<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="/rss-style.xsl"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:media="http://search.yahoo.com/mrss/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/">
<channel>
<title><![CDATA[tsecurity.de - 📰 Alle Kategorien]]></title>
<link><![CDATA[https://tsecurity.de/export/rss/alle-kategorien.xml]]></link>
<description><![CDATA[Das Gesamte Cyber Threat Intelligence Feed-Archiv von TSecurity.de. Alle Nachrichten, Sicherheitsmeldungen, Videos, Downloads und Analysen in einer zentralen Übersicht.]]></description>
<language>de-DE</language>
<lastBuildDate>Thu, 06 Aug 2026 03:16:12 +0200</lastBuildDate>
<pubDate>Thu, 06 Aug 2026 03:16:12 +0200</pubDate>
<ttl>15</ttl>
<copyright>2026 tsecurity.de - 📰 Alle Kategorien</copyright>
<managingEditor>tsecurity.de (tsecurity.de)</managingEditor>
<webMaster>tsecurity.de (tsecurity.de)</webMaster>
<image>
<url>https://tsecurity.de/templates/mydraft-basis-isharestuff-com/media/logo.png</url>
<title><![CDATA[tsecurity.de - 📰 Alle Kategorien]]></title>
<link><![CDATA[https://tsecurity.de/export/rss/alle-kategorien.xml]]></link>
</image>
<atom:link href="https://tsecurity.de/RSS/1/" rel="self" type="application/rss+xml" />
<item>
<title><![CDATA[FCC Reportedly Drafting Ban on Chinese Optical Transceivers]]></title>
<description><![CDATA[The FCC is reportedly considering restrictions on Chinese optical transceivers as Washington targets security risks in U.S. AI data centers.]]></description>
<link>https://tsecurity.de/de/3707054/it-nachrichten/fcc-reportedly-drafting-ban-on-chinese-optical-transceivers/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707054/it-nachrichten/fcc-reportedly-drafting-ban-on-chinese-optical-transceivers/</guid>
<pubDate>Thu, 06 Aug 2026 03:16:03 +0200</pubDate>
<content:encoded><![CDATA[The FCC is reportedly considering restrictions on Chinese optical transceivers as Washington targets security risks in U.S. AI data centers.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2022-41521 | TOTOLINK NR1800X 9.1.0u.6279_B20210910 setIpPortFilterRules sPort/ePort stack-based overflow (EUVD-2022-44714)]]></title>
<description><![CDATA[A vulnerability described as critical has been identified in TOTOLINK NR1800X 9.1.0u.6279_B20210910. Affected by this issue is the function setIpPortFilterRules. The manipulation of the argument sPort/ePort results in stack-based buffer overflow.

This vulnerability is reported as CVE-2022-41521....]]></description>
<link>https://tsecurity.de/de/3707053/sicherheitsluecken/cve-2022-41521-totolink-nr1800x-910u6279b20210910-setipportfilterrules-sporteport-stack-based-overflow-euvd-2022-44714/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707053/sicherheitsluecken/cve-2022-41521-totolink-nr1800x-910u6279b20210910-setipportfilterrules-sporteport-stack-based-overflow-euvd-2022-44714/</guid>
<pubDate>Thu, 06 Aug 2026 01:34:12 +0200</pubDate>
<content:encoded><![CDATA[A vulnerability described as <a href="https://vuldb.com/kb/risk">critical</a> has been identified in <a href="https://vuldb.com/product/totolink:nr1800x">TOTOLINK NR1800X 9.1.0u.6279_B20210910</a>. Affected by this issue is the function <code>setIpPortFilterRules</code>. The manipulation of the argument <em>sPort/ePort</em> results in stack-based buffer overflow.

This vulnerability is reported as <a href="https://vuldb.com/cve/CVE-2022-41521">CVE-2022-41521</a>. The attacker must have access to the local network to execute the attack. No exploit exists.]]></content:encoded>
</item>
<item>
<title><![CDATA[AI Attacks Are Evolving: TryHackMe Demo Explores Prompt Injection ]]></title>
<description><![CDATA[TryHackMe demo: Explore how prompt injection is reshaping AI security risks.
The post AI Attacks Are Evolving: TryHackMe Demo Explores Prompt Injection  appeared first on eSecurity Planet.]]></description>
<link>https://tsecurity.de/de/3707052/it-security-nachrichten/ai-attacks-are-evolving-tryhackme-demo-explores-prompt-injection/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707052/it-security-nachrichten/ai-attacks-are-evolving-tryhackme-demo-explores-prompt-injection/</guid>
<pubDate>Thu, 06 Aug 2026 01:29:39 +0200</pubDate>
<content:encoded><![CDATA[<p>TryHackMe demo: Explore how prompt injection is reshaping AI security risks.</p>
<p>The post <a href="https://www.esecurityplanet.com/threats/ai-attacks-are-evolving-tryhackme-demo-explores-prompt-injection/">AI Attacks Are Evolving: TryHackMe Demo Explores Prompt Injection </a> appeared first on <a href="https://www.esecurityplanet.com/">eSecurity Planet</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Smashing Security podcast #479: How a fake police officer nearly stole Graham’s cryptocurrency]]></title>
<description><![CDATA[Graham gets a phone call from the police. Well, someone who sounds convincingly like the police.  There's just one small problem: what they really want is the 24-word seed key to Graham's cryptocurrency wallet.

Meanwhile, if you've stayed in a hotel recently, the free Wi-Fi you connected to mi...]]></description>
<link>https://tsecurity.de/de/3707051/it-security-nachrichten/smashing-security-podcast-479-how-a-fake-police-officer-nearly-stole-grahams-cryptocurrency/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707051/it-security-nachrichten/smashing-security-podcast-479-how-a-fake-police-officer-nearly-stole-grahams-cryptocurrency/</guid>
<pubDate>Thu, 06 Aug 2026 01:20:53 +0200</pubDate>
<content:encoded><![CDATA[Graham gets a phone call from the police. Well, someone who sounds convincingly like the police.  There's just one small problem: what they really want is the 24-word seed key to Graham's cryptocurrency wallet.

Meanwhile, if you've stayed in a hotel recently, the free Wi-Fi you connected to might have come with an unexpected extra: an all-you-can-eat buffet of "Captive Crunch" for a Russian intelligence-linked hacking group.

And a group calling itself the "ExFilSquad" has walked off with 600,000 records of the UK's teachers and head teachers from the Department for Education — sending an unusually polite ransom demand.

All this and more in episode 479 of the "Smashing Security" podcast with cybersecurity expert and keynote speaker Graham Cluley, and special guest Danny Palmer.]]></content:encoded>
</item>
<item>
<title><![CDATA[Ransom Cartel ransomware creator sentenced to 16 years in prison]]></title>
<description><![CDATA[Maksim Silnikau, the creator and administrator of the Ransom Cartel ransomware operation, was sentenced to 16 years in prison for his role in ransomware attacks against at least 18 companies worldwide. [...]]]></description>
<link>https://tsecurity.de/de/3707050/it-security-nachrichten/ransom-cartel-ransomware-creator-sentenced-to-16-years-in-prison/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707050/it-security-nachrichten/ransom-cartel-ransomware-creator-sentenced-to-16-years-in-prison/</guid>
<pubDate>Thu, 06 Aug 2026 01:20:19 +0200</pubDate>
<content:encoded><![CDATA[Maksim Silnikau, the creator and administrator of the Ransom Cartel ransomware operation, was sentenced to 16 years in prison for his role in ransomware attacks against at least 18 companies worldwide. [...]]]></content:encoded>
</item>
<item>
<title><![CDATA[Waymo CEO Explains Why Camera-Only Self-Driving Falls Short]]></title>
<description><![CDATA[Longtime Slashdot reader AmiMoJo shares a report from Electrek: Waymo co-CEO Dmitri Dolgov laid out the clearest technical case yet for why cameras alone can't take a self-driving system to full autonomy, arguing that "weak sensing" hits a safety ceiling long before it reaches superhuman performa...]]></description>
<link>https://tsecurity.de/de/3707049/it-security-nachrichten/waymo-ceo-explains-why-camera-only-self-driving-falls-short/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707049/it-security-nachrichten/waymo-ceo-explains-why-camera-only-self-driving-falls-short/</guid>
<pubDate>Thu, 06 Aug 2026 01:20:02 +0200</pubDate>
<content:encoded><![CDATA[Longtime Slashdot reader AmiMoJo shares a report from Electrek: Waymo co-CEO Dmitri Dolgov laid out the clearest technical case yet for why cameras alone can't take a self-driving system to full autonomy, arguing that "weak sensing" hits a safety ceiling long before it reaches superhuman performance. [...] Dolgov made the comments in a talk at Y Combinator's Startup School, walking through the lessons Waymo has learned building its driver over close to two decades. He put the sensor question on the table plainly: "there's been a long-standing debate about what kind of sensors do you actually need for autonomous driving."
 
His answer draws the line that camera-only advocates tend to skip right past. "Humans of course can drive with just eyes, so there's that proof of existence," he said. "If the goal were to just approximately match human performance or to build an assist product, that's a very reasonable way to go." Then the catch. If you're targeting full autonomy and strongly superhuman performance, he said, "you find that weak sensing just leads to a safety curve that flattens out way too early." Dolgov said that cameras, lidar, and radar are complementary rather than redundant: "These different sensing modalities, they're not backups to each other," and combining them produces a view "vastly superior to what you get with any one sensor." He said multiple sensor types also protect against physical failures, such as a leaf or branch blocking a camera, while helping Waymo climb the "exponential ladder of nines" required for fully driverless safety.
 
