</p>



<p>Levy added, “in an ideal world, Anthropic would announce alongside this major expansion a parallel effort to tighten internal security protocols to ensure the code doesn’t fall into the wrong hands. Bringing in a much larger cohort of researchers signals to potential attackers that they will soon have a larger pool of potential targets, and fails to allay fears of future breaches.”</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Anthropic grants Project Glasswing access to 150 more companies, with a focus on critical infrastructure]]></title>
<description><![CDATA[Anthropic on Tuesday announced that it was adding 150 more companies to its Project Glasswing AI-based vulnerability hunting initiative, with a particular focus on critical infrastructure companies including those involved in “power, water, healthcare, communications and hardware.”



Analysts an...]]></description>
<link>https://tsecurity.de/de/3567949/it-nachrichten/anthropic-grants-project-glasswing-access-to-150-more-companies-with-a-focus-on-critical-infrastructure/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3567949/it-nachrichten/anthropic-grants-project-glasswing-access-to-150-more-companies-with-a-focus-on-critical-infrastructure/</guid>
<pubDate>Wed, 03 Jun 2026 02:47:13 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Anthropic on Tuesday announced that it was adding 150 more companies to its Project Glasswing AI-based vulnerability hunting initiative, with a particular focus on critical infrastructure companies including those involved in “power, water, healthcare, communications and hardware.”</p>



<p>Analysts and security vendors agreed that the move is a positive step, noting that the more companies involved in bug identification, the better. But the bigger background issue is a practical one: the bottleneck problem. </p>



<p>If Project Glasswing, and similar projects from other major AI vendors, increase the stream of vulnerability identifications by 10 or more times, will vendors be able to triage and patch them in a timely manner? Vendors have historically been notoriously slow to patch known security issues. Microsoft, for example, <a href="https://www.csoonline.com/article/4178869/microsoft-and-security-researchers-dueling-posts-about-cybersecurity-disclosures-get-nasty.html" target="_blank">recently argued with a security researcher </a>who went public with holes because he felt that Microsoft was too slow in addressing them. </p>



<p>And even if those vendors can keep up, are enterprise SOCs going to be able to keep up with the avalanche of patches? And if extensive automation is deployed to generate those patches, will CISOs trust them enough to let them be deployed without manual verification? Trust is not a common CISO trait.</p>



<p>“What each partner has in common is that a successful attack on their codebase could be catastrophic. For most partners, we estimate that a major attack could affect more than 100 million people, with important ramifications for both global and national security,” <a href="https://www.anthropic.com/news/expanding-project-glasswing" target="_blank" rel="nofollow">Anthropic said in its blog post</a> announcing the new participants. “This expansion is the next step toward our long-term goals: for AI to make all software more secure, and for us to help the industry adjust to how AI could change many of the core assumptions of cybersecurity.”</p>



<p><a href="https://www.csoonline.com/article/4176865/project-glasswing-has-uncovered-10000-vulnerabilities-anthropic.html" target="_blank">Glasswing </a>was announced on April 7 and was initially supported by AWS, Apple, Broadcom, Cisco, CrowdStrike, Google, JPMorganChase, the Linux Foundation, Microsoft, NVIDIA, and Palo Alto Networks. Okta later confirmed that it was also involved. </p>



<h2 class="wp-block-heading">The patch bottleneck</h2>



<p>The bottleneck problem is a difficult one to solve, given that even the largest vendors can only cost-justify so many resources for patching security holes and distributing those patches.</p>



<p>“The biggest issue is adaptability: once a vulnerability or weakness is found, defenders have to validate it, prioritize it, and fix it before attackers can operationalize the same insight. And that validation step matters,” said <a href="https://www.linkedin.com/in/tomfindling/" target="_blank" rel="nofollow">Tom Findling</a>, CEO of Conifers.ai. “While testing the tool ourselves, we saw a lot of false positives, which means organizations cannot simply treat every finding as immediately actionable. They need the ability to separate signal from noise quickly, then adapt their processes, engineering workflows, and patching pipelines around the real issues.”</p>



<p>“The most important metric for organizations to track may not just be how many vulnerabilities are found, but how long it takes them to adapt once a credible issue is identified. For some organizations, that adaptation cycle can still take months,” he added. “Reducing that time-to-adapt is what will determine whether AI-assisted vulnerability discovery actually improves defense or just increases the speed and volume of security noise.”</p>



<h2 class="wp-block-heading">A remediation problem</h2>



<p><a href="https://acceligence.com/talent/profiles/justin-greis/" target="_blank" rel="nofollow">Justin Greis</a>, CEO of consulting firm Acceligence, agreed that the Glasswing expansion may simply demonstrate to CISOs how much the security hole problem is shifting, not shrinking. </p>



<p>“It’s no secret that cybersecurity has been treated as a vulnerability discovery problem. AI is proving that it was really a remediation problem all along. The industry already struggles to validate, prioritize, patch, test, and deploy fixes fast enough. It may even be worse if security teams own the vulnerability identification and the IT teams, or the business teams, own the patching itself,” Greis said. “If AI can identify vulnerabilities 10x or 100x faster than humans, the bottleneck simply moves downstream. Organizations may soon find themselves in the uncomfortable position of knowing about far more vulnerabilities than they can realistically address. AI is turning cybersecurity from a visibility problem into an execution problem.”</p>



<p>Greis added a frightening prediction: “AI could make organizations simultaneously more secure and more overwhelmed, if that’s possible. They’ll have unprecedented visibility into their risk, but they’ll also discover just how large that risk really is.”</p>



<h2 class="wp-block-heading">Trust required</h2>



<p><a href="https://my.idc.com/getdoc.jsp?containerId=PRF005722" target="_blank" rel="nofollow">Grace Trinidad</a>, research director for AI security at IDC, said the bottleneck problem at the enterprise needs to be addressed via extensive automation. But given the lack of trust by cybersecurity staff, vendors must have a rigorous method for producing a numerical confidence score for every patch. </p>



<p>“Having a confidence score accompanying these patches is a new concept. There must be an ability of the enterprise to identify, triage and address the vulnerabilities that are specific to their environment,” Trinidad said. “We are learning a skillset that we are not ready for: How do we trust automated technologies? Given that we are having to move at this speed, that trust is going to get broken. Confidence scoring is a discipline that needs transparency. Don’t make the confidence [explanation] so complicated that you can’t explain it to a human being.”</p>



<p>Trinidad also noted that the Anthropic announcement pointed out that each of the 150 new participants, in Anthropic’s phrasing, “will need to meet our security requirements before they gain access.”</p>



<p>Trinidad said the security requirement claim doesn’t build confidence, because “nobody knows what those security requirements are.”</p>



<p>One possible solution is for security vendors to use high-trust third parties so that they are not seen as ‘grading their own homework’. Enterprise software vendor Workday is using a similar third-party approach, relying on trusted services that use public standards such as Mitre ATLAS to validate the security and compliance of AI agents using its platform. <a href="https://www.cio.com/article/4179876/workday-launches-agent-passport-to-test-and-monitor-ai-agents-in-the-enterprise.html" target="_blank">Workday’s approach</a> deals with security checks and not reliability scores, but the idea could potentially be tweaked. </p>



<h2 class="wp-block-heading">Expansion creates security concerns</h2>



<p><a href="https://www.linkedin.com/in/carmi/" target="_blank" rel="nofollow">Carmi Levy</a>, an independent technology analyst, was more skeptical about what Glasswing will ultimately be able to accomplish by adding 150 more participants.</p>



<p>“The entire point of Project Glasswing was to allow Anthropic to work closely with a small, fully vetted group of vendors to develop stronger defenses against the cybersecurity risks posed by what was, and is, an entirely new LLM class that would otherwise pose unacceptable risks to existing protective technologies and protocols,” Levy said. “Expanding access into the hundreds may very well bring in more minds to build better defensive measures, but it simultaneously introduces significant concerns around potential leaks. And this from a company that has already reported two leaks involving this same model.”</p>



<p>Levy added, “in an ideal world, Anthropic would announce alongside this major expansion a parallel effort to tighten internal security protocols to ensure the code doesn’t fall into the wrong hands. Bringing in a much larger cohort of researchers signals to potential attackers that they will soon have a larger pool of potential targets, and fails to allay fears of future breaches.”</p>



<p><em>This article originally appeared on <a href="https://www.csoonline.com/article/4180265/anthropic-grants-project-glasswing-access-to-150-more-companies-with-a-focus-on-critical-infrastructure.html" target="_blank">CSOonline</a>.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Microsoft’s next-gen quantum chip cuts timeline to useful quantum computing]]></title>
<description><![CDATA[Microsoft claimed last year that it had made a key breakthrough in quantum computing with Majorana 1, the company's first quantum processor. While physicists were immediately skeptical of Microsoft's claims, the software giant is announcing Majorana 2 today, the next generation of its topological...]]></description>
<link>https://tsecurity.de/de/3567251/it-nachrichten/microsofts-next-gen-quantum-chip-cuts-timeline-to-useful-quantum-computing/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3567251/it-nachrichten/microsofts-next-gen-quantum-chip-cuts-timeline-to-useful-quantum-computing/</guid>
<pubDate>Tue, 02 Jun 2026 20:17:30 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Microsoft claimed last year that it had made a key breakthrough in quantum computing with Majorana 1, the company's first quantum processor. While physicists were immediately skeptical of Microsoft's claims, the software giant is announcing Majorana 2 today, the next generation of its topological quantum chip. Majorana 2 contains qubits, a unit of information in […]]]></content:encoded>
</item>
<item>
<title><![CDATA[The Rust Programming Language Blog: Launching the Rust Foundation Maintainers Fund]]></title>
<description><![CDATA[If you want to financially support the development of Rust, please consider donating to the Rust Foundation Maintainers Fund.

A few months ago, the Rust Foundation announced the Rust Foundation Maintainers Fund (RFMF). Since then, the Rust Project has been closely cooperating with the Rust Found...]]></description>
<link>https://tsecurity.de/de/3567033/tools/the-rust-programming-language-blog-launching-the-rust-foundation-maintainers-fund/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3567033/tools/the-rust-programming-language-blog-launching-the-rust-foundation-maintainers-fund/</guid>
<pubDate>Tue, 02 Jun 2026 19:09:27 +0200</pubDate>
<category>💾  Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<blockquote>
<p>If you want to financially support the development of Rust, please consider <a href="https://github.com/sponsors/rustfoundation" rel="external">donating</a> to the Rust Foundation Maintainers Fund.</p>
</blockquote>
<p>A few months ago, the Rust Foundation announced the <a href="https://rustfoundation.org/media/announcing-the-rust-foundation-maintainers-fund/" rel="external">Rust Foundation Maintainers Fund</a> (RFMF). Since then, the Rust Project has been closely cooperating with the Rust Foundation to determine how exactly this fund will be used to support Rust maintainers. This resulted in the acceptance of <a href="https://rust-lang.github.io/rfcs/3931-rfmf-rust-foundation-maintainer-fund.html" rel="external">RFC #3931</a>, which established the <a href="https://rust-lang.org/governance/teams/launching-pad/#team-funding" rel="external">Funding team</a> and the <a href="https://rust-lang.github.io/rfcs/3931-rfmf-rust-foundation-maintainer-fund.html#expectations-placed-on-maintainers-in-residence" rel="external">Maintainer in Residence</a> program.</p>
<p>The primary goal of the Funding team is to ensure that maintainers who work on Rust and its toolchain will be properly supported. We will talk to Rust Project members to figure out their funding situation, meet Rust team leads to learn about their maintenance needs, approach companies to find opportunities for them to invest into Rust by supporting Rust maintainers, coordinate various funding efforts and ensure that the beneficial effects of funded maintenance are visibly promoted, with the help of the <a href="https://rust-lang.org/governance/teams/launching-pad/#team-content" rel="external">Content team</a>.</p>
<p><a href="https://rust-lang.github.io/rfcs/3931-rfmf-rust-foundation-maintainer-fund.html#expectations-placed-on-maintainers-in-residence" rel="external">Maintainer in Residence</a> is a new program dedicated to financially supporting existing Rust Project maintainers<sup class="footnote-reference"><a href="https://blog.rust-lang.org/2026/06/02/launching-the-rust-foundation-maintainers-fund/#fn-dir">1</a></sup>. Each Maintainer in Residence will be funded to <a href="https://blog.rust-lang.org/inside-rust/2026/01/12/what-is-maintenance-anyway/" rel="external">maintain</a> one or more critical parts of Rust, such as the compiler, the standard library, Cargo, Clippy or one of many other projects that the Rust Project develops and maintains. The funded work will include activities such as performing large-scale refactorings, code reviews, unblocking new features, issue triaging, mentoring other contributors and more, and will be split between priorities guided by the teams they are supporting and priorities of their own choosing within the Project. Where applicable, Maintainers in Residence are also encouraged to propose, champion, and drive forward <a href="https://rust-lang.github.io/rust-project-goals/" rel="external">Rust Project Goals</a>.</p>
<p>The goal of this program is to provide stable and long-term funding so that maintainers can focus on important work that ensures the long-term health of Rust. The funding team will select Maintainers in Residence based on funding availability and maintenance needs within the Rust Project, and help ensure that they are successful. We expect that this will usually be a (near) full-time position, but that will depend on the nature of the work and the area of maintenance.</p>
<p>This program extends our existing support for Rust maintainers, such as the <a href="https://blog.rust-lang.org/inside-rust/2026/04/09/program-management-update-2026-03/" rel="external">program management program</a> and the <a href="https://blog.rust-lang.org/inside-rust/2025/06/05/a-glance-at-the-team-compiler-operations" rel="external">compiler-ops program</a>. An important development is that we now have a centralized <a href="https://github.com/sponsors/rustfoundation" rel="external">mechanism</a> for gathering donations from both individuals and companies, and a dedicated team that will help direct those funds to specific maintainers. You can find more details about the funding team and the Maintainer in Residence program in the <a href="https://rust-lang.github.io/rfcs/3931-rfmf-rust-foundation-maintainer-fund.html" rel="external">RFC</a>.</p>
<p>We expect to hire the first Maintainer in Residence in the upcoming months and announce it on this blog, so stay tuned!</p>
<h3><a class="anchor" href="https://blog.rust-lang.org/2026/06/02/launching-the-rust-foundation-maintainers-fund/#how-to-contribute-funds"></a>
How to contribute funds</h3>
<p>If you are an individual who wants to help Rust succeed and thrive, you can donate to the RFMF through <a href="https://github.com/sponsors/rustfoundation" rel="external">GitHub Sponsors</a><sup class="footnote-reference"><a href="https://blog.rust-lang.org/2026/06/02/launching-the-rust-foundation-maintainers-fund/#fn-sponsors">2</a></sup>. Companies who would like to invest in better maintenance of Rust can also donate through GitHub Sponsors or they can contact the Rust Foundation <a href="mailto:contact@rustfoundation.org">directly</a>.</p>
<p>The important thing is that <strong>all proceeds from this fund will be directly used to support Rust Project maintainers</strong>. We currently expect that to happen primarily through the Maintainer in Residence program, but it can also be done in the form of smaller-scale grants or other mechanisms, as determined by the Funding team. We will figure this out on the go, as this is also quite new for us.</p>
<p>We really appreciate each donation, however small, because with more money we can hire more maintainers to ensure that we can continue to develop Rust and that important improvements are not blocked on maintenance tasks. This is especially important at this time, where Rust is starting to get used more and more in the industry in various application areas, which increases the need for sustained maintenance. The importance of multiple funding sources is underscored by an unfortunate trend we currently observe, where key Rust maintainers are losing their funding for Rust work due to budget shifts. The Rust Foundation Maintainers Fund is designed to provide stable funding for Rust maintainers that is less dependent on sudden shifts in the job market and the IT industry.</p>
<p>As with most things, there is no one-size-fits-all solution, so there are multiple ways to support Rust financially. The <a href="https://rustnl.org/maintainers" rel="external">RustNL Maintainers Team</a> recently hired several Rust Project maintainers. Previously, we <a href="https://blog.rust-lang.org/2025/12/08/making-it-easier-to-sponsor-rust-contributors/" rel="external">wrote</a> about how you can support specific individuals working on Rust. And there are also Rust Project Goals <a href="https://rust-lang.github.io/rust-project-goals/2026/funding.html" rel="external">in search of funding</a>. We welcome all efforts that can help support Rust Project maintainers, who often do work that is near invisible and thankless, while at the same time incredibly important and necessary, on a volunteer basis.</p>
<p>Thank you for considering sponsoring the development and maintenance of Rust! You can find more information about funding Rust on our <a href="https://rust-lang.org/funding/" rel="external">Funding page</a>.</p>
<section class="footnotes">
<ol class="footnotes-list">
<li>
<p>This program was inspired by the <a href="https://www.python.org/psf/developersinresidence/" rel="external">Developer in Residence</a> concept used by the Python Software Foundation (PSF), with which we led several helpful discussions. Thank you, PSF! <a href="https://blog.rust-lang.org/2026/06/02/launching-the-rust-foundation-maintainers-fund/#fr-dir-1">↩</a></p>
</li>
<li>
<p>Note that the fact that GitHub Sponsors is currently enabled on the <code>rustfoundation</code> GitHub organization, and not the <code>rust-lang</code> organization, is an implementation detail that might change in the future. All donations raised on this Sponsors page will be routed to the Rust Foundation Maintainers Fund and will be spent on directly supporting Rust Project maintainers. <a href="https://blog.rust-lang.org/2026/06/02/launching-the-rust-foundation-maintainers-fund/#fr-sponsors-1">↩</a></p>
</li>
</ol>
</section>]]></content:encoded>
</item>
<item>
<title><![CDATA[Cisco Live: The network is back, and AI rewrote the rules]]></title>
<description><![CDATA[For much of the past decade, enterprise networking was something the industry tried to abstract away. Cloud-first architectures commoditized switching and routing, burying them under software-defined layers. AI infrastructure has reversed that trajectory. Tom Gillis, senior vice president and gen...]]></description>
<link>https://tsecurity.de/de/3567031/it-security-nachrichten/cisco-live-the-network-is-back-and-ai-rewrote-the-rules/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3567031/it-security-nachrichten/cisco-live-the-network-is-back-and-ai-rewrote-the-rules/</guid>
<pubDate>Tue, 02 Jun 2026 19:08:51 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>For much of the past decade, enterprise networking was something the industry tried to abstract away. Cloud-first architectures commoditized switching and routing, burying them under software-defined layers. AI infrastructure has reversed that trajectory. <a href="https://www.linkedin.com/in/tomgillis1/">Tom Gillis</a>, senior vice president and general manager of Cisco’s infrastructure and security group, has a theory about why, and it starts with the network.</p>



<p>At Cisco Live this week, <a href="https://www.networkworld.com/article/4179673/cisco-brings-agentic-ops-platform-and-security-overhaul-to-cisco-live.html">Cisco is announcing a broad set of security and infrastructure capabilities</a> spanning vulnerability protection, network enforcement and agentic access control.</p>



<p>In the AI era, Gillis said, the network performs the role the PCI bus once played inside a single server. Distributed AI systems require memory, compute, GPU, and storage to work together across physical infrastructure at scale. The network is the backplane that makes that possible. The result, he said, is that customers have come to see it as the one thing they can count on.</p>



<p>“There is a new operating model necessary for infrastructure,” Gillis told <em>Network World</em>.</p>



<h2 class="wp-block-heading">AI changed how Cisco builds its own products</h2>



<p>The shift shows up inside Cisco’s own development organization. Gillis runs a team of roughly 12,000 software developers, and AI coding tools have fundamentally changed how that team works.</p>



<p>Earlier generations of AI coding tools produced significant gains on new projects, where a team of five to 10 developers could accomplish what once required 100 people working for a year. But those tools hit a ceiling on complex legacy products. A Catalyst switch or Cisco firewall can contain 50 to 100 million lines of code, more context than prior models could handle at once. Newer AI coding tools have removed that ceiling, allowing Cisco to accelerate development across its entire product portfolio.</p>



<p>The other side of that acceleration is vulnerability discovery. Frontier AI models like Anthropic’s Claude Mythos can now comprehend entire complex codebases and are finding vulnerabilities that humans have been unable to find.</p>



<p>“Frontier models are finding vulnerabilities at a scale that has never been achieved before, and it’s not one and done. These things are going to continue to find new vulnerabilities,” Gillis said.</p>



<h2 class="wp-block-heading">A new security stack built from the Linux kernel up</h2>



<p>The standard data center response to vulnerabilities has been to build a configuration, test and validate it, lock it down, and leave it alone. Gillis described that model as no longer viable. Switches and routers are inline, high-performance systems that require taking offline to update, which is why customers do it infrequently. Continuous AI-driven vulnerability discovery makes that approach untenable.</p>



<p>Cisco’s answer is built on <a href="https://www.networkworld.com/article/1291149/cisco-buy-highlights-container-networking-security.html">Isovalent</a>, its commercial platform based on the open source Cilium project, which uses <a href="https://www.networkworld.com/article/3518212/why-ebpf-is-critical-and-how-its-getting-better.html">eBPF technology</a> built into the Linux kernel.</p>



<p>“What’s great about eBPF is that we can inspect memory, so we can look at that memory, we can see what’s happening, we intercept every system call and every function call, and we can modify those system calls and function calls,” Gillis said. </p>



<p>The eBPF based functionality enables multiple new capabilities in the Cisco platform. The headline capability is Live Protect, a feature built directly into Cisco network operating systems such as NXOS and IOS. A compensating control can be scoped to a specific process ID and file, blocking a particular action without affecting anything else on the system. For an administrator, the experience is a vulnerability flagged in the Nexus dashboard with a button to apply a shield.</p>



<p>“We’ve introduced a capability that can apply a compensating control to a running system without rebooting, touching, or modifying the binaries of that running system,” Gillis said.</p>



<h2 class="wp-block-heading">Not every workload is an AI app</h2>



<p>Live Protect and the Isovalent platform address the security challenge for infrastructure running today. But the infrastructure itself is also in transition, and Cisco is building for where most enterprises actually are, not just where they are headed.</p>



<p>“The enterprise, most of their workloads are not AI, right? They’re excited about AI, AI is gonna be cool as a rapid transition, but the vast majority of their workloads are still VM-based,” Gillis said. “VMs have been around for 20 years, and so our vision for this kind of data center of the future for the enterprise is that Kubernetes becomes the orchestration layer that runs all applications.” </p>



<p>The friction point is networking. VMware operates at Layer 2, Kubernetes is Layer 3, born in the cloud. Moving a VM from a VMware environment into Kubernetes has historically meant reengineering how it connects to everything else. Cisco’s Isovalent-based software bridge allows VMs to migrate one at a time without changing their IP addresses. The result is legacy VM workloads, container-based applications, and AI workloads running together on the same infrastructure, with no forced full migration.</p>



<p>At Cisco Live, Gillis is demoing that vision on the main stage. VM-based and Kubernetes-based workloads appear as peers in the same Nexus dashboard, with the Isovalent-based software bridge handling the Layer 2 to Layer 3 translation underneath.</p>



<h2 class="wp-block-heading">The future of networking in the AI era</h2>



<p>The announcements at <a href="https://www.ciscolive.com/">Cisco Live</a> address the infrastructure challenges of today. The next challenge is already visible. As AI agents begin acting on behalf of users across enterprise systems, the network faces a new access control problem it was not designed to solve.</p>



<p>A typical enterprise user has password-based access to hundreds of applications, with credentials that rotate on a six-month cycle. Extending that same access to an agent is too permissive. “We need to put task-based controls, much more ephemeral controls, in place for agents,” Gillis said. “An agent authorized to file an expense report should have no ability to make purchases; I do not want the agent to buy a Porsche.”</p>



<p>Cisco is addressing this through Cisco Secure Access, its SSE solution, and through its hybrid mesh firewall, with controls that are task-scoped and session-specific for both user-to-application and server-to-server scenarios.</p>



<p>Beyond the show floor, Gillis said Cisco has additional announcements planned for the fall. “We’ll make some announcements in the fall that I think are going to be startling,” he said, without providing details.</p>



<p>His near-term vision is a single infrastructure architecture that spans all application types. “A year from now, I hope customers are realizing, hey, I can build infrastructure that can power my AI apps that are kind of tomorrow, the same infrastructure can power my Kubernetes-based apps that are today, in my VM-based apps, which are yesterday, all with one design, one architecture,” Gillis said.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Anthropic Files to Go Public]]></title>
<description><![CDATA[Anthropic says it has confidentially filed an IPO prospectus with the SEC, "setting up a potentially historic share sale for investors ready to jump into artificial intelligence," reports CNBC. The move puts Anthropic ahead of OpenAI's expected filing and follows explosive reported growth, a mass...]]></description>
<link>https://tsecurity.de/de/3564253/it-security-nachrichten/anthropic-files-to-go-public/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3564253/it-security-nachrichten/anthropic-files-to-go-public/</guid>
<pubDate>Mon, 01 Jun 2026 22:20:01 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Anthropic says it has confidentially filed an IPO prospectus with the SEC, "setting up a potentially historic share sale for investors ready to jump into artificial intelligence," reports CNBC. The move puts Anthropic ahead of OpenAI's expected filing and follows explosive reported growth, a massive new valuation, major infrastructure deals, and ongoing tensions with the Pentagon over its models. From the report: "This gives us the option to go public after the SEC completes its review," Anthropic said in a statement on Monday. "The proposed initial public offering will depend on market conditions and other factors."
 