Dolgov warned that camera-only systems may improve quickly before plateauing "way before the performance that is required by your product." He also pushed back on the cost argument against lidar, calling it "a number that has a fairly short shelf life" as hardware costs continue to fall.<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=Waymo+CEO+Explains+Why+Camera-Only+Self-Driving+Falls+Short%3A+https%3A%2F%2Ftech.slashdot.org%2Fstory%2F26%2F08%2F05%2F229237%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Ftech.slashdot.org%2Fstory%2F26%2F08%2F05%2F229237%2Fwaymo-ceo-explains-why-camera-only-self-driving-falls-short%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://tech.slashdot.org/story/26/08/05/229237/waymo-ceo-explains-why-camera-only-self-driving-falls-short?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Quordle hints and answers for Thursday, August 6 (game #1655)]]></title>
<description><![CDATA[Looking for Quordle clues? We can help. Plus get the answers to Quordle today and past solutions.]]></description>
<link>https://tsecurity.de/de/3707048/it-nachrichten/quordle-hints-and-answers-for-thursday-august-6-game-1655/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707048/it-nachrichten/quordle-hints-and-answers-for-thursday-august-6-game-1655/</guid>
<pubDate>Thu, 06 Aug 2026 01:19:46 +0200</pubDate>
<content:encoded><![CDATA[Looking for Quordle clues? We can help. Plus get the answers to Quordle today and past solutions.]]></content:encoded>
</item>
<item>
<title><![CDATA[NYT Connections hints and answers for Thursday, August 6 (game #1152)]]></title>
<description><![CDATA[Looking for NYT Connections answers and hints? Here's all you need to know to solve today's game, plus my commentary on the puzzles.]]></description>
<link>https://tsecurity.de/de/3707047/it-nachrichten/nyt-connections-hints-and-answers-for-thursday-august-6-game-1152/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707047/it-nachrichten/nyt-connections-hints-and-answers-for-thursday-august-6-game-1152/</guid>
<pubDate>Thu, 06 Aug 2026 01:19:46 +0200</pubDate>
<content:encoded><![CDATA[Looking for NYT Connections answers and hints? Here's all you need to know to solve today's game, plus my commentary on the puzzles.]]></content:encoded>
</item>
<item>
<title><![CDATA[NYT Strands hints and answers for Thursday, August 6 (game #886)]]></title>
<description><![CDATA[Looking for NYT Strands answers and hints? Here's all you need to know to solve today's game, including the spangram.]]></description>
<link>https://tsecurity.de/de/3707046/it-nachrichten/nyt-strands-hints-and-answers-for-thursday-august-6-game-886/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707046/it-nachrichten/nyt-strands-hints-and-answers-for-thursday-august-6-game-886/</guid>
<pubDate>Thu, 06 Aug 2026 01:19:46 +0200</pubDate>
<content:encoded><![CDATA[Looking for NYT Strands answers and hints? Here's all you need to know to solve today's game, including the spangram.]]></content:encoded>
</item>
<item>
<title><![CDATA['It's not our job to make the audience comfortable': Gugu Mbatha-Raw on why new supernatural Sky TV thriller Possession will make colonial history 'accessible' — not more palatable]]></title>
<description><![CDATA[New Sky TV supernatural thriller Possession is one of the most uncomfortable watches of the year — so don't think its colonial history is going to be toned down.]]></description>
<link>https://tsecurity.de/de/3707045/it-nachrichten/its-not-our-job-to-make-the-audience-comfortable-gugu-mbatha-raw-on-why-new-supernatural-sky-tv-thriller-possession-will-make-colonial-history-accessible-not-more-palatable/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707045/it-nachrichten/its-not-our-job-to-make-the-audience-comfortable-gugu-mbatha-raw-on-why-new-supernatural-sky-tv-thriller-possession-will-make-colonial-history-accessible-not-more-palatable/</guid>
<pubDate>Thu, 06 Aug 2026 01:19:46 +0200</pubDate>
<content:encoded><![CDATA[New Sky TV supernatural thriller Possession is one of the most uncomfortable watches of the year — so don't think its colonial history is going to be toned down.]]></content:encoded>
</item>
<item>
<title><![CDATA[Zillow revenue climbs 18% but layoff costs push company to a loss, amid executive changes]]></title>
<description><![CDATA[Zillow Group's second-quarter revenue rose 18% to $772 million, but a $36 million restructuring charge from this week's layoffs pushed the company to a $4 million net loss. Zillow also expanded CFO Jeremy Hofmann's role to include chief operating officer and hired a Google litigation executive as...]]></description>
<link>https://tsecurity.de/de/3707044/it-nachrichten/zillow-revenue-climbs-18-but-layoff-costs-push-company-to-a-loss-amid-executive-changes/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707044/it-nachrichten/zillow-revenue-climbs-18-but-layoff-costs-push-company-to-a-loss-amid-executive-changes/</guid>
<pubDate>Thu, 06 Aug 2026 01:19:35 +0200</pubDate>
<content:encoded><![CDATA[<img fetchpriority="high" loading="eager" width="1260" height="709" src="https://cdn.geekwire.com/wp-content/uploads/2026/08/zillow-logo-1260x709.png" class="webfeedsFeaturedVisual wp-post-image" alt="" decoding="async" srcset="https://cdn.geekwire.com/wp-content/uploads/2026/08/zillow-logo-1260x709.png 1260w, https://cdn.geekwire.com/wp-content/uploads/2026/08/zillow-logo-768x432.png 768w, https://cdn.geekwire.com/wp-content/uploads/2026/08/zillow-logo-1536x864.png 1536w, https://cdn.geekwire.com/wp-content/uploads/2026/08/zillow-logo.png 1672w" sizes="(max-width: 1260px) 100vw, 1260px"><br>Zillow Group's second-quarter revenue rose 18% to $772 million, but a $36 million restructuring charge from this week's layoffs pushed the company to a $4 million net loss. Zillow also expanded CFO Jeremy Hofmann's role to include chief operating officer and hired a Google litigation executive as its first chief legal and policy officer. <a href="https://www.geekwire.com/2026/zillow-revenue-climbs-18-but-layoff-costs-push-company-to-a-loss-amid-executive-changes/">Read More</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Get up to $400 off your TechCrunch Disrupt 2026 pass until Friday]]></title>
<description><![CDATA[Starting today, you can take an additional $100 off your founder, investor, or attendee TechCrunch Disrupt 2026 pass, which is a nice bonus on top of our current discounted pricing. ]]></description>
<link>https://tsecurity.de/de/3707043/ai-nachrichten/get-up-to-400-off-your-techcrunch-disrupt-2026-pass-until-friday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707043/ai-nachrichten/get-up-to-400-off-your-techcrunch-disrupt-2026-pass-until-friday/</guid>
<pubDate>Thu, 06 Aug 2026 01:15:06 +0200</pubDate>
<content:encoded><![CDATA[Starting today, you can take an additional $100 off your founder, investor, or attendee TechCrunch Disrupt 2026 pass, which is a nice bonus on top of our current discounted pricing. ]]></content:encoded>
</item>
<item>
<title><![CDATA[August Apple Watch deals deliver savings of up to $172 off Series 11, Ultra 3 styles]]></title>
<description><![CDATA[Summer Apple Watch sales at Amazon and Walmart deliver discounts of up to $172 off SE 3, Series 11, and Ultra 3 styles.Save up to $172 across the Apple Watch lineup - Image credit: ApplePrices across Apple's wearables line start at $219 this week, with standout offers being a $172 discount on the...]]></description>
<link>https://tsecurity.de/de/3707040/ios-mac-os/august-apple-watch-deals-deliver-savings-of-up-to-172-off-series-11-ultra-3-styles/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707040/ios-mac-os/august-apple-watch-deals-deliver-savings-of-up-to-172-off-series-11-ultra-3-styles/</guid>
<pubDate>Thu, 06 Aug 2026 01:13:15 +0200</pubDate>
<content:encoded><![CDATA[Summer Apple Watch sales at Amazon and Walmart deliver discounts of up to $172 off SE 3, Series 11, and Ultra 3 styles.<br><br><div><img src="https://media.appleinsider.com/gallery/68481-144287-apple-watch-sale-august-2026-xl.jpg" alt="Three Apple Watch Series 11 models on a colorful gradient background, displaying fitness rings, a heart rate screen showing 68 BPM, and an Outdoor Run workout with play controls"><br><span>Save up to $172 across the Apple Watch lineup - Image credit: Apple</span></div><br>Prices across Apple's wearables line start at $219 this week, with standout offers being a <a href="https://howl.link/cy5gjrqqsxlhp" target="_blank" rel="nofollow">$172 discount</a> on the 42mm GPS + Cellular Apple Watch Series 11 at Walmart and a <a href="https://www.amazon.com/dp/B0FQFHVZYL/?tag=apinsiderdeals-20" target="_blank" rel="nofollow">$100 markdown</a> on the Apple Watch Ultra 3 at Amazon.<br><br><a href="https://www.amazon.com/s?k=apple+watch&amp;s=exact-aware-popularity-rank&amp;tag=apinsiderdeals-20" rel="nofollow" class="deal-highlight">Grab Apple Watch deals from $219</a><br><br><br> <a href="https://appleinsider.com/articles/26/08/05/august-apple-watch-deals-deliver-savings-of-up-to-172-off-series-11-ultra-3-styles?utm_source=rss">Continue Reading on AppleInsider</a> | <a href="https://forums.appleinsider.com/discussion/245180?urm_source=rss">Discuss on our Forums</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[GitHub: v8.23.0-beta.1]]></title>
<description><![CDATA[Tweaks, bug fixes, and performance enhancements. Keep on texting, calling, and video chatting as usual.]]></description>
<link>https://tsecurity.de/de/3707039/downloads/github-v8230-beta1/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707039/downloads/github-v8230-beta1/</guid>
<pubDate>Thu, 06 Aug 2026 01:08:52 +0200</pubDate>
<content:encoded><![CDATA[<div class="github-feed-entry"><ul>
<li>Tweaks, bug fixes, and performance enhancements. Keep on texting, calling, and video chatting as usual.</li>
</ul></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Microsoft is bringing AI to Windows 11’s performance tools to figure out why PCs are slow, and it’s a big deal]]></title>
<description><![CDATA[We've been told a faster Windows is coming, but how does the company plan to figure out why a PC is running slowly? AI-powered diagnosis.
The post Microsoft is bringing AI to Windows 11’s performance tools to figure out why PCs are slow, and it’s a big deal appeared first on Windows Latest]]></description>
<link>https://tsecurity.de/de/3707038/windows-tipps/microsoft-is-bringing-ai-to-windows-11s-performance-tools-to-figure-out-why-pcs-are-slow-and-its-a-big-deal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707038/windows-tipps/microsoft-is-bringing-ai-to-windows-11s-performance-tools-to-figure-out-why-pcs-are-slow-and-its-a-big-deal/</guid>
<pubDate>Thu, 06 Aug 2026 01:05:41 +0200</pubDate>
<content:encoded><![CDATA[<p>We've been told a faster Windows is coming, but how does the company plan to figure out why a PC is running slowly? AI-powered diagnosis.</p>
<p>The post <a rel="nofollow" href="https://www.windowslatest.com/2026/08/06/microsoft-is-bringing-ai-to-windows-11s-performance-tools-to-figure-out-why-pcs-are-slow-and-its-a-big-deal/">Microsoft is bringing AI to Windows 11’s performance tools to figure out why PCs are slow, and it’s a big deal</a> appeared first on <a rel="nofollow" href="https://www.windowslatest.com/">Windows Latest</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Halo Studios is the latest Xbox Games Studio to be hit by layoffs just days after Campaign Evolved launch, as reports reveal "troubled" development]]></title>
<description><![CDATA[A number of developers previously employed at Halo Studios have posted on LinkedIn confirming layoffs at the studio.]]></description>
<link>https://tsecurity.de/de/3707037/windows-tipps/halo-studios-is-the-latest-xbox-games-studio-to-be-hit-by-layoffs-just-days-after-campaign-evolved-launch-as-reports-reveal-troubled-development/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707037/windows-tipps/halo-studios-is-the-latest-xbox-games-studio-to-be-hit-by-layoffs-just-days-after-campaign-evolved-launch-as-reports-reveal-troubled-development/</guid>
<pubDate>Thu, 06 Aug 2026 01:05:36 +0200</pubDate>
<content:encoded><![CDATA[A number of developers previously employed at Halo Studios have posted on LinkedIn confirming layoffs at the studio.]]></content:encoded>
</item>
<item>
<title><![CDATA[GitHub: v8.23.0-beta.1]]></title>
<description><![CDATA[Tweaks, bug fixes, and performance enhancements. Keep on texting, calling, and video chatting as usual.]]></description>
<link>https://tsecurity.de/de/3707036/tools/github-v8230-beta1/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707036/tools/github-v8230-beta1/</guid>
<pubDate>Thu, 06 Aug 2026 01:05:23 +0200</pubDate>
<content:encoded><![CDATA[<div class="github-feed-entry"><ul>
<li>Tweaks, bug fixes, and performance enhancements. Keep on texting, calling, and video chatting as usual.</li>
</ul></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-53368 | Linux Kernel F2fs f2fs_need_dentry_mark node_write improper synchronization (WID-SEC-2026-2403)]]></title>
<description><![CDATA[A vulnerability described as problematic has been identified in Linux Kernel. This issue affects the function f2fs_need_dentry_mark of the component F2fs. Executing a manipulation of the argument node_write can lead to improper synchronization.

This vulnerability appears as CVE-2026-53368. The a...]]></description>
<link>https://tsecurity.de/de/3707035/sicherheitsluecken/cve-2026-53368-linux-kernel-f2fs-f2fsneeddentrymark-nodewrite-improper-synchronization-wid-sec-2026-2403/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707035/sicherheitsluecken/cve-2026-53368-linux-kernel-f2fs-f2fsneeddentrymark-nodewrite-improper-synchronization-wid-sec-2026-2403/</guid>
<pubDate>Thu, 06 Aug 2026 01:05:02 +0200</pubDate>
<content:encoded><![CDATA[A vulnerability described as <a href="https://vuldb.com/kb/risk">problematic</a> has been identified in <a href="https://vuldb.com/product/linux:kernel">Linux Kernel</a>. This issue affects the function <code>f2fs_need_dentry_mark</code> of the component <em>F2fs</em>. Executing a manipulation of the argument <em>node_write</em> can lead to improper synchronization.

This vulnerability appears as <a href="https://vuldb.com/cve/CVE-2026-53368">CVE-2026-53368</a>. The attack requires local access. There is no available exploit.

A patch should be applied to remediate this issue.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-53369 | Linux Kernel Udf udf_read_tagged Local Privilege Escalation (WID-SEC-2026-2403)]]></title>
<description><![CDATA[A vulnerability classified as critical was found in Linux Kernel. The affected element is the function udf_read_tagged of the component Udf. The manipulation results in Local Privilege Escalation.

This vulnerability is known as CVE-2026-53369. Attacking locally is a requirement. No exploit is av...]]></description>
<link>https://tsecurity.de/de/3707034/sicherheitsluecken/cve-2026-53369-linux-kernel-udf-udfreadtagged-local-privilege-escalation-wid-sec-2026-2403/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707034/sicherheitsluecken/cve-2026-53369-linux-kernel-udf-udfreadtagged-local-privilege-escalation-wid-sec-2026-2403/</guid>
<pubDate>Thu, 06 Aug 2026 01:05:01 +0200</pubDate>
<content:encoded><![CDATA[A vulnerability classified as <a href="https://vuldb.com/kb/risk">critical</a> was found in <a href="https://vuldb.com/product/linux:kernel">Linux Kernel</a>. The affected element is the function <code>udf_read_tagged</code> of the component <em>Udf</em>. The manipulation results in Local Privilege Escalation.

This vulnerability is known as <a href="https://vuldb.com/cve/CVE-2026-53369">CVE-2026-53369</a>. Attacking locally is a requirement. No exploit is available.