Submitting a confidential prospectus doesn't lock Anthropic into a certain timeframe for going public. Its official prospectus just has to land in the hands of investors at least 15 days before the company begins a roadshow. [...] The company has experienced explosive growth this year, announcing in May that its revenue run rate has ballooned to $47 billion, up from $10 billion in annual revenue last year. Last week, it closed a funding round at a $965 billion valuation, topping OpenAI, which was valued at $852 billion in late March.<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=Anthropic+Files+to+Go+Public%3A+https%3A%2F%2Fslashdot.org%2Fstory%2F26%2F06%2F01%2F1837259%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fslashdot.org%2Fstory%2F26%2F06%2F01%2F1837259%2Fanthropic-files-to-go-public%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://slashdot.org/story/26/06/01/1837259/anthropic-files-to-go-public?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Dell Announces an Affordable XPS 13 Laptop for Students]]></title>
<description><![CDATA[Dell explicitly called out the Apple MacBook Neo in announcing a $599 XPS 13 laptop for students.
The post Dell Announces an Affordable XPS 13 Laptop for Students appeared first on Thurrott.com.]]></description>
<link>https://tsecurity.de/de/3564100/windows-tipps/dell-announces-an-affordable-xps-13-laptop-for-students/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3564100/windows-tipps/dell-announces-an-affordable-xps-13-laptop-for-students/</guid>
<pubDate>Mon, 01 Jun 2026 21:09:31 +0200</pubDate>
<category>🪟 Windows Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Dell explicitly called out the Apple MacBook Neo in announcing a $599 XPS 13 laptop for students.</p>
<p>The post <a href="https://www.thurrott.com/windows/windows-11/336909/dell-announces-an-affordable-xps-13-laptop-for-students">Dell Announces an Affordable XPS 13 Laptop for Students</a> appeared first on <a href="https://www.thurrott.com/">Thurrott.com</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Computex 2026: All the news and announcements]]></title>
<description><![CDATA[Computex 2026 is kicking off in Taipei, Taiwan this week, where Nvidia, AMD, Qualcomm, Intel, and other tech brands are announcing new laptops, handhelds, chips, and more.  Nvidia unveiled RTX Spark, its first family of consumer PC chips, arriving in laptops and mini PCs starting this fall. Intel...]]></description>
<link>https://tsecurity.de/de/3563442/it-nachrichten/computex-2026-all-the-news-and-announcements/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3563442/it-nachrichten/computex-2026-all-the-news-and-announcements/</guid>
<pubDate>Mon, 01 Jun 2026 16:47:15 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Computex 2026 is kicking off in Taipei, Taiwan this week, where Nvidia, AMD, Qualcomm, Intel, and other tech brands are announcing new laptops, handhelds, chips, and more.  Nvidia unveiled RTX Spark, its first family of consumer PC chips, arriving in laptops and mini PCs starting this fall. Intel is launching two new custom chips made […]]]></content:encoded>
</item>
<item>
<title><![CDATA[Cisco Secure Access and Microsoft Purview Integration for Simplified Data Protection]]></title>
<description><![CDATA[Announcing the new integration between Cisco Secure Access and Microsoft Purview designed to provide unified DLP based on Purview policies that can be enforced locally and in the cloud within Cisco Secure Access.]]></description>
<link>https://tsecurity.de/de/3562942/it-security-nachrichten/cisco-secure-access-and-microsoft-purview-integration-for-simplified-data-protection/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3562942/it-security-nachrichten/cisco-secure-access-and-microsoft-purview-integration-for-simplified-data-protection/</guid>
<pubDate>Mon, 01 Jun 2026 14:08:44 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Announcing the new integration between Cisco Secure Access and Microsoft Purview designed to provide unified DLP based on Purview policies that can be enforced locally and in the cloud within Cisco Secure Access.]]></content:encoded>
</item>
<item>
<title><![CDATA[Finding what lives between the alerts: Announcing Cisco Talos Threat Hunting]]></title>
<description><![CDATA[Announcing Cisco Talos Threat Hunting expansion across Cisco Secure Endpoint, Cisco Secure Firewall, and Cisco Duo, delivered via Security in Cloud Control.]]></description>
<link>https://tsecurity.de/de/3562941/it-security-nachrichten/finding-what-lives-between-the-alerts-announcing-cisco-talos-threat-hunting/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3562941/it-security-nachrichten/finding-what-lives-between-the-alerts-announcing-cisco-talos-threat-hunting/</guid>
<pubDate>Mon, 01 Jun 2026 14:08:43 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Announcing Cisco Talos Threat Hunting expansion across Cisco Secure Endpoint, Cisco Secure Firewall, and Cisco Duo, delivered via Security in Cloud Control.]]></content:encoded>
</item>
<item>
<title><![CDATA[Nvidia announces RTX Spark as ‘the most efficient PC chip ever built’]]></title>
<description><![CDATA[This fall, Nvidia will officially become a consumer PC chipmaker like Intel, AMD, Apple, and Qualcomm, putting a complete computing chip - not just graphics - into the very heart of laptops and mini-PCs. After many months of leaks, it's finally announcing the RTX Spark, the first in a family of c...]]></description>
<link>https://tsecurity.de/de/3561852/it-nachrichten/nvidia-announces-rtx-spark-as-the-most-efficient-pc-chip-ever-built/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3561852/it-nachrichten/nvidia-announces-rtx-spark-as-the-most-efficient-pc-chip-ever-built/</guid>
<pubDate>Mon, 01 Jun 2026 06:31:12 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[This fall, Nvidia will officially become a consumer PC chipmaker like Intel, AMD, Apple, and Qualcomm, putting a complete computing chip - not just graphics - into the very heart of laptops and mini-PCs. After many months of leaks, it's finally announcing the RTX Spark, the first in a family of chips that will meet […]]]></content:encoded>
</item>
<item>
<title><![CDATA[Dell is bringing back the XPS 13 as a MacBook Neo competitor — with a temporary discount to $599]]></title>
<description><![CDATA[Dell is making good on its tease from CES and finally announcing a new XPS 13. The XPS 13 returns as a budget-friendly option, launching in July at a promotional student price of $599 - though that introductory deal only runs until September for back-to-school shopping; it'll start at $699 for ev...]]></description>
<link>https://tsecurity.de/de/3561527/it-nachrichten/dell-is-bringing-back-the-xps-13-as-a-macbook-neo-competitor-with-a-temporary-discount-to-599/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3561527/it-nachrichten/dell-is-bringing-back-the-xps-13-as-a-macbook-neo-competitor-with-a-temporary-discount-to-599/</guid>
<pubDate>Mon, 01 Jun 2026 01:17:08 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Dell is making good on its tease from CES and finally announcing a new XPS 13. The XPS 13 returns as a budget-friendly option, launching in July at a promotional student price of $599 - though that introductory deal only runs until September for back-to-school shopping; it'll start at $699 for everyone else. The $599 […]]]></content:encoded>
</item>
<item>
<title><![CDATA[Claude Mythos exposed a hard truth: Your enterprise patching process is way too slow]]></title>
<description><![CDATA[In 2024, researchers from the University of Illinois found that GPT-4, when provided with a common vulnerabilities and exposures (CVE) description, could autonomously exploit 87% of a curated 15-vulnerability one-day dataset. Without the description, it could only exploit 7%. This provided a “mar...]]></description>
<link>https://tsecurity.de/de/3561173/it-nachrichten/claude-mythos-exposed-a-hard-truth-your-enterprise-patching-process-is-way-too-slow/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3561173/it-nachrichten/claude-mythos-exposed-a-hard-truth-your-enterprise-patching-process-is-way-too-slow/</guid>
<pubDate>Sun, 31 May 2026 19:17:26 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>In 2024,<a href="https://arxiv.org/abs/2404.08144"> <u>researchers from the University of Illinois</u></a> found that GPT-4, when provided with a common vulnerabilities and exposures (CVE) description, could autonomously exploit 87% of a curated 15-vulnerability one-day dataset. Without the description, it could only exploit 7%. This provided a “margin of safety” for the industry because while AI could exploit known vulnerabilities, it could not discover them. </p><p>However, on April 7,<a href="https://www.anthropic.com/glasswing"> <u>Anthropic announced</u></a> that Claude Mythos Preview had closed that margin, with the model autonomously discovering thousands of zero-day vulnerabilities across major operating systems and browsers. Separately, Mythos scored 83.1% on the CyberGym vulnerability reproduction benchmark. In one campaign targeting OpenBSD across 1,000 scaffold runs, the total compute cost was less than $20,000. </p><p>Exploitation timelines are collapsing. Langflow’s CVE-2026-33017 (CVSS 9.8) was<a href="https://www.sysdig.com/blog/cve-2026-33017-how-attackers-compromised-langflow-ai-pipelines-in-20-hours"> <u>exploited 20 hours after disclosure</u></a> with no public proof-of-concept. Marimo’s CVE-2026-39987 (CVSS 9.3) was<a href="https://www.sysdig.com/blog/marimo-oss-python-notebook-rce-from-disclosure-to-exploitation-in-under-10-hours"> <u>hit in 9 hours and 41 minutes</u></a>.</p><p>The defensive infrastructure most organizations rely on wasn’t designed for this.<a href="https://www.rapid7.com/research/report/global-threat-landscape-report-2026/"> <u>Rapid7’s 2026 threat landscape report</u></a> states that the median time from CVE publication to CISA's known exploited vulnerabilities (KEV) listing is five days.<a href="https://cloud.google.com/blog/topics/threat-intelligence/m-trends-2026"> <u>Google’s M-Trends 2026</u></a> report found that exploitation is happening before a patch is even released. When the Langflow advisory was published, the first exploit arrived in 20 hours. When the Marimo advisory was published, it took under 10 hours. </p><p>The assumption that your patch window is safe because exploitation takes time is no longer true. Here are your building blocks.</p><h2><b>Replace CVSS-only prioritization with a three-layer filter</b></h2><p>Most vulnerability management programs still prioritize by CVSS score alone. CVSS quantifies a vulnerability’s “theoretical” severity without considering whether a vulnerability is being exploited in the wild or how quickly someone could weaponize it. A CVSS 8.8 vulnerability with a history of active exploitation (like Docker’s<a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34040"> <u>CVE-2026-34040</u></a>) gets lower priority than a CVSS 9.8 vulnerability that may never be exploited in the wild.</p><p>A<a href="https://arxiv.org/abs/2506.01220"> <u>recent study</u></a> validated against 28,377 real-world vulnerabilities offers a concrete replacement: A three-layer decision tree incorporating CISA KEV status, Exploit Prediction Scoring System (EPSS) scores, and CVSS, thus forming a singular prioritization filter.</p><h4><b>Three-Layer Vulnerability Prioritization Filter</b></h4><table><tbody><tr><td><p><b>Layer</b></p></td><td><p><b>Data source</b></p></td><td><p><b>Threshold</b></p></td><td><p><b>Action</b></p></td><td><p><b>SLA</b></p></td></tr><tr><td><p>1. Active exploitation</p></td><td><p>CISA KEV catalog</p></td><td><p>Listed</p></td><td><p>Immediate patching</p></td><td><p>Hours</p></td></tr><tr><td><p>2. Predicted exploitation</p></td><td><p>EPSS via FIRST.org</p></td><td><p>Score ≥ 0.088</p></td><td><p>Escalate to Tier 0 pipeline</p></td><td><p>24 hours</p></td></tr><tr><td><p>3. Severity baseline</p></td><td><p>CVSS via NVD</p></td><td><p>Score ≥ 7.0</p></td><td><p>Typical remediation</p></td><td><p>Per policy</p></td></tr></tbody></table><p><i>Validated result: 18x efficiency gain, 85.6% coverage of exploited vulnerabilities, ~95% reduction in urgent remediation workload. All three data sources are open and free.</i></p><p>The described integration is entirely automatable. It’s possible to build a script to query the CISA KEV API, the EPSS API from FIRST.org, and the <a href="https://nvd.nist.gov/">NVD</a>, and have that script run against your asset inventory for every published CVE. The human in this process should remain in the loop as an approver, but not as the trigger.</p><h2><b>Close the agent authorization gap</b></h2><p>Creating exploits quickly not only changes how patches are prioritized, but how controls are configured for all the agent-driven systems that now possess privileged credentials. Your authorization policies have not been assessed against the behavior of AI agents, and that is now a measurable risk. CVE-2026-34040 showed that Docker’s authorization plugin architecture silently bypasses every plugin when the request body exceeds 1MB. Common AuthZ plugins (OPA, Casbin, Prisma Cloud) are unaware of this type of bypass, which occurs in Docker’s middleware before the request reaches the plugin.</p><p>When<a href="https://www.cyera.com/blog/cyera-research-discovers-docker-authorization-bypass-that-silently-disables-security-policies"> <u>Cyera demonstrated this vulnerability</u></a>, they showed that an AI agent debugging infrastructure could infer the bypass path while completing a legitimate task, without any instruction to exploit anything.</p><p>The Internet Engineering Task Force (IETF) is working on authorization models for agents. The document<a href="https://datatracker.ietf.org/doc/draft-klrc-aiagent-auth/"> <u>draft-klrc-aiagent-auth-01</u></a>, published in March by participants from AWS, Zscaler, Ping Identity, and OpenAI, proposes the use of the current Secure Production Identity Framework for Everyone (SPIFFE) and OAuth 2.0 for AI agents to obtain dynamically provisioned and short-lived credentials. </p><p>Separately, the IETF<a href="https://datatracker.ietf.org/doc/draft-prakash-aip/"> <u>Agent Identity Protocol draft</u></a> (draft-prakash-aip-00) reports that out of about 2,000 surveyed model context protocol (MCP) servers, none had authentication. </p><p>But these standards are months to years away from implementation. For now, security teams must proactively incorporate agent-level test scenarios for all authorization boundaries, such as oversized requests, burst frequency, and multi-step escalation of privileged requests.</p><h2><b>Map your credential blast radius</b></h2><p>In a<a href="https://cloudsecurityalliance.org/press-releases/2026/04/16/more-than-half-of-organizations-experience-ai-agent-scope-violations-cloud-security-alliance-study-finds"> <u>survey conducted by CSA/Zenity</u></a> and published on April 16, 53% of organizations said they had already seen cases where AI agents exceeded their intended permissions, and 47% experienced a security incident involving an agent. </p><p>When AI builder tools such as<a href="https://thehackernews.com/2026/04/flowise-ai-agent-builder-under-active.html"> <u>Flowise</u></a> (CVE-2025-59528, CVSS 10.0), Langflow, or n8n become compromised, the blast radius extends far beyond the host. These tools contain API keys to frontier models, database credentials, vector store tokens, and OAuth tokens to business systems. A compromised AI builder host is not just a single-system breach. It is a credential harvest that unlocks authenticated access to every connected service.</p><p>Without credential dependency maps for each AI tool host, incident response for agent compromise is guesswork. For every instance, document each credential, the extent of its access, and the relevant credential rotation process. Also begin migrating static API keys to short-lived tokens where downstream services allow.</p><h2><b>Five actions for this quarter</b></h2><p><b>1. Deploy the three-layer KEV-EPSS-CVSS filter</b></p><p>Substitute CVSS-only prioritization according to the table above. Automate the collection of data from all three APIs as part of a scheduled script against your asset inventory. Desired outcome: 18 times more efficient, 85.6% coverage of exploited vulnerabilities, 95% reduction in urgent remediation workload.</p><p><b>2. Implement event-driven patching for Tier 0 services.</b> </p><p>Determine which services fall under the critical exposure tier: Services exposed directly to internet users, AI builder hosts, and container orchestration control plane. Trigger event-driven patching on a CVE publication instead of waiting for the next maintenance window for this tier. </p><p>Goal: deploy patch to canary within four hours of a CVE being declared critical. Use the CISA KEV and EPSS feeds to trigger event-driven patching. In situations where it is impossible to meet the goal of four-hour patching because of legacy dependencies, change-freeze windows, or rollback risk, immediately apply compensating controls such as removing internet exposure to the vulnerable service, rotating credentials for the vulnerable service, disabling affected functionality of the service (if applicable), and identifying an exception owner for the exposure until a patch can be deployed. </p><p>It is not acceptable to allow unbounded exposures for extended periods while awaiting a maintenance window.</p><p><b>3. Test authorization boundaries at agent scale.</b> </p><p>Create test cases for every API that AI agents may communicate with via AuthZ policies. Specifically, include test cases for requests exceeding 1MB, 5MB, and 10MB body sizes. This includes test cases for burst rate &gt; 100 requests per second and test cases for unusual parameter combinations (privileged flags, host mounts, capability additions). Additionally,<a href="https://www.csoonline.com/article/4157405/old-docker-authorization-bypass-pops-up-despite-previous-patch.html"> <u>patch to Docker Engine 29.3.1</u></a> to fix CVE-2026-34040.</p><p><b>4. Credential blast radius mapping for all AI builder hosts.</b> </p><p>Document each credential for each Langflow, Flowise, n8n, and custom AI pipeline instance. Classify each credential by its lifespan (static key vs. short-lived token). Identify what each credential can access. Set up alerts for anomalous IP or identity for any credential access.</p><p><b>5. Shadow AI discovery scan for this week.</b> </p><p>According to CSA data, there is a greater than 50% chance that your agents have exceeded their expected boundaries. Check your Security Information and Event Management (SIEM) and network monitoring tools for communications to the default ports of the AI builder: Langflow 7860, Flowise 3000, and n8n 5678. Any unauthorized instances are an unmonitored attack surface.</p><h2>The takeaway</h2><p>AI agents are emerging, and t<!-- -->he standards bodies are responding. The IETF has multiple drafts related to agent authentication and authorization. The<a href="https://www.coalitionforsecureai.org/"> <u>Coalition for Secure AI</u></a> has published its <a href="https://www.coalitionforsecureai.org/wp-content/uploads/2026/03/model-context-protocol-security-1.pdf"><u>MCP Security taxonomy</u></a> and <a href="https://www.coalitionforsecureai.org/announcing-the-cosai-principles-for-secure-by-design-agentic-systems/"><u>Secure-by-Design principles</u></a>. </p><p>But these standards move at standards-body speed, and the exploit window is now measured in hours. Organizations that implement the three-layer filter and event-driven patching this quarter will have a measurable reduction in exposure. Those who wait will be running calendar-based patch cycles against an adversary that operates in less than 20 hours. </p><p><i>Nik Kale is a principal engineer specializing in enterprise AI platforms and security</i></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Announcing new builds for 29 May 2026]]></title>
<description><![CDATA[Hello Windows Insiders,
This week we continue to expand the rollout of the new Windows Insider Program changes to devices in channels already announced.
New builds this week
Today we are releasing new Windows 11 Insider Preview B
The post Announcing new builds for 29 May 2026 appeared first on Wi...]]></description>
<link>https://tsecurity.de/de/3557963/windows-tipps/announcing-new-builds-for-29-may-2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3557963/windows-tipps/announcing-new-builds-for-29-may-2026/</guid>
<pubDate>Sat, 30 May 2026 01:20:25 +0200</pubDate>
<category>🪟 Windows Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Hello Windows Insiders,</p>
<p>This week we continue to expand the rollout of the new Windows Insider Program changes to devices in channels already announced.</p>
<p><strong>New builds this week</strong></p>
<p>Today we are releasing new Windows 11 Insider Preview B</p>
<p>The post <a href="https://blogs.windows.com/windows-insider/2026/05/29/announcing-new-builds-for-29-may-2026/">Announcing new builds for 29 May 2026</a> appeared first on <a href="https://blogs.windows.com/windows-insider">Windows Insider Blog</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Cisco Secure Access and Microsoft Edge for Business Integration]]></title>
<description><![CDATA[Announcing the new integration between Cisco Secure Access and Microsoft Edge for Business, designed to enhance enterprise browser security and protect an organization’s applications and data.]]></description>
<link>https://tsecurity.de/de/3557686/it-security-nachrichten/cisco-secure-access-and-microsoft-edge-for-business-integration/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3557686/it-security-nachrichten/cisco-secure-access-and-microsoft-edge-for-business-integration/</guid>
<pubDate>Sat, 30 May 2026 01:12:37 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Announcing the new integration between Cisco Secure Access and Microsoft Edge for Business, designed to enhance enterprise browser security and protect an organization’s applications and data.]]></content:encoded>
</item>
<item>
<title><![CDATA[Announcing Trento Version 3.1]]></title>
<description><![CDATA[Trento 3.1 continues the road started with Trento 3.0 around automation and AI capabilities. It also strengthens the application core and brings important observability improvements. Timezone Awareness Trento 3.1 allows users to select the timezone in which date and time stamps are displayed acro...]]></description>
<link>https://tsecurity.de/de/3557238/unix-server/announcing-trento-version-31/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3557238/unix-server/announcing-trento-version-31/</guid>
<pubDate>Fri, 29 May 2026 19:01:03 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Trento 3.1 continues the road started with Trento 3.0 around automation and AI capabilities. It also strengthens the application core and brings important observability improvements. Timezone Awareness Trento 3.1 allows users to select the timezone in which date and time stamps are displayed across the UI. This facilitates the user understanding when past events collected in the […]</p>
<p>The post <a href="https://www.suse.com/c/announcing-trento-version-3-1/">Announcing Trento Version 3.1</a> appeared first on <a href="https://www.suse.com/c">SUSE Communities</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Motorola Image Privacy App Auto Wipes Metadata]]></title>
<description><![CDATA[Along with announcing official GrapheneOS support, Motorola highlights a privacy feature of their image storage. When enabled, it automatically removes sensitive metadata from all new camera images on the device, helping protect details like location and device information. This protection runs q...]]></description>
<link>https://tsecurity.de/de/3556294/it-security-nachrichten/motorola-image-privacy-app-auto-wipes-metadata/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3556294/it-security-nachrichten/motorola-image-privacy-app-auto-wipes-metadata/</guid>
<pubDate>Fri, 29 May 2026 08:52:53 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Along with announcing official GrapheneOS support, Motorola highlights a privacy feature of their image storage. When enabled, it automatically removes sensitive metadata from all new camera images on the device, helping protect details like location and device information. This protection runs quietly in the background, preserving the image itself while clearing some of the private … <a href="https://www.flyingpenguin.com/motorola-image-privacy-app-auto-wipes-metadata/" class="more-link">Continue reading <span class="screen-reader-text">Motorola Image Privacy App Auto Wipes Metadata</span> <span class="meta-nav">→</span></a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Apple TV’s ‘Shrinking’ season four adds Karen Gillan to its star-studded ensemble]]></title>
<description><![CDATA[Apple TV continues to build momentum with its hit dramedy "Shrinking," announcing today that Scottish actress Karen Gillan has joined…
The post Apple TV’s ‘Shrinking’ season four adds Karen Gillan to its star-studded ensemble appeared first on MacDailyNews.]]></description>
<link>https://tsecurity.de/de/3555371/ios-mac-os/apple-tvs-shrinking-season-four-adds-karen-gillan-to-its-star-studded-ensemble/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3555371/ios-mac-os/apple-tvs-shrinking-season-four-adds-karen-gillan-to-its-star-studded-ensemble/</guid>
<pubDate>Thu, 28 May 2026 21:24:17 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Apple TV continues to build momentum with its hit dramedy "Shrinking," announcing today that Scottish actress Karen Gillan has joined…</p>
<p>The post <a href="https://macdailynews.com/2026/05/28/apple-tvs-shrinking-season-four-adds-karen-gillan-to-its-star-studded-ensemble/">Apple TV’s ‘Shrinking’ season four adds Karen Gillan to its star-studded ensemble</a> appeared first on <a href="https://macdailynews.com/">MacDailyNews</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Corgi announces $106M raise at $2.6B valuation — triple what it was worth three weeks ago]]></title>
<description><![CDATA[Insurance tech Corgi announced today an $106 million Series B1 raise, valuing the company at $2.6 billion, just three weeks after announcing a $160 million Series B.]]></description>
<link>https://tsecurity.de/de/3555062/it-nachrichten/corgi-announces-106m-raise-at-26b-valuation-triple-what-it-was-worth-three-weeks-ago/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3555062/it-nachrichten/corgi-announces-106m-raise-at-26b-valuation-triple-what-it-was-worth-three-weeks-ago/</guid>
<pubDate>Thu, 28 May 2026 19:17:13 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Insurance tech Corgi announced today an $106 million Series B1 raise, valuing the company at $2.6 billion, just three weeks after announcing a $160 million Series B.]]></content:encoded>
</item>
<item>
<title><![CDATA[Announcing the VMware Cloud Foundation 9.1 Upgrade Planning Tool]]></title>
<description><![CDATA[One of the biggest advantages of VMware Cloud Foundation (VCF) 9.1 is its flexibility and broad support for existing customer environments, meeting customers where they are at in their Private Cloud journey. From existing standalone vSphere deployments with VCF Operations to environments with dif...]]></description>
<link>https://tsecurity.de/de/3554276/downloads/announcing-the-vmware-cloud-foundation-91-upgrade-planning-tool/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3554276/downloads/announcing-the-vmware-cloud-foundation-91-upgrade-planning-tool/</guid>
<pubDate>Thu, 28 May 2026 15:17:29 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div><img width="300" height="148" src="https://blogs.vmware.com/cloud-foundation/wp-content/uploads/sites/75/2026/05/VCF-9.1-VCF-Operations-e1779901090289.png?w=300" class="attachment-medium size-medium wp-post-image" alt="" decoding="async"></div>
<p>One of the biggest advantages of VMware Cloud Foundation (VCF) 9.1 is its flexibility and broad support for existing customer environments, meeting customers where they are at in their Private Cloud journey. From existing standalone vSphere deployments with VCF Operations to environments with different combinations of vSAN, NSX and Aria Automation, all the way to … <a href="https://blogs.vmware.com/cloud-foundation/2026/05/28/announcing-the-vmware-cloud-foundation-9-1-upgrade-planning-tool/">Continued</a></p>
<p>The post <a href="https://blogs.vmware.com/cloud-foundation/2026/05/28/announcing-the-vmware-cloud-foundation-9-1-upgrade-planning-tool/">Announcing the VMware Cloud Foundation 9.1 Upgrade Planning Tool</a> appeared first on <a href="https://blogs.vmware.com/cloud-foundation">VMware Cloud Foundation (VCF) Blog</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Official: Intel’s first handheld gaming chip is the Arc G3 and this Acer is using it]]></title>
<description><![CDATA[Intel is barely in the handheld gaming PC space - but that might be about to change. After the embarrassment that was the first MSI Claw and the excellent MSI Claw 8 AI Plus that followed it, Intel announced it would create custom handheld gaming chips. Today, it's formally announcing them as the...]]></description>
<link>https://tsecurity.de/de/3554212/it-nachrichten/official-intels-first-handheld-gaming-chip-is-the-arc-g3-and-this-acer-is-using-it/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3554212/it-nachrichten/official-intels-first-handheld-gaming-chip-is-the-arc-g3-and-this-acer-is-using-it/</guid>
<pubDate>Thu, 28 May 2026 15:02:33 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Intel is barely in the handheld gaming PC space - but that might be about to change. After the embarrassment that was the first MSI Claw and the excellent MSI Claw 8 AI Plus that followed it, Intel announced it would create custom handheld gaming chips. Today, it's formally announcing them as the Arc G3 […]]]></content:encoded>
</item>
<item>
<title><![CDATA[Meta To Start Testing AI Subscription Services]]></title>
<description><![CDATA[Meta will begin testing paid subscriptions for its Meta AI app and website, with a $7.99/month Meta One Plus plan and a more capable $19.99/month Meta One Premium plan offering. The test will start next month in Singapore, Guatemala, and Bolivia as Meta looks for AI revenue beyond advertising whi...]]></description>
<link>https://tsecurity.de/de/3552604/it-security-nachrichten/meta-to-start-testing-ai-subscription-services/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3552604/it-security-nachrichten/meta-to-start-testing-ai-subscription-services/</guid>
<pubDate>Thu, 28 May 2026 01:07:43 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Meta will begin testing paid subscriptions for its Meta AI app and website, with a $7.99/month Meta One Plus plan and a more capable $19.99/month Meta One Premium plan offering. The test will start next month in Singapore, Guatemala, and Bolivia as Meta looks for AI revenue beyond advertising while continuing to offer a free tier. CNBC reports: Naomi Gleit, the head of product at Meta, revealed the subscription testing in an Instagram video, announcing that the plans "give people who use Meta AI more to work with, more capacity, bigger, more complex requests, and more room to create for businesses and creators."
 
Meta One Plus will cost $7.99 a month and the Meta One Premium plan will cost $19.99 a month, the company confirmed. The more expensive version offers users additional computing capacity to produce more comprehensive responses and other advanced features. The company will continue to provide a free version of the app and site.
 
"We're offering premium tools that allow you to enhance presence, supercharge content, automate tasks, and protect your brand," Gleit said in the post. "We're also thinking about how to bring this all together in a way that makes sense."<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=Meta+To+Start+Testing+AI+Subscription+Services%3A+https%3A%2F%2Fnews.slashdot.org%2Fstory%2F26%2F05%2F27%2F2142239%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fnews.slashdot.org%2Fstory%2F26%2F05%2F27%2F2142239%2Fmeta-to-start-testing-ai-subscription-services%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://news.slashdot.org/story/26/05/27/2142239/meta-to-start-testing-ai-subscription-services?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Facebook launches a ‘Plus’ subscription that gives you extra features]]></title>
<description><![CDATA[After announcing tests of premium subscriptions for Facebook, Instagram, WhatsApp earlier this year, TechCrunch and Bloomberg report that Meta is launching a global rollout over the next few weeks and is also starting to test subscriptions for Meta AI. With the new offerings, Meta joins many othe...]]></description>
<link>https://tsecurity.de/de/3552350/it-nachrichten/facebook-launches-a-plus-subscription-that-gives-you-extra-features/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3552350/it-nachrichten/facebook-launches-a-plus-subscription-that-gives-you-extra-features/</guid>
<pubDate>Wed, 27 May 2026 22:17:12 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[After announcing tests of premium subscriptions for Facebook, Instagram, WhatsApp earlier this year, TechCrunch and Bloomberg report that Meta is launching a global rollout over the next few weeks and is also starting to test subscriptions for Meta AI. With the new offerings, Meta joins many other tech companies in changing up its subscription plans […]]]></content:encoded>
</item>
<item>
<title><![CDATA[Nvidia has retired its GeForce Control Panel app after 20 years]]></title>
<description><![CDATA[Nvidia announced more than two years ago that it was working to replace its Control Panel app on Windows with a new Nvidia app. After porting across various features to the Nvidia app, Nvidia is announcing today that it has officially retired the Control Panel app. "With the introduction of our m...]]></description>
<link>https://tsecurity.de/de/3548293/it-nachrichten/nvidia-has-retired-its-geforce-control-panel-app-after-20-years/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3548293/it-nachrichten/nvidia-has-retired-its-geforce-control-panel-app-after-20-years/</guid>
<pubDate>Tue, 26 May 2026 16:17:44 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Nvidia announced more than two years ago that it was working to replace its Control Panel app on Windows with a new Nvidia app. After porting across various features to the Nvidia app, Nvidia is announcing today that it has officially retired the Control Panel app. "With the introduction of our most recent Nvidia App […]]]></content:encoded>
</item>
<item>
<title><![CDATA[General Availability of AlmaLinux OS 9.8 and 10.2 Stable!]]></title>
<description><![CDATA[AlmaLinux OS 9.8 and 10.2 Stable Now AvailableHello Community! The AlmaLinux OS Foundation is announcing the general availability of two stable releases at once: AlmaLinux OS 9.8 codenamed “Olive Jaguar” and AlmaLinux OS 10.2 codenamed “Lavender Lion”!
This is the first time we have ever shipped ...]]></description>
<link>https://tsecurity.de/de/3548121/unix-server/general-availability-of-almalinux-os-98-and-102-stable/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3548121/unix-server/general-availability-of-almalinux-os-98-and-102-stable/</guid>
<pubDate>Tue, 26 May 2026 15:16:35 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h1>AlmaLinux OS 9.8 and 10.2 Stable Now Available</h1><p>Hello Community! The AlmaLinux OS Foundation is announcing the general availability of two stable releases at once: <a href="https://mirrors.almalinux.org/isos.html">AlmaLinux OS 9.8</a> codenamed “Olive Jaguar” and <a href="https://mirrors.almalinux.org/isos.html">AlmaLinux OS 10.2</a> codenamed “Lavender Lion”!</p>
<p>This is the first time we have ever shipped two AlmaLinux releases on the same day, and it’s a milestone we’re proud of. It’s the direct result of concerted effort by our Build, Core, and Infrastructure SIGs on our release engineering procedures. This work resulted in better automation, tighter QA pipelines, and a build system that can carry two parallel release trains without one slowing the other down.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Announcing Risk Automations: From Discovery to Resolution In Seconds | UpGuard]]></title>
<description><![CDATA[Learn about UpGuard's new product launch. Transform your risk resolution engine by moving from alert to resolution in seconds, not days.]]></description>
<link>https://tsecurity.de/de/3544665/it-security-nachrichten/announcing-risk-automations-from-discovery-to-resolution-in-seconds-upguard/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3544665/it-security-nachrichten/announcing-risk-automations-from-discovery-to-resolution-in-seconds-upguard/</guid>
<pubDate>Mon, 25 May 2026 06:08:02 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Learn about UpGuard's new product launch. Transform your risk resolution engine by moving from alert to resolution in seconds, not days.]]></content:encoded>
</item>
<item>
<title><![CDATA[AI 'Crashes the Party' at This Year's Cannes Film Festival - Including Multi-Year Meta Partnership]]></title>
<description><![CDATA[AI "crashed the party" at this year's Cannes Film Festival, writes The Hollywood Reporter. The festival exposed "the fault lines reshaping cinema," their article argues, including how "AI is here — and the industry has stopped pretending otherwise."

A humanoid robot spotted marching up and down ...]]></description>
<link>https://tsecurity.de/de/3544513/it-security-nachrichten/ai-crashes-the-party-at-this-years-cannes-film-festival-including-multi-year-meta-partnership/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3544513/it-security-nachrichten/ai-crashes-the-party-at-this-years-cannes-film-festival-including-multi-year-meta-partnership/</guid>
<pubDate>Mon, 25 May 2026 03:50:16 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[AI "crashed the party" at this year's Cannes Film Festival, writes The Hollywood Reporter. The festival exposed "the fault lines reshaping cinema," their article argues, including how "AI is here — and the industry has stopped pretending otherwise."