It is advisable to implement a patch to correct this issue.]]></content:encoded>
</item>
<item>
<title><![CDATA[CaptiveCrunch: Russische Hacker spionieren Geschäftsreisende aus - Börse Express]]></title>
<description><![CDATA[Microsoft Threat Intelligence hat am 5. August eine dringende Sicherheitswarnung zu einer hochentwickelten Hacker-Kampagne namens „CaptiveCrunch“ ...]]></description>
<link>https://tsecurity.de/de/3707033/hacking/captivecrunch-russische-hacker-spionieren-geschaeftsreisende-aus-boerse-express/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707033/hacking/captivecrunch-russische-hacker-spionieren-geschaeftsreisende-aus-boerse-express/</guid>
<pubDate>Thu, 06 Aug 2026 01:04:33 +0200</pubDate>
<content:encoded><![CDATA[Microsoft Threat Intelligence hat am 5. August eine dringende Sicherheitswarnung zu einer hochentwickelten <b>Hacker</b>-Kampagne namens „CaptiveCrunch“ ...]]></content:encoded>
</item>
<item>
<title><![CDATA[Telegram-geleitete KI-Toolchain: DeepSeek startet autonome Angriffe]]></title>
<description><![CDATA[ZHUHAI / LONDON (IT BOLTWISE) – Ein chinesischsprachiger Angreifer soll über Telegram die Open-Source-Agent-Engine Hermes genutzt haben, um DeepSeek-gestützte Angriffe teils ohne weitere manuelle Eingaben auszuführen. Nach einer ersten Anweisung ließ der Agent internetseitige Systeme suchen, vers...]]></description>
<link>https://tsecurity.de/de/3707032/it-security-nachrichten/telegram-geleitete-ki-toolchain-deepseek-startet-autonome-angriffe/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707032/it-security-nachrichten/telegram-geleitete-ki-toolchain-deepseek-startet-autonome-angriffe/</guid>
<pubDate>Thu, 06 Aug 2026 01:02:58 +0200</pubDate>
<content:encoded><![CDATA[<p><img width="1024" height="1024" src="https://www.it-boltwise.de/wp-content/uploads/2026/08/ai-telegram-hermes-agent-deepseek-autonomous-attack-session.jpg" class="attachment- size- wp-post-image" alt="" decoding="async" srcset="https://www.it-boltwise.de/wp-content/uploads/2026/08/ai-telegram-hermes-agent-deepseek-autonomous-attack-session.jpg 1024w, https://www.it-boltwise.de/wp-content/uploads/2026/08/ai-telegram-hermes-agent-deepseek-autonomous-attack-session-300x300.jpg 300w, https://www.it-boltwise.de/wp-content/uploads/2026/08/ai-telegram-hermes-agent-deepseek-autonomous-attack-session-150x150.jpg 150w, https://www.it-boltwise.de/wp-content/uploads/2026/08/ai-telegram-hermes-agent-deepseek-autonomous-attack-session-768x768.jpg 768w, https://www.it-boltwise.de/wp-content/uploads/2026/08/ai-telegram-hermes-agent-deepseek-autonomous-attack-session-840x840.jpg 840w, https://www.it-boltwise.de/wp-content/uploads/2026/08/ai-telegram-hermes-agent-deepseek-autonomous-attack-session-120x120.jpg 120w" sizes="(max-width: 1024px) 100vw, 1024px">ZHUHAI / LONDON (IT BOLTWISE) – Ein chinesischsprachiger Angreifer soll über Telegram die Open-Source-Agent-Engine Hermes genutzt haben, um DeepSeek-gestützte Angriffe teils ohne weitere manuelle Eingaben auszuführen. Nach einer ersten Anweisung ließ der Agent internetseitige Systeme suchen, versionieren und passende öffentliche Exploits auswählen. Unit 42 ordnet die Kampagne anhand von Aliassen dem Umfeld „knaithe“ und „KnYuan“ […]</p>
<div><a href="https://www.it-boltwise.de/telegram-geleitete-ki-toolchain-deepseek-startet-autonome-angriffe.html">... den vollständigen Artikel <strong>»Telegram-geleitete KI-Toolchain: DeepSeek startet autonome Angriffe«</strong> lesen</a></div>
<p>Dieser Beitrag <a href="https://www.it-boltwise.de/telegram-geleitete-ki-toolchain-deepseek-startet-autonome-angriffe.html">Telegram-geleitete KI-Toolchain: DeepSeek startet autonome Angriffe</a> erschien als erstes auf <a href="https://www.it-boltwise.de/">IT BOLTWISE x Artificial Intelligence</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Claude-Tests führen zu Sandbox-Escape: Anthropic meldet drei echte Sicherheitsvorfälle]]></title>
<description><![CDATA[LONDON (IT BOLTWISE) – Anthropic berichtet, dass drei seiner Claude-Modelle bei externen Cybersecurity-Tests unbeabsichtigt das offene Internet erreicht haben. Dabei soll der Zugriff auf realen Systemen dazu geführt haben, dass mehrere Organisationen unautorisierte Infrastrukturzugriffe erlebten....]]></description>
<link>https://tsecurity.de/de/3707031/it-security-nachrichten/claude-tests-fuehren-zu-sandbox-escape-anthropic-meldet-drei-echte-sicherheitsvorfaelle/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707031/it-security-nachrichten/claude-tests-fuehren-zu-sandbox-escape-anthropic-meldet-drei-echte-sicherheitsvorfaelle/</guid>
<pubDate>Thu, 06 Aug 2026 01:02:58 +0200</pubDate>
<content:encoded><![CDATA[<p><img width="1024" height="1024" src="https://www.it-boltwise.de/wp-content/uploads/2026/08/ai-sandbox-escape-ctf-internet.jpg" class="attachment- size- wp-post-image" alt="" decoding="async" fetchpriority="high" srcset="https://www.it-boltwise.de/wp-content/uploads/2026/08/ai-sandbox-escape-ctf-internet.jpg 1024w, https://www.it-boltwise.de/wp-content/uploads/2026/08/ai-sandbox-escape-ctf-internet-300x300.jpg 300w, https://www.it-boltwise.de/wp-content/uploads/2026/08/ai-sandbox-escape-ctf-internet-150x150.jpg 150w, https://www.it-boltwise.de/wp-content/uploads/2026/08/ai-sandbox-escape-ctf-internet-768x768.jpg 768w, https://www.it-boltwise.de/wp-content/uploads/2026/08/ai-sandbox-escape-ctf-internet-840x840.jpg 840w, https://www.it-boltwise.de/wp-content/uploads/2026/08/ai-sandbox-escape-ctf-internet-120x120.jpg 120w" sizes="(max-width: 1024px) 100vw, 1024px">LONDON (IT BOLTWISE) – Anthropic berichtet, dass drei seiner Claude-Modelle bei externen Cybersecurity-Tests unbeabsichtigt das offene Internet erreicht haben. Dabei soll der Zugriff auf realen Systemen dazu geführt haben, dass mehrere Organisationen unautorisierte Infrastrukturzugriffe erlebten. Auslöser war nach Unternehmensangaben eine Fehlkonfiguration in der Testumgebung, die für „Capture-the-Flag“-Aufgaben eigentlich gesperrt sein sollte. Gleichzeitig betont Anthropic, dass […]</p>
<div><a href="https://www.it-boltwise.de/claude-tests-fuehren-zu-sandbox-escape-anthropic-meldet-drei-echte-sicherheitsvorfaelle.html">... den vollständigen Artikel <strong>»Claude-Tests führen zu Sandbox-Escape: Anthropic meldet drei echte Sicherheitsvorfälle«</strong> lesen</a></div>
<p>Dieser Beitrag <a href="https://www.it-boltwise.de/claude-tests-fuehren-zu-sandbox-escape-anthropic-meldet-drei-echte-sicherheitsvorfaelle.html">Claude-Tests führen zu Sandbox-Escape: Anthropic meldet drei echte Sicherheitsvorfälle</a> erschien als erstes auf <a href="https://www.it-boltwise.de/">IT BOLTWISE x Artificial Intelligence</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Verändert die 2-Milliarden-US-Dollar-Offensive von PNC in den Bereichen Filialausbau und ...]]></title>
<description><![CDATA[... Filialnetzes weiterhin sowohl Wert auf physische Präsenz als auch auf Cybersicherheit legt. Nun wollen wir untersuchen, wie...]]></description>
<link>https://tsecurity.de/de/3707030/it-security-nachrichten/veraendert-die-2-milliarden-us-dollar-offensive-von-pnc-in-den-bereichen-filialausbau-und/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707030/it-security-nachrichten/veraendert-die-2-milliarden-us-dollar-offensive-von-pnc-in-den-bereichen-filialausbau-und/</guid>
<pubDate>Thu, 06 Aug 2026 01:02:56 +0200</pubDate>
<content:encoded><![CDATA[... Filialnetzes weiterhin sowohl Wert auf physische Präsenz als auch auf <b>Cybersicherheit</b> legt. Nun wollen wir untersuchen, wie...]]></content:encoded>
</item>
<item>
<title><![CDATA[Krankenhausnetzwerke werden zu Zielen von Cyberangriffen und sind nicht darauf ... - Health-ISAC]]></title>
<description><![CDATA[Die Frage, vor der die Verantwortlichen für die Cybersicherheit in Krankenhäusern heute stehen, lautet nicht mehr, ob sie zu Kollateralschäden in ...]]></description>
<link>https://tsecurity.de/de/3707029/it-security-nachrichten/krankenhausnetzwerke-werden-zu-zielen-von-cyberangriffen-und-sind-nicht-darauf-health-isac/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707029/it-security-nachrichten/krankenhausnetzwerke-werden-zu-zielen-von-cyberangriffen-und-sind-nicht-darauf-health-isac/</guid>
<pubDate>Thu, 06 Aug 2026 01:02:56 +0200</pubDate>
<content:encoded><![CDATA[Die Frage, vor der die Verantwortlichen für die <b>Cybersicherheit</b> in Krankenhäusern heute stehen, lautet nicht mehr, ob sie zu Kollateralschäden in ...]]></content:encoded>
</item>
<item>
<title><![CDATA[Oracle SQL Injection Attack Enables Remote Code Execution]]></title>
<description><![CDATA[A Huntress investigation reveals how attackers used SQL injection to achieve RCE and steal credentials.
Read more →
The post Oracle SQL Injection Attack Enables Remote Code Execution appeared first on IT Security News.]]></description>
<link>https://tsecurity.de/de/3707028/it-security-nachrichten/oracle-sql-injection-attack-enables-remote-code-execution/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707028/it-security-nachrichten/oracle-sql-injection-attack-enables-remote-code-execution/</guid>
<pubDate>Thu, 06 Aug 2026 01:02:50 +0200</pubDate>
<content:encoded><![CDATA[<p>A Huntress investigation reveals how attackers used SQL injection to achieve RCE and steal credentials.</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/oracle-sql-injection-attack-enables-remote-code-execution/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/oracle-sql-injection-attack-enables-remote-code-execution/">Oracle SQL Injection Attack Enables Remote Code Execution</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Could Japan be the next drone giant? Prime Minister looks to push domestic production to reduce reliance on China]]></title>
<description><![CDATA[Japan is racing to build a domestic drone industry, pushing startups toward defense work amid growing missile and China concerns.]]></description>
<link>https://tsecurity.de/de/3707027/it-nachrichten/could-japan-be-the-next-drone-giant-prime-minister-looks-to-push-domestic-production-to-reduce-reliance-on-china/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707027/it-nachrichten/could-japan-be-the-next-drone-giant-prime-minister-looks-to-push-domestic-production-to-reduce-reliance-on-china/</guid>
<pubDate>Thu, 06 Aug 2026 00:57:11 +0200</pubDate>
<content:encoded><![CDATA[Japan is racing to build a domestic drone industry, pushing startups toward defense work amid growing missile and China concerns.]]></content:encoded>
</item>
<item>
<title><![CDATA[X's head of product is leaving the company one year after joining]]></title>
<description><![CDATA[Nikita Bier was the face of some of the platform's biggest changes.]]></description>
<link>https://tsecurity.de/de/3707026/it-nachrichten/xs-head-of-product-is-leaving-the-company-one-year-after-joining/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707026/it-nachrichten/xs-head-of-product-is-leaving-the-company-one-year-after-joining/</guid>
<pubDate>Thu, 06 Aug 2026 00:57:04 +0200</pubDate>
<content:encoded><![CDATA[Nikita Bier was the face of some of the platform's biggest changes.]]></content:encoded>
</item>
<item>
<title><![CDATA[Welp, Nobody Saw SpaceX’s Falcon 9 Rocket Crash Into the Moon]]></title>
<description><![CDATA[Although no one captured a direct image of the impact, scientists have detected signals confirming the rocket hit the lunar surface. Orbiters could provide the first images of the crash site in the coming days.]]></description>
<link>https://tsecurity.de/de/3707025/it-nachrichten/welp-nobody-saw-spacexs-falcon-9-rocket-crash-into-the-moon/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707025/it-nachrichten/welp-nobody-saw-spacexs-falcon-9-rocket-crash-into-the-moon/</guid>
<pubDate>Thu, 06 Aug 2026 00:57:03 +0200</pubDate>
<content:encoded><![CDATA[Although no one captured a direct image of the impact, scientists have detected signals confirming the rocket hit the lunar surface. Orbiters could provide the first images of the crash site in the coming days.]]></content:encoded>
</item>
<item>
<title><![CDATA[Get up to $400 off your TechCrunch Disrupt 2026 pass until Friday]]></title>
<description><![CDATA[Starting today, you can take an additional $100 off your founder, investor, or attendee TechCrunch Disrupt 2026 pass, which is a nice bonus on top of our current discounted pricing. ]]></description>
<link>https://tsecurity.de/de/3707024/it-nachrichten/get-up-to-400-off-your-techcrunch-disrupt-2026-pass-until-friday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707024/it-nachrichten/get-up-to-400-off-your-techcrunch-disrupt-2026-pass-until-friday/</guid>
<pubDate>Thu, 06 Aug 2026 00:57:03 +0200</pubDate>
<content:encoded><![CDATA[Starting today, you can take an additional $100 off your founder, investor, or attendee TechCrunch Disrupt 2026 pass, which is a nice bonus on top of our current discounted pricing. ]]></content:encoded>
</item>
<item>
<title><![CDATA[50 States, 50 Different Ways: Who Owns AI Once It's Deployed?]]></title>
<description><![CDATA[Now that most states have built AI governance frameworks, guardrails or road maps, a new question has started to emerge: who exactly is responsible for AI once it is deployed?]]></description>
<link>https://tsecurity.de/de/3707023/ai-nachrichten/50-states-50-different-ways-who-owns-ai-once-its-deployed/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707023/ai-nachrichten/50-states-50-different-ways-who-owns-ai-once-its-deployed/</guid>
<pubDate>Thu, 06 Aug 2026 00:55:47 +0200</pubDate>
<content:encoded><![CDATA[Now that most states have built AI governance frameworks, guardrails or road maps, a new question has started to emerge: who exactly is responsible for AI once it is deployed?]]></content:encoded>
</item>
<item>
<title><![CDATA[LockBit string deobfuscation: affine cipher DLL loading reversed with Ghidra]]></title>
<description><![CDATA[submitted by    /u/AldairMaihuiri   [link]   [comments]]]></description>
<link>https://tsecurity.de/de/3707022/reverse-engineering/lockbit-string-deobfuscation-affine-cipher-dll-loading-reversed-with-ghidra/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707022/reverse-engineering/lockbit-string-deobfuscation-affine-cipher-dll-loading-reversed-with-ghidra/</guid>
<pubDate>Thu, 06 Aug 2026 00:45:01 +0200</pubDate>
<content:encoded><![CDATA[  submitted by   <a href="https://www.reddit.com/user/AldairMaihuiri"> /u/AldairMaihuiri </a> <br> <span><a href="https://ginomaihuiri.github.io/lockbit-string-deobfuscation">[link]</a></span>   <span><a href="https://www.reddit.com/r/ReverseEngineering/comments/1vgc1dv/lockbit_string_deobfuscation_affine_cipher_dll/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[Western government leaders call for a focus on infrastructure resilience, not AI hype]]></title>
<description><![CDATA[U.S. and allied officials said companies should start preparing now for a cyberattack that changes how they provide essential services.]]></description>
<link>https://tsecurity.de/de/3707021/it-security-nachrichten/western-government-leaders-call-for-a-focus-on-infrastructure-resilience-not-ai-hype/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707021/it-security-nachrichten/western-government-leaders-call-for-a-focus-on-infrastructure-resilience-not-ai-hype/</guid>
<pubDate>Thu, 06 Aug 2026 00:43:01 +0200</pubDate>
<content:encoded><![CDATA[<figure><div><img src="https://imgproxy.divecdn.com/q0GcJs1NoWhrfU7I9r4PwT5EbIqMZwpxopDFWvm8lZ0/g:ce/rs:fill:1600:900:1/Z3M6Ly9kaXZlc2l0ZS1zdG9yYWdlL2RpdmVpbWFnZS9QWExfMjAyNjA4MDVfMTc1ODIwNDQ0LmpwZw==.webp"></div></figure><p>U.S. and allied officials said companies should start preparing now for a cyberattack that changes how they provide essential services.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[OpenAI warns autonomous hacks are ‘watershed moment for computer security’]]></title>
<description><![CDATA[Company employees said their industry should rethink how it balances capabilities and safeguards.]]></description>
<link>https://tsecurity.de/de/3707020/it-security-nachrichten/openai-warns-autonomous-hacks-are-watershed-moment-for-computer-security/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707020/it-security-nachrichten/openai-warns-autonomous-hacks-are-watershed-moment-for-computer-security/</guid>
<pubDate>Thu, 06 Aug 2026 00:43:01 +0200</pubDate>
<content:encoded><![CDATA[<figure><div><img src="https://imgproxy.divecdn.com/knCCzJQisc1IG8_F7mrDfJP91kSIWf-rKf1UCDItDhA/g:nowe:71:409/c:3129:1767/rs:fill:1600:900:1/Z3M6Ly9kaXZlc2l0ZS1zdG9yYWdlL2RpdmVpbWFnZS9QWExfMjAyNjA4MDVfMjAyNzEzODEwLmpwZw==.webp"></div></figure><p>Company employees said their industry should rethink how it balances capabilities and safeguards.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Samsung Removes Smart TV Apps Over Residential Proxy Software Concerns]]></title>
<description><![CDATA[Samsung just began to remove Smart TV apps that contained software capable of sharing users’ home internet access with third parties. The company made the move after security researchers found residential proxy software development kits (SDKs) inside several Smart TV apps. Samsung also introduced...]]></description>
<link>https://tsecurity.de/de/3707019/it-security-nachrichten/samsung-removes-smart-tv-apps-over-residential-proxy-software-concerns/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707019/it-security-nachrichten/samsung-removes-smart-tv-apps-over-residential-proxy-software-concerns/</guid>
<pubDate>Thu, 06 Aug 2026 00:40:53 +0200</pubDate>
<content:encoded><![CDATA[<p>Samsung just began to remove Smart TV apps that contained software capable of sharing users’ home internet access with third parties. The company made the move after security researchers found residential proxy software development kits (SDKs) inside several Smart TV apps. Samsung also introduced new rules to stop developers from adding the same software to […]</p>
<p>The post <a href="https://privacysavvy.com/news/cybersecurity/samsung-removes-smart-tv-apps-residential-proxy/">Samsung Removes Smart TV Apps Over Residential Proxy Software Concerns</a> appeared first on <a href="https://privacysavvy.com/">PrivacySavvy</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Match Group’s CEO Says Gen Z Values In-Person Connection Over Dating Apps]]></title>
<description><![CDATA[Online dating is evolving to be more, well, offline.]]></description>
<link>https://tsecurity.de/de/3707018/it-nachrichten/match-groups-ceo-says-gen-z-values-in-person-connection-over-dating-apps/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707018/it-nachrichten/match-groups-ceo-says-gen-z-values-in-person-connection-over-dating-apps/</guid>
<pubDate>Thu, 06 Aug 2026 00:39:23 +0200</pubDate>
<content:encoded><![CDATA[Online dating is evolving to be more, well, offline.]]></content:encoded>
</item>
<item>
<title><![CDATA[Made by Google 2026: Pixel 11 Event Date, Time, How to Watch and What to Expect]]></title>
<description><![CDATA[New Pixel and watches are on the way, but what else could Google have in store?]]></description>
<link>https://tsecurity.de/de/3707017/it-nachrichten/made-by-google-2026-pixel-11-event-date-time-how-to-watch-and-what-to-expect/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707017/it-nachrichten/made-by-google-2026-pixel-11-event-date-time-how-to-watch-and-what-to-expect/</guid>
<pubDate>Thu, 06 Aug 2026 00:39:23 +0200</pubDate>
<content:encoded><![CDATA[New Pixel and watches are on the way, but what else could Google have in store?]]></content:encoded>
</item>
<item>
<title><![CDATA[Disaster hits home: How Amazon and other companies are responding to Washington state wildfires]]></title>
<description><![CDATA[Amazon's Disaster Relief team is sending emergency supplies; Boeing is donating $250,000; F5 is supporting employees; and other efforts are responding to the devastation in Spokane, Wash. Read More]]></description>
<link>https://tsecurity.de/de/3707016/it-nachrichten/disaster-hits-home-how-amazon-and-other-companies-are-responding-to-washington-state-wildfires/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707016/it-nachrichten/disaster-hits-home-how-amazon-and-other-companies-are-responding-to-washington-state-wildfires/</guid>
<pubDate>Thu, 06 Aug 2026 00:39:23 +0200</pubDate>
<content:encoded><![CDATA[<img fetchpriority="high" loading="eager" width="1260" height="840" src="https://cdn.geekwire.com/wp-content/uploads/2026/08/amznrelief-1260x840.jpeg" class="webfeedsFeaturedVisual wp-post-image" alt="" decoding="async" srcset="https://cdn.geekwire.com/wp-content/uploads/2026/08/amznrelief-1260x840.jpeg 1260w, https://cdn.geekwire.com/wp-content/uploads/2026/08/amznrelief-768x512.jpeg 768w, https://cdn.geekwire.com/wp-content/uploads/2026/08/amznrelief-1536x1024.jpeg 1536w, https://cdn.geekwire.com/wp-content/uploads/2026/08/amznrelief.jpeg 1600w" sizes="(max-width: 1260px) 100vw, 1260px"><br>Amazon's Disaster Relief team is sending emergency supplies; Boeing is donating $250,000; F5 is supporting employees; and other efforts are responding to the devastation in Spokane, Wash. <a href="https://www.geekwire.com/2026/disaster-hits-home-how-amazon-and-other-companies-are-responding-to-washington-state-wildfires/">Read More</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[X product chief Nikita Bier is leaving after one year]]></title>
<description><![CDATA[X head of product Nikita Bier is stepping down and says he will move into a role as an advisor, writing that "it's time to pass the torch and demote myself to my natural state: a poster." He shared the update just over a month after celebrating his one-year anniversary on the job, and just […]]]></description>
<link>https://tsecurity.de/de/3707015/it-nachrichten/x-product-chief-nikita-bier-is-leaving-after-one-year/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707015/it-nachrichten/x-product-chief-nikita-bier-is-leaving-after-one-year/</guid>
<pubDate>Thu, 06 Aug 2026 00:39:17 +0200</pubDate>
<content:encoded><![CDATA[X head of product Nikita Bier is stepping down and says he will move into a role as an advisor, writing that "it's time to pass the torch and demote myself to my natural state: a poster." He shared the update just over a month after celebrating his one-year anniversary on the job, and just […]]]></content:encoded>
</item>
<item>
<title><![CDATA[III: Synology erklärt, warum die zweite Backup-Warnung nie kommt]]></title>
<description><![CDATA[Der Microsoft Defender hält Synology-Backups auf den Servern der Betroffenen für einen Trojaner und schiebt diese Software in Quarantäne, wodurch das Backup nicht mehr ausgeführt wird. Zum Problem wird das, weil Windows nur einmalig eine Warnung über ein gescheitertes Backup … Weiterlesen →
Quelle]]></description>
<link>https://tsecurity.de/de/3707014/it-nachrichten/iii-synology-erklaert-warum-die-zweite-backup-warnung-nie-kommt/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707014/it-nachrichten/iii-synology-erklaert-warum-die-zweite-backup-warnung-nie-kommt/</guid>
<pubDate>Thu, 06 Aug 2026 00:38:39 +0200</pubDate>
<content:encoded><![CDATA[Der Microsoft Defender hält Synology-Backups auf den Servern der Betroffenen für einen Trojaner und schiebt diese Software in Quarantäne, wodurch das Backup nicht mehr ausgeführt wird. Zum Problem wird das, weil Windows nur einmalig eine Warnung über ein gescheitertes Backup … <a href="https://borncity.com/blog/2026/08/06/iii-synology-erklaert-warum-die-zweite-backup-warnung-nie-kommt/">Weiterlesen <span class="meta-nav">→</span></a>
<p><a href="https://borncity.com/blog/2026/08/06/iii-synology-erklaert-warum-die-zweite-backup-warnung-nie-kommt/" rel="nofollow">Quelle</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Big shake-up in Google’s AI team as DeepMind chief executive steps down]]></title>
<description><![CDATA[Two senior engineers are leaving company to launch startup amid fears Google is falling behind in AI raceSir Demis Hassabis is stepping down as chief executive of Google DeepMind, in a leadership overhaul of the UK-based AI research lab.Hassabis, a Nobel prize recipient, is leaving his main manag...]]></description>
<link>https://tsecurity.de/de/3707013/ai-nachrichten/big-shake-up-in-googles-ai-team-as-deepmind-chief-executive-steps-down/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707013/ai-nachrichten/big-shake-up-in-googles-ai-team-as-deepmind-chief-executive-steps-down/</guid>
<pubDate>Thu, 06 Aug 2026 00:38:10 +0200</pubDate>
<content:encoded><![CDATA[<p>Two senior engineers are leaving company to launch startup amid fears Google is falling behind in AI race</p><p>Sir Demis Hassabis is stepping down as chief executive of Google DeepMind, in a leadership overhaul of the UK-based AI research lab.</p><p>Hassabis, a <a href="https://www.theguardian.com/science/2024/oct/09/google-deepmind-scientists-win-nobel-chemistry-prize">Nobel prize recipient</a>, is leaving his main managerial role to become chair of DeepMind – as well as taking on the new position of chief scientist at Alphabet, which is also Google’s parent company. DeepMind will now be led by Koray Kavukcuoglu, its chief technology officer, under the title of senior vice-president.</p> <a href="https://www.theguardian.com/technology/2026/aug/05/big-shake-up-in-googles-ai-team-as-deepmind-chief-executive-steps-down">Continue reading...</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Taming Outlier Tokens in Diffusion Transformers]]></title>
<description><![CDATA[We study outlier tokens in Diffusion Transformers (DiTs) for image generation. Prior work has shown that Vision Transformers (ViTs) can produce a small number of high-norm tokens that attract disproportionate attention while carrying limited local information, but their role in generative models ...]]></description>
<link>https://tsecurity.de/de/3707012/ai-nachrichten/taming-outlier-tokens-in-diffusion-transformers/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707012/ai-nachrichten/taming-outlier-tokens-in-diffusion-transformers/</guid>
<pubDate>Thu, 06 Aug 2026 00:38:00 +0200</pubDate>
<content:encoded><![CDATA[We study outlier tokens in Diffusion Transformers (DiTs) for image generation. Prior work has shown that Vision Transformers (ViTs) can produce a small number of high-norm tokens that attract disproportionate attention while carrying limited local information, but their role in generative models remains underexplored. We show that this phenomenon appears in both the encoder and denoiser of modern Representation Autoencoder (RAE)-DiT pipelines: pretrained ViT encoders can produce outlier representations, and DiTs themselves can develop internal outlier tokens, especially in intermediate layers…]]></content:encoded>
</item>
<item>
<title><![CDATA[PSA: don't fall for the scam Uber email making the rounds]]></title>
<description><![CDATA[No, your Uber payment method didn't expire, it's just a scam attempting to steal your payment information. Here's how to spot such scams.Spotting a scam email isn't always easy, but knowing what to look for goes a long wayEmail is a ubiquitous tool that everyone needs for basic web access and acc...]]></description>
<link>https://tsecurity.de/de/3707000/ios-mac-os/psa-dont-fall-for-the-scam-uber-email-making-the-rounds/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3707000/ios-mac-os/psa-dont-fall-for-the-scam-uber-email-making-the-rounds/</guid>
<pubDate>Thu, 06 Aug 2026 00:36:12 +0200</pubDate>
<content:encoded><![CDATA[No, your Uber payment method didn't expire, it's just a scam attempting to steal your payment information. Here's how to spot such scams.<br><br><div><img src="https://media.appleinsider.com/gallery/68480-144285-Apple-Mail-app-Liquid-Glass-icon-xl.jpg" alt="White envelope mail app icon centered on a rounded blue square, set against a smooth blue gradient background, suggesting an email or messaging application logo"><br><span>Spotting a scam email isn't always easy, but knowing what to look for goes a long way</span></div><br>Email is a ubiquitous tool that everyone needs for basic web access and account creation. While some tools like Hide My Email attempt to reduce spam, they <a href="https://appleinsider.com/articles/26/07/21/hide-my-email-flaw-still-worked-two-weeks-after-apples-claimed-fix">aren't foolproof</a>.<br><br>Users across social media and some staff at <em>AppleInsider</em> have received a bogus email claiming to be Uber. While there are many red flags that suggest the email is a fake at first glance, not everyone is going to have the skills to recognize that.<br><br><br> <a href="https://appleinsider.com/articles/26/08/05/psa-dont-fall-for-the-scam-uber-email-making-the-rounds?utm_source=rss">Continue Reading on AppleInsider</a> | <a href="https://forums.appleinsider.com/discussion/245179?urm_source=rss">Discuss on our Forums</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-19022 | OpenHands up to 0.62.0 send_pull_request.py initialize_repo command injection (Issue 14903)]]></title>
<description><![CDATA[A vulnerability marked as critical has been reported in OpenHands up to 0.62.0. The affected element is the function initialize_repo of the file OpenHands/resolver/send_pull_request.py. This manipulation causes command injection.