A humanoid robot spotted marching up and down the Croisette seemed to sum up the worst AI fears of the film industry — the machines have arrived and they are taking your place. But inside the Palais and the market tents, the conversation over artificial intelligence had moved beyond fear into something more like uneasy acceptance. Fighting AI "is a battle we will lose," said Demi Moore, a Cannes jury member this year, at the festival's opening press conference, suggesting the film industry needs to "find ways in which we can work with it." 

That's not the official Cannes line. The festival has banned films using generative artificial intelligence from its competition lineup. But at the Cannes film market, and in discussions at industry events over the past two weeks, the tone has shifted. AI-friendly tech giant Meta signed on as an official partner to the festival in a multiyear deal. Its AI tools were used to help produce an [out of competition] festival entry: Steven Soderbergh's documentary John Lennon: The Last Interview. [Meta's press release announcing the partnership touts "our creator partnerships," their Meta AI assistant, and "our latest AI and wearable technologies" including Ray-Ban Meta AI features for smartglasses like "AI-powered translations that break down language barriers in real-time".] At the Marché du Film [film market], there was an "AI for Talent Summit" that took the AI revolution as given, focusing instead on ethical AI use, data sovereignty and on the ways the technology can be used to enhance, rather than replace, creativity. 

For the indie film industry, it felt like a turning point.<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=AI+'Crashes+the+Party'+at+This+Year's+Cannes+Film+Festival+-+Including+Multi-Year+Meta+Partnership%3A+https%3A%2F%2Fentertainment.slashdot.org%2Fstory%2F26%2F05%2F24%2F173224%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fentertainment.slashdot.org%2Fstory%2F26%2F05%2F24%2F173224%2Fai-crashes-the-party-at-this-years-cannes-film-festival---including-multi-year-meta-partnership%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://entertainment.slashdot.org/story/26/05/24/173224/ai-crashes-the-party-at-this-years-cannes-film-festival---including-multi-year-meta-partnership?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[US Layoffs Haven't Increased, and New Tech Industry Hiring Balances Firings]]></title>
<description><![CDATA["The numbers show that layoffs in the U.S. are roughly at or below levels from before the pandemic," reports the Washington Post, "although they are higher than in 2022 when businesses snapped up workers as the economy roared back to life... 

"A different measure that accounts for the growing U....]]></description>
<link>https://tsecurity.de/de/3542595/it-security-nachrichten/us-layoffs-havent-increased-and-new-tech-industry-hiring-balances-firings/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3542595/it-security-nachrichten/us-layoffs-havent-increased-and-new-tech-industry-hiring-balances-firings/</guid>
<pubDate>Sat, 23 May 2026 22:52:39 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA["The numbers show that layoffs in the U.S. are roughly at or below levels from before the pandemic," reports the Washington Post, "although they are higher than in 2022 when businesses snapped up workers as the economy roared back to life... 

"A different measure that accounts for the growing U.S. workforce shows that layoffs affected about 1.2% of employed people in March, a number that has been steady for years outside of the pandemic..."

In the technology industry, where Meta and other companies are regularly announcing job cuts, the layoff picture is complex. There has been a marked increase in layoffs in recent months in what the Labor Department calls the information industry, which includes employment of software developers and other tech workers. But Matthew Martin, senior U.S. economist at the research and consulting firm Oxford Economics, noted that hiring has also increased in that category, which includes media and entertainment. The combination of hiring minus layoffs in the information industry is effectively a wash, Martin said. Layoffs at Big Tech companies like Meta and other high-profile employers don't necessarily reflect what is happening in the country, Martin said, and draw far more attention than what may be slow and steady workforce growth. "There's a lot more headlines about job cuts than there are [about] expansion plans by businesses," he said. 

In his view, technology companies may be pushing out some workers and replacing them with people who have different skills as they respond to the demands of AI. It's true that businesses in some industries are devoting enormous sums of money and attention to AI. It's changing how some people work and a minority of American businesses are rolling out AI tools. But it's also become a trend for bosses to blame layoffs on the productive capabilities of AI and its ability to replace workers, even when job cuts may have little to do with the technology. Sam Altman, CEO of ChatGPT-maker OpenAI, has taken note of the pattern that he and others call "AI washing," essentially a high-tech form of whitewashing... "You know something is happening all the time when they have a word for it," said Gautam Mukunda, who teaches leadership at the Yale School of Management... 

AI-related employment changes are tiny so far, said Nathan Goldschlag, director of research at the Economic Innovation Group, a Washington think tank. He pointed to a recently published analysis of Census Bureau surveys, which found more than 95 percent of businesses that use AI said it hasn't changed their staff sizes — and AI-related employment increases were more common than decreases.<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=US+Layoffs+Haven't+Increased%2C+and+New+Tech+Industry+Hiring+Balances+Firings%3A+https%3A%2F%2Fit.slashdot.org%2Fstory%2F26%2F05%2F23%2F064223%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fit.slashdot.org%2Fstory%2F26%2F05%2F23%2F064223%2Fus-layoffs-havent-increased-and-new-tech-industry-hiring-balances-firings%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://it.slashdot.org/story/26/05/23/064223/us-layoffs-havent-increased-and-new-tech-industry-hiring-balances-firings?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Tech CEOs Call for a Universal Basic Income. But What are the Alternatives?]]></title>
<description><![CDATA[The Washington Post looks at arguments that "AI's coming upheaval may demand massive infusions of cash to everyday Americans". But they also look at some of the alternatives:

Anthropic CEO Dario Amodei has called for similar public-relief measures, including, potentially, universal basic income,...]]></description>
<link>https://tsecurity.de/de/3542092/it-security-nachrichten/tech-ceos-call-for-a-universal-basic-income-but-what-are-the-alternatives/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3542092/it-security-nachrichten/tech-ceos-call-for-a-universal-basic-income-but-what-are-the-alternatives/</guid>
<pubDate>Sat, 23 May 2026 16:52:00 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The Washington Post looks at arguments that "AI's coming upheaval may demand massive infusions of cash to everyday Americans". But they also look at some of the alternatives:

Anthropic CEO Dario Amodei has called for similar public-relief measures, including, potentially, universal basic income, or UBI. Eventually "our current economic setup will no longer make sense," he wrote in a blog post, adding that "there will be a need for a broader societal conversation about how the economy should be organized." 

Though OpenAI CEO Sam Altman once championed universal basic income, he has since embraced a new structure where the public has "collective ownership" of aspects of AI, according to Business Insider. "I think any version of the future that I can get really excited about means that everybody's got to participate in the upside," he said in a recent podcast interview. In April, OpenAI laid out a set of policy proposals aiming to address the coming upheaval, referencing the transition to the industrial age and the New Deal as points of comparison for what's on the horizon... 


But some experts question whether tech billionaires, who spent decades resisting regulation, unions and higher taxes, would support the kind of massive redistribution such programs would require. "The only way to pay for UBI is to massively tax those enormously rich people who own the UBI machines," said Jesse Rothstein, a professor of public policy and economics at the University of California at Berkeley who served as chief economist at the U.S. Department of Labor. "It's a nice surprise to hear Elon Musk advocating for that...." Rothstein co-authored a study in 2019 that estimated granting a small income to the entire country would cost a massive amount — nearly double the total spending of Social Security, Medicare and Medicaid. To issue payments of $12,000 a year to U.S. adults, for example, "would require nearly doubling federal tax revenues," according to the paper... 

Economists appear to broadly support other solutions beyond redistribution, such as job retraining. A working paper published this spring by the Federal Reserve Bank of Chicago showed economists support more narrowly tailored solutions to the economic disruption. In late April, Meta appeared to embrace that path, announcing "a multi-year initiative that provides free, rapid training to turn thousands of Americans with no prior experience into high-paid fiber technicians" for projects including data centers. 

Key quotes from the article:

Elon Musk said in an X post that "Universal HIGH INCOME via checks issued by the Federal government is the best way to deal with unemployment caused by AI."
"I think it's a marketing tactic" responded Scott Santens, a universal basic income advocate and is CEO of the nonprofit Income to Support All Foundation. He argued to the Washington Post that Musk's comment is "trying to thread this needle of, 'I want to solve this stuff that will potentially put a lot of people out of work.' And how do you avoid people getting really [angry] at that? Okay, well, you're still going to get money, everything will be great it's just you won't have to work anymore...."
The article also cites a recent commentary from Jay W. Richards, a senior research fellow and VP of social and domestic policy at the Heritage Foundation. "The new AI prophets of doom suffer from a failure of imagination. They simply cannot envision what work the future will bring, so they conclude it will bring none,"<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=Tech+CEOs+Call+for+a+Universal+Basic+Income.+But+What+are+the+Alternatives%3F%3A+https%3A%2F%2Fyro.slashdot.org%2Fstory%2F26%2F05%2F23%2F055224%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fyro.slashdot.org%2Fstory%2F26%2F05%2F23%2F055224%2Ftech-ceos-call-for-a-universal-basic-income-but-what-are-the-alternatives%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://yro.slashdot.org/story/26/05/23/055224/tech-ceos-call-for-a-universal-basic-income-but-what-are-the-alternatives?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Announcing new builds for 22 May 2026]]></title>
<description><![CDATA[Hello Windows Insiders,
Today, we continue to expand the rollout of the new Windows Insider Program changes to devices in channels already announced. As a reminder, we have not yet begun moving devices in the Canary 29500 Series Channel 
The post Announcing new builds for 22 May 2026 appeared fir...]]></description>
<link>https://tsecurity.de/de/3540368/windows-tipps/announcing-new-builds-for-22-may-2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3540368/windows-tipps/announcing-new-builds-for-22-may-2026/</guid>
<pubDate>Fri, 22 May 2026 19:24:19 +0200</pubDate>
<category>🪟 Windows Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Hello Windows Insiders,</p>
<p>Today, we continue to expand the rollout of the new Windows Insider Program changes to devices in channels already announced. As a reminder, we have not yet begun moving devices in the <strong>Canary 29500 Series Channel 
<p>The post <a href="https://blogs.windows.com/windows-insider/2026/05/22/announcing-new-builds-for-22-may-2026/">Announcing new builds for 22 May 2026</a> appeared first on <a href="https://blogs.windows.com/windows-insider">Windows Insider Blog</a>.</p></strong></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Meta says goodbye to those who won’t use AI]]></title>
<description><![CDATA[Meta is the latest company to trim its workforce as a result of the growing use of AI within the industry. The company laid off 8,000 employees earlier this week, while also moving 7,000 more to AI-focused roles.



“AI is the most consequential technology of our lifetimes,” Zuckerberg said in a ...]]></description>
<link>https://tsecurity.de/de/3540347/it-nachrichten/meta-says-goodbye-to-those-who-wont-use-ai/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3540347/it-nachrichten/meta-says-goodbye-to-those-who-wont-use-ai/</guid>
<pubDate>Fri, 22 May 2026 19:17:28 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Meta is the latest company to trim its workforce as a result of the growing use of AI within the industry. The company laid off 8,000 employees earlier this week, while also moving 7,000 more to AI-focused roles.</p>



<p>“AI is the most consequential technology of our lifetimes,” Zuckerberg said in a memo that he sent to employees, informing them of the cuts.  “The companies that lead the way will define the next generation,” he added.</p>



<p>The company has not revealed too much detail of the changes in the workforce, but it’s clear that jobs focused on AI infrastructure will be protected.</p>



<p>Meta is not alone in announcing cuts. In a blog this month, <a href="https://blogs.cisco.com/news/our-path-forward" target="_blank" rel="noreferrer noopener">Cisco said it was cutting 4,000 jobs</a> and <a href="https://www.computerworld.com/article/4163188/microsoft-to-offer-voluntary-retirement-buyouts-to-about-7-of-the-us-workforce.html">Microsoft is looking at inciting employees to take voluntary retirement </a>for the first time.</p>



<p>The Meta reorganization is following the trend that businesses that don’t adapt to AI usage will struggle. Earlier this year, <a href="https://www.computerworld.com/article/4148219/pwc-us-tells-staff-to-opt-out-of-company-not-ai.html">PwC US CEO Paul Griggs caused consternation</a> when he suggested that executives who failed to get to grips with AI had a limited future in the company.</p>



<p>While workforces are increasingly dependent on AI as a path to progress, IT departments are not necessarily on top of the game. A Dataiku survey earlier this year revealed that <a href="https://www.cio.com/article/4172555/how-it-teams-are-putting-ai-agents-to-work.html#:~:text=74%25%20of%20CIOs%20say%20their%20role%20will%20be%20at%20risk%20if%20their%20company%20does%20not%20deliver%20measurable%20business%20gains%20from%20AI%20within%20the%20next%20two%20years.">74% of CIOs were fearful that their career paths were dependent on AI</a> outcomes.</p>



<p></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[We’re announcing the first Texas Energy Impact Fund recipients.]]></title>
<description><![CDATA[The Texas Energy Impact Fund announced its first grant recipients from its $30 million commitment to energy efficiency in the Lone Star State.]]></description>
<link>https://tsecurity.de/de/3537021/it-nachrichten/were-announcing-the-first-texas-energy-impact-fund-recipients/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3537021/it-nachrichten/were-announcing-the-first-texas-energy-impact-fund-recipients/</guid>
<pubDate>Thu, 21 May 2026 18:02:39 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<img src="https://storage.googleapis.com/gweb-uniblog-publish-prod/images/_TGP8761.max-600x600.format-webp.webp">The Texas Energy Impact Fund announced its first grant recipients from its $30 million commitment to energy efficiency in the Lone Star State.]]></content:encoded>
</item>
<item>
<title><![CDATA[Microsoft pushed 16GB RAM as must-have for Windows 11 for years, now sells an 8GB Surface Laptop for $1,299]]></title>
<description><![CDATA[Microsoft spent months declaring that 16GB of RAM is the absolute minimum requirement for its next-generation Copilot+ PCs. However, the company just completely contradicted its own AI strategy by announcing a $1,300 Surface Laptop for Business that will ship with a measly 8GB of memory.
The post...]]></description>
<link>https://tsecurity.de/de/3536997/windows-tipps/microsoft-pushed-16gb-ram-as-must-have-for-windows-11-for-years-now-sells-an-8gb-surface-laptop-for-1299/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3536997/windows-tipps/microsoft-pushed-16gb-ram-as-must-have-for-windows-11-for-years-now-sells-an-8gb-surface-laptop-for-1299/</guid>
<pubDate>Thu, 21 May 2026 17:41:14 +0200</pubDate>
<category>🪟 Windows Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Microsoft spent months declaring that 16GB of RAM is the absolute minimum requirement for its next-generation Copilot+ PCs. However, the company just completely contradicted its own AI strategy by announcing a $1,300 Surface Laptop for Business that will ship with a measly 8GB of memory.</p>
<p>The post <a rel="nofollow" href="https://www.windowslatest.com/2026/05/21/microsoft-pushed-16gb-ram-as-must-have-for-windows-11-for-years-now-sells-an-8gb-surface-laptop-for-1299/">Microsoft pushed 16GB RAM as must-have for Windows 11 for years, now sells an 8GB Surface Laptop for $1,299</a> appeared first on <a rel="nofollow" href="https://www.windowslatest.com/">Windows Latest</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[This Week In Rust: This Week in Rust 652]]></title>
<description><![CDATA[Hello and welcome to another issue of This Week in Rust!
Rust is a programming language empowering everyone to build reliable and efficient software.
This is a weekly summary of its progress and community.
Want something mentioned? Tag us at
@thisweekinrust.bsky.social on Bluesky or
@ThisWeekinRu...]]></description>
<link>https://tsecurity.de/de/3535118/tools/this-week-in-rust-this-week-in-rust-652/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3535118/tools/this-week-in-rust-this-week-in-rust-652/</guid>
<pubDate>Thu, 21 May 2026 07:08:37 +0200</pubDate>
<category>💾  Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Hello and welcome to another issue of <em>This Week in Rust</em>!
<a href="https://www.rust-lang.org/">Rust</a> is a programming language empowering everyone to build reliable and efficient software.
This is a weekly summary of its progress and community.
Want something mentioned? Tag us at
<a href="https://bsky.app/profile/thisweekinrust.bsky.social">@thisweekinrust.bsky.social</a> on Bluesky or
<a href="https://mastodon.social/@thisweekinrust">@ThisWeekinRust</a> on mastodon.social, or
<a href="https://github.com/rust-lang/this-week-in-rust">send us a pull request</a>.
Want to get involved? <a href="https://github.com/rust-lang/rust/blob/main/CONTRIBUTING.md">We love contributions</a>.</p>
<p><em>This Week in Rust</em> is openly developed <a href="https://github.com/rust-lang/this-week-in-rust">on GitHub</a> and archives can be viewed at <a href="https://this-week-in-rust.org/">this-week-in-rust.org</a>.
If you find any errors in this week's issue, <a href="https://github.com/rust-lang/this-week-in-rust/pulls">please submit a PR</a>.</p>
<p>Want TWIR in your inbox? <a href="https://this-week-in-rust.us11.list-manage.com/subscribe?u=fd84c1c757e02889a9b08d289&amp;id=0ed8b72485">Subscribe here</a>.</p>
<h4><a class="toclink" href="https://this-week-in-rust.org/atom.xml#updates-from-rust-community">Updates from Rust Community</a></h4>


<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#official">Official</a></h5>
<ul>
<li><a href="https://blog.rust-lang.org/2026/05/18/project-goals-2026-04/">Project goals update — April 2026 (end of 2025H2)</a></li>
<li><a href="https://blog.rust-lang.org/inside-rust/2026/05/13/program-management-update--april-2026/">Program management update — April 2026</a></li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#newsletters">Newsletters</a></h5>
<ul>
<li><a href="https://rust-osdev.com/this-month/2026-04/">This Month in Rust OSDev: April 2026</a></li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#projecttooling-updates">Project/Tooling Updates</a></h5>
<ul>
<li><a href="https://luciofranco.com/blog/tonic-joins-grpc/">Tonic is joining the gRPC project</a></li>
<li><a href="https://tokio.rs/blog/2026-05-15-announcing-toasty-0-6-0">Toasty 0.6.0 - What is new?</a></li>
<li><a href="https://hexdocs.pm/ex_ratatui">ex_ratatui: Elixir bindings for ratatui via Rustler NIFs</a></li>
<li><a href="https://medium.com/@jinhopers/in-depth-llvm-ir-how-omniscope-tracks-ownership-across-languages-2919e418ca61">OmniScope: A Cross-Language LLVM IR Static Analyzer Targeting Unsafe/FFI Boundaries</a>: </li>
<li><a href="https://citum.org/">citum: a new Rust citation processor and associated tools.</a></li>
<li><a href="https://minikin.me/blog/cargo-crap">cargo-crap: Finding Untested Complexity in AI-Generated Rust Code</a></li>
<li><a href="https://aimdb.dev/blog/graph-owes">What the Graph Owes: Connectors That Drive Outputs</a></li>
<li><a href="https://beeb.li/blog/introducing-swpui">swpui: a TUI for case-aware search and replace</a></li>
<li><a href="https://kunobi.ninja/blog/kache-update">kache 0.3.0: zero-copy efficient worktree compilation</a></li>
<li><a href="https://catcoding.me/ghr/">ghr: a Rust TUI for managing GitHub pull requests, issues, notifications, and reviews</a></li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#observationsthoughts">Observations/Thoughts</a></h5>
<ul>
<li><a href="https://kerkour.com/rust-organize-large-projects-code-error-handling">Scaling Rust codebases: Lessons learned organizing large projects and managing errors</a></li>
<li><a href="https://corrode.dev/learn/migration-guides/go-to-rust/">Migrating from Go to Rust</a></li>
<li><a href="https://blog.gokuls.in/posts/why-i-built-wrkflw.html">Why I built wrkflw</a></li>
<li>[video] <a href="https://www.youtube.com/watch?v=VIsKIzFz_zA">Rust's God Mode</a></li>
<li>[video] <a href="https://www.youtube.com/watch?v=FUg1y-yv6cs">How Rust engineered the perfect async runtime</a></li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#rust-walkthroughs">Rust Walkthroughs</a></h5>
<ul>
<li><a href="https://apas.tel/blog/optimizing-image-rs-blur">5× faster fast_blur in image-rs</a></li>
<li><a href="https://thejpster.org.uk/blog/blog-2026-05-17/">Finding the Time Part 2 - Rust Async and the Arm Generic Timer</a></li>
<li><a href="https://assethoard.com/blog/parsing-godot-tres-files">Parsing Godot .tres files and walking the resource graph</a></li>
<li><a href="https://jonahnestrick.com/blog/rust-gba-tutorial-1/">Rust x GBA: Setup and Pixels</a></li>
<li><a href="https://blog.sheerluck.dev/posts/learn-rust-lifetimes-by-building-a-lru-cache/">Learn Rust Lifetimes by Building a Generic LRU Cache</a></li>
<li><a href="https://bencher.dev/learn/benchmarking/rust/gungraun/">How to benchmark Rust code with Gungraun</a></li>
<li><a href="https://root-11.github.io/intro-book/">Book: An Introduction to Programming, using ECS &amp; EBP in Rust</a></li>
</ul>
<h4><a class="toclink" href="https://this-week-in-rust.org/atom.xml#crate-of-the-week">Crate of the Week</a></h4>
<p>This week's crate is <a href="https://github.com/minikin/cargo-crap">cargo-crap</a>, a cargo subcommand to calculate the Change Risk Anti-Patterns metric for a crate.</p>
<p>Despite a lamentable lack of suggestions, llogiq is pleased with his choice.</p>
<p><a href="https://users.rust-lang.org/t/crate-of-the-week/2704">Please submit your suggestions and votes for next week</a>!</p>
<h4><a class="toclink" href="https://this-week-in-rust.org/atom.xml#calls-for-testing">Calls for Testing</a></h4>
<p>An important step for RFC implementation is for people to experiment with the
implementation and give feedback, especially before stabilization.</p>
<p>If you are a feature implementer and would like your RFC to appear in this list, add a
<code>call-for-testing</code> label to your RFC along with a comment providing testing instructions and/or
guidance on which aspect(s) of the feature need testing.</p>
<p><em>No calls for testing were issued this week by
<a href="https://github.com/rust-lang/rust/issues?q=state%3Aopen%20label%3Acall-for-testing%20state%3Aopen">Rust</a>,
<a href="https://github.com/rust-lang/cargo/issues?q=state%3Aopen%20label%3Acall-for-testing%20state%3Aopen">Cargo</a>,
<a href="https://github.com/rust-lang/rustup/issues?q=state%3Aopen%20label%3Acall-for-testing%20state%3Aopen">Rustup</a> or
<a href="https://github.com/rust-lang/rfcs/issues?q=label%3Acall-for-testing%20state%3Aopen">Rust language RFCs</a>.</em></p>
<p><a href="https://github.com/rust-lang/this-week-in-rust/issues">Let us know</a> if you would like your feature to be tracked as a part of this list.</p>
<h4><a class="toclink" href="https://this-week-in-rust.org/atom.xml#call-for-participation-projects-and-speakers">Call for Participation; projects and speakers</a></h4>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#cfp-projects">CFP - Projects</a></h5>
<p>Always wanted to contribute to open-source projects but did not know where to start?
Every week we highlight some tasks from the Rust community for you to pick and get started!</p>
<p>Some of these tasks may also have mentors available, visit the task page for more information.</p>




<p>If you are a Rust project owner and are looking for contributors, please submit tasks <a href="https://github.com/rust-lang/this-week-in-rust?tab=readme-ov-file#call-for-participation-guidelines">here</a> or through a <a href="https://github.com/rust-lang/this-week-in-rust">PR to TWiR</a> or by reaching out on <a href="https://bsky.app/profile/thisweekinrust.bsky.social">Bluesky</a> or <a href="https://mastodon.social/@thisweekinrust">Mastodon</a>!</p>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#cfp-events">CFP - Events</a></h5>
<p>Are you a new or experienced speaker looking for a place to share something cool? This section highlights events that are being planned and are accepting submissions to join their event as a speaker.</p>