This vulnerability is registered as CVE-2026-19022. Remote exploit...]]></description>
<link>https://tsecurity.de/de/3706999/sicherheitsluecken/cve-2026-19022-openhands-up-to-0620-sendpullrequestpy-initializerepo-command-injection-issue-14903/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3706999/sicherheitsluecken/cve-2026-19022-openhands-up-to-0620-sendpullrequestpy-initializerepo-command-injection-issue-14903/</guid>
<pubDate>Thu, 06 Aug 2026 00:29:51 +0200</pubDate>
<content:encoded><![CDATA[A vulnerability marked as <a href="https://vuldb.com/kb/risk">critical</a> has been reported in <a href="https://vuldb.com/product/openhands">OpenHands up to 0.62.0</a>. The affected element is the function <code>initialize_repo</code> of the file <em>OpenHands/resolver/send_pull_request.py</em>. This manipulation causes command injection.

This vulnerability is registered as <a href="https://vuldb.com/cve/CVE-2026-19022">CVE-2026-19022</a>. Remote exploitation of the attack is possible. No exploit is available.

The vendor deleted the original GitHub issue report. It appears that the affected path/file got removed in version 1.7.0.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-64192 | Linux Kernel BPF inode_storage_map_alloc missing initialization (WID-SEC-2026-2427)]]></title>
<description><![CDATA[A vulnerability labeled as problematic has been found in Linux Kernel. This issue affects the function inode_storage_map_alloc of the component BPF. The manipulation results in missing initialization of a variable.

This vulnerability is known as CVE-2026-64192. Attacking locally is a requirement...]]></description>
<link>https://tsecurity.de/de/3706998/sicherheitsluecken/cve-2026-64192-linux-kernel-bpf-inodestoragemapalloc-missing-initialization-wid-sec-2026-2427/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3706998/sicherheitsluecken/cve-2026-64192-linux-kernel-bpf-inodestoragemapalloc-missing-initialization-wid-sec-2026-2427/</guid>
<pubDate>Thu, 06 Aug 2026 00:29:51 +0200</pubDate>
<content:encoded><![CDATA[A vulnerability labeled as <a href="https://vuldb.com/kb/risk">problematic</a> has been found in <a href="https://vuldb.com/product/linux:kernel">Linux Kernel</a>. This issue affects the function <code>inode_storage_map_alloc</code> of the component <em>BPF</em>. The manipulation results in missing initialization of a variable.

This vulnerability is known as <a href="https://vuldb.com/cve/CVE-2026-64192">CVE-2026-64192</a>. Attacking locally is a requirement. No exploit is available.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-64205 | Linux Kernel up to 6.18.37/7.1.3 i801 i2c-i801.c i801_access race condition (WID-SEC-2026-2427)]]></title>
<description><![CDATA[A vulnerability marked as problematic has been reported in Linux Kernel up to 6.18.37/7.1.3. Impacted is the function i801_access of the file drivers/i2c/busses/i2c-i801.c of the component i801. This manipulation causes race condition.

This vulnerability is handled as CVE-2026-64205. It is possi...]]></description>
<link>https://tsecurity.de/de/3706997/sicherheitsluecken/cve-2026-64205-linux-kernel-up-to-61837713-i801-i2c-i801c-i801access-race-condition-wid-sec-2026-2427/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3706997/sicherheitsluecken/cve-2026-64205-linux-kernel-up-to-61837713-i801-i2c-i801c-i801access-race-condition-wid-sec-2026-2427/</guid>
<pubDate>Thu, 06 Aug 2026 00:29:51 +0200</pubDate>
<content:encoded><![CDATA[A vulnerability marked as <a href="https://vuldb.com/kb/risk">problematic</a> has been reported in <a href="https://vuldb.com/product/linux:kernel">Linux Kernel up to 6.18.37/7.1.3</a>. Impacted is the function <code>i801_access</code> of the file <em>drivers/i2c/busses/i2c-i801.c</em> of the component <em>i801</em>. This manipulation causes race condition.