<ul>
<li><a href="https://scientificcomputing.rs/2026/submit-talk"><strong>Scientific Computing in Rust 2026</strong></a>| 2026-06-05 | Virtual | 2026-07-08 - 2026-07-10</li>
</ul>
<p>If you are an event organizer hoping to expand the reach of your event, please submit a link to the website through a <a href="https://github.com/rust-lang/this-week-in-rust">PR to TWiR</a> or by reaching out on <a href="https://bsky.app/profile/thisweekinrust.bsky.social">Bluesky</a> or <a href="https://mastodon.social/@thisweekinrust">Mastodon</a>!</p>
<h4><a class="toclink" href="https://this-week-in-rust.org/atom.xml#updates-from-the-rust-project">Updates from the Rust Project</a></h4>
<p>369 pull requests were <a href="https://github.com/search?q=is%3Apr+org%3Arust-lang+is%3Amerged+merged%3A2026-05-12..2026-05-19">merged in the last week</a></p>
<h6><a class="toclink" href="https://this-week-in-rust.org/atom.xml#compiler">Compiler</a></h6>
<ul>
<li><a href="https://github.com/rust-lang/rust/pull/155815">add Swift function call ABI</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/156452">implement pinned drop sugar</a></li>
</ul>
<h6><a class="toclink" href="https://this-week-in-rust.org/atom.xml#library">Library</a></h6>
<ul>
<li><a href="https://github.com/rust-lang/rust/pull/155360"><code>map_try_insert</code> changes</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/156444">implement <code>OsStr::split_at</code></a></li>
<li><a href="https://github.com/rust-lang/rust/pull/156234">implement <code>into_array</code> for <code>Vec&lt;T&gt;</code></a></li>
<li><a href="https://github.com/rust-lang/rust/pull/156428">move <code>std::io::Cursor</code> to <code>core::io</code></a></li>
<li><a href="https://github.com/rust-lang/rust/pull/156431">move <code>std::io::util</code> to <code>core::io</code></a></li>
<li><a href="https://github.com/rust-lang/rust/pull/156644">widen the result of <code>widening_mul</code></a></li>
</ul>
<h6><a class="toclink" href="https://this-week-in-rust.org/atom.xml#cargo">Cargo</a></h6>
<ul>
<li><a href="https://github.com/rust-lang/cargo/pull/16988"><code>clean</code>: respect <code>build.target</code> config for <code>clean -p</code></a></li>
<li><a href="https://github.com/rust-lang/cargo/pull/16989"><code>diag</code>: Consolidate verify/run diagnostics passes</a></li>
<li><a href="https://github.com/rust-lang/cargo/pull/16994"><code>diag</code>: Report deferred diagnostics like other diagnostics</a></li>
<li><a href="https://github.com/rust-lang/cargo/pull/17008"><code>diag</code>: Pull in the parse pass</a></li>
<li><a href="https://github.com/rust-lang/cargo/pull/17007"><code>lints</code>: Avoid compiling where possible</a></li>
<li><a href="https://github.com/rust-lang/cargo/pull/17002">drop <code>-Zunstable-options</code> for <code>rustdoc --emit</code></a></li>
</ul>
<h6><a class="toclink" href="https://this-week-in-rust.org/atom.xml#rustdoc">Rustdoc</a></h6>
<ul>
<li><a href="https://github.com/rust-lang/rust/pull/146220">stabilize <code>--emit</code> flag</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/156587">correctly handle associated items in rustdoc macro expansion</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/156413">correctness &amp; perf improvements to link-to-definition</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/152449">properly support macros with multiple kinds</a></li>
</ul>
<h6><a class="toclink" href="https://this-week-in-rust.org/atom.xml#clippy">Clippy</a></h6>
<ul>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/16922">fix <code>duration_suboptimal_units</code> for small literals</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17011">fix arithmetic side effects false positive</a></li>
</ul>
<h6><a class="toclink" href="https://this-week-in-rust.org/atom.xml#rust-analyzer">Rust-Analyzer</a></h6>
<ul>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22347">add diagnostic for E0029</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22380">add diagnostic for E0614</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22355">add diagnostic for E0638</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22378">add handler for E0040</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22329">encode the name instead of index in <code>EnumVariantId</code></a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22354">fix assist <code>qualify_path</code> loses path segment</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22335">add param on result methods for <code>replace_method_eager_lazy</code></a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22399">complete <code>ref_match</code> in macro</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22368">fully support pattern types</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22344">handle usages in macro for <code>extract_function</code></a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22386">no complete module colons before exists colons</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22363">no lint unsized adt <code>self_ty</code> missing bounded assoc</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22376">not complete same name inherent deref methods</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22367">only ref match non-unknown value items</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22357">show Run lens for fn main in bench targets</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22384">handle <code>TyKind::{Pat,UnsafeBinder}</code> in <code>has_drop_glue</code></a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22082">implement <code>pattern_type</code> macro</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22372">method-resolution: emit error for method calls with illegal Sized bound</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22352">migrate <code>inline_call</code> assist to SyntaxFactory</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22191">perf: provide access to <code>RootDatabase</code>'s <code>LineIndex</code> for the proc macro protocol</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22358">show <code>const</code> in the signature help if applicable</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22381">show <code>unsafe</code> in the signature help if applicable</a></li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#rust-compiler-performance-triage">Rust Compiler Performance Triage</a></h5>
<p>Fewer than usual PRs merged, mostly due to a shorter week than normal and some
CI trouble. Overall a slightly positive week for performance.</p>
<p>Triage done by <strong>@simulacrum</strong>.
Revision range: <a href="https://perf.rust-lang.org/?start=29b7590130c83542a095cdf1323ed0f78eec2bb8&amp;end=281c97c3240a9abd984ca0c6a2cd7389115e80d5&amp;absolute=false&amp;stat=instructions%3Au">29b75901..281c97c3</a></p>
<p>0 Regressions, 0 Improvements, 4 Mixed; 1 of them in rollups
17 artifact comparisons made in total</p>
<p><a href="https://github.com/rust-lang/rustc-perf/blob/master/triage/2026/2026-05-17.md">Full report here</a></p>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#approved-rfcs"></a><a href="https://github.com/rust-lang/rfcs/commits/master">Approved RFCs</a></h5>
<p>Changes to Rust follow the Rust <a href="https://github.com/rust-lang/rfcs#rust-rfcs">RFC (request for comments) process</a>. These
are the RFCs that were approved for implementation this week:</p>
<ul>
<li><a href="https://github.com/rust-lang/rfcs/pull/3923">Cargo RFC for min publish age</a></li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#final-comment-period">Final Comment Period</a></h5>
<p>Every week, <a href="https://www.rust-lang.org/team.html">the team</a> announces the 'final comment period' for RFCs and key PRs
which are reaching a decision. Express your opinions now.</p>
<h6><a class="toclink" href="https://this-week-in-rust.org/atom.xml#tracking-issues-prs">Tracking Issues &amp; PRs</a></h6>
<a class="toclink" href="https://this-week-in-rust.org/atom.xml#compiler-team-mcps-only"></a><a href="https://github.com/rust-lang/compiler-team/issues?q=label%3Amajor-change%20label%3Afinal-comment-period%20state%3Aopen">Compiler Team</a> <a href="https://forge.rust-lang.org/compiler/mcp.html">(MCPs only)</a>
<ul>
<li><a href="https://github.com/rust-lang/compiler-team/issues/990">Removing the unstable ptx linker flavor</a></li>
<li><a href="https://github.com/rust-lang/compiler-team/issues/988">Create a new Tier 3 target: <code>powerpc64le-unknown-none</code></a></li>
<li><a href="https://github.com/rust-lang/compiler-team/issues/922">Optimize <code>repr(Rust)</code> enums by omitting tags in more cases involving uninhabited variants.</a></li>
<li><a href="https://github.com/rust-lang/compiler-team/issues/906">Proposal for a dedicated test suite for the parallel frontend</a></li>
<li><a href="https://github.com/rust-lang/compiler-team/issues/864">Promote tier 3 riscv32 ESP-IDF targets to tier 2</a></li>
<li><a href="https://github.com/rust-lang/compiler-team/issues/841">Proposal for Adapt Stack Protector for Rust</a></li>
</ul>
<p><em>No Items entered Final Comment Period this week for
<a href="https://github.com/rust-lang/rust/issues?q=is%3Aopen%20label%3Afinal-comment-period%20sort%3Aupdated-desc%20state%3Aopen">Rust</a>,
<a href="https://github.com/rust-lang/rfcs/issues?q=state%3Aopen%20label%3Afinal-comment-period%20state%3Aopen">Rust RFCs</a>,
<a href="https://github.com/rust-lang/cargo/issues?q=is%3Aopen%20label%3Afinal-comment-period%20sort%3Aupdated-desc%20state%3Aopen">Cargo</a>,
<a href="https://github.com/rust-lang/lang-team/issues?q=is%3Aopen%20label%3Afinal-comment-period%20sort%3Aupdated-desc%20state%3Aopen">Language Team</a>,
<a href="https://github.com/rust-lang/reference/issues?q=is%3Aopen%20label%3Afinal-comment-period%20sort%3Aupdated-desc%20state%3Aopen">Language Reference</a>,
<a href="https://github.com/rust-lang/leadership-council/issues?q=state%3Aopen%20label%3Afinal-comment-period%20state%3Aopen">Leadership Council</a> or
<a href="https://github.com/rust-lang/unsafe-code-guidelines/issues?q=is%3Aopen%20label%3Afinal-comment-period%20sort%3Aupdated-desc%20state%3Aopen">Unsafe Code Guidelines</a>.</em></p>
<p>Let us know if you would like your PRs, Tracking Issues or RFCs to be tracked as a part of this list.</p>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#new-and-updated-rfcs"></a><a href="https://github.com/rust-lang/rfcs/pulls">New and Updated RFCs</a></h5>
<ul>
<li><a href="https://github.com/rust-lang/rfcs/pull/3962">Documentation interpolation</a></li>
</ul>
<h4><a class="toclink" href="https://this-week-in-rust.org/atom.xml#upcoming-events">Upcoming Events</a></h4>
<p>Rusty Events between 2026-05-20 - 2026-06-17 🦀</p>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#virtual">Virtual</a></h5>
<ul>
<li>2026-05-20 | Hybrid (Vancouver, BC, CA) | <a href="https://www.meetup.com/vancouver-rust">Vancouver Rust</a><ul>
<li><a href="https://www.meetup.com/vancouver-rust/events/313572925/"><strong>Mouse Control with Rust</strong></a></li>
</ul>
</li>
<li>2026-05-20 | Virtual (Girona, ES) | <a href="https://lu.ma/rust-girona">Rust Girona</a><ul>
<li><a href="https://luma.com/548kbqhl"><strong>Weekly coding session</strong></a></li>
</ul>
</li>
<li>2026-05-21 | Hybrid (Seattle, WA, US) | <a href="https://www.meetup.com/join-srug">Seattle Rust User Group</a><ul>
<li><a href="https://www.meetup.com/seattle-rust-user-group/events/313873203/"><strong>May, 2026 SRUG (Seattle Rust User Group) Meetup</strong></a></li>
</ul>
</li>
<li>2026-05-21 | Virtual (Berlin, DE) | <a href="https://www.meetup.com/rust-berlin">Rust Berlin</a><ul>
<li><a href="https://www.meetup.com/rust-berlin/events/308455929/"><strong>Rust Hack and Learn</strong></a></li>
</ul>
</li>
<li>2026-05-21 | Virtual (Charlottesville, VA, US) | <a href="https://www.meetup.com/charlottesville-rust-meetup">Charlottesville Rust Meetup</a><ul>
<li><a href="https://www.meetup.com/charlottesville-rust-meetup/events/314477948/"><strong>Tock OS Part #4 - Capsule coding in QEMU!</strong></a></li>
</ul>
</li>
<li>2026-05-26 | Virtual (Cardiff, GB) | <a href="https://www.meetup.com/rust-and-c-plus-plus-in-cardiff/events/">Rust and C++ Cardiff</a><ul>
<li><a href="https://www.meetup.com/rust-and-c-plus-plus-in-cardiff/events/314820642/"><strong>Hybrid event with Rust Dortmund!</strong></a></li>
</ul>
</li>
<li>2026-05-26 | Virtual (Dallas, TX, US) | <a href="https://www.meetup.com/dallasrust">Dallas Rust User Meetup</a><ul>
<li><a href="https://www.meetup.com/dallasrust/events/310254781/"><strong>Fourth Tuesday</strong></a></li>
</ul>
</li>
<li>2026-05-26 | Virtual (London, UK) | <a href="https://www.meetup.com/women-in-rust">Women in Rust</a><ul>
<li><a href="https://www.meetup.com/women-in-rust/events/313506048/"><strong>Lunch &amp; Learn: Seeing Into Your Code - A Practical Guide to Tracing in Rust</strong></a></li>
</ul>
</li>
<li>2026-05-27 | Virtual (Girona, ES) | <a href="https://lu.ma/rust-girona">Rust Girona</a><ul>
<li><a href="https://luma.com/9v7hv2g1"><strong>Weekly coding session</strong></a></li>
</ul>
</li>
<li>2026-06-02 | Virtual | <a href="https://luma.com/libp2p">libp2p Events</a><ul>
<li><a href="https://luma.com/ukfh0mcf"><strong>rust-libp2p Open Maintainers Call</strong></a></li>
</ul>
</li>
<li>2026-06-03 | Virtual (Indianapolis, IN, US) | <a href="https://www.meetup.com/indyrs">Indy Rust</a><ul>
<li><a href="https://www.meetup.com/indyrs/events/314691782/"><strong>Indy.rs - with Social Distancing</strong></a></li>
</ul>
</li>
<li>2026-06-04 | Virtual (Berlin, DE) | <a href="https://www.meetup.com/rust-berlin/events/">Rust Berlin</a><ul>
<li><a href="https://www.meetup.com/rust-berlin/events/308455930/"><strong>Rust Hack and Learn</strong></a></li>
</ul>
</li>
<li>2026-06-04 | Virtual (Nürnberg, DE) | <a href="https://www.meetup.com/rust-noris/events/">Rust Nuremberg</a><ul>
<li><a href="https://www.meetup.com/rust-noris/events/313345241/"><strong>Rust Nürnberg online</strong></a></li>
</ul>
</li>
<li>2026-06-07 | Virtual (Dallas, TX, US) | <a href="https://www.meetup.com/dallasrust/events/">Dallas Rust User Meetup</a><ul>
<li><a href="https://www.meetup.com/dallasrust/events/314095285/"><strong>Rust Deep Learning: First Sunday</strong></a></li>
</ul>
</li>
<li>2026-06-09 | Virtual (Dallas, TX, US) | <a href="https://www.meetup.com/dallasrust/events/">Dallas Rust User Meetup</a><ul>
<li><a href="https://www.meetup.com/dallasrust/events/310254780/"><strong>Second Tuesday</strong></a></li>
</ul>
</li>
<li>2026-06-10 | Virtual (Girona, ES) | <a href="https://lu.ma/rust-girona">Rust Girona</a><ul>
<li><a href="https://luma.com/3bcnx1jb"><strong>Weekly coding session</strong></a></li>
</ul>
</li>
<li>2026-06-16 | Virtual (Washington, DC, US) | <a href="https://www.meetup.com/rustdc/events/">Rust DC</a><ul>
<li><a href="https://www.meetup.com/rustdc/events/rdhhptyjcjbvb/"><strong>Mid-month Rustful</strong></a></li>
</ul>
</li>
<li>2026-06-02 | Virtual | <a href="https://luma.com/libp2p">libp2p Events</a><ul>
<li><a href="https://luma.com/pegz5x4h"><strong>rust-libp2p Open Maintainers Call</strong></a></li>
</ul>
</li>
<li>2026-06-17 | Virtual (Girona, ES) | <a href="https://lu.ma/rust-girona">Rust Girona</a><ul>
<li><a href="https://luma.com/ekws5nr4"><strong>Weekly coding session</strong></a></li>
</ul>
</li>
<li>2026-06-17 | Virtual (Vancouver, BC, CA) | <a href="https://www.meetup.com/vancouver-rust/events/">Vancouver Rust</a><ul>
<li><a href="https://www.meetup.com/vancouver-rust/events/314000478/"><strong>Rust Study/Hack/Hang-out</strong></a></li>
</ul>
</li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#asia">Asia</a></h5>
<ul>
<li>2026-06-02 | Beijing, CN | <a href="https://www.meetup.com/wasm-rust-meetup/events/">Voice AI and Rust Meetup (Rust for AI, lowcoderust.com)</a><ul>
<li><a href="https://www.meetup.com/wasm-rust-meetup/events/314750465/"><strong>AI Agents and Open Source LLM (Call for Speakers)</strong></a></li>
</ul>
</li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#europe">Europe</a></h5>
<ul>
<li>2026-05-18 - 2026-05-23 | Utrecht, NL | <a href="https://2026.rustweek.org/">RustWeek 2026</a><ul>
<li><a href="https://2026.rustweek.org/"><strong>RustWeek 2026</strong></a></li>
</ul>
</li>
<li>2026-05-21 | Amsterdam, NL | <a href="https://www.meetup.com/rust-amsterdam">RustNL</a><ul>
<li><a href="https://www.meetup.com/rust-nederland/events/314301699/"><strong>RustWeek Hackathon</strong></a></li>
</ul>
</li>
<li>2026-05-22 | Amsterdam, NL | <a href="https://www.meetup.com/rust-amsterdam/events/">RustNL</a><ul>
<li><a href="https://www.meetup.com/rust-nederland/events/314770275/"><strong>Walking Tour around Utrecht</strong></a></li>
</ul>
</li>
<li>2026-05-22 | Amsterdam, NL | <a href="https://www.meetup.com/rust-amsterdam">RustNL</a><ul>
<li><a href="https://www.meetup.com/rust-nederland/events/314523659/"><strong>Bike tour around Utrecht</strong></a></li>
</ul>
</li>
<li>2026-05-26 | Dortmund, DE | <a href="https://www.meetup.com/rust-dortmund">Rust Dortmund</a><ul>
<li><a href="https://www.meetup.com/rust-dortmund/events/314522781/"><strong>Rust Dortmund Meetup - Agentic Programming - May</strong></a></li>
</ul>
</li>
<li>2026-05-26 | Manchester, UK | <a href="https://www.meetup.com/rust-manchester">Rust Manchester</a><ul>
<li><a href="https://www.meetup.com/rust-manchester/events/314452972/"><strong>Rust Manchester May Code Night</strong></a></li>
</ul>
</li>
<li>2026-05-26 | Trondheim, NO | <a href="https://www.meetup.com/rust-trondheim/events/">Rust Trondheim</a><ul>
<li><a href="https://www.meetup.com/rust-trondheim/events/314711434/"><strong>Motorized blinds, and replacing Docker, in Rust!</strong></a></li>
</ul>
</li>
<li>2026-05-28 | London, UK | <a href="https://www.meetup.com/rust-london-user-group/events/">Rust London User Group</a><ul>
<li><a href="https://www.meetup.com/rust-london-user-group/events/314846861/"><strong>LDN Talks May Community Showcase</strong></a></li>
</ul>
</li>
<li>2026-05-29 | Berlin, DE | <a href="https://www.meetup.com/rust-berlin">Rust Berlin</a><ul>
<li><a href="https://www.meetup.com/rust-berlin/events/314396588/"><strong>Rust Berlin Talks: The next generation</strong></a></li>
</ul>
</li>
<li>2026-06-03 | Dublin, IE | <a href="https://www.meetup.com/rust-dublin/events/">Rust Dublin</a><ul>
<li><a href="https://www.meetup.com/rust-dublin/events/314689875/"><strong>Join us live and INPERSON for Rust 261</strong></a></li>
</ul>
</li>
<li>2026-06-03 | Girona, ES | <a href="https://lu.ma/rust-girona">Rust Girona</a><ul>
<li><a href="https://luma.com/4bmlc7qd"><strong>Rust Girona Hack &amp; Learn 06 2026</strong></a></li>
</ul>
</li>
<li>2026-06-11 | Switzerland, CH | <a href="https://www.posttenebraslab.ch/wiki/events/start">PostTenebrasLab</a><ul>
<li><a href="https://www.posttenebraslab.ch/wiki/events/monthly_meeting/rust_meetup"><strong>Rust Meetup Geneva</strong></a></li>
</ul>
</li>
<li>2026-06-16 | Leipzig, SN, DE | <a href="https://www.meetup.com/rust-modern-systems-programming-in-leipzig/events/">Rust - Modern Systems Programming in Leipzig</a><ul>
<li><a href="https://www.meetup.com/rust-modern-systems-programming-in-leipzig/events/313813937/"><strong>Interactive: Everything is Open Source</strong></a></li>
</ul>
</li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#north-america">North America</a></h5>
<ul>
<li>2026-05-20 | Hybrid (Vancouver, BC, CA) | <a href="https://www.meetup.com/vancouver-rust">Vancouver Rust</a><ul>
<li><a href="https://www.meetup.com/vancouver-rust/events/313572925/"><strong>Mouse Control with Rust</strong></a></li>
</ul>
</li>
<li>2026-05-20 | San Francisco, CA, US | <a href="https://luma.com/bayarearust">Bay Area Rust Meetup</a><ul>
<li><a href="https://luma.com/9j3q5ejl"><strong>Bay Area Rust Meetup</strong></a></li>
</ul>
</li>
<li>2026-05-21 | Hybrid (Seattle, WA, US) | <a href="https://www.meetup.com/join-srug">Seattle Rust User Group</a><ul>
<li><a href="https://www.meetup.com/seattle-rust-user-group/events/313873203/"><strong>May, 2026 SRUG (Seattle Rust User Group) Meetup</strong></a></li>
</ul>
</li>
<li>2026-05-21 | New York, NY, US | <a href="https://www.meetup.com/rust-nyc/events/">Rust NYC</a><ul>
<li><a href="https://www.meetup.com/rust-nyc/events/314783868/"><strong>Rust NYC: "Boring File Storage" &amp; "Indie News Feed Optimization"</strong></a></li>
</ul>
</li>
<li>2026-05-21 | Nashville, TN, US | <a href="https://www.meetup.com/music-city-rust-developers">Music City Rust Developers</a><ul>
<li><a href="https://www.meetup.com/music-city-rust-developers/events/314359076/"><strong>Community Meetup</strong></a></li>
</ul>
</li>
<li>2026-05-23 | Boston, MA, US | <a href="https://www.meetup.com/bostonrust">Boston Rust Meetup</a><ul>
<li><a href="https://www.meetup.com/bostonrust/events/314480534/"><strong>Allston Rust Lunch, May 23</strong></a></li>
</ul>
</li>
<li>2026-05-27 | Austin, TX, US | <a href="https://www.meetup.com/rust-atx">Rust ATX</a><ul>
<li><a href="https://www.meetup.com/rust-atx/events/314209662/"><strong>Rust Lunch - Fareground</strong></a></li>
</ul>
</li>
<li>2026-05-28 | Atlanta, GA, US | <a href="https://www.meetup.com/rust-atl">Rust Atlanta</a><ul>
<li><a href="https://www.meetup.com/rust-atl/events/313539319/"><strong>Rust-Atl</strong></a></li>
</ul>
</li>
<li>2026-05-28 | Los Angeles, CA, US | <a href="https://www.meetup.com/rust-los-angeles">Rust Los Angeles</a><ul>
<li><a href="https://www.meetup.com/rust-los-angeles/events/314218564/"><strong>Rust LA: Rust in Embedded &amp; Autonomous Systems at Parallel Systems in DTLA</strong></a></li>
</ul>
</li>
<li>2026-05-28 | Mountain View, CA, US | <a href="https://www.meetup.com/hackerdojo/events/">Hacker Dojo</a><ul>
<li><a href="https://www.meetup.com/hackerdojo/events/314716463/"><strong>RUST MEETUP at HACKER DOJO</strong></a></li>
</ul>
</li>
<li>2026-05-30 | Boston, MA, US | <a href="https://www.meetup.com/bostonrust">Boston Rust Meetup</a><ul>
<li><a href="https://www.meetup.com/bostonrust/events/314480537/"><strong>Central Cambridge Rust Lunch, May 30</strong></a></li>
</ul>
</li>
<li>2026-06-04 | Saint Louis, MO, US | <a href="https://www.meetup.com/stl-rust/events/">STL Rust</a><ul>
<li><a href="https://www.meetup.com/stl-rust/events/314106244/"><strong>Testing, Coverage, Tracey &amp; Mutations</strong></a></li>
</ul>
</li>
<li>2026-06-06 | Boston, MA, US | <a href="https://www.meetup.com/bostonrust/events/">Boston Rust Meetup</a><ul>
<li><a href="https://www.meetup.com/bostonrust/events/314480539/"><strong>Boston Common Rust Lunch, June 6</strong></a></li>
</ul>
</li>
<li>2026-06-11 | Lehi, UT, US | <a href="https://www.meetup.com/utah-rust/events/">Utah Rust</a><ul>
<li><a href="https://www.meetup.com/utah-rust/events/314696643/"><strong>Utah Rust June Meetup</strong></a></li>
</ul>
</li>
<li>2026-06-11 | San Diego, CA, US | <a href="https://www.meetup.com/san-diego-rust/events/">San Diego Rust</a><ul>
<li><a href="https://www.meetup.com/san-diego-rust/events/313721899/"><strong>San Diego Rust June Meetup - Back in person!</strong></a></li>
</ul>
</li>
<li>2026-06-16 | San Francisco, CA, US | <a href="https://www.meetup.com/san-francisco-rust-study-group/events/">San Francisco Rust Study Group</a><ul>
<li><a href="https://www.meetup.com/san-francisco-rust-study-group/events/ghhwqtyjcjbvb/"><strong>Rust Hacking in Person</strong></a></li>
</ul>
</li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#oceania">Oceania</a></h5>
<ul>
<li>2026-05-26 | Barton, ACT, AU | <a href="https://www.meetup.com/rust-canberra">Canberra Rust User Group</a><ul>
<li><a href="https://www.meetup.com/rust-canberra/events/314050576/"><strong>May Meetup</strong></a></li>
</ul>
</li>
</ul>
<p>If you are running a Rust event please add it to the <a href="https://www.google.com/calendar/embed?src=apd9vmbc22egenmtu5l6c5jbfc%40group.calendar.google.com">calendar</a> to get
it mentioned here. Please remember to add a link to the event too.
Email the <a href="mailto:community-team@rust-lang.org">Rust Community Team</a> for access.</p>
<h4><a class="toclink" href="https://this-week-in-rust.org/atom.xml#jobs">Jobs</a></h4>
<p>Please see the latest <a href="https://www.reddit.com/r/rust/comments/1sobu1s/official_rrust_whos_hiring_thread_for_jobseekers/">Who's Hiring thread on r/rust</a></p>
<h3><a class="toclink" href="https://this-week-in-rust.org/atom.xml#quote-of-the-week">Quote of the Week</a></h3>
<blockquote>
<p>Posts like this are useful for those of us who like to help, and who work on rustc to make it more helpful, by letting us learn about what kinds of mistakes people make.</p>
</blockquote>
<p>– <a href="https://users.rust-lang.org/t/slightly-surprising-behavior-of-a-while-loop/140117/5">Kevin Reid on rust-users</a></p>
<p>Thanks to <a href="https://users.rust-lang.org/t/crate-of-the-week/2704/1605">firebits.io</a> for the suggestion!</p>
<p><a href="https://users.rust-lang.org/t/twir-quote-of-the-week/328">Please submit quotes and vote for next week!</a></p>
<p>This Week in Rust is edited by:</p>
<ul>
<li><a href="https://github.com/nellshamrell">nellshamrell</a></li>
<li><a href="https://github.com/llogiq">llogiq</a></li>
<li><a href="https://github.com/ericseppanen">ericseppanen</a></li>
<li><a href="https://github.com/extrawurst">extrawurst</a></li>
<li><a href="https://github.com/U007D">U007D</a></li>
<li><a href="https://github.com/mariannegoldin">mariannegoldin</a></li>
<li><a href="https://github.com/bdillo">bdillo</a></li>
<li><a href="https://github.com/opeolluwa">opeolluwa</a></li>
<li><a href="https://github.com/bnchi">bnchi</a></li>
<li><a href="https://github.com/KannanPalani57">KannanPalani57</a></li>
<li><a href="https://github.com/tzilist">tzilist</a></li>
</ul>
<p><em>Email list hosting is sponsored by <a href="https://foundation.rust-lang.org/">The Rust Foundation</a></em></p>
<p><small><a href="https://www.reddit.com/r/rust/comments/1tj8ja6/this_week_in_rust_652/">Discuss on r/rust</a></small></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Announcing OpenAI-compatible API support for Amazon SageMaker AI endpoints]]></title>
<description><![CDATA[Today, Amazon SageMaker AI introduces OpenAI-compatible API support for real-time inference endpoints. If you use the OpenAI SDK, LangChain, or Strands Agents, you can now invoke models on SageMaker AI by changing only your endpoint URL. You don’t need a custom client, a SigV4 wrapper, or code re...]]></description>
<link>https://tsecurity.de/de/3534696/ai-nachrichten/announcing-openai-compatible-api-support-for-amazon-sagemaker-ai-endpoints/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3534696/ai-nachrichten/announcing-openai-compatible-api-support-for-amazon-sagemaker-ai-endpoints/</guid>
<pubDate>Thu, 21 May 2026 02:03:00 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Today, Amazon SageMaker AI introduces OpenAI-compatible API support for real-time inference endpoints. If you use the OpenAI SDK, LangChain, or Strands Agents, you can now invoke models on SageMaker AI by changing only your endpoint URL. You don’t need a custom client, a SigV4 wrapper, or code rewrites. Overview With this launch, SageMaker AI endpoints […]]]></content:encoded>
</item>
<item>
<title><![CDATA[Cohere cracks lossless quantization and native citations with first full Apache 2.0 licensed open model Command A+]]></title>
<description><![CDATA[Canadian AI lab Cohere made waves recently by announcing a merger with German AI startup Aleph Alpha, but now it has even more in store for enterprise builders around the globe: today, the firm co-founded by former Googler and "Attention Is All You Need" co-author Aidan Gomez unveiled Command A+,...]]></description>
<link>https://tsecurity.de/de/3534565/it-nachrichten/cohere-cracks-lossless-quantization-and-native-citations-with-first-full-apache-20-licensed-open-model-command-a/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3534565/it-nachrichten/cohere-cracks-lossless-quantization-and-native-citations-with-first-full-apache-20-licensed-open-model-command-a/</guid>
<pubDate>Thu, 21 May 2026 00:02:19 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Canadian AI lab <a href="https://cohere.com/">Cohere</a> made waves recently by <a href="https://cohere.com/blog/cohere-alephalpha-join-forces">announcing a merger with German AI startup Aleph Alpha</a>, but now it has even more in store for enterprise builders around the globe: today, the firm <a href="https://venturebeat.com/ai/openai-rival-cohere-ai-has-flown-under-the-radar-that-may-be-about-to-change">co-founded by former Googler and "Attention Is All You Need" co-author Aidan Gomez</a> unveiled <a href="https://cohere.com/blog/command-a-plus">Command A+</a>, a highly optimized, 218-billion-parameter language model engineered specifically for complex reasoning, multimodal document processing, and agentic workflows.</p><p>The most significant aspect of the release is not just the model’s capabilities; it is its accessibility. </p><p>By releasing the model weights free on the <a href="https://huggingface.co/CohereLabs/command-a-plus-05-2026-w4a4">popular AI code sharing repository Hugging Face</a> under a <a href="https://x.com/aidangomez/status/2057142232860258527">highly permissive Apache 2.0 open-source license</a> — a first for the company, according to <a href="https://x.com/aidangomez/status/2057142232860258527?s=20">a post by Gomez, now Cohere's CEO, on X</a> — Cohere is making a calculated bet on "sovereign AI"—the thesis that enterprises, governments, and developers should have the ability to run, control, and adapt frontier-grade AI entirely within their own secure environments, without sacrificing performance.</p><h2><b>Sparse architecture with extreme quantization</b></h2><p>At the architectural level, Command A+ represents a major evolution from Cohere’s previous dense models. It is a decoder-only Sparse Mixture-of-Experts (MoE) Transformer. </p><p>While the model houses a relatively modest 218 billion total parameters, even fewer — only 25 billion — are active during any given generation step. It's a much lighter footprint and requires far less compute resources to run in inference (serving the model in production environments to end users or via agents) than the proprietary U.S. giants like OpenAI's GPT-5.5 and Anthropic's Claude Opus 4.7, which are <a href="https://www.linkedin.com/posts/zainhas_a-viral-ai-paper-last-week-claimed-gpt-55-activity-7456465306660749312-5EmU">estimated by third-party observers to be in the trillions of parameters.</a> </p><p>This sparse architecture is the key to the model’s efficiency. In plain terms, an MoE model routes incoming queries only to the specific "expert" neural networks best suited to handle them, leaving the rest of the model dormant.</p><p>This is a familiar formulation and one followed by most leading LLMs these days, allowing models to retain the vast knowledge base and nuanced reasoning capabilities of a giant, but at the faster speeds and reduced compute and energy requirements of a much smaller model, since only a fraction of parameters are ever activated at any time. </p><p>But where Cohere has taken an extra step beyond most for Command A+ is that it has focused heavily on hardware efficiency through quantization—a process that compresses the model's memory footprint by reducing the <i>precision</i> of its parameters. </p><p>Command A+ is available in 16-bit (BF16), 8-bit (FP8), and a highly compressed 4-bit (W4A4) format.</p><p>The W4A4 quantization is the technical centerpiece of this release. Typically, reasoning models suffer an outsized "quantization tax," where compressing the model leads to visible regressions in complex problem-solving. </p><p><b>Cohere mitigated this by only quantizing the MoE experts to 4-bit, </b>while<b> keeping the critical attention pathways at full precision, </b>supplemented by a technique called Quantization-Aware Distillation.</p><p>The result is a <b>nearly lossless compression </b>that allows this massive model to run on a single NVIDIA Blackwell B200 GPU or just two NVIDIA H100 GPUs.</p><p>The speed gains are equally notable. According to performance data released by the company, the W4A4 quantization at low concurrency achieves 375 tokens per second (TOPS) with a Time-to-First-Token (TTFT) latency of just 113 milliseconds—representing up to a 63% increase in output speed and a 17% reduction in latency compared to the previous Command A Reasoning model.</p><p>Furthermore, Cohere has overhauled the model's tokenizer. Tokenizers break text down into the fragments that AI models process. The new tokenizer is highly optimized for global enterprise use, featuring native support for 48 languages. </p><p>More importantly, it <b>dramatically improves tokenization efficiency for non-European languages,</b> reducing the number of tokens required to generate responses in Arabic by 20%, Japanese by 18%, and Korean by 16%. Because inference costs are calculated per token, this translates directly to lower operational costs for global, multilingual or non-English deployments.</p><h2><b>Agentic workflows and high benchmarks on math, specialized fields</b></h2><p>While raw speed and size dictate deployment, a model’s utility is defined by its product capabilities. Command A+ was built specifically for "agentic" tasks — workflows where the AI operates autonomously or semi-autonomously, uses external tools, queries databases, and synthesizes information across multiple steps.</p><p>The benchmark leaps over the previous generation are stark. </p><p>On 𝜏²-Bench Telecom, which tests complex reasoning, the model jumped from a 37% score to 85%. On Terminal-Bench Hard, which measures agentic coding performance, it climbed from 3% to 25%. In complex mathematics, it scored 90% on AIME 25, up from 57%.</p><p>Command A+ punches above its weight class (25B active parameters) in pure reasoning and mathematics, competing directly with much larger models like DeepSeek V4 Pro on math benchmarks. However, for deep agentic coding and general broad-scale intelligence indexing, it currently trails behind the latest generations from Chinese open source rivals like <a href="https://venturebeat.com/technology/deepseek-v4-arrives-with-near-state-of-the-art-intelligence-at-1-6th-the-cost-of-opus-4-7-gpt-5-5">DeepSeek</a>, <a href="https://venturebeat.com/technology/ai-joins-the-8-hour-work-day-as-glm-ships-5-1-open-source-llm-beating-opus-4">Z.ai (GLM)</a>, and <a href="https://venturebeat.com/technology/new-minimax-m2-7-proprietary-ai-model-is-self-evolving-and-can-perform-30-50">MiniMax</a>.</p><p>That said, comparing them directly ignores Cohere's core value proposition: <b>hardware efficiency</b>.</p><p>Beyond the benchmarks, Command A+ introduces deep integrations for enterprise trust and verification. The model supports conversational tool use via standard chat templates, allowing developers to connect it seamlessly to internal APIs, search engines, or SQL databases.</p><p>Crucially,<b> Command A+ features native citation generation. </b>When Command A+ retrieves information from an external tool, it doesn't just synthesize the answer; it generates explicit "grounding spans." Using special tags embedded in the output, the <b>model directly links every factual claim it makes to the specific source document or database row</b> it pulled the information from. </p><p><b>For enterprises heavily regulated industries like finance, healthcare, or legal, this traceability is the difference between an interesting prototype and a production-ready application.</b> If a user asks for a daily sales report, the model will output the total sales amount and explicitly cite the database query result that provided that number, minimizing the risk of undetected hallucinations.</p><p>Additionally, Command A+ is fully multimodal, capable of processing both text and images natively within its massive 128K input context window, making it highly effective for complex document processing, such as analyzing scanned invoices, charts, or technical manuals.</p><h2><b>The first fully Apache 2.0 licensed Cohere AI model</b></h2><p>In the current AI landscape, "open source" has become a fraught term. Many leading AI companies release their model weights under restrictive commercial licenses or acceptable use policies that explicitly forbid large enterprises from using the models for commercial purposes, or prohibit the models from being used to train competing AI systems.</p><p>Indeed, Cohere's prior models, including<a href="https://venturebeat.com/ai/cohere-releases-powerful-command-r-language-model-for-enterprise-use"> Command R </a>and <a href="https://venturebeat.com/ai/cohere-launches-command-r-a-powerful-llm-optimized-for-enterprise-ai">Command R+</a>, were released under a CC-BY-NC 4.0 (Creative Commons NonCommercial) license. While their model weights were open for researchers and developers to download, tinker with, and evaluate, they were strictly prohibited from being used for commercial purposes without purchasing a separate enterprise license from Cohere or going through its application programming interface (API), similar to the arrangement many enterprises use for accessing AI models from OpenAI, Anthropic, Google and other leading labs.</p><p>Cohere has changed up its approach by releasing Command A+ under the Apache 2.0 license. This is a critical distinction for the developer community. Apache 2.0 is a true, OSI-approved open-source license. It allows anyone—from independent developers to Fortune 500 corporations—to use, modify, distribute, and commercialize the model without paying licensing fees or adhering to restrictive non-compete clauses.</p><p>As <a href="https://x.com/aidangomez/status/2057198038616007097?s=20">Gomez wrote on X</a>, the decision was championed by fellow Cohere co-founder Nick Frosst, who posted a two-minute long overview calling it "the best model we've ever put out."</p><div></div><p>For the enterprise, this license means total vendor independence. A company can download the Command A+ weights, fine-tune them on highly classified internal data, and deploy them on their own private servers or air-gapped networks. They are not tethered to Cohere’s infrastructure, pricing changes, or API uptime. It is the ultimate realization of sovereign AI.</p><p>The release was met with immediate traction across the AI developer ecosystem, driven heavily by its day-one integration with major open-source inference frameworks like Hugging Face and vLLM.</p><h2><b>What's next?</b></h2><p>The release of Command A+ marks a maturing of the open-source AI ecosystem. By combining frontier-level reasoning, robust agentic tool use, and multimodal capabilities with an architecture specifically designed for hardware efficiency, Cohere is changing the calculus for enterprise AI adoption.</p><p>The requirement of massive, centralized compute clusters has long been a bottleneck for companies prioritizing data privacy and cost control. By democratizing access to a model of this caliber under a true open-source license, Cohere has provided the enterprise market with exactly what it has been asking for: the power of the cloud, capable of running securely in the server room down the hall.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[We’re announcing new community investments in Missouri.]]></title>
<description><![CDATA[We’re helping build the state’s next-generation workforce and investing in energy programs.]]></description>
<link>https://tsecurity.de/de/3534272/it-nachrichten/were-announcing-new-community-investments-in-missouri/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3534272/it-nachrichten/were-announcing-new-community-investments-in-missouri/</guid>
<pubDate>Wed, 20 May 2026 21:32:32 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<img src="https://storage.googleapis.com/gweb-uniblog-publish-prod/images/MissouriSocial.max-600x600.format-webp.webp">We’re helping build the state’s next-generation workforce and investing in energy programs.]]></content:encoded>
</item>
<item>
<title><![CDATA[Copilot Chat: Your hub for document creation and analysis]]></title>
<description><![CDATA[Many years ago, Microsoft created a handy hub for its Office suite: type office.com into your browser, and you’d see a web page where you could launch the various Office apps — Word, Excel, PowerPoint, and so on — or access recently used documents in those apps. This hub’s appearance changed a bi...]]></description>
<link>https://tsecurity.de/de/3532710/it-nachrichten/copilot-chat-your-hub-for-document-creation-and-analysis/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3532710/it-nachrichten/copilot-chat-your-hub-for-document-creation-and-analysis/</guid>
<pubDate>Wed, 20 May 2026 13:17:42 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Many years ago, Microsoft created a handy hub for its Office suite: type <a href="https://www.office.com/" target="_blank" rel="noreferrer noopener">office.com</a> into your browser, and you’d see a web page where you could launch the various Office apps — Word, Excel, PowerPoint, and so on — or access recently used documents in those apps. This hub’s appearance changed a bit over time as the Office suite was rebranded as Office 365 and then <a href="https://www.computerworld.com/article/1691110/microsoft-365-explained.html">Microsoft 365</a>, but it still served as a launch pad for your M365 files and apps.</p>



<p>Now, however, Microsoft has deeply integrated its Copilot generative AI assistant throughout Microsoft 365, and the hub has been transformed. <a href="https://support.microsoft.com/en-us/office/the-microsoft-365-app-transition-to-the-microsoft-365-copilot-app-22eac811-08d6-4df3-92dd-77f193e354a5" target="_blank" rel="noreferrer noopener">Currently called the M365 Copilot app</a>, the page puts the Copilot Chat interface front and center. You can still get to your M365 files or apps by clicking <em>Search</em> or <em>Apps</em> in the sidebar on the left, but the main purpose of the hub these days is to let you chat with Copilot.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/05/copilot-chat-app-01-home-screen.png?w=1024" alt="screenshot of the m365 copilot web app featuring the copilot chat interface" class="wp-image-4171340" width="1024" height="576" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption"><p>The old Microsoft Office hub has been taken over by Copilot Chat.</p>
</figcaption></figure><p class="imageCredit">Howard Wen / Foundry</p></div>



<p>With the rollout of new Word, Excel, and PowerPoint AI agents, you can use Copilot Chat in the M365 Copilot app to generate first-draft Word documents, Excel spreadsheets, and PowerPoint presentations. If you have a qualifying Microsoft subscription, you can also use the advanced Analyst agent in Copilot Chat to analyze M365 files in various ways. We’ll show you how.</p>



<h4 class="wp-block-heading"><strong>In this article:</strong></h4>



<ul class="wp-block-list">
<li>Who can use Copilot Chat in the M365 Copilot app</li>



<li>Create a document, spreadsheet, or presentation with Copilot Chat</li>



<li>Analyze your M365 documents in Copilot Chat</li>



<li>Get collaboration insights using Copilot Chat</li>
</ul>



<h3 class="wp-block-heading"><a></a>Who can use Copilot Chat in the M365 Copilot app</h3>



<p>As of mid-2026, Microsoft has integrated Copilot Chat into most M365 plans, which include:</p>



<ul class="wp-block-list">
<li>Microsoft 365 for individuals: <a href="https://www.microsoft.com/en-us/microsoft-365/buy/compare-all-microsoft-365-products" target="_blank" rel="noreferrer noopener">Personal, Family, and Premium</a> plans. Note that only the subscriber account has access to Copilot tools. They cannot be shared with other users on a Family or Premium plan.</li>



<li>Microsoft 365 for business users: A basic version of Copilot Chat is included with the small-business <a href="https://www.microsoft.com/en-us/microsoft-365/business/microsoft-365-plans-and-pricing" target="_blank" rel="noreferrer noopener">M365 Business Basic, Standard, and Premium</a> plans as well as enterprise-level Office 365 E1/E3/E5 and <a href="https://www.microsoft.com/en-us/microsoft-365/enterprise/microsoft-365-plans-and-pricing#plans" target="_blank" rel="noreferrer noopener">Microsoft 365 E3/E5/E7</a> plans. Add-on M365 Copilot licenses for <a href="https://www.microsoft.com/en-us/microsoft-365-copilot/pricing" target="_blank" rel="noreferrer noopener">small business</a> and <a href="https://www.microsoft.com/en-us/microsoft-365-copilot/pricing/enterprise" target="_blank" rel="noreferrer noopener">enterprise</a> offer advanced Copilot features (these are included with the top-level M365 E7 plan).</li>
</ul>



<p>Microsoft recently <a href="https://www.computerworld.com/article/4150022/microsoft-backtracks-on-copilot-chat-access-in-m365-apps.html">removed access</a> to Copilot Chat from within Word and other M365 apps for large enterprise users who don’t have an add-on M365 Copilot license. That means the M365 Copilot app is now the only way for those users to access Copilot Chat.</p>



<p>If you don’t have a Microsoft 365 plan, you don’t have access to Copilot Chat. You can still use the M365 Copilot app to get to your Office files and apps, but if you click <em>New chat</em>, you’ll see a message saying that Copilot Chat requires an upgraded account.</p>



<p>In this guide, we’ll focus on using Copilot Chat in the <a href="https://m365.cloud.microsoft/" target="_blank" rel="noreferrer noopener">M365 Copilot web app</a>. There are also <a href="https://www.microsoft.com/en-US/microsoft-365-copilot/download-copilot-app" target="_blank" rel="noreferrer noopener">downloadable M365 Copilot apps</a> for Windows, macOS, iOS, and Android. Depending on your M365 plan and computing environment, your interface may not exactly match the screenshots you see here, but it should work similarly.</p>



<h2 class="wp-block-heading"><a></a>Create a document, spreadsheet, or presentation with Copilot Chat</h2>



<p>Using the M365 agents in Copilot Chat works mostly the same whether you’re creating a new Word document, Excel spreadsheet, or PowerPoint presentation.</p>



<h3 class="wp-block-heading"><a></a>1. Add the AI agents (if needed)</h3>



<p>Depending on your Microsoft 365 plan and how it’s configured, you may or may not have the Word, Excel, and PowerPoint AI agents installed by default in Copilot Chat. If you don’t see them listed under “Agents” in the left sidebar, you’ll need to add them.</p>



<p>Click <em>All agents</em> in the left sidebar. You’ll be taken to the Agent Store, where you can browse through available agents built by Microsoft, third-party vendors, and/or your own organization. Type <strong>word</strong> into the search bar and select the <em>Word (Agent)</em> result that appears. A panel pops up with information about the agent.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/05/copilot-chat-app-02-add-word-agent.png?w=1024" alt="screenshot of copilot chat with pop-up screen with info about word agent" class="wp-image-4171336" width="1024" height="650" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption"><p>Adding the Word agent to Copilot Chat.</p>
</figcaption></figure><p class="imageCredit">Howard Wen / Foundry</p></div>



<p>Click <em>Add</em> to install the agent in Copilot Chat. It will appear in your Agents list in the left sidebar. Repeat the process for the Excel and PowerPoint agents.</p>



<h3 class="wp-block-heading">2. Select the AI agent</h3>



<p>On the Copilot Chat page, you first need to invoke a specific AI agent: In the left sidebar, select <em>Word</em>, <em>PowerPoint</em>, or <em>Excel</em> from the Agents list. (If you don’t see the agent you want, select <em>All agents</em> and then click on it.)</p>



<p>Alternatively, inside the Copilot chat box, type <strong>@</strong> and select <em>Word</em> (or whichever agent you want) from the results that appear below the chat box.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/05/copilot-chat-app-03-agents-menu.png?w=1024" alt="screenshot of copilot chat app with m365 agents in drop-down menu" class="wp-image-4171337" width="1024" height="576" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption"><p>Select the Word, PowerPoint, or Excel agent to get started.</p>
</figcaption></figure><p class="imageCredit">Howard Wen / Foundry</p></div>



<h3 class="wp-block-heading"><a></a>3. Enter your prompt</h3>



<p>Enter your prompt in the chat box, describing the details about the document, spreadsheet, or presentation that you want.</p>



<p>Example to generate a Word document:</p>



<ul class="wp-block-list">
<li><em>Create a document titled “Project Proposal.” Include sections for Executive Summary, Technical Requirements, and Budget. Use a formal business tone.</em></li>
</ul>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/05/copilot-chat-app-04-word-agent-prompt.png?w=1024" alt="screenshot of word agent in copilot chat with a document request prompt typed in" class="wp-image-4171335" width="1024" height="402" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption"><p>After invoking the agent, type in your prompt.</p>
</figcaption></figure><p class="imageCredit">Howard Wen / Foundry</p></div>



<p>To generate an Excel spreadsheet, describe its structure. Example:</p>



<ul class="wp-block-list">
<li><em>Generate a sales report for Q4 2026. Include columns for Date, Product Name, Units Sold, and Total Revenue. Format the Revenue column as currency.</em></li>
</ul>



<p>To generate a PowerPoint presentation, specify important aspects of the presentation, such as its topic, audience, number of slides, etc. Example:</p>



<ul class="wp-block-list">
<li><em>Build a presentation with 10 slides for a meeting announcing our new sustainability initiative. Include a slide for the timeline. Use an enthusiastic but professional tone.</em></li>
</ul>



<h3 class="wp-block-heading"><a></a>4. Attach a file for reference (optional)</h3>



<p>You can attach one or more files to the chat box for Copilot to use as reference when generating your request. For example, you can attach a Word document and prompt the PowerPoint agent to create a presentation based on it:</p>



<ul class="wp-block-list">
<li><em>Create a presentation from this document.</em></li>
</ul>



<p>or have the Word agent create a document based on an Excel spreadsheet:</p>



<ul class="wp-block-list">
<li><em>Create a summary report based on the attached spreadsheet.</em></li>
</ul>



<p>To attach a file, click the + icon on the chat box and select <em>Add content</em> (to attach a file in your OneDrive) or <em>Upload files</em> (to attach a file that’s on your local PC drive).</p>



<p>Alternatively, if the file is stored in your OneDrive, you can type <strong>/</strong> (forward slash) in the chat box and start typing its filename. This also pulls up a list of files recently added to your OneDrive that you can select from, and there’s also a search box you can use to find the file.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/05/copilot-chat-app-05-attach-file.png?w=1024" alt="screenshot of powerpoint agent in copilot chat with list of documents for upload" class="wp-image-4171339" width="1024" height="619" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption"><p>Adding a document to use as a source for a PowerPoint agent prompt.</p>
</figcaption></figure><p class="imageCredit">Howard Wen / Foundry</p></div>



<h3 class="wp-block-heading">5. Review the generated result</h3>



<p>When you’ve finished typing your prompt and optionally uploading a source file, press Enter or click the right-arrow button at the bottom right of the chat box.</p>



<p>The agent may ask you a few questions, mostly presented as options you select, before generating a result.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/05/copilot-chat-app-06-powerpoint-agent-questions.png?w=1024" alt="screenshot of powerpoint agent in copilot chat asking questions about the presentation to be generated" class="wp-image-4171338" width="1024" height="756" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption"><p>The PowerPoint agent typically asks a few questions about the presentation before it starts creating it.</p>
</figcaption></figure><p class="imageCredit">Howard Wen / Foundry</p></div>



<p>Depending on the complexity of your prompt, Copilot will take several seconds to several minutes to generate a result. As it works, it will notify you of its progress.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/05/copilot-chat-app-07-word-agent-progress.png?w=1024" alt="screenshot of word agent in copilot chat detailing the steps it is taking" class="wp-image-4171341" width="1024" height="747" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption"><p>Copilot will tell you what it’s doing as it prepares a result.</p>
</figcaption></figure><p class="imageCredit">Howard Wen / Foundry</p></div>



<p>When it’s done, it will automatically save the document, spreadsheet, or presentation that it generated to the Documents folder in your OneDrive.</p>



<p>A large pane will also open in the right half of the screen, displaying the full document, spreadsheet, or presentation that Copilot generated. You can scroll vertically through it to review it. </p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/05/copilot-chat-app-08-word-agent-generated-doc.png?w=1024" alt="screenshot of word agent in copilot chat with a generated document in a pane on the right" class="wp-image-4171342" width="1024" height="576" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption"><p>The generated document appears in pane on the right.</p>
</figcaption></figure><p class="imageCredit">Howard Wen / Foundry</p></div>



<p><strong>Important: </strong>As always when using generative AI tools, check all results carefully for errors or fabrications. (See “<a href="https://www.computerworld.com/article/4067372/how-to-curb-hallucinations-in-copilot-and-other-genai-tools.html">How to curb hallucinations in Copilot</a>” for tips on minimizing such errors.)</p>



<h3 class="wp-block-heading"><a></a>6. Refine the generated result</h3>



<p>You can refine the generated result by entering a follow-up prompt in the chat box.</p>



<p>Example to refine a Word document:</p>



<ul class="wp-block-list">
<li><em>Add a section on Network Security, and make the tone more casual.</em></li>
</ul>



<p>To refine a generated Excel spreadsheet or PowerPoint presentation, you have to first attach it to the chat box: Type the forward slash (“/”) in the chat box. This will pull up a list of files recently added to your OneDrive, including the generated spreadsheet or presentation. Select it and then enter your prompt to refine it.</p>



<p>Example to refine an Excel spreadsheet:</p>



<ul class="wp-block-list">
<li><em>Add a column titled Price Per Unit and calculate this value for every row.</em></li>
</ul>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-full is-resized"> width="654" height="461" sizes="auto, (max-width: 654px) 100vw, 654px"&gt;<figcaption class="wp-element-caption"><p>To refine a generated Excel spreadsheet, attach the file and say how you want it changed.</p>
</figcaption></figure><p class="imageCredit">Howard Wen / Foundry</p></div>



<p>Example to refine a PowerPoint presentation:</p>



<ul class="wp-block-list">
<li><em>Remove Slide 4. Add a blank slide at the end.</em></li>
</ul>



<p>Copilot will generate a revised version. This will be saved as a new file in the Documents folder in your OneDrive.</p>



<h3 class="wp-block-heading"><a></a>7. Edit the generated result in a Microsoft 365 app</h3>



<p>It’s best to think of genAI output as a template or first draft that you will update, add to, and otherwise tailor for your own needs. To do so, it’s easiest to open the generated file in the appropriate M365 app.</p>



<p>At the upper right, click <em>Open in Word</em>, <em>Open in Excel</em>, or <em>Open in PowerPoint</em> to launch the web version of that app in a new browser tab. The generated document, spreadsheet, or presentation will appear inside the app so you can do further work on it.</p>



<h2 class="wp-block-heading"><a></a>Analyze your M365 documents in Copilot Chat</h2>



<p>You can use Copilot Chat to analyze your M365 documents in various ways by invoking the Analyst agent. This agent is available only if you have a Microsoft 365 Premium plan or, in a business environment, if you have an add-on M365 Copilot license. (That said, there is a workaround for the third tip below for those who don’t have an advanced license.)</p>



<p>In the left sidebar, select <em>Analyst</em> in the Agents list. (If you don’t see it, follow the instructions in step 1 above to add it.) Or, inside the Copilot chat box, type <strong>@analyst</strong> and press the Enter key.</p>



<p>Next, attach the file or files that you want Copilot to analyze. Click the + icon on the chat box and select <em>Add content</em> (to attach a file in your OneDrive) or <em>Upload files</em> (to attach a file that’s on your local PC drive).</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/05/copilot-chat-app-10-analyst-agent.png?w=1024" alt="screenshot of analyst agent in copilot with drop-down menu to upload a file for analysis" class="wp-image-4171360" width="1024" height="576" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption"><p>Call up the Analyst agent and upload the files you want it to analyze.</p>
</figcaption></figure><p class="imageCredit">Howard Wen / Foundry</p></div>



<p><strong>Notes for Excel and PowerPoint files:</strong></p>



<ul class="wp-block-list">
<li>Ensure that the data in an attached Excel file is formatted as a table. In this way, Copilot can better identify the range of values in it for analysis.</li>



<li>For PowerPoint, the Analyst agent works best if your slide deck is text-heavy.</li>
</ul>



<p>Here are a few ways you can have Copilot analyze your files:</p>



<h3 class="wp-block-heading"><a></a><a></a>Identify trends in data sets or presentations</h3>



<p>Using the Analyst agent, Copilot can act as a data analyst, spotting patterns and anomalies in your Excel or PowerPoint files. It can also identify missing data that would provide a more complete picture.  </p>



<p><strong>Tip:</strong> For the most accurate results, describe a specific source (such as the name of a table or slide numbers) and the timeframe to give the agent boundaries for its analysis.</p>



<p>PowerPoint example:</p>



<ul class="wp-block-list">
<li><em>Look at slides 4 through 8. What are the themes or trends in our sales?</em></li>
</ul>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/05/copilot-chat-app-11-analyst-agent-powerpoint-trend-analysis.png?w=1024" alt="screenshot of analyst agent in copilot chat with generated analysis of a powerpoint file" class="wp-image-4171359" width="1024" height="749" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption"><p>Copilot Chat’s Analyst agent can surface key themes in a PowerPoint presentation.</p>
</figcaption></figure><p class="imageCredit">Howard Wen / Foundry</p></div>



<p>Excel example:</p>



<ul class="wp-block-list">
<li><em>Show me the sales trends over the last month. Identify which product category is growing the fastest.</em></li>
</ul>



<p>If your source file is missing the data Copilot needs for the trend analysis you’ve asked for, it will tell you so. It may instead provide a summary of the data the file does include and/or what can be inferred from the file’s data.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/05/copilot-chat-app-12-analyst-agent-impossible-request.png?w=1024" alt="screenshot of analyst agent in copilot chat saying it cannot provide the requested analysis based on the data in the spreadsheet" class="wp-image-4171362" width="1024" height="754" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption"><p>Copilot correctly says it can’t provide the requested analysis from the source data.</p>
</figcaption></figure><p class="imageCredit">Howard Wen / Foundry</p></div>



<h3 class="wp-block-heading"><a></a>Project forecasts</h3>



<p>The Analyst agent can use statistical models to project future values based on historical data in an Excel file. (These are simple projections and should not be presented as official forecasts.) Your source spreadsheet must include a time-based column, such as dates, and a numerical column for the values you want Copilot to forecast.</p>



<p>Example:</p>



<ul class="wp-block-list">
<li><em>Create a forecast for January based on the months of October, November, December in this spreadsheet.</em></li>
</ul>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/05/copilot-chat-app-13-analyst-agent-excel-forecast.png?w=1024" alt="screenshot of analyst agent in copilot chat with generated forecast from excel spreadsheet data" class="wp-image-4171356" width="1024" height="749" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption"><p>Copilot has projected January sales based on the average growth rate from October to December.</p>
</figcaption></figure><p class="imageCredit">Howard Wen / Foundry</p></div>



<p>You can also prompt the Analyst agent to create a projection based on an Excel spreadsheet and output it on a PowerPoint slide that you can download. Example:</p>



<ul class="wp-block-list">
<li><em>Create one slide that shows a sales forecast based on the months of October, November, December in this spreadsheet.</em></li>
</ul>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/05/copilot-chat-app-14-analyst-agent-generated-forecast-slide.png?w=1024" alt="screenshot of sales forecast powerpoint slide generated by analyst agent in copilot chat" class="wp-image-4171361" width="1024" height="576" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption"><p>A sales forecast slide generated by Copilot.</p>
</figcaption></figure><p class="imageCredit">Howard Wen / Foundry</p></div>



<p>The agent explains how it calculated the forecast and offers suggestions for tweaking the result. Type whatever changes you want to make into the chat box, and Copilot will generate a new version of the slide.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/05/copilot-chat-app-15-analyst-agent-forecast-explanation.png?w=1024" alt="screenshot of analyst agent in copilot chat explaining how it created a sales forecast slide" class="wp-image-4171357" width="1024" height="749" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption"><p>Copilot explains what it did and suggests possible changes.</p>
</figcaption></figure><p class="imageCredit">Howard Wen / Foundry</p></div>



<h3 class="wp-block-heading">Compare document versions</h3>



<p>Documents often go through multiple revisions, especially in a collaborative work environment. Unlike a basic versioning feature that lists literal differences, Copilot can provide contextual understanding and explain why a change is significant.</p>



<p>After you’ve attached two files to the chat box, enter a prompt, such as:</p>



<ul class="wp-block-list">
<li><em>Compare these two documents and highlight their key differences.</em></li>
</ul>



<p>The Analyst agent summarizes the changes in the document’s overall direction and details the main differences in specific aspects of the document.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/05/copilot-chat-app-16-analyst-agent-doc-version-comparison.png?w=1024" alt="screenshot of document version comparison generated by analyst agent in copilot chat" class="wp-image-4171358" width="1024" height="737" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption"><p>The Analyst agent explains how a document has changed overall, then cites key differences in areas such as title and positioning.</p>
</figcaption></figure><p class="imageCredit">Howard Wen / Foundry</p></div>



<p><strong>Note:</strong> If you don’t have access to the Analyst agent, you can alternatively try using the Word agent or the main Copilot Chat interface to compare two document versions. Like the Analyst agent, Copilot Chat presents its results in the chat window. If you use the Word agent, it creates a detailed comparison document after asking a series of questions about purpose, audience, and style.</p>



<h2 class="wp-block-heading"><a></a>Get collaboration insights using Copilot Chat</h2>



<p>When working on a project with your co-workers, it can be a challenge to keep up with who did what to a file. You can prompt Copilot to list edits and comments to a file. This allows you to catch up on the context of changes without having to open it.</p>



<p>You don’t need to invoke the Analyst agent to do this. This works better if you use the main Copilot Chat. Click the + icon to attach the file (document, spreadsheet, presentation).</p>



<p>Optionally: At the upper-right corner, click <em>Auto</em>, which will open a dropdown. Here you can select an AI model that gives you results faster, or one that spends more time “thinking” in order to give you better-quality results. A second dropdown at the bottom lets you select a specific AI model by name, such as GPT-5.3 or GPT-5.4. We recommend picking a “think deeper” model for insights retrieval.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/05/copilot-chat-app-17-choose-model.png?w=1024" alt="screenshot of model selection drop-down menu in copilot chat" class="wp-image-4171363" width="1024" height="621" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption"><p>You can optionally pick a model for Copilot to use when it generates results.</p>
</figcaption></figure><p class="imageCredit">Howard Wen / Foundry</p></div>



<p>Example prompts to extract collaboration insights:</p>



<ul class="wp-block-list">
<li><em>What has [CO-WORKER NAME] updated or commented on in this document?</em></li>



<li><em>Summarize the comments and feedback left by everyone in this attached document.</em></li>
</ul>