This vulnerability is handled as <a href="https://vuldb.com/cve/CVE-2026-64205">CVE-2026-64205</a>. It is possible to launch the attack on the local host. There is not any exploit available.

It is suggested to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-64207 | Linux Kernel up to 6.18.38/7.1.3 dualpi2 net/sched qfq_dequeue null pointer dereference (WID-SEC-2026-2427)]]></title>
<description><![CDATA[A vulnerability classified as critical has been found in Linux Kernel up to 6.18.38/7.1.3. The impacted element is the function qfq_dequeue of the file net/sched of the component dualpi2. Performing a manipulation results in null pointer dereference.

This vulnerability was named CVE-2026-64207. ...]]></description>
<link>https://tsecurity.de/de/3706996/sicherheitsluecken/cve-2026-64207-linux-kernel-up-to-61838713-dualpi2-netsched-qfqdequeue-null-pointer-dereference-wid-sec-2026-2427/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3706996/sicherheitsluecken/cve-2026-64207-linux-kernel-up-to-61838713-dualpi2-netsched-qfqdequeue-null-pointer-dereference-wid-sec-2026-2427/</guid>
<pubDate>Thu, 06 Aug 2026 00:29:51 +0200</pubDate>
<content:encoded><![CDATA[A vulnerability classified as <a href="https://vuldb.com/kb/risk">critical</a> has been found in <a href="https://vuldb.com/product/linux:kernel">Linux Kernel up to 6.18.38/7.1.3</a>. The impacted element is the function <code>qfq_dequeue</code> of the file <em>net/sched</em> of the component <em>dualpi2</em>. Performing a manipulation results in null pointer dereference.

This vulnerability was named <a href="https://vuldb.com/cve/CVE-2026-64207">CVE-2026-64207</a>. The attack may be initiated remotely. There is no available exploit.

It is recommended to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-64206 | Linux Kernel up to 6.18.38/7.1.3/7.2-rc2 L2CAP l2cap_conn_del pending_rx_work deadlock (WID-SEC-2026-2427)]]></title>
<description><![CDATA[A vulnerability described as critical has been identified in Linux Kernel up to 6.18.38/7.1.3/7.2-rc2. The affected element is the function l2cap_conn_del of the component L2CAP. Such manipulation of the argument pending_rx_work leads to deadlock.

This vulnerability is uniquely identified as CVE...]]></description>
<link>https://tsecurity.de/de/3706995/sicherheitsluecken/cve-2026-64206-linux-kernel-up-to-6183871372-rc2-l2cap-l2capconndel-pendingrxwork-deadlock-wid-sec-2026-2427/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3706995/sicherheitsluecken/cve-2026-64206-linux-kernel-up-to-6183871372-rc2-l2cap-l2capconndel-pendingrxwork-deadlock-wid-sec-2026-2427/</guid>
<pubDate>Thu, 06 Aug 2026 00:29:51 +0200</pubDate>
<content:encoded><![CDATA[A vulnerability described as <a href="https://vuldb.com/kb/risk">critical</a> has been identified in <a href="https://vuldb.com/product/linux:kernel">Linux Kernel up to 6.18.38/7.1.3/7.2-rc2</a>. The affected element is the function <code>l2cap_conn_del</code> of the component <em>L2CAP</em>. Such manipulation of the argument <em>pending_rx_work</em> leads to deadlock.

This vulnerability is uniquely identified as <a href="https://vuldb.com/cve/CVE-2026-64206">CVE-2026-64206</a>. The attack can be launched remotely. No exploit exists.

Upgrading the affected component is recommended.]]></content:encoded>
</item>
<item>
<title><![CDATA[Security validation should begin where attackers begin]]></title>
<description><![CDATA[Modern attacks increasingly begin with the web application.



Customer portals, partner platforms, APIs, external business applications, and AI-powered services have become the front door to the enterprise. The systems organizations build to create value are now the same systems attackers target...]]></description>
<link>https://tsecurity.de/de/3706994/it-security-nachrichten/security-validation-should-begin-where-attackers-begin/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3706994/it-security-nachrichten/security-validation-should-begin-where-attackers-begin/</guid>
<pubDate>Thu, 06 Aug 2026 00:27:43 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Modern attacks increasingly begin with the web application.</p>



<p class="wp-block-paragraph">Customer portals, partner platforms, APIs, external business applications, and AI-powered services have become the front door to the enterprise. The systems organizations build to create value are now the same systems attackers target for initial access.</p>



<p class="wp-block-paragraph">For years, security teams have invested heavily in protecting networks, endpoints, identities, and cloud infrastructure. Those investments remain essential, but the way attackers gain initial access has changed. Business-critical applications are internet-facing, constantly evolving, deeply connected to enterprise systems, and often changing faster than organizations can continuously validate them.</p>



<p class="wp-block-paragraph">Artificial intelligence is accelerating this shift. The time between vulnerability discovery and exploitation continues to shrink, allowing attackers to identify and weaponize weaknesses at machine speed. Yet while attacks have evolved, much of security validation still reflects yesterday’s architecture.</p>



<p class="wp-block-paragraph"><em>That shift is exactly why we built </em><a href="http://horizon3.ai/nodezero/webapp" target="_blank" rel="noreferrer noopener"><em>NodeZero WebApp</em></a><em>, extending autonomous attack validation to where modern attacks increasingly begin.</em></p>



<p class="wp-block-paragraph"><strong>Validation still reflects yesterday’s architecture</strong></p>



<p class="wp-block-paragraph">Most organizations still organize security by technology. Application security teams test web applications. Identity teams validate authentication and access controls. Cloud teams secure cloud infrastructure, while infrastructure teams assess networks and endpoints. Each discipline performs valuable work.</p>



<p class="wp-block-paragraph">The problem is that attackers don’t organize themselves the same way. They move across technologies, chaining weaknesses together until they reach their objective. A vulnerable application becomes compromised credentials. Compromised credentials become identity abuse. Identity abuse becomes access to cloud resources, infrastructure, and eventually the business systems they were after all along.</p>



<p class="wp-block-paragraph">Taken together, this means security validation often stops where the next stage of the attack begins.</p>



<p class="wp-block-paragraph"><strong>Attack paths don’t stop at the web application</strong></p>



<p class="wp-block-paragraph">A SQL injection isn’t the outcome. It’s the beginning of an attack path. An authentication weakness isn’t the breach. It’s simply the first opportunity to move deeper into the environment.</p>



<p class="wp-block-paragraph">The question isn’t whether a vulnerability exists. Security teams already have plenty of ways to answer that. The real question is what an attacker can do after exploiting it.</p>



<p class="wp-block-paragraph">Can they compromise identities? Reach sensitive data? Pivot into cloud resources? Move laterally into critical business systems?</p>



<p class="wp-block-paragraph">Security teams don’t lose because they missed a vulnerability. They lose because they never validated where it could lead. Modern attacks don’t unfold within a single technology stack. They move across applications, identities, infrastructure, and cloud environments until they create business impact. Security validation has to reflect that reality.</p>



<p class="wp-block-paragraph"><strong>Security validation has to change</strong></p>



<p class="wp-block-paragraph">For years, organizations validated individual technologies because that’s how enterprise environments were built. That approach made sense when applications, identities, infrastructure, and cloud platforms operated more independently and attackers moved more slowly.</p>



<p class="wp-block-paragraph">Today’s attacks don’t respect those boundaries. Validation shouldn’t either.</p>



<p class="wp-block-paragraph">It has to begin where attackers begin and continue until business impact is understood.</p>



<p class="wp-block-paragraph"><strong>Asking the right question</strong></p>



<p class="wp-block-paragraph">Many security tools begin with privileged knowledge. They analyze source code, configuration files, or other internal artifacts before identifying weaknesses. Those approaches answer important questions during software development and secure coding, and they remain an important part of building secure software.</p>



<p class="wp-block-paragraph">Attackers begin with what they can reach, interacting with an application as it exists in production, scouring exposed source code looking for novel vulnerabilities and stored identities, authenticating when they can, observing how it behaves, and looking for opportunities to move deeper into the environment. Every decision is driven by what the application reveals, not what its developers intended.</p>



<p class="wp-block-paragraph">Security validation should begin with the same perspective an attacker has, and answer the same question every attacker is trying to answer:</p>



<p class="wp-block-paragraph"><strong>What can I actually reach from here?</strong></p>



<p class="wp-block-paragraph">That shift changes more than where testing starts. It fundamentally changes what security teams learn from the exercise.</p>



<p class="wp-block-paragraph"> src="https://b2b-contenthub.com/wp-content/uploads/2026/08/configurationimages.png" alt="horizon3"&gt;Se<em>curity validation shouldn’t stop at anonymous pages. NodeZero WebApp safely validates authenticated application workflows, helping organizations assess the same privileged experiences attackers seek after gaining initial access.</em></p>



<p class="wp-block-paragraph">Click <a href="https://horizon3.ai/intelligence/blogs/web-application-security-validation/#:~:text=Extending%20Attack%20Validation%20to%20the%20Modern%20Entry%20Point" target="_blank" rel="noreferrer noopener">here</a> to discover how NodeZero WebApp addresses modern attacks.</p>



<p class="wp-block-paragraph"><strong>See NodeZero WebApp in action</strong></p>



<p class="wp-block-paragraph">Modern attacks start with web applications — but they rarely end there. Join our live webinar to see how NodeZero WebApp safely validates real attack paths from authenticated applications into identity, cloud, and infrastructure, helping you understand the business impact of exploitable weaknesses before attackers do.</p>



<p class="wp-block-paragraph">Register for our <a href="https://events.horizon3.ai/introducing-nodezero-webapp">webinar</a></p>