<p>Copilot will generate a detailed response based on your prompt.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/05/copilot-chat-app-18-comments-summary.png?w=1024" alt="screenshot of copilot chat app with generated summary of commenter feedback in a document " class="wp-image-4171364" width="1024" height="576" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption"><p>Copilot can summarize who did what to a shared document.</p>
</figcaption></figure><p class="imageCredit">Howard Wen / Foundry</p></div>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Announcing Risk Automations: From Discovery to Resolution In Seconds | UpGuard]]></title>
<description><![CDATA[Learn about UpGuard's new product launch. Transform your risk resolution engine by moving from alert to resolution in seconds, not days.]]></description>
<link>https://tsecurity.de/de/3531832/it-security-nachrichten/announcing-risk-automations-from-discovery-to-resolution-in-seconds-upguard/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3531832/it-security-nachrichten/announcing-risk-automations-from-discovery-to-resolution-in-seconds-upguard/</guid>
<pubDate>Wed, 20 May 2026 08:35:41 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Learn about UpGuard's new product launch. Transform your risk resolution engine by moving from alert to resolution in seconds, not days.]]></content:encoded>
</item>
<item>
<title><![CDATA[ON THIS DAY: Microsoft is working on its own 'Bing Concierge Bot' to rival Google Assistant]]></title>
<description><![CDATA[From our archives: Ten years ago today, Microsoft was testing a Bing “concierge bot” designed to live inside your conversations, handle tasks, and fetch info — basically the same thing Google is now announcing as its new AI information agents. The irony is hard to miss.]]></description>
<link>https://tsecurity.de/de/3530908/windows-tipps/on-this-day-microsoft-is-working-on-its-own-bing-concierge-bot-to-rival-google-assistant/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3530908/windows-tipps/on-this-day-microsoft-is-working-on-its-own-bing-concierge-bot-to-rival-google-assistant/</guid>
<pubDate>Tue, 19 May 2026 23:26:09 +0200</pubDate>
<category>🪟 Windows Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[From our archives: Ten years ago today, Microsoft was testing a Bing “concierge bot” designed to live inside your conversations, handle tasks, and fetch info — basically the same thing Google is now announcing as its new AI information agents. The irony is hard to miss.]]></content:encoded>
</item>
<item>
<title><![CDATA[Google just redesigned the search box for the first time in 25 years — here’s why it matters more than you think.]]></title>
<description><![CDATA[For a quarter century, the Google search box has been one of the most recognizable interfaces in computing: a thin white rectangle, a blinking cursor, a few typed words, and a list of blue links. On Tuesday, Google will formally retire that paradigm.At its annual I/O developer conference, Google ...]]></description>
<link>https://tsecurity.de/de/3530355/it-nachrichten/google-just-redesigned-the-search-box-for-the-first-time-in-25-years-heres-why-it-matters-more-than-you-think/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3530355/it-nachrichten/google-just-redesigned-the-search-box-for-the-first-time-in-25-years-heres-why-it-matters-more-than-you-think/</guid>
<pubDate>Tue, 19 May 2026 20:04:34 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>For a quarter century, the Google search box has been one of the most recognizable interfaces in computing: a thin white rectangle, a blinking cursor, a few typed words, and a list of blue links. On Tuesday, Google will formally retire that paradigm.</p><p>At its annual <a href="https://io.google/2026/">I/O developer conference</a>, Google announced a <a href="https://blog.google/products-and-platforms/products/search/search-io-2026/">sweeping redesign</a> of the search box itself — the literal text field where billions of queries begin every day — transforming it from a simple keyword input into a dynamic, AI-driven conversation starter that can accept text, images, PDFs, videos, and even open Chrome tabs as inputs. The company is also merging its <a href="https://search.google/ways-to-search/ai-overviews/">AI Overviews</a> and <a href="https://search.google/ways-to-search/ai-mode/">AI Mode</a> features into a single, seamless search flow, eliminating the friction that previously forced users to choose between a traditional results page and an AI-forward experience.</p><p>Liz Reid, Google's vice president and head of Search, called it "the biggest upgrade to our iconic search box since its debut over 25 years ago" during a press briefing on Monday.</p><p>The announcement arrived alongside a blizzard of other news — new <a href="https://blog.google/innovation-and-ai/models-and-research/gemini-models/gemini-3-5/">Gemini models</a>, a personal <a href="https://blog.google/products-and-platforms/products/search/search-io-2026/">AI agent called Spark</a>, an intelligent <a href="https://blog.google/products-and-platforms/products/shopping/google-shopping-cart/">shopping cart</a>, a <a href="https://blog.google/innovation-and-ai/technology/developers-tools/google-io-2026-developer-highlights/">reimagined developer platform</a> — but the search box redesign may prove to be the most consequential. It is the clearest signal yet that Google views the future of its flagship product not as a place where users type fragmented keywords, but as an interface where they hold open-ended, multimodal conversations with an AI system backed by the entire web.</p><h2><b>The new search box expands, accepts files, and coaches you on what to ask</b></h2><p>The changes show a fundamental shift in how Google expects people to interact with the product that generates the vast majority of Alphabet's revenue.</p><p>The box itself now dynamically expands to accommodate longer, more conversational queries. Where the old interface subtly encouraged brevity — a narrow field suited to two- or three-word keyword strings — the new design invites users to fully articulate complex questions in granular detail. It also now supports multimodal inputs directly. Users can upload images, PDFs, files, and videos, or drag in content from Chrome tabs, right from the main search interface. Previously, some of these capabilities existed in AI Mode, but reaching them required extra steps. Now they sit at the primary entry point.</p><p>Google is also deploying what it describes as an AI-powered query suggestion system that "goes beyond autocomplete." Rather than simply predicting the next word a user might type based on popular searches, the system helps users formulate complex, nuanced queries — essentially coaching them toward the kind of detailed questions that AI Mode handles best.</p><p>The new search box is starting to roll out immediately in all countries and languages where AI Mode is available.</p><h2><b>Google is merging AI overviews and AI mode into one seamless experience</b></h2><p>Perhaps more significant than the box itself is the architectural change happening behind it. Google is unifying <a href="https://search.google/ways-to-search/ai-overviews/">AI Overviews</a> — the AI-generated summary panels that appear atop traditional search results — with <a href="https://search.google/ways-to-search/ai-mode/">AI Mode</a>, the more immersive conversational search experience the company launched at I/O one year ago.</p><p>Starting Tuesday, this merged experience will be live across mobile and desktop worldwide. A user can type a question, receive an AI Overview alongside traditional results, and then continue directly into a back-and-forth AI Mode conversation to ask follow-up questions — all without navigating to a separate interface.</p><p>Reid explained the logic during the press briefing: the new AI search box is "an upgrade of our traditional search box, and so the results take you directly to main search rather than AI mode." She noted that while some power users actively sought out AI Mode, "for most users, they don't actually want to have to think about, do they want more of a traditional page or an AI-forward search experience."</p><p>The goal, she said, was to ensure that "for most users, they don't have to think about where to go, they can just go to the search box they're familiar with, and it feels like they get the best experience afterwards."</p><h2><b>One billion users and doubling queries reveal how fast search behavior is shifting</b></h2><p>Google's decision to redesign the foundational interface of its most important product did not happen in a vacuum. The company shared a set of usage statistics during the briefing that reveal just how rapidly user behavior is already changing.</p><p><a href="https://search.google/ways-to-search/ai-mode/">AI Mode</a>, which launched in the United States at I/O 2025, has surpassed one billion monthly users in its first year. AI Mode queries have been doubling every quarter since launch. AI Overviews, the lighter-weight AI summaries, now reach more than 2.5 billion monthly users. And overall <a href="https://www.theverge.com/tech/920815/google-alphabet-q1-2026-earnings-sundar-pichai">search query volume hit an all-time high</a> last quarter — a data point the company had previously disclosed on its earnings call.</p><p>Sundar Pichai, Google's CEO, framed these figures as evidence that AI features are additive, not cannibalistic, to search usage. "When people use our AI-powered features in search, they use search more," he said. He added that he loves "how search has become less about individual queries and feels more like an ongoing conversation, giving users deeper insights and connecting you with the vastness of the web."</p><p>Reid reinforced the point: "It's not just that people are searching more, it's that they're searching differently. They're fully expressing their questions in granular detail, asking those follow-up questions and searching across modalities."</p><h2><b>Gemini 3.5 Flash gives Google's AI search the speed it needs to work at scale</b></h2><p>Under the hood, the new search experience runs on <a href="https://blog.google/innovation-and-ai/models-and-research/gemini-models/gemini-3-5/">Gemini 3.5 Flash</a>, Google's newest AI model, which the company also introduced at I/O. Google upgraded AI Mode's underlying model to 3.5 Flash to deliver what Reid described as "an even more powerful AI search experience."</p><p><a href="https://blog.google/innovation-and-ai/models-and-research/gemini-models/gemini-3-5/">Gemini 3.5 Flash</a> is the workhorse of this year's announcements. Google claims it outperforms its previous frontier model, <a href="https://deepmind.google/models/gemini/pro/">Gemini 3.1 Pro</a>, on nearly all benchmarks while running four times faster in output tokens per second than comparable frontier models. Pichai described it as being "in a league of its own in the top right quadrant" of the <a href="https://artificialanalysis.ai/">Artificial Analysis index</a>, which plots intelligence against speed — meaning it delivers near-frontier quality at dramatically lower latency.</p><p>That speed matters enormously for search. A conversational AI search experience that feels sluggish would be dead on arrival for a product that serves billions of queries daily. By coupling the redesigned interface with a model optimized for both quality and throughput, Google is attempting to make AI-powered search feel as instantaneous as the old keyword experience — while being dramatically more capable.</p><h2><b>Search can now build interactive visuals and custom mini apps on the fly</b></h2><p>The redesigned search box is also the gateway to a set of new capabilities that push search far beyond text-based answers. Google announced what it calls "<a href="https://blog.google/products-and-platforms/products/search/search-io-2026/">generative UI</a>" — the ability for search to dynamically build custom widgets, interactive visualizations, and even mini applications in real time, tailored to a user's specific question.</p><p>Reid offered a concrete example during the briefing: a user could ask "How do black holes affect space time?" and receive an interactive visual in an AI Overview that brings the concept to life. Follow-up questions would trigger the system to dynamically generate entirely new visuals in real time. This is possible, she explained, because of "a novel real-time code generation system we built in partnership with the Google DeepMind team" that runs on Gemini 3.5 Flash. Generative UI capabilities will roll out to everyone this summer, free of charge.</p><p>But Google is going further still. For ongoing tasks — planning a wedding, organizing a move, tracking a fitness routine — users will be able to build what the company describes as customizable, stateful experiences within search, powered by its <a href="https://blog.google/innovation-and-ai/technology/developers-tools/google-io-2026-developer-highlights/">Antigravity development platform</a>. These require no coding expertise. Users simply describe what they want in natural language, and search builds it. Those experiences will be available in coming months, starting with <a href="https://gemini.google/subscriptions/">Google AI Pro</a> and <a href="https://gemini.google/subscriptions/">Ultra</a> subscribers in the United States.</p><h2><b>AI agents that monitor the web around the clock are coming to search results</b></h2><p>The redesign also opens the door to what Google calls "<a href="https://blog.google/products-and-platforms/products/search/search-io-2026/">information agents</a>" — AI agents that users can configure directly within search to monitor the web 24/7 for specific conditions and deliver synthesized updates when those conditions are met.</p><p>A user could, for example, set up an agent to track market movements in a particular sector with specific parameters. The agent would create a monitoring plan, tap into real-time finance data, and proactively notify the user when conditions are met — complete with links and context for further research. Other use cases include apartment hunting, tracking sneaker drops, or monitoring any topic a user cares about. Information agents will launch first for <a href="https://gemini.google/subscriptions/">Google AI Pro</a> and <a href="https://gemini.google/subscriptions/">Ultra</a> subscribers this summer.</p><p>These agents sit within a much larger strategic pivot that Google articulated throughout the briefing: the company is going all-in on AI systems that don't just answer questions but proactively take actions on users' behalf. Beyond search, Google introduced <a href="https://blog.google/innovation-and-ai/products/gemini-app/next-evolution-gemini-app/">Gemini Spark</a>, a 24/7 personal AI agent that runs on dedicated virtual machines in Google Cloud. It unveiled the <a href="https://blog.google/products-and-platforms/products/shopping/google-shopping-cart">Universal Cart</a>, an intelligent cross-merchant shopping cart. It announced the <a href="https://cloud.google.com/blog/products/ai-machine-learning/announcing-agents-to-payments-ap2-protocol">Agent Payments Protocol</a> for agents to make secure purchases. And it expanded its <a href="https://blog.google/innovation-and-ai/technology/developers-tools/google-io-2026-developer-highlights/">Antigravity developer platform</a> into a full ecosystem for building autonomous AI agents.</p><h2><b>Publishers, advertisers, and SEO professionals face a new reality</b></h2><p>The redesign raises profound questions for the sprawling ecosystem — publishers, advertisers, SEO professionals — that has been built around the old model of keyword search and blue links.</p><p>If users increasingly express their needs as full, conversational sentences rather than fragmented keywords, the entire discipline of search engine optimization will need to evolve. Keyword-density strategies become less relevant when the AI is parsing natural language intent rather than matching strings. Content that answers deep, nuanced questions in authoritative ways becomes more valuable; content engineered to rank for two-word keyword fragments becomes less so.</p><p>For publishers, <a href="https://www.npr.org/2025/07/31/nx-s1-5484118/google-ai-overview-online-publishers">the stakes are existential</a>. AI Overviews already synthesize information from across the web and present it directly in search results, reducing the need for users to click through to source material. The new seamless AI Mode integration deepens that dynamic: users can now get an AI-generated answer and ask multiple follow-up questions without ever leaving the search page. Google has consistently maintained that its AI features drive more traffic to publishers, but the redesign puts that claim under renewed scrutiny as the search results page becomes more self-contained.</p><p>For advertisers — who fund the vast majority of Google's revenue — the shift from keywords to conversations changes the calculus of ad targeting. Conversational queries contain richer intent signals, which could make ad targeting more precise and valuable. But they also create new ambiguities: when a user is in the middle of a multi-turn conversation with AI Mode, where does an ad naturally fit? Google did not detail changes to its advertising model during the briefing, but the structural shift in the interface will inevitably reshape how ads are surfaced and measured.</p><h2><b>The search box was always more than a product — it was a habit for billions of people</b></h2><p>There is a reason Google chose to redesign the search box rather than simply adding new features behind it. The search box is not just a product element at this point; it is a cultural artifact — one of the few pieces of digital infrastructure used by essentially the entire internet-connected world. Changing it sends an unmistakable message about where the company believes computing is headed.</p><p>For 25 years, the search box trained billions of people to think in keywords — to compress their curiosity into the shortest possible string of words. The new box invites them to do the opposite: to think out loud, to upload what they're looking at, to ask follow-up questions, to let an AI system handle the compression.</p><p>Pichai tied the company's broader ambitions to a striking statistic: Google's surfaces now process over 3.2 quadrillion tokens per month, up seven-fold from a year ago. The company expects capital expenditures of approximately $180 to $190 billion in 2026 — roughly six times the $31 billion it spent four years ago — largely to support the infrastructure required for this AI transformation. When asked about the future of traditional search, he was direct. "Search is the most used AI product in the world," he said.</p><p>The blinking cursor in Google's search box still invites you to type. But after 25 years of teaching the world to speak in keywords, Google is now asking it to speak in sentences — and betting roughly $190 billion that it will.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Google’s new AI agent can draft your emails, monitor your inbox and eventually spend your money]]></title>
<description><![CDATA[Google on Tuesday unveiled Gemini Spark, a personal AI agent designed to work around the clock — drafting emails, assembling documents, monitoring inboxes, and eventually making purchases — even when a user's laptop is closed and their phone is locked.The announcement, made at Google I/O 2026, is...]]></description>
<link>https://tsecurity.de/de/3530348/it-nachrichten/googles-new-ai-agent-can-draft-your-emails-monitor-your-inbox-and-eventually-spend-your-money/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3530348/it-nachrichten/googles-new-ai-agent-can-draft-your-emails-monitor-your-inbox-and-eventually-spend-your-money/</guid>
<pubDate>Tue, 19 May 2026 20:04:25 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Google on Tuesday unveiled <a href="https://blog.google/innovation-and-ai/products/gemini-app/next-evolution-gemini-app/">Gemini Spark</a>, <!-- -->a personal AI agent designed to work around the clock — drafting emails, assembling documents, monitoring inboxes, and eventually making purchases — even when a user's laptop is closed and their phone is locked.</p><p>The announcement, made at <a href="https://io.google/2026/">Google I/O 2026</a>, <!-- -->is the company's most ambitious attempt yet to transform its AI assistant from a tool that answers questions into one that autonomously completes tasks. It also arrives at a moment of extraordinary competition, as Microsoft, OpenAI, Anthropic, and Apple all race to build AI systems that don't merely converse but act — completing multi-step workflows with decreasing human supervision.</p><p>"We are in that part of the cycle where people want to see real value in the products they use on a day-to-day basis," Sundar Pichai, CEO of Google and Alphabet, said during a press briefing ahead of the keynote address. With Spark, he argued, that value comes from an agent that never stops working. It operates around the clock in Google's cloud, he said, so "you don't need to keep your laptop open to make sure it's running."</p><p>The product arrives at an inflection point for the technology industry, as <a href="https://www.google.com/">Google</a>, <a href="https://microsoft.com/">Microsoft</a>, <a href="https://openai.com/">OpenAI</a>, <a href="https://www.anthropic.com/">Anthropic</a>, and <a href="https://www.apple.com/">Apple</a> all race to build AI systems that don't merely converse but <i>do</i> — completing multi-step workflows with decreasing human supervision. It also raises urgent questions about trust, spending guardrails, and what happens when an artificial intelligence agent misinterprets a user's intent.</p><p>Spark will begin rolling out this week to a small group of trusted testers, with a beta planned for <a href="https://gemini.google/subscriptions/">Google AI Ultra</a> subscribers in the United States next week.</p><h2><b>Inside the cloud architecture that lets Gemini Spark work while you sleep</b></h2><p>Unlike conventional AI assistants that activate only when prompted, <a href="https://blog.google/innovation-and-ai/products/gemini-app/next-evolution-gemini-app/">Gemini Spark</a> is architecturally different. It runs persistently on Google Cloud infrastructure, powered by the company's new <a href="https://blog.google/innovation-and-ai/models-and-research/gemini-models/gemini-3-5/">Gemini 3.5 Flash model </a>and what Google calls the <a href="https://developers.googleblog.com/build-with-google-antigravity-our-new-agentic-development-platform/">Antigravity</a> agent harness — the same underlying system that powers the company's internal developer tools.</p><p>In practical terms, this means Spark can accept a complex instruction — "email my boss a status update pulling the latest figures from our shared spreadsheet and the project timeline in our Slides deck" — and then execute it across multiple Google applications without further input. The agent can pull context from emails, documents, and calendar entries, synthesize the information, and produce a finished output.</p><p>Josh Woodward, VP of Google Labs, Gemini App, and AI Studio, described the experience in visceral terms during the briefing: "When you use it, it almost feels like you're tossing things over your shoulder — Spark's catching them and gets the job done."</p><p>The cloud-based architecture is a deliberate design choice. Because <a href="https://blog.google/innovation-and-ai/products/gemini-app/next-evolution-gemini-app/">Spark</a> operates on remote servers rather than on a user's device, it can continue working through tasks after a user walks away. A student could ask Spark to build a study guide that updates itself as new assignments arrive from a professor. A small business owner could instruct it to monitor their inbox and flag potential customer inquiries. A parent could delegate the logistics of a neighborhood block party — tracking RSVPs, coordinating contributions, scouting venues. These are not hypothetical scenarios. Woodward said they reflect how early testers have actually been using the product.</p><p>Over the coming months, Google plans to expand Spark's capabilities significantly. The company will roll out <a href="https://modelcontextprotocol.io/docs/getting-started/intro">MCP (Model Context Protocol)</a> connections to more than 30 third-party partners, including <a href="https://www.canva.com/">Canva</a>, <a href="https://www.opentable.com/">OpenTable</a>, and <a href="https://www.instacart.com/">Instacart</a>. Users will also be able to text and email <a href="https://blog.google/innovation-and-ai/products/gemini-app/next-evolution-gemini-app/">Spark</a> directly, create custom sub-agents for specialized tasks, and connect Spark to Chrome for web-based actions. Later this year, a new Android interface called <a href="https://blog.google/products-and-platforms/platforms/android/android-halo/">Android Halo</a> will provide live, at-a-glance visibility into what Spark is working on, displayed at the top of a user's phone screen.</p><h2><b>Google compares its AI spending safeguards to giving a teenager their first debit card</b></h2><p>For all its ambition, <a href="https://blog.google/innovation-and-ai/products/gemini-app/next-evolution-gemini-app/">Spark</a> confronts a fundamental challenge that has bedeviled every AI agent to date: How do you trust an autonomous system to act on your behalf — particularly when money is involved?</p><p>Google is acutely aware of the concern. When asked during the press briefing how Spark would avoid making unauthorized purchases, Woodward reached for an analogy that was striking in its candor. "On the team, we think a lot of it is like if you're giving a teenager their first debit card — there's sort of limits and sort of constraints around it, and that's how we'll be designing Spark as we go through the year," he said.</p><p>At launch, <a href="https://blog.google/innovation-and-ai/products/gemini-app/next-evolution-gemini-app/">Spark</a> will not autonomously make purchases. Users will be given explicit opportunities to review and approve any transaction before it goes through. But Google has built the infrastructure for a more autonomous future. Vidhya Srinivasan, who leads Google's ads and commerce teams, introduced the <a href="https://cloud.google.com/blog/products/ai-machine-learning/announcing-agents-to-payments-ap2-protocol">Agent Payments Protocol</a>, or AP2 — a system designed to let AI agents make secure purchases within user-defined boundaries.</p><p>The concept works like this: a user tells their agent the specific brands, products, and spending limits they're comfortable with. If the criteria are met, the agent can automatically complete a purchase. AP2 creates what Google describes as a transparent, verifiable link between the user, the merchant, and payment processors, using privacy-preserving technology and tamper-proof digital mandates to ensure the agent is acting within its authorization. AP2 also generates a permanent digital paper trail, so that if a return is needed, the user and the merchant are looking at the same record. Google plans to bring AP2 to its products in the coming months, starting with Gemini Spark.</p><p>The system is underpinned by the <a href="https://ucp.dev/">Universal Commerce Protocol (UCP)</a>, an open-source standard Google announced earlier this year that gives agents and commerce systems a common language across the entire shopping journey. The <a href="https://github.com/Universal-Commerce-Protocol/ucp/discussions/379">UCP Tech Council</a> now includes <a href="https://www.amazon.com/">Amazon</a>, <a href="https://www.meta.ai/">Meta</a>, <a href="https://microsoft.com/">Microsoft</a>, <a href="https://www.salesforce.com/">Salesforce</a>, and <a href="https://stripe.com/">Stripe</a> — a remarkable coalition that underscores how seriously the industry takes the prospect of agent-driven commerce.</p><p>Google also announced the <a href="https://blog.google/products-and-platforms/products/shopping/google-shopping-cart/">Universal Cart</a>, an intelligent shopping cart that works across merchants and Google services. Users can add items while browsing Search, chatting with Gemini, watching YouTube, or reading Gmail. The cart then works in the background — tracking price drops, surfacing deals based on payment card perks, and even flagging product incompatibilities. The shopping infrastructure is rolling out in the U.S. this summer across Search and the Gemini app, with YouTube and Gmail to follow.</p><h2><b>How Google, OpenAI, Microsoft, Anthropic, and Apple are racing to build the definitive AI agent</b></h2><p>The announcement lands in the middle of the most intense competitive period in AI history. <a href="https://www.google.com/">Google</a>, <a href="https://microsoft.com/">Microsoft</a>, <a href="https://openai.com/">OpenAI</a>, <a href="https://www.anthropic.com/">Anthropic</a>, and <a href="https://www.apple.com/">Apple</a> are all racing to ship autonomous agents that can do real work — and each is placing a fundamentally different architectural bet on how to get there.</p><p>OpenAI recently unified its <a href="https://openai.com/index/introducing-operator/">Operator</a> and <a href="https://openai.com/index/introducing-deep-research/">deep research</a> capabilities into <a href="https://chatgpt.com/features/agent/">ChatGPT agent</a> — a system that brings together website interaction, information synthesis, and conversational intelligence. It carries out tasks using its own virtual computer, shifting between reasoning and action to handle complex workflows. The company emphasizes that users remain in control, with ChatGPT requesting permission before taking consequential actions. But the product has faced scrutiny over reliability. OpenAI's Computer-Using Agent scores 38.1% on <a href="https://os-world.github.io/">OSWorld</a>, the industry benchmark for computer use tasks, while humans score over 72%.</p><p>Anthropic launched its <a href="https://platform.claude.com/docs/en/agents-and-tools/tool-use/computer-use-tool">Claude Computer Use Agent</a> in research preview in March, giving Claude the ability to see, navigate, and control a user's desktop — clicking buttons, opening applications, filling spreadsheets, and completing multi-step workflows. <a href="https://www.anthropic.com/product/claude-cowork">Claude Cowork</a> handles tasks autonomously — users give it a goal and Claude works on their computer, local files, and applications to return a finished deliverable. Anthropic has iterated aggressively, recently shipping ten pre-built financial agents and pursuing <a href="https://finance.yahoo.com/news/microsoft-and-anthropic-team-up-to-bring-claude-cowork-to-microsoft-365-130001836.html?guccounter=1&amp;guce_referrer=aHR0cHM6Ly93d3cuZ29vZ2xlLmNvbS8&amp;guce_referrer_sig=AQAAAHf-_bBGe7n63ZmL9WvbJbVBUGvQZot0f8rsq87h8bUNAIiqZczpokQ3tX9ArNpd3yadf_i7gxP_a35_uPzOBFRnIFxWOzRGqPeocr5xUZNWqXDf5QeCOq4ADeZlPq3-k3ktkDu16dQ56dOTJTsRziQVGltoklvhgAlV0ig6jmM1">deep Microsoft 365 integration</a>.</p><p>Microsoft introduced <a href="https://www.microsoft.com/en-us/microsoft-365/blog/2026/03/09/copilot-cowork-a-new-way-of-getting-work-done/">Copilot Cowork</a> to move beyond chat and into execution — helping users delegate real tasks and have them completed. Cowork runs in the cloud, meaning users don't have to worry about closing their laptop. The system is grounded in Work IQ, Microsoft's intelligence layer that understands organizational data, tools, and structure. The shift moves Copilot from a sidebar helper to an orchestrator of autonomous agents.</p><p>Apple is also preparing a <a href="https://techcrunch.com/2026/05/17/apples-siri-revamp-could-include-auto-deleting-chats/">revamped Siri for WWDC 2026</a> that will act as an "always-on agent" capable of handling tasks across apps using personal data. Google's Gemini models will help power the upgraded Siri through a multi-year deal reportedly costing Apple around $1 billion per year.</p><p>The convergence is unmistakable: every major platform is moving from assistants that talk to agents that act. But each is approaching the problem differently. OpenAI's agent operates primarily through a browser. Anthropic's works directly on a user's desktop. Microsoft's is tightly bound to the Office 365 ecosystem. Apple's emphasizes on-device processing and privacy. Google's approach with Spark is distinctive in its bet on cloud persistence and deep integration with its own services. </p><p>Rather than controlling a user's screen pixel by pixel, Spark works through structured integrations — Google's own <a href="https://developers.google.com/workspace/explore">Workspace APIs</a>, and increasingly, third-party connections through MCP. The advantage is reliability and speed: structured tool use is far more predictable than screen-reading. The disadvantage is that Spark, at least initially, can only act within the systems it's been connected to.</p><h2><b>The AI model behind Spark processes trillions of tokens a day — and Google says it could save enterprises billions</b></h2><p>Spark's capabilities are inseparable from the model that drives it. <a href="https://blog.google/innovation-and-ai/products/gemini-app/next-evolution-gemini-app/">Gemini 3.5 Flash</a>, also announced Monday, is Google's new workhorse AI model — designed specifically for the demands of agentic workflows.</p><p>The performance claims are important. Google says <a href="https://blog.google/innovation-and-ai/products/gemini-app/next-evolution-gemini-app/">3.5 Flash</a> outperforms its previous frontier model, <a href="https://deepmind.google/models/gemini/pro/">Gemini 3.1 Pro</a>, across nearly all benchmarks, while running four times faster than comparable frontier models in terms of output tokens per second. An even more optimized version, available within Google's <a href="https://developers.googleblog.com/build-with-google-antigravity-our-new-agentic-development-platform/">Antigravity</a> development platform, runs twelve times faster.</p><p>Pichai framed the economics bluntly. Companies processing roughly one trillion tokens per day on Google Cloud — a figure he said top enterprise customers are hitting — could save over $1 billion annually by shifting 80% of their workloads to a mix of Flash and frontier models like 3.5 Pro. In a market where, as Pichai noted, CIOs are already "blowing through their annual token budgets and it's only May," the cost argument may matter as much as the capability argument.</p><p>Internally, Google's own developers have been consuming <a href="https://blog.google/innovation-and-ai/products/gemini-app/next-evolution-gemini-app/">Gemini 3.5 Flash</a> at a staggering and rapidly accelerating pace. In March, Google was processing about half a trillion tokens per day internally. That figure has since grown to more than three trillion — doubling roughly every few weeks. Pichai described this as a "powerful feedback loop" that continually improves the model.</p><p>Koray Kavukcuoglu, CTO of Google DeepMind and Chief AI Architect for Google, said the model's speed is what makes agentic use cases practical. "3.5 Flash is especially good when deploying multiple agents simultaneously and completing long-running tasks," he said during the briefing, adding that Google had successfully tested agents building "a working operating system entirely from scratch."</p><p>The 3.5 Pro model, the more powerful sibling, is currently being tested internally and will roll out next month.</p><h2><b>What Gemini Spark costs and where it fits in Google's new subscription tiers</b></h2><p><a href="https://blog.google/innovation-and-ai/products/gemini-app/next-evolution-gemini-app/">Gemini Spark</a> will be available to <a href="https://gemini.google/subscriptions/">Google AI Ultra</a> subscribers. The company is simultaneously restructuring its subscription tiers to make the technology more accessible. A new Ultra plan at $100 per month provides a 5x higher usage limit than the Pro plan, along with priority access to Antigravity and 20TB of cloud storage. The top-tier Ultra plan drops from $250 to $200 per month, with a 20x higher usage limit and access to the full suite of capabilities.</p><p>Both tiers include Gemini Spark, the Daily Brief agent — a proactive morning digest that triages email, calendar, and tasks overnight — and access to the new Gemini Omni and 3.5 Flash models. The pricing positions Spark as a premium product — more expensive than Anthropic's Claude Pro at $20 per month, but comparable to the higher tiers of competing products like <a href="https://support.claude.com/en/articles/11049741-what-is-the-max-plan">Claude Max</a> ($100–$200/month) and OpenAI's <a href="https://chatgpt.com/plans/pro/">ChatGPT Pro</a> ($200/month).</p><h2><b>Why privacy, reliability, and ecosystem lock-in could undermine Google's agent ambitions</b></h2><p>The risks are real and multidimensional.</p><p>Reliability remains the industry's greatest challenge. Even the best AI models hallucinate, misinterpret instructions, and make errors that a human would never make. An agent that drafts an email to the wrong person, misreads a spreadsheet figure, or sends a payment to the wrong merchant could create consequences that are difficult to reverse. Google's approach of requiring explicit approval for high-stakes actions like spending money or sending emails is a sensible safeguard — but it also limits how autonomous the agent can actually be. An agent that asks for confirmation at every turn isn't much of an agent at all.</p><p>Privacy is another concern. Spark's ability to synthesize information across a user's entire Gmail inbox, calendar, documents, and chat history means it has an extraordinarily deep view of a person's digital life. Google says Spark operates on a fully managed, secure runtime with isolated ephemeral virtual machines, encrypted credentials, and Data Loss Prevention policies. But the concentration of personal context in a single AI system — accessible through natural language — creates a surface area that will attract scrutiny from regulators, privacy advocates, and security researchers.</p><p>Market timing is uncertain, too. The consumer appetite for always-on AI agents is unproven at scale. Google says the Gemini app has 900 million monthly users, but it's unclear how many of those users are ready for the conceptual leap from "ask a question, get an answer" to "delegate a task, trust the outcome." The history of digital assistants — from Clippy to early Siri to Alexa — is littered with products that promised proactive intelligence and delivered frustration.</p><p>And then there is the question of ecosystem lock-in. Spark works best within Google's own services. While MCP connections to third-party apps will broaden its reach, the initial experience is one of deep Workspace integration. For the billions of people who live inside Google's ecosystem, this is a natural fit. For those who split their digital lives across Microsoft, Apple, and other platforms, Spark's utility will be more limited — at least initially.</p><p>Woodward acknowledged as much when asked whether Spark would remain confined to the Google ecosystem. "It's going to be cross-platform in two ways," he said — through MCP integrations with third-party apps, and through availability on the web, Android, and iOS, with tasks syncing across devices via the cloud.</p><h2><b>The real test for Gemini Spark isn't whether it can do the work — it's whether people will let it</b></h2><p>Google's bet with <a href="https://blog.google/innovation-and-ai/products/gemini-app/next-evolution-gemini-app/">Gemini Spark</a> is that the AI industry's center of gravity is shifting from models that think to systems that act — and that the company best positioned to win that transition is the one with the most comprehensive set of consumer services to act within. It is a bet backed by enormous infrastructure investment. Google expects to spend approximately $180 to $190 billion in capital expenditure this year — roughly six times what it spent in 2022 — much of it on the AI compute required to run agents like Spark at scale for hundreds of millions of users.</p><p>The technology, in other words, is arriving. The models are fast enough, the integrations deep enough, the payment rails secure enough. Google has built a system that can draft your emails, organize your calendar, monitor your inbox, and soon enough, spend your money — all while you sleep.</p><p>But the hardest problem in artificial intelligence has never been making a machine capable. It has been making a human comfortable. For two decades, Google's core promise has been ten blue links and a search box — a transaction built on the assumption that the user is in control. Gemini Spark asks users to renegotiate that relationship entirely, to hand a set of keys to a system that is brilliant, tireless, and still, by its maker's own admission, best compared to a teenager with a debit card.</p><p>Gemini Spark rolls out to trusted testers this week, with a broader beta for U.S. Google AI Ultra subscribers expected next week.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[New ways to create and get things done in Google Workspace]]></title>
<description><![CDATA[Announcing new voice capabilities in Gmail, Docs and Keep, a new design tool called Google Pics and updates to AI Inbox.]]></description>
<link>https://tsecurity.de/de/3530330/it-nachrichten/new-ways-to-create-and-get-things-done-in-google-workspace/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3530330/it-nachrichten/new-ways-to-create-and-get-things-done-in-google-workspace/</guid>
<pubDate>Tue, 19 May 2026 20:03:13 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<img src="https://storage.googleapis.com/gweb-uniblog-publish-prod/images/GoogleWorkspace-IO.max-600x600.format-webp.webp">Announcing new voice capabilities in Gmail, Docs and Keep, a new design tool called Google Pics and updates to AI Inbox.]]></content:encoded>
</item>
<item>
<title><![CDATA[Google can now vibe-code you an Android app]]></title>
<description><![CDATA[Google is announcing a major upgrade to one of its vibe coding platforms: Beginning today, you can now use AI Studio to build native Android apps. With Google AI Studio, you can prompt your idea for an app and preview it with an embedded emulator of Android. When you want to try it out on […]]]></description>
<link>https://tsecurity.de/de/3530318/it-nachrichten/google-can-now-vibe-code-you-an-android-app/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3530318/it-nachrichten/google-can-now-vibe-code-you-an-android-app/</guid>
<pubDate>Tue, 19 May 2026 20:02:56 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Google is announcing a major upgrade to one of its vibe coding platforms: Beginning today, you can now use AI Studio to build native Android apps. With Google AI Studio, you can prompt your idea for an app and preview it with an embedded emulator of Android. When you want to try it out on […]]]></content:encoded>
</item>
<item>
<title><![CDATA[Updates to the Android XR SDK: Introducing Developer Preview 4]]></title>
<description><![CDATA[Posted by Stevan Silva, Group Product Manager and Amy Zeppenfeld, Developer Relations EngineerToday we're excited to launch Developer Preview 4 of the Android XR SDK, continuing our focus on unifying cross-device development for headsets, wired XR glasses, and intelligent eyewear. To keep our pla...]]></description>
<link>https://tsecurity.de/de/3530272/android-tipps/updates-to-the-android-xr-sdk-introducing-developer-preview-4/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3530272/android-tipps/updates-to-the-android-xr-sdk-introducing-developer-preview-4/</guid>
<pubDate>Tue, 19 May 2026 19:56:35 +0200</pubDate>
<category>🤖 Android Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[
<img src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj9qKZCLcJmsSe9qRHpaIOBfW0rlMCfVdFM_-_fwyfW5IlhU11azXpGtWNnrFnrylqm6cDN-gyXQ2A9Tj5WDTbHj_YJF7u024pWDhkn9Wwe47WTdkDIib-wyjMWRoSnbN-bB5zLJjizVAy5-NlFP_A61wTWggOvLZkQu1WxIZGeMsc0LtFOhzd7DkAiVvY/s2048/GoogleForDevelopers-AndroidText-StrapiMetacard-2048x1323.png">



<div><div class="separator"><i>Posted by Stevan Silva, Group Product Manager and Amy Zeppenfeld, Developer Relations Engineer</i></div></div><div><div class="separator"><a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh2c0ihA3gGLvIsVHFAW4TuJWUOmDEuotU6v7-9Jhcx4Soff-W_ZMTF35n046dcKu2NGjwBDA4R9n08g95W3e1TMfwoRrap0Y9agKZ7nbFO2dmwHoV7cSPopjngCnVajA-bS5XsDMeqaiGg1cfvAmQsSTfvxpx-ibR5DF3rnNIlBy9vE93UjjQMpGNVjhA/s4209/GoogleForDevelopers-AndroidText-Blogger-4209x1253.png"><img border="0" data-original-height="1253" data-original-width="4209" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh2c0ihA3gGLvIsVHFAW4TuJWUOmDEuotU6v7-9Jhcx4Soff-W_ZMTF35n046dcKu2NGjwBDA4R9n08g95W3e1TMfwoRrap0Y9agKZ7nbFO2dmwHoV7cSPopjngCnVajA-bS5XsDMeqaiGg1cfvAmQsSTfvxpx-ibR5DF3rnNIlBy9vE93UjjQMpGNVjhA/s16000/GoogleForDevelopers-AndroidText-Blogger-4209x1253.png"></a></div><br><p dir="ltr"><br></p><p dir="ltr">Today we're excited to launch Developer Preview 4 of the Android XR SDK, continuing our focus on unifying cross-device development for headsets, wired XR glasses, and <a href="https://blog.google/products-and-platforms/platforms/android/android-xr-io-2026">intelligent eyewear</a>. To keep our platform intuitive, we are adopting more descriptive naming for our form factors, where AI glasses are now audio glasses and display AI glasses are now display glasses, with these changes appearing in our documentation starting today.</p>
  
  <p dir="ltr">This release is packed with updates that help you build incredible experiences for XR devices, enable deeper immersive experiences on XR headsets, and streamline the path for creating augmented experiences on audio and display glasses. Also, our core libraries—including XR Runtime, Jetpack SceneCore, and ARCore for Jetpack XR— will be officially moving to Beta soon!</p>
  
  <p dir="ltr">To give you early access to hardware and resources for building immersive and augmented experiences on upcoming devices—like display and audio glasses and XREAL’s Project Aura — we’re announcing the <a href="https://goo.gle/Catalyst_IO26">Android XR Developer Catalyst Program</a>. Learn more and <a href="http://g.co/dev/catalyst">start your application</a> today.</p>

  <h3>Building Augmented Experiences for Audio and Display Glasses</h3>
  
  <p dir="ltr">Starting out with our libraries for augmented experiences, Developer Preview 4 introduces new APIs that help you create and test your apps.</p>

  <b><span>Jetpack Projected: Device Availability and ProjectedTestRule APIs</span></b>
  
  <p dir="ltr">The Jetpack Projected library helps bridge app experiences from the phone to the user's field of view. We've added the <a href="https://developer.android.com/develop/xr/jetpack-xr-sdk/ai-glasses/check-availability">Device Availability API</a>, which consolidates wear state and connectivity signals into standard Android <a href="https://developer.android.com/reference/kotlin/androidx/lifecycle/Lifecycle.State">Lifecycle.State</a> values. This lets you adjust your applications behavior based on whether the device is worn.</p>

  <pre>val xrDevice = XrDevice.getCurrentDevice(projectedContext)

// Observe the device lifecycle flow
xrDevice.getLifecycle().currentStateFlow
    .collect { state -&gt;
        when (state) {
            Lifecycle.State.STARTED -&gt; { /* Device is available (worn) */ }
            Lifecycle.State.CREATED -&gt; { /* Device is unavailable (not worn) */ }
            Lifecycle.State.DESTROYED -&gt; { /* Device is DISCONNECTED */ }
        }
    }
  </pre>

  <p dir="ltr">To simplify testing, the new <code>ProjectedTestRule</code> API in the <code>projected-testing</code> artifact automates the setup of projected test environments. This helps you write clean, reliable unit tests without the boilerplate code.</p>

  <pre>// from the 'androidx.xr.projected:projected-testing:1.0.0-alpha07' artifact
@get:Rule
val projectedTestRule = ProjectedTestRule()

@Test
fun testProjectedContextInitialization() {
    // by default, ProjectedTestRule automatically creates and connects
    // a projected device before each test
    val projectedContext = ProjectedContext.createProjectedDeviceContext(context)

    // assert the projected context is successfully initialized
    assertThat(projectedContext).isNotNull()
}
  </pre>

  <b><span>Jetpack Compose Glimmer: Google Sans Flex and new components</span></b>
  
  <p dir="ltr">Our UI library for display glasses, Jetpack Compose Glimmer, now includes <a href="https://fonts.google.com/specimen/Google+Sans+Flex">Google Sans Flex</a> for improved legibility on optical see-through displays. We’ve also added several interactive components:</p>

  <ul>
    <li><a href="https://developer.android.com/develop/xr/jetpack-xr-sdk/jetpack-compose-glimmer/stacks">Stacks</a>: Designed for touchpad-optimized groups, showing one item at a time.</li>
    <li><a href="https://developer.android.com/develop/xr/jetpack-xr-sdk/jetpack-compose-glimmer/title-chips">Title Chips</a>: Provides categorization and context for content cards.</li>
  </ul>

  <div class="separator"><img border="0" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjURjqIjRqx4w887_z6WFLsKAuBhvNmzYshrqVno0lO9-MBzLh087wOBCvYEL30LBpi62QIfDXB23X_1cz_v3VbAdQ0VvjZ-jQq48QPOs2f41WmveveW8OgndqoKg_bc4fHQVWUHfPiExBnEmCXhyphenhyphentkXDh53GBE4RqUvVvbQvtQbTRBuT2rqAVtR6y3gPs/s16000/glimmer.gif"></div>

  <h3>Building Immersive Experiences for XR Headsets and Wired XR Glasses</h3>
  
  <p dir="ltr">If you're looking to build fully immersive experiences for XR Headsets and wired XR Glasses, we have several big updates.</p>

  <b><span>Beta Transition &amp; Modern Architecture</span></b>
  
  <p dir="ltr">XR Runtime, Jetpack SceneCore, and the ARCore for Jetpack XR perception features (<a href="https://developer.android.com/develop/xr/jetpack-xr-sdk/arcore/depth">Depth Maps</a>, <a href="https://developer.android.com/develop/xr/jetpack-xr-sdk/arcore/face">Eye/Hand Tracking</a>, Hit Testing, and <a href="https://developer.android.com/develop/xr/jetpack-xr-sdk/arcore/anchors">Spatial Anchors</a>) will soon move to Beta, so we’ve streamlined the Jetpack XR APIs. We've removed legacy Guava and RxJava3 packages in favor of a modern, Kotlin-first architecture.</p>

  <b><span>Jetpack SceneCore: glTF and Custom Meshes</span></b><p dir="ltr">We're expanding 3D model capabilities by adding the ability to fine tune 3D models and access specific nodes with a 3D model. Using <a href="https://developer.android.com/reference/androidx/xr/scenecore/GltfModelNode">GltfModelNode</a>, you can modify properties like pose, materials, and textures, and even run <a href="https://developer.android.com/reference/kotlin/androidx/xr/scenecore/GltfAnimation">animations</a> for specific nodes.</p>

  <pre>// Create a new PBR material
pbrMaterial = KhronosPbrMaterial.create(
    session = xrSession,
    alphaMode = AlphaMode.OPAQUE
)

// Load a texture.
val texture = Texture.create(
    session = xrSession,
    path = Path("textures/texture_name.png")
)

// Apply the texture and configure occlusion
pbrMaterial.setOcclusionTexture(
    texture = texture,
    strength = 0.5f
)

// Access the hierarchy of nodes
val entityNodes = entity.nodes

// Find the specific node
val myEntityNode = entityNodes.find { it.name == "node_name" }

// Apply the PBR material override
myEntityNode?.setMaterialOverride(
   material = newMaterial
)
  </pre>

  <div class="separator"><img border="0" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhD-R-O2D-AHZ_E-_VoYSIIAaU0Jfd2UdKZO3ySh1LrfIj-TC3L0GyhkmIo0TgCatKvwB4aarmdUx5GvwXxyOTReuijHhQJlj5n0ZSZsRKxP7GRnwifuajP21FDYe5vqa-LWHW9C4cAyozx_JYFqEix4Si6-R5nZ6-qXQ5ccnZnyf7fzUJLT0aBnHkQDxU/s16000/custom_material.gif"></div><div><br></div><div><br></div>We're also bringing Custom Meshes to SceneCore. Custom meshes let you build geometry on the fly programmatically, which is ideal for creating custom 3D models. This feature will launch as experimental, so try it out and let us know what you think!</div><div><br> 

  <pre>// Create the mesh<span><p dir="ltr"><span>val roadMesh =</span></p><p dir="ltr"><span>    CustomMesh.BuilderFromMeshData(session, roadVertexLayout)</span></p><p dir="ltr"><span>        .addVertexData(ByteBufferRegion(roadDataBuffer, 0, vertexDataSize))</span></p><p dir="ltr"><span>        .setIndexData(ByteBufferRegion(roadDataBuffer, vertexDataSize, indexDataSize))</span></p><p dir="ltr"><span>        .setTopology(MeshSubsetTopology.TRIANGLES)</span></p><p dir="ltr"><span>        .build()</span></p><br><p dir="ltr"><span>// Define the material</span></p><p dir="ltr"><span>val roadMaterial = KhronosPbrMaterial.create(session, AlphaMode.OPAQUE)</span></p><br><p dir="ltr"><span>// Instantiate the entity using the custom mesh and material</span></p><p dir="ltr"><span>val roadEntity =</span></p><p dir="ltr"><span>    MeshEntity.create(</span></p><p dir="ltr"><span>        session,</span></p><p dir="ltr"><span>        roadMesh,</span></p><p dir="ltr"><span>        listOf(roadMaterial),</span></p><p dir="ltr"><span>        pose = roadPose,</span></p></span>)<br></pre>

  <div class="separator"><br></div><div class="separator"><img border="0" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjaZ_4o2joX1mfFhSoQzrEmLPItDnayQviaz43vthTtDPe-zbCUQT-nZTvRcCca3L2XBo2iLDHA91xRty-HqClNvPQoOEZHzAnYWzZnJvhBL1-3KuJrm_3HluzazcmmNWYW_zBhMD-GGSnp039rREaJ9dH3AO9U2if1uSJ0FR8RGjKJuAW5gjaafY3R0kA/s16000/custom_mesh.gif"></div>

  <b><span><div><b><span><br></span></b></div>Compose for XR: Native glTF Support</span></b>
  
  <p dir="ltr">We now have native glTF support directly in Compose for XR with <a href="https://developer.android.com/reference/kotlin/androidx/xr/compose/subspace/SpatialGltfModel.composable">SpatialGltfModel</a>. Use this along with <a href="https://developer.android.com/reference/kotlin/androidx/xr/compose/subspace/SpatialGltfModelState#SpatialGltfModelState(androidx.xr.compose.subspace.SpatialGltfModelSource)">SpatialGltfModelState</a> to access <a href="https://developer.android.com/reference/kotlin/androidx/xr/compose/subspace/SpatialGltfModelState#nodes()">nodes</a> and <a href="https://developer.android.com/reference/kotlin/androidx/xr/compose/subspace/SpatialGltfModelState#animations()">animations</a> in the glTF model, or use them to add textures and materials to your 3D models.</p>

  <pre>   val myGltfModelState = rememberSpatialGltfModelState(
        source = SpatialGltfModelSource.fromPath(
            Paths.get("models/my_animated_model.glb")
        )
    )

    val myGltfAnimation =
        myGltfModelState.animations.find { it.name == "animation_name" }

    DisposableEffect(myGltfAnimation) {
        myGltfAnimation?.loop()

        onDispose {
            myGltfAnimation?.stop()
        }
    }

    SpatialGltfModel(state = myGltfModelState, modifier = modifier)
  </pre>

  <div class="separator"><img border="0" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiV_PBd_vb1mDF0GbmR44I7E-2VMK2kQFhDK5_MW4dLGWyH-kXdpMKUmDf_7PzprxwMaNpUQgtMTHkJ3-CjEumK-Zd_Y4XiMqK78dxwk78eZel-wh3udnwCEtBFdgfxvX0oY-JyMK_gDAtc-4tKH5ZgXAIs4NaNT6eqZBu9n4Fl37tK8vYk8iKwPD_5VUo/s16000/animated_tiger.gif"></div>

  <b><span><div><b><span><br></span></b></div>ARCore for Jetpack XR: Geospatial API Preview for Wired XR Glasses</span></b>
  
  <p dir="ltr">We’re also providing an early preview of the Geospatial API for wired XR Glasses in ARCore for Jetpack XR. This update enables high-precision anchoring of digital content tied to real-world locations in over 87 countries.</p>
  
  <p dir="ltr">By combining ARCore’s Visual Positioning System (VPS) with the reasoning and audio capabilities of the Gemini Live API, you can create contextually aware experiences that understand both the location and position of your user. Imagine building an immersive, AI-guided walking tour that provides real-time audio descriptions of nearby places, seamlessly blending digital information with the physical environment.</p><div class="separator"><img border="0" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjEwhzig0cd_Ku_6ge9WjDQLaMyKNwnSO5791yXlhEYx68mYW3joOpt8DC0juWbW13HwNP_sS-SUFENSjpW9CWpPCdFUTL8a-jBSsYtHMkouhuCWvHnJ18P0lTwmUXGFwRatXeGiTt_RVn46fbWOgCag0iEz8gApm5A6QudGKpo7xc3ieqOte-8-c0uMS8/s16000/Aura%20Geospatial%20Tour%20Demo%20-%20Draft%2001.gif"></div><br><h3>Start Building the Future Today</h3><p dir="ltr">It's an amazing time to develop for Android XR. With the Jetpack XR SDK moving to Beta soon and a robust set of new tools at your fingertips, explore each of the following areas to get your app's experiences ready for XR!</p>

  <b><span>Read the documentation, explore the samples, and check out the XR experiments</span></b>
  
  <p dir="ltr">Head to the <a href="http://developer.android.com/xr">official Android Developer site</a> for full technical guides, API reference, and instructions on setting up the new emulator. Get inspired with our samples and experiments. See how we've used these APIs to build immersive spatial layouts, load 3D models, explore spatial audio, and more!</p>

  <ul><li>Visit <a href="http://developer.android.com/xr">the Android XR webpage</a></li><li><a href="https://developer.android.com/develop/xr/samples">Explore XR examples</a></li><li><a href="https://developer.android.com/develop/xr/experiments">Explore XR experiments</a></li></ul><b><span><div><b><span><br></span></b></div>Check out what's new for game engines</span></b><br><p dir="ltr">We've added official support for <a href="https://www.unrealengine.com/">Unreal Engine</a> and <a href="https://godotengine.org/">Godot</a>, and we've launched two new tools to accelerate development for Android XR with Unity and the <a href="https://developer.android.com/xr/axrif">Android XR Interaction Framework</a>. And, based on your feedback, we are introducing the <a href="https://developer.android.com/xr/engine-hub">Android XR Engine Hub</a> to allow you to run your experiences directly from your preferred engine,</p>

  <ul>
    <li><a href="https://android-developers.googleblog.com/2026/05/android-xr-updates-unity-unreal-godot.html">Read the blog post about what's new for game engines</a></li>
  </ul>

  <b><span><div><b><span><br></span></b></div>Apply for the <a href="http://g.co/dev/catalyst">Android XR Developer Catalyst Program</a></span></b>
  
  <p dir="ltr">Don’t miss your chance to build for the latest Android XR hardware. Apply today for the opportunity to gain access to pre-release hardware, including our audio and display glasses prototype and XREAL’s Project Aura.</p>

  <ul>
    <li><a href="http://g.co/dev/catalyst">Learn more and apply today.</a></li>
  </ul>

  <p dir="ltr">We look forward to seeing the amazing XR experiences you build as we move toward the launch of more Android XR devices later this year!<br></p><p dir="ltr">Explore this announcement and all Google I/O 2026 updates on <span></span><a href="https://io.google/2026/?utm_source=blogpost&amp;utm_medium=pr&amp;utm_campaign=devblogs&amp;utm_content=" rel="noopener nofollow noreferrer" target="_blank">io.google<span></span></a>.</p>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Coming Bright Up: Apple’s AI moment looms]]></title>
<description><![CDATA[Apple has confirmed this year’s Worldwide Developers Conference (WWDC) will take place June 8-12. The show begins with a keynote speech likely to be Tim Cook’s final public appearance as Apple’s CEO. His successor, John Ternus, will also be in the spotlight, but perhaps not quite as much as Apple...]]></description>
<link>https://tsecurity.de/de/3529810/it-nachrichten/coming-bright-up-apples-ai-moment-looms/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3529810/it-nachrichten/coming-bright-up-apples-ai-moment-looms/</guid>
<pubDate>Tue, 19 May 2026 18:18:44 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Apple has confirmed this year’s <a href="https://www.apple.com/newsroom/2026/05/apple-kicks-off-worldwide-developers-conference-on-june-8/" target="_blank" rel="noreferrer noopener">Worldwide Developers Conference</a> (WWDC) will take place June 8-12. The show begins with a keynote speech likely to be Tim Cook’s final public appearance as Apple’s CEO. His successor, <a href="https://fortune.com/article/who-is-john-ternus-new-apple-ceo-tim-cook-retirement/" target="_blank" rel="noreferrer noopener">John Ternus</a>, will also be in the spotlight, but perhaps not quite as much as Apple’s promised smart Siri successor.</p>



<p>Getting AI right is <a href="https://www.computerworld.com/article/4164979/apple-will-be-behind-on-ai-until-it-isnt.html">incredibly important to the company</a> this year, and Apple seems to recognize that. The <a href="https://www.applemust.com/apple-announces-june-8-wwdc/#google_vignette" target="_blank" rel="noreferrer noopener">official media invitation</a> features a brightly glowing Swift logo with the tagline “<em>Coming Bright Up</em>,” which some see as a hint at the advanced AI capabilities Apple intends making available. It also hints at the new Siri user interface Apple is building, while the use of a Swift suggests the introduction of additional Foundation Models with which developers can add AI tools to their products.</p>



<p>On the developer website, Apple’s media images all show that bright glow, which also hints at potential improvements to <a href="https://www.computerworld.com/article/4100974/there-is-no-dye-in-apples-design-team.html">Liquid Glass</a>. There’s no doubt at all that the entire industry will be tuned into WWDC to find out where Apple is going with AI. So, no pressure there, right?</p>



<h2 class="wp-block-heading"><strong>AI tools developers can use</strong></h2>



<p>The company told developers to expect more than 100 new videos about tools, technologies, and design, many of them to be revealed during the Platforms State of the Union address, which follows the keynote.</p>



<p>“WWDC26 will kick off June 8 with the Keynote and Platforms State of the Union, introducing incredible updates for Apple platforms, including AI advancements and exciting new software and developer tools,” Apple said, announcing the event.</p>



<p>Apple <a href="https://www.computerworld.com/article/4167906/apple-intelligence-hype-cost-the-company-250m.html">knows the world is watching</a> and seems unlikely to want to disappoint its audience again, though the way it framed this in suggests some of the improvements will be for developers, with end users to benefit later. This is the approach Apple has taken with Foundation Models so far, though it isn’t yet clear if the company intends introducing a paid tier of APIs for developers. I’d consider that a risk at this stage, given the perception Apple faces.</p>



<h2 class="wp-block-heading"><strong>What’s at stake?</strong></h2>



<p>A confluence of challenges means Apple is <a href="https://www.computerworld.com/article/4170159/wwdc-from-nextstep-for-apple-to-apples-next-step-for-ai.html">perceived as having fallen behind on AI</a>. That’s got to hurt. The company is under a lot of pressure to push back against that viewpoint, and while that’s a challenge, it’s also a big opportunity. </p>



<p>Wedbush Securities analyst <a href="https://www.investors.com/research/ibd-stock-of-the-day/apple-stock-buy-zone-wwdc-2026/" target="_blank" rel="noreferrer noopener">Dan Ives</a> says Apple is a “sleeping tech giant” poised for growth if it gets the mix right, predicting the company’s ecosystem could become the “consumer hub” of AI, to the extent that 20% of the global population will use Apple to access it. At Morgan Stanley, analyst Erik Woodring thinks what Apple is about to introduce will prompt a mass upgrade and sees revenue potential in AI services for the company. In general, people seem to agree that Apple’s ecosystem is more than capable of handling the demands of AI; the challenge is properly integrating it within Apple’s environment.</p>



<h2 class="wp-block-heading"><strong>What is Apple Planning?</strong></h2>



<p>At the moment, <a href="https://www.computerworld.com/article/4168225/wwdc-2026-how-apple-can-take-a-great-leap-in-ai.html">strong speculation suggests</a> Apple has added new Writing Tools, improved image generation on its devices, and has worked with Google Gemini to extend the number of available APIs developers can use, as well as enhancing contextual understanding by Siri.</p>



<p>Any one of these things would have impressed us all at one time, but in an AI world of Claude, Gemini, or even Grok, some will likely see even these enhancements as weak sauce. Additional key expectations include:</p>



<ul class="wp-block-list">
<li>Siri will become a chatbot-style assistant in the form of an LLM-enhanced app, built in partnership with Google Gemini.</li>



<li>Apple will <a href="https://www.computerworld.com/article/4171288/apples-app-store-model-for-ai.html">give users a choice of AI apps</a>, including the ability to make whatever they choose the default on their system.</li>



<li>Siri will gain a new interface hosted in the Dynamic Island on devices that support it.</li>



<li>Siri might also gain the ability to string instructions together using a combination of text/speech and Shortcuts abilities. </li>



<li>You should see improved contextual awareness; Siri will be able to “see’”what’s on your screen and take relevant actions across one or more third-party apps.</li>



<li>Those functions are likely to be delivered by App Intents, which permits developers to make app functions available across the system without opening the apps.</li>



<li>Visual Intelligence will let the iPhone camera app identify more options, including objects and passes, such as for events and public transit.</li>



<li>Multitasking on iPads should improve, while macOS might gain some touch-based interface improvements. That could set the scene for better integration between iPad and Mac, and, of course, make a touchscreen Mac possible.</li>
</ul>



<p>Most recently, there’s been chatter about Apple introducing an iMac equipped with an M5 processor. If so, this could emerge at, or slightly before, WWDC.</p>



<p>As it does each year, the conference will feature the Apple Design Awards, Swift Student Challenge, Labs, and an in-person, 1,000 people gathering in Cupertino for the keynote. </p>



<h2 class="wp-block-heading"><strong>Watch it in real time</strong></h2>



<p>The keynote will be available to stream on Apple’s website. It will also be hosted on the Apple TV app and Apple’s YouTube channel, with playback on-demand after the event.</p>



<p><em>You can follow me on social media! Join me on <a href="https://bsky.app/profile/jonnyevanssays.bsky.social" target="_blank" rel="noreferrer noopener">BlueSky</a>,  LinkedIn, and <a href="https://social.vivaldi.net/@jonnyevans" target="_blank" rel="noreferrer noopener">Mastodon</a>.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Accelerate ML feature pipelines with new capabilities in Amazon SageMaker Feature Store]]></title>
<description><![CDATA[Today, we’re announcing three new capabilities available in SageMaker Python SDK v3.8.0. In this post, we walk through each capability with code examples you can use to get started. For complete end-to-end walkthroughs, see the accompanying notebooks for Lake Formation governance and Iceberg tabl...]]></description>
<link>https://tsecurity.de/de/3529694/ai-nachrichten/accelerate-ml-feature-pipelines-with-new-capabilities-in-amazon-sagemaker-feature-store/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3529694/ai-nachrichten/accelerate-ml-feature-pipelines-with-new-capabilities-in-amazon-sagemaker-feature-store/</guid>
<pubDate>Tue, 19 May 2026 17:34:24 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Today, we’re announcing three new capabilities available in SageMaker Python SDK v3.8.0. In this post, we walk through each capability with code examples you can use to get started. For complete end-to-end walkthroughs, see the accompanying notebooks for Lake Formation governance and Iceberg table properties in the SageMaker Python SDK repository.]]></content:encoded>
</item>
<item>
<title><![CDATA[How AI is transforming network incident response (and where it still falls short)]]></title>
<description><![CDATA[If you’ve sat through any vendor pitch in the last year, you’ve heard the promise. AI will detect the anomaly, correlate the signals, identify the root cause, maybe even remediate it. The autonomous network operations center is just around the corner.



I’ve spent close to a decade building anom...]]></description>
<link>https://tsecurity.de/de/3528494/it-security-nachrichten/how-ai-is-transforming-network-incident-response-and-where-it-still-falls-short/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3528494/it-security-nachrichten/how-ai-is-transforming-network-incident-response-and-where-it-still-falls-short/</guid>
<pubDate>Tue, 19 May 2026 11:23:03 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>If you’ve sat through any vendor pitch in the last year, you’ve heard the promise. AI will detect the anomaly, correlate the signals, identify the root cause, maybe even remediate it. The autonomous network operations center is just around the corner.</p>



<p>I’ve spent close to a decade building anomaly detection and telemetry systems at scale, and I think that promise is partly true, partly aspirational and partly misleading. The reality is messier. AI is genuinely helping in a few specific places, and it’s nowhere close to delivering in others, mostly for reasons that have nothing to do with model quality.</p>



<p>The biggest reason: we still can’t see most of what’s happening on our own networks.</p>



<h2 class="wp-block-heading">The visibility problem comes first</h2>



<p>Network operators love to talk about observability. The actual state of observability in 2026 is much less impressive than the marketing suggests. According to <a href="https://www.networkworld.com/article/4093229/netops-teams-struggle-with-ai-readiness-despite-growing-adoption.html">Broadcom’s 2026 State of Network Operations report</a>, 95% of IT professionals report lacking visibility into network segments, especially in public cloud. Only 49% believe their network can support the bandwidth and latency that AI workloads need.</p>



<p>That tracks with what I see in practice. At the scale I’ve worked, you typically have SNMP polling every few minutes, syslog arriving with variable delay and streaming telemetry on a fraction of your interfaces. Even with all of that running, the blind spots are enormous. Anything traversing a third-party network is invisible. Specific paths through ECMP fabrics are often uninstrumented. The state of a BGP decision process on a router three hops away usually require SSH and a manual look.</p>



<p>Traceroute, still one of the most-used diagnostic tools, has well-known limits. It can’t see through firewalls that block ICMP. It doesn’t handle asymmetric routing well. It gives you a snapshot of a path that may have already changed by the time you read the output. Load balancing distorts the result. Muted interfaces look identical to real packet loss. None of this is news to anyone who has run a traceroute and squinted at the output.</p>



<p>The implication for AI is direct. AI can only reason about data it has. If 30% of the relevant paths during an incident are uninstrumented, no model is going to make up for that. Better algorithms operating on the same partial data give you marginally better partial answers.</p>



<h2 class="wp-block-heading">Where AI is actually pulling its weight</h2>



<p>That said, AI is delivering real value in network operations today, just narrower than the marketing implies. Three areas in particular.</p>



<ul class="wp-block-list">
<li><strong>Anomaly detection at scale.</strong> This is the most concrete win. The basic idea is simple: instead of statically thresholding every counter (“alert when CRC errors &gt; 100”), you compare each device against its own history and against its peers. If a router’s error rate has crept up, and the dozen other routers running the same model with the same role haven’t, that device gets flagged. Across hundreds of millions of data points a day on tens of thousands of devices, no human is going to spot that drift. This is where statistical methods earn their keep, and it’s the part of “AI in network ops” that has been quietly working for a while.</li>



<li><strong>Alert correlation.</strong> During a major incident, hundreds of alerts fire at once. Most are symptoms, not causes: an interface goes down and you get the interface alarm, the BGP session alarm, the BFD alarm, downstream prefix alarms, plus every monitoring system’s reachability alarm for things behind that interface. AI can group these by topology and timing and collapse hundreds of signals into a handful of clusters. It still doesn’t tell you the root cause, but it stops you from having to mentally filter the noise. The difference between staring at 300 alerts and looking at five clusters is the difference between a long war room and a focused one.</li>



<li><strong>Pulling context together.</strong> This is the newer area where LLMs are starting to be useful. During an investigation, an engineer typically bounces between several tools: route collectors, looking glasses, syslog viewers, monitoring dashboards, ticketing, the CLI of whatever device is misbehaving. Assembling the picture is slow and mostly copy-paste. I’ve been working on an open-source tool called <a href="https://github.com/jd9091/route-sherlock">route-sherlock</a> that pulls together BGP routing data, looking glass output and historical context, and uses an LLM to write a plain-language summary of what might be going on. It doesn’t do the investigation. It compresses the first 30 minutes of context-gathering, so you start with a hypothesis instead of an empty terminal.</li>
</ul>



<p>Notice what these have in common. They all augment a human investigation. They speed up the parts that were already mechanical. None of them replace judgment.</p>



<h2 class="wp-block-heading">What AI still can’t do</h2>



<p>The harder boundary is causation in novel scenarios. Networks fail in ways that depend heavily on context. A BGP route leak looks different depending on whether it’s coming from a peer, a transit provider or an internal confederation. A fiber cut in one geography cascades differently than an identical cut elsewhere because of how traffic was pre-engineered. The same ECMP hash that worked for years can produce a microloop after a seemingly unrelated topology change.</p>



<p>The <a href="https://www.thousandeyes.com/blog/cloudflare-outage-analysis-july-14-2025">Cloudflare 1.1.1.1 outage in July 2025</a> is a useful example. For about an hour, Cloudflare’s public DNS resolver was unreachable. From the outside, it looked like a BGP hijack: another network appeared to be announcing Cloudflare’s prefixes. The actual cause was internal. A configuration error caused Cloudflare’s routes to disappear from the global routing table, and what looked like hijacking was an artifact of the withdrawal exposing the address space.</p>



<p>A pattern-matching system would have flagged the BGP anomaly and probably labeled it a hijack. The label would have been wrong. The real story required understanding the operational intent behind a config change, and that kind of context simply isn’t in the telemetry.</p>



<p>This is the core problem. AI models learn from historical patterns. The most damaging incidents are usually the ones that don’t look like anything in the training data. When an experienced engineer troubleshoots, they’re reasoning about protocol behavior, vendor implementation quirks, traffic engineering intent and recent organizational changes (“we touched the peering policy last month, could that be related?”). That mental model of the network isn’t something current AI systems have.</p>



<h2 class="wp-block-heading">Better data first, better models second</h2>



<p>The current industry instinct is to throw bigger AI models at network operations. I think that’s the wrong order of operations. The bottleneck isn’t model sophistication, it’s coverage. A more sophisticated model analyzing 70% of the relevant data will still miss things rooted in the 30% you can’t see.</p>



<p>The investments that pay off are the unglamorous ones. Expanding streaming telemetry. Instrumenting cloud-to-cloud paths. Correlating network signals with application-layer data. Running continuous synthetic probes so you’re not waiting for a customer ticket to discover a blind spot. None of it is as exciting as a generative AI demo, but it’s the part that has to come first.</p>



<p>AI’s role here is real and growing. It processes telemetry at scale, suppresses alert noise, surfaces outliers and pulls context together across tools. Those capabilities genuinely cut mean time to detect and mean time to resolve. But they augment the engineer’s investigation. They don’t replace it, and they won’t until we can actually see what’s happening on our networks end to end.</p>



<p>Is AI transforming network incident response? Yes, but not the way the slides suggest. It’s not eliminating the 2 a.m. page. It’s making the hours after the page more focused. That’s a real improvement, and it’s worth investing in. The fully autonomous NOC remains a story for another decade, and it won’t arrive until the visibility gap closes.</p>



<p><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><strong><a href="https://www.networkworld.com/expert-contributor-network/">Want to join?</a></strong></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[YouTube’s Likeness Detection Tool Is Now Available to All Adult Creators]]></title>
<description><![CDATA[YouTube is finally ready to release its Likeness Detection tool to all adult creators on the platform. After first announcing it in 2024, the company has also expanded its access to users. Last year, a select group of content creators received the tool, and in March this year, the streaming giant...]]></description>
<link>https://tsecurity.de/de/3525872/it-nachrichten/youtubes-likeness-detection-tool-is-now-available-to-all-adult-creators/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3525872/it-nachrichten/youtubes-likeness-detection-tool-is-now-available-to-all-adult-creators/</guid>
<pubDate>Mon, 18 May 2026 14:03:01 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[YouTube is finally ready to release its Likeness Detection tool to all adult creators on the platform. After first announcing it in 2024, the company has also expanded its access to users. Last year, a select group of content creators received the tool, and in March this year, the streaming giant opened the deepfake spotting tool to government officials and journalist...]]></content:encoded>
</item>
<item>
<title><![CDATA[Linux head says "AI tools are great" but they're making the security list "almost entirely unmanageable"]]></title>
<description><![CDATA[While announcing the fourth release candidate for Linux kernel 7.1, Linux head Linus Torvalds had some interesting words to say about AI.Read the full article on GamingOnLinux.]]></description>
<link>https://tsecurity.de/de/3525384/linux-tipps/linux-head-says-ai-tools-are-great-but-theyre-making-the-security-list-almost-entirely-unmanageable/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3525384/linux-tipps/linux-head-says-ai-tools-are-great-but-theyre-making-the-security-list-almost-entirely-unmanageable/</guid>
<pubDate>Mon, 18 May 2026 11:09:57 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[While announcing the fourth release candidate for Linux kernel 7.1, Linux head Linus Torvalds had some interesting words to say about AI.<p><img src="https://www.gamingonlinux.com/uploads/tagline_gallery/defaulttagline.png" alt></p><p>Read the full article on <a href="https://www.gamingonlinux.com/2026/05/linux-head-says-ai-tools-are-great-but-theyre-making-the-security-list-almost-entirely-unmanageable/">GamingOnLinux</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Intercom, now called Fin, launches an AI agent whose only job is managing another AI agent]]></title>
<description><![CDATA[The company formerly known as Intercom just did something that no major customer service platform has attempted at scale: it built an AI agent whose sole job is to manage another AI agent.Fin Operator, announced Thursday at a live event in San Francisco, is a new AI-powered system designed specif...]]></description>
<link>https://tsecurity.de/de/3520879/it-nachrichten/intercom-now-called-fin-launches-an-ai-agent-whose-only-job-is-managing-another-ai-agent/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3520879/it-nachrichten/intercom-now-called-fin-launches-an-ai-agent-whose-only-job-is-managing-another-ai-agent/</guid>
<pubDate>Fri, 15 May 2026 23:47:13 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>The company formerly known as <a href="https://www.intercom.com/">Intercom</a> just did something that no major customer service platform has attempted at scale: it built an AI agent whose sole job is to manage another AI agent.</p><p><a href="https://fin.ai/operator">Fin Operator</a>, announced Thursday at a live event in San Francisco, is a new AI-powered system designed specifically for the back-office teams that configure, monitor, and improve <a href="https://fin.ai/">Fin</a>, the company's customer-facing AI agent. Rather than replacing human support agents — which is what Fin itself does on the front lines — Operator targets the growing army of support operations professionals who spend their days updating knowledge bases, debugging conversation failures, and combing through performance dashboards.</p><p>"Fin is an agent for your customers," Brian Donohue, the company's VP of Product, told VentureBeat in an exclusive interview ahead of the launch. "Operator is an agent for your support ops team. This is an agent for the back office team who manages Fin and then manages their human agents."</p><p>The announcement arrives at a pivotal moment for the company. Just two days ago, CEO Eoghan McCabe formally <a href="https://www.linkedin.com/pulse/today-intercom-becomes-fin-eoghan-mccabe-7ov5c/">renamed the 15-year-old company from Intercom to Fin</a> — an aggressive signal that the AI agent is now the business, not merely a feature of it. Fin recently crossed $100 million in annual recurring revenue and is growing at 3.5x. The broader company generates<a href="https://fin.ai/about"> $400 million in ARR</a>, meaning the AI agent now accounts for roughly a quarter of total revenue and virtually all of its growth.</p><p><a href="https://fin.ai/operator">Fin Operator</a> enters early access for Pro-tier users starting today, with general availability planned for summer 2026.</p><h2>The invisible crisis behind every AI customer service deployment</h2><p>As companies push their AI agents to handle more conversations — Fin alone now resolves more than two million customer issues each week across 8,000 customers globally, including <a href="https://www.anthropic.com/">Anthropic</a>, <a href="https://doordash.com/">DoorDash</a>, and <a href="https://mercury.com/">Mercury</a> — the operational complexity behind those systems has exploded. Someone has to keep the knowledge base current. Someone has to figure out why the bot entered an infinite loop with a frustrated customer last Tuesday. Someone has to analyze whether the automation rate dropped after a product update.</p><p>That "someone" is the support operations team, and according to Donohue, they are drowning.</p><p>"Almost every support ops team is already doing data analysis and knowledge management — that's table stakes today," Donohue said. "Where teams struggle is the agent builder work. It's a new skill set, and most don't have enough time for it. They get their first iteration up and running, and then they get stuck."</p><p>The problem is structural. AI customer agents are not static software. They require constant tuning — a process that looks more like training a new employee than configuring a SaaS tool. Each customer conversation is a potential source of failure, and each failure requires diagnosis, root-cause analysis, a configuration fix, testing, and monitoring. It is tedious, technical, and relentless. <a href="https://fin.ai/operator">Fin Operator</a> aims to collapse that entire loop into a conversational interface.</p><h2>How one AI system plays data analyst, knowledge manager, and debugger all at once</h2><p>Donohue described <a href="https://fin.ai/operator">Operator</a> as filling three distinct roles that typically consume the bandwidth of support ops teams: expert data analyst, expert knowledge manager, and expert agent builder.</p><p>As a data analyst, Operator can field high-level questions like, "How did my team perform last week?" and generate on-the-fly charts, trend reports, and drill-down analyses across all of the data already stored in Intercom's platform. The company has loaded Operator with contextual knowledge about customer-specific data attributes to help it interpret workspace-specific metrics accurately.</p><p>As a knowledge manager, Operator can ingest a product update — say, a three-page PDF describing a new feature — and autonomously search the company's entire content library to identify what needs to change. It finds gaps, drafts new articles, suggests edits to existing ones, and presents everything in a diff-style review interface. The underlying search engine is the same semantic search system that Intercom has built and optimized for Fin over more than two years.</p><p>"On that knowledge management front, you just have such a time compression of something that would take, certainly hours, sometimes days, into the space of about 10 minutes," Donohue said.</p><p>As an agent builder, Operator introduces what the company calls a "<a href="https://fin.ai/operator">debugger skill</a>." Support ops teams can paste in a link to a conversation where Fin misbehaved, and Operator will trace every step of Fin's internal reasoning, identify the root cause — often a piece of guidance that unintentionally creates a loop — propose a rewrite, back-test the change against the original conversation, and then suggest creating a production monitor to catch similar issues going forward.</p><p>"This is literally what our professional services team does," Donohue explained. "You've written guidance that is unintentionally causing Fin to repeat itself — this happens a lot. You didn't realize it, but you never gave it an escape hatch."</p><h2>The 'pull request' safety net that keeps humans in control of AI changes</h2><p>One of the most consequential design decisions in <a href="https://fin.ai/operator">Fin Operator</a> is what the company calls its "proposal system" — a mechanism that functions like a pull request in software engineering.</p><p>Every change that Operator recommends — whether it is an edit to a help article, a rewrite of an AI guidance rule, or the creation of a new QA monitor — appears as a proposal with a full diff view. Users can inspect, edit, and approve each change before it takes effect. Nothing goes live without a human clicking "Apply."</p><p>"Right now, we're taking zero risk on this — Fin cannot make any changes to the system without human approval," Donohue emphasized. "Nothing goes live until a human clicks apply."</p><p>This is a notable architectural choice. In a market increasingly enamored with fully autonomous AI systems, the company is deliberately keeping a human approval gate in place — at least for now. Donohue acknowledged this will evolve, but said the current moment demands caution: "It's too big a leap to just let Operator make changes automatically and then tell the team, 'Hey, let me tell you about what I did.'"</p><p>For enterprise buyers evaluating AI tools, this design point matters. It is the difference between an AI system that proposes changes and one that enacts them — a distinction that compliance teams, security officers, and risk managers will scrutinize closely.</p><h2>Why Fin Operator runs on Anthropic's Claude instead of the company's own AI models</h2><p>In a revealing technical detail, Donohue confirmed that <a href="https://fin.ai/operator">Fin Operator</a> does not use the company's proprietary Apex models — the same custom AI models that power the customer-facing Fin agent and that the company has promoted as outperforming GPT-5.4 and Claude Sonnet 4.6 in customer service benchmarks.</p><p>Instead, Operator runs on Anthropic's Claude.</p><p>"We're not using our custom models," Donohue said. "Those are designed to directly answer customer questions, whereas these are closer to what frontier models are best suited for. This is really closer to software engineering."</p><p>The distinction is telling. Fin's <a href="https://fin.ai/cx-models">Apex models</a> are optimized for one thing: resolving customer service conversations with minimal hallucination and maximum accuracy. Operator's tasks — analyzing data, writing code-like configurations, debugging complex reasoning chains — demand a different kind of intelligence. Donohue characterized these capabilities as more akin to software engineering, an area where Anthropic's Claude models have been deliberately optimized.</p><p>The company has not ruled out building custom models for <a href="https://fin.ai/operator">Operator</a> in the future, but Donohue positioned it as a lower priority. What the team has built around Claude, he argued, is the differentiated layer: the proposal system, the debugger skill, the semantic search integration, the data attribution logic, and the charting capabilities that make Operator more than just "Claude inside the app."</p><h2>Early beta testers say Fin Operator feels like adding five people to the team</h2><p><a href="https://fin.ai/operator">Fin Operator</a> is currently in beta with roughly 200 customers, a number Donohue said has "ramped up pretty fast the last couple of weeks."</p><p>Constantina Samara, VP of Customer Support, Enablement &amp; Trust at <a href="https://www.synthesia.io/">Synthesia</a>, said the tool has already changed how her team works: "Previously, improving how Fin handles a conversation often meant reviewing everything yourself — the conversation, the configuration, the content. With Fin Operator, you just ask. It walks you through what happened and makes improving Fin dramatically easier."</p><p>Jordan Thompson, an AI Conversational Analyst at <a href="https://www.raylo.com/">Raylo</a>, reported that he has been using Operator daily and has run head-to-head comparisons between Operator's analysis and his own manual work. "It's very accurate," Thompson said. "It's just as strong at high-level trend analysis as it is at debugging individual conversations. That's a real limitation when using an LLM connector on its own — you get conversational depth but nothing on reporting or trends."</p><p>Donohue also shared an internal anecdote from the company's own knowledge management team. Beth, who leads knowledge operations, told the product team that Operator made her feel like she had "five more people on my team." Whether internal testimonials carry the same weight as external customer validation is debatable, but Donohue said the knowledge management use case consistently generates the most visceral reactions because the time savings are so stark — collapsing hours or days of content auditing into roughly 10 minutes.</p><h2>A new pricing model signals how AI is reshaping the economics of enterprise software</h2><p><a href="https://fin.ai/operator">Fin Operator</a> will live inside the company's Pro add-on tier — a relatively new bundle that already includes advanced analytics features like CX scoring, topic detection, real-time issue detection, and quality assurance monitoring across both AI and human agent conversations.</p><p>The pricing model introduces something new for the company: usage-based billing. Intercom has historically relied on outcome-based pricing — charging roughly $0.99 per conversation that Fin resolves without human intervention. Operator's work does not map cleanly to that model because it produces configuration changes, not customer resolutions.</p><p>"This has pushed us to a different model, to go more into that usage model for support ops teams," Donohue said. "We'll try to be generous with the usage amounts that come into Pro, but for people who are leaning heavily in, we'll have the ability to buy more usage blocks."</p><p>The shift is worth watching. Outcome-based pricing was one of the company's most distinctive market positions — a bet that customers would pay for results rather than seats. Extending that philosophy to internal operations work proved impractical, which suggests that as AI agents take on more diverse roles within an organization, the pricing models that support them will need to become equally diverse.</p><h2>How Fin Operator stacks up in a crowded field of AI customer service competitors</h2><p>Fin Operator lands in an increasingly competitive landscape. <a href="https://www.zendesk.com/">Zendesk</a>, <a href="https://www.salesforce.com/">Salesforce</a>, <a href="https://sierra.ai/">Sierra</a>, and a constellation of AI-native startups are all building some version of AI-powered support operations tooling. The broader AI automation market is projected to reach <a href="https://www.grandviewresearch.com/industry-analysis/ai-automation-market-report">$169 billion in 2026</a>, according to Grand View Research, growing at a 31.4% compound annual rate.</p><p>But Donohue argued that Operator's differentiation lies in two areas. First, breadth: Operator works across the full surface area of the company's configuration system — data, content, procedures, simulations, guidance, and monitoring — rather than addressing a single narrow use case. Second, the fact that it spans both AI and human operations.</p><p>"Most critically, where I think we have the most differentiation is because it's for your human system and your AI system," Donohue said. "That's really one of the unique spaces we have — to have a first-class AI agent and a first-class help desk, and Operator works across both."</p><p>The competitive positioning also benefits from timing. The company's <a href="https://www.linkedin.com/pulse/today-intercom-becomes-fin-eoghan-mccabe-7ov5c/">recent corporate rebrand </a>from Intercom to Fin signals a wholesale commitment to AI that legacy players may struggle to match. As CEO McCabe wrote in announcing the name change, the AI agent "is about to be the largest part of our business." The help desk product continues as Intercom 2, but the parent company now carries the name of its AI agent — a branding move that some industry observers have interpreted as pre-IPO positioning. The Fin <a href="https://fin.ai/api-platform">API Platform</a>, launched in early April, adds another dimension: the company opened its proprietary Apex models to third-party developers and even offered to license the technology to direct competitors like Decagon and Sierra.</p><h2>The real paradigm shift isn't a new chat interface — it's an agent that does the thinking for you</h2><p>Step back from the product specifics and <a href="https://fin.ai/operator">Fin Operator</a> represents something potentially more consequential than a new dashboard or analytics tool. It is one of the first commercial products to explicitly embody the emerging paradigm of AI agents that manage other AI agents — a two-layer abstraction that is beginning to reshape how companies think about operational software.</p><p>Donohue was emphatic on this point. The real paradigm shift, he argued, is not the chat interface replacing buttons and menus. It is that the AI is doing the actual knowledge work — figuring out what should change, why, and how.</p><p>"The UX change is secondary, even though it's most visible," Donohue said. "The change is that we are identifying and doing the work of support operations. It's doing the work of what the knowledge manager is doing, so that they just have to approve that. That's the huge shift."</p><p>The analogy to software engineering is apt. Over the past year, AI coding agents have fundamentally altered the daily workflow of developers, shifting their primary responsibility from writing code to reviewing and guiding the AI that writes it. Donohue sees the same transformation arriving for support operations professionals.</p><p>"Software engineers — three months have upended their world, where their primary job now is managing agents who are actually writing the code," he said. "Similarly now, support ops, your job is to manage an agent who's managing the agent for your customers."</p><p>Whether this vision pans out at enterprise scale remains to be seen. The company is still launching <a href="https://fin.ai/operator">Operator</a> in beta precisely because it wants to keep refining quality through what Donohue described as a painstaking, conversation-by-conversation debugging process. "We've spent three months, conversation by conversation, learning, fixing, learning, fixing, to get it where it's robust," he said.</p><p>But if the early returns hold, <a href="https://fin.ai/operator">Fin Operator</a> may preview what the next generation of enterprise software looks like: not tools that help humans do work faster, but agents that do the work themselves, subject to human judgment and approval. For customer service leaders already running AI agents in production, the question is no longer just "how good is my bot?" It is now, inevitably, "who is managing it?" And increasingly, the answer is another bot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Exchange Server zero-day vulnerability can be triggered by opening a malicious email]]></title>
<description><![CDATA[A newly discovered zero-day vulnerability in Microsoft Exchange Server has experts declaring an emergency and urging CSOs to think about the need to abandon on-premises email solutions.



“Because it’s already being exploited in the wild, this isn’t a ‘patch next week situation; it’s a ‘mitigate...]]></description>
<link>https://tsecurity.de/de/3520767/it-security-nachrichten/exchange-server-zero-day-vulnerability-can-be-triggered-by-opening-a-malicious-email/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3520767/it-security-nachrichten/exchange-server-zero-day-vulnerability-can-be-triggered-by-opening-a-malicious-email/</guid>
<pubDate>Fri, 15 May 2026 22:22:28 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>A newly discovered zero-day vulnerability in Microsoft Exchange Server has experts declaring an emergency and urging CSOs to think about the need to abandon on-premises email solutions.</p>



<p>“Because it’s already being exploited in the wild, this isn’t a ‘patch next week situation; it’s a ‘mitigate right now’ emergency,” warned <a href="https://www.linkedin.com/in/rob-enderle-03729" target="_blank" rel="noreferrer noopener">Rob Enderle</a> of the Enderle Group.</p>



<p>“This is another reminder to find a trusted cloud provider for e-mail,” added <a href="https://www.sans.org/profiles/dr-johannes-ullrich" target="_blank" rel="noreferrer noopener">Johannes Ullrich</a>, dean of research at the SANS Institute. “On-premises Exchange is becoming a legacy product, and while some organizations need it for internal and outbound email, its attack surface should be minimized by reducing its exposure to external email.”</p>



<p>Ullrich<a href="https://techcommunity.microsoft.com/blog/exchange/addressing-exchange-server-may-2026-vulnerability-cve-2026-42897/4518498" target="_blank" rel="noreferrer noopener"> was commenting on an alert from Microsoft this week</a> about a cross-site scripting vulnerability affecting Exchange Outlook Web Access (OWA) that could be exploited merely by sending a specially crafted email to a user.  If the user opens the message in Outlook Web Access and certain interaction conditions are met, arbitrary JavaScript can be executed in the browser context.</p>



<p>Avoiding cross-site scripting problems in webmail systems like Outlook Web Access is hard, Ullrich admitted. A webmail system must include HTML email received from users within the application’s HTML without confusing the two. Techniques like sandboxed iFrames can help, but need to be applied carefully.</p>



<p>At the same time, he said, cross-site scripting flaws in webmail can usually be used to read the content of an email, and in some cases even to send an email.</p>



<p>“Luckily,” he added, “many organizations have moved away from on-premises Exchange and Outlook Web Access.”</p>



<p>“I’m guessing this is bad,” said <a href="https://ca.linkedin.com/in/kellman" target="_blank" rel="noreferrer noopener">Kellman Meghu</a>,” CTO of DeepCove Cybersecurity, “but so is running an onsite Exchange Server in general.”</p>



<p>Affected by the vulnerability (<a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42897" target="_blank" rel="noreferrer noopener">CVE-2026-42897</a>) are Exchange Server 2016, 2019, and Server Subscription Edition (SE), regardless of their update levels.</p>



<p>The cloud service, Exchange Online, is unaffected.</p>



<h2 class="wp-block-heading">Mitigation</h2>



<p>Microsoft is still working on a security patch. In the meantime, Exchange administrators should know that if the Exchange EM Service is enabled on their servers – and it should be; since its release in September 2021 it has been enabled by default – then Microsoft’s automatic mitigation for this vulnerability has already been published for affected versions of Exchange.</p>



<p>If EM Service for whatever reason has been disabled, it should be enabled immediately. Note, however, that EM Service won’t be able to check for new mitigations if the server is running an Exchange Server version older than March 2023.</p>



<p>Those who can’t use the EM Server, because, for example, they are disconnected or have air-gapped environments, should download the latest version of the Exchange on-premises <a href="https://aka.ms/UnifiedEOMT" target="_blank" rel="noreferrer noopener">Mitigation Tool (EOMT)</a> and apply the mitigation on a per server base, or on all servers at once by running the script via an elevated Exchange Management Shell.</p>



<h2 class="wp-block-heading">Known issues with mitigation tactics</h2>



<p>However, admins should note there are known issues once the mitigation is applied either manually or automatically through the EM Service.</p>



<p>OWA Print Calendar functionality might not work. As a workaround, copy the data or screenshot the calendar you want to print, or use Outlook Desktop client. </p>



<p>Inline images might not display correctly in the recipient’s OWA reading pane. As a workaround, send images as email attachments or use Outlook Desktop client. </p>



<p>OWA light (OWA URL ending in <em>/?layout=light</em>) does not work properly. Note that this feature was <a href="https://support.microsoft.com/en-us/office/learn-more-about-the-light-version-of-outlook-2aec8c2d-da48-4707-ba37-c800e1c284cd" target="_blank" rel="noreferrer noopener">deprecated several years ago</a> and is not intended for regular production use.</p>



<p>Admins may get a message saying “Mitigation invalid for this Exchange version.” in mitigation details. This issue is cosmetic and the mitigation does apply successfully if the status is shown as “Applied”. Microsoft is investigating how to address this glitch.</p>



<h2 class="wp-block-heading">Updates coming ‘in the future’</h2>



<p>A Microsoft spokesperson was asked when the security update would be released. We were referred to the company’s statement. </p>



<p>In its warning, Microsoft says security updates for impacted versions of Exchange Server will come “in the future.” They will be for Exchange SE RTM, Exchange 2016 CU23, and Exchange Server 2019 CU14 and CU15. Those running older CU versions are urged to update now.</p>



<p>An Exchange SE update will be released as a publicly available security update. Exchange 2016 and 2019 updates will be released only to customers who are enrolled in the <a href="https://techcommunity.microsoft.com/blog/exchange/announcing-period-2-exchange-20162019-extended-security-update-esu-program/4511603" target="_blank" rel="noreferrer noopener">Period 2 Exchange Server ESU program</a>. Period 1-only ESU customers will not receive this update, as that program ended last month.</p>



<p> Enderle said the fact that Microsoft issued an interim fix that breaks features like calendar printing and inline images is “a clear sign of how desperate they are to stop the bleeding.</p>



<p>“CSOs need to move past the ‘wait and see’ approach and treat this as a litmus test for their security automation,” he said. “If your team has the Exchange Emergency Mitigation (EM) Service enabled, you should already be protected, but you need to verify that ‘Mitigation M2’ is actually active across your entire inventory. If you’re running air-gapped or have the EM service disabled, you’re sitting ducks until you manually run the EOMT script.”</p>



<p>This is another “massive nudge” from Redmond to shift from on-premises email, Enderle added. “If you aren’t already planning your exit from on-site Exchange, your risk profile is only going to keep climbing as these zero days become the new normal. This does showcase that Azure, and web services in general, are where the industry, and particularly Microsoft, is pushing IT to go, whether they want to or not.”</p>
</div></div></div></div>]]></content:encoded>
</item>
</channel>
</rss>
<!-- Generated in 0,14ms -->