<p class="wp-block-paragraph"></p>



<p class="wp-block-paragraph"></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Crackme 01 — Hardcoded strcmp reversed with GDB: x86_64 calling convention, AVX2 strcmp internals, full assembly flow]]></title>
<description><![CDATA[submitted by    /u/AldairMaihuiri   [link]   [comments]]]></description>
<link>https://tsecurity.de/de/3706993/malware-trojaner-viren/crackme-01-hardcoded-strcmp-reversed-with-gdb-x8664-calling-convention-avx2-strcmp-internals-full-assembly-flow/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3706993/malware-trojaner-viren/crackme-01-hardcoded-strcmp-reversed-with-gdb-x8664-calling-convention-avx2-strcmp-internals-full-assembly-flow/</guid>
<pubDate>Thu, 06 Aug 2026 00:15:42 +0200</pubDate>
<content:encoded><![CDATA[  submitted by   <a href="https://www.reddit.com/user/AldairMaihuiri"> /u/AldairMaihuiri </a> <br> <span><a href="https://ginomaihuiri.github.io/crackmes/cm1-strcmp">[link]</a></span>   <span><a href="https://www.reddit.com/r/ExploitDev/comments/1vgc3cd/crackme_01_hardcoded_strcmp_reversed_with_gdb_x86/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[Microsoft Bug Bounty Payouts Reach $20 Million as Researcher Participation Surges]]></title>
<description><![CDATA[Microsoft paid a record $20 million to 562 bug bounty researchers as AI-assisted reporting and growing participation reshaped vulnerability discovery.
Read more →
The post Microsoft Bug Bounty Payouts Reach $20 Million as Researcher Participation Surges appeared first on IT Security News.]]></description>
<link>https://tsecurity.de/de/3706992/it-security-nachrichten/microsoft-bug-bounty-payouts-reach-20-million-as-researcher-participation-surges/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3706992/it-security-nachrichten/microsoft-bug-bounty-payouts-reach-20-million-as-researcher-participation-surges/</guid>
<pubDate>Thu, 06 Aug 2026 00:15:02 +0200</pubDate>
<content:encoded><![CDATA[<p>Microsoft paid a record $20 million to 562 bug bounty researchers as AI-assisted reporting and growing participation reshaped vulnerability discovery.</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/microsoft-bug-bounty-payouts-reach-20-million-as-researcher-participation-surges/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/microsoft-bug-bounty-payouts-reach-20-million-as-researcher-participation-surges/">Microsoft Bug Bounty Payouts Reach $20 Million as Researcher Participation Surges</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[UK AI tests found 19 unauthorized agent actions involving Anthropic and OpenAI models]]></title>
<description><![CDATA[UK researchers reported 19 unsanctioned actions by Anthropic and OpenAI agents during permissive cyber tests involving real external systems.
Read more →
The post UK AI tests found 19 unauthorized agent actions involving Anthropic and OpenAI models appeared first on IT Security News.]]></description>
<link>https://tsecurity.de/de/3706991/it-security-nachrichten/uk-ai-tests-found-19-unauthorized-agent-actions-involving-anthropic-and-openai-models/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3706991/it-security-nachrichten/uk-ai-tests-found-19-unauthorized-agent-actions-involving-anthropic-and-openai-models/</guid>
<pubDate>Thu, 06 Aug 2026 00:15:02 +0200</pubDate>
<content:encoded><![CDATA[<p>UK researchers reported 19 unsanctioned actions by Anthropic and OpenAI agents during permissive cyber tests involving real external systems.</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/uk-ai-tests-found-19-unauthorized-agent-actions-involving-anthropic-and-openai-models/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/uk-ai-tests-found-19-unauthorized-agent-actions-involving-anthropic-and-openai-models/">UK AI tests found 19 unauthorized agent actions involving Anthropic and OpenAI models</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Prompt injection isn’t the bug, AI agent frameworks are]]></title>
<description><![CDATA[Check Point researchers tried to break the frameworks enterprises use to build AI apps. Now they're telling Black Hat attendees what they found
Read more →
The post Prompt injection isn’t the bug, AI agent frameworks are appeared first on IT Security News.]]></description>
<link>https://tsecurity.de/de/3706990/it-security-nachrichten/prompt-injection-isnt-the-bug-ai-agent-frameworks-are/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3706990/it-security-nachrichten/prompt-injection-isnt-the-bug-ai-agent-frameworks-are/</guid>
<pubDate>Thu, 06 Aug 2026 00:15:02 +0200</pubDate>
<content:encoded><![CDATA[<p>Check Point researchers tried to break the frameworks enterprises use to build AI apps. Now they're telling Black Hat attendees what they found</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/prompt-injection-isnt-the-bug-ai-agent-frameworks-are/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/prompt-injection-isnt-the-bug-ai-agent-frameworks-are/">Prompt injection isn’t the bug, AI agent frameworks are</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[AWS partners with Anthropic and OpenAI to bring AWS Continuum into developer workflows]]></title>
<description><![CDATA[Customers have access to models that are continuously getting better with each new generation bringing larger context windows, stronger reasoning, and…
Read more →
The post AWS partners with Anthropic and OpenAI to bring AWS Continuum into developer workflows appeared first on IT Security News.]]></description>
<link>https://tsecurity.de/de/3706989/it-security-nachrichten/aws-partners-with-anthropic-and-openai-to-bring-aws-continuum-into-developer-workflows/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3706989/it-security-nachrichten/aws-partners-with-anthropic-and-openai-to-bring-aws-continuum-into-developer-workflows/</guid>
<pubDate>Thu, 06 Aug 2026 00:15:02 +0200</pubDate>
<content:encoded><![CDATA[<p>Customers have access to models that are continuously getting better with each new generation bringing larger context windows, stronger reasoning, and…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/aws-partners-with-anthropic-and-openai-to-bring-aws-continuum-into-developer-workflows/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/aws-partners-with-anthropic-and-openai-to-bring-aws-continuum-into-developer-workflows/">AWS partners with Anthropic and OpenAI to bring AWS Continuum into developer workflows</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[OpenAI and Anthropic Agents Took 19 Unauthorised Actions During UK Cyber Tests]]></title>
<description><![CDATA[UK cyber tests found OpenAI and Anthropic agents taking 19 unauthorised actions, including deception and attempts to plant malicious code.
Read more →
The post OpenAI and Anthropic Agents Took 19 Unauthorised Actions During UK Cyber Tests appeared first on IT Security News.]]></description>
<link>https://tsecurity.de/de/3706988/it-security-nachrichten/openai-and-anthropic-agents-took-19-unauthorised-actions-during-uk-cyber-tests/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3706988/it-security-nachrichten/openai-and-anthropic-agents-took-19-unauthorised-actions-during-uk-cyber-tests/</guid>
<pubDate>Thu, 06 Aug 2026 00:15:02 +0200</pubDate>
<content:encoded><![CDATA[<p>UK cyber tests found OpenAI and Anthropic agents taking 19 unauthorised actions, including deception and attempts to plant malicious code.</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/openai-and-anthropic-agents-took-19-unauthorised-actions-during-uk-cyber-tests/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/openai-and-anthropic-agents-took-19-unauthorised-actions-during-uk-cyber-tests/">OpenAI and Anthropic Agents Took 19 Unauthorised Actions During UK Cyber Tests</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[AI Attacks Are Evolving: TryHackMe Demo Explores Prompt Injection]]></title>
<description><![CDATA[TryHackMe demo: Explore how prompt injection is reshaping AI security risks.
Read more →
The post AI Attacks Are Evolving: TryHackMe Demo Explores Prompt Injection appeared first on IT Security News.]]></description>
<link>https://tsecurity.de/de/3706987/it-security-nachrichten/ai-attacks-are-evolving-tryhackme-demo-explores-prompt-injection/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3706987/it-security-nachrichten/ai-attacks-are-evolving-tryhackme-demo-explores-prompt-injection/</guid>
<pubDate>Thu, 06 Aug 2026 00:15:02 +0200</pubDate>
<content:encoded><![CDATA[<p>TryHackMe demo: Explore how prompt injection is reshaping AI security risks.</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/ai-attacks-are-evolving-tryhackme-demo-explores-prompt-injection/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/ai-attacks-are-evolving-tryhackme-demo-explores-prompt-injection/">AI Attacks Are Evolving: TryHackMe Demo Explores Prompt Injection</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Anthropic's AI Used Fake Identities, Malware In Rogue Attack On GitHub Project]]></title>
<description><![CDATA[An anonymous reader quotes a report from Ars Technica: Routine cybersecurity testing of frontier AI models sparked a series of unexpected security incidents -- the most serious case arising when Anthropic's Mythos 5 model attempted to insert malicious code into an open source software application...]]></description>
<link>https://tsecurity.de/de/3706986/it-security-nachrichten/anthropics-ai-used-fake-identities-malware-in-rogue-attack-on-github-project/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3706986/it-security-nachrichten/anthropics-ai-used-fake-identities-malware-in-rogue-attack-on-github-project/</guid>
<pubDate>Thu, 06 Aug 2026 00:11:49 +0200</pubDate>
<content:encoded><![CDATA[An anonymous reader quotes a report from Ars Technica: Routine cybersecurity testing of frontier AI models sparked a series of unexpected security incidents -- the most serious case arising when Anthropic's Mythos 5 model attempted to insert malicious code into an open source software application and created fake identities to deceive the human developers maintaining the project. The security incidents occurred during a cyber evaluation of seven leading AI models' capabilities by the AI Security Institute (AISI), a research organization within the UK government, in late July. The researchers discovered (PDF) 19 instances in which "AI agents took unsanctioned action on the live Internet, including cases that targeted real people and organizations," according to an AISI blog post published on August 4.
 
Almost all the "autonomous, unsanctioned" actions came from Anthropic's Mythos 5 model, with two such actions coming from OpenAI's GPT-5.6 Sol. [...] The most serious case involved Mythos making multiple attempts to execute a supply chain attack on the open source project repository hosted on the developer platform GitHub, including using social engineering techniques to try to convince the repository's human maintainers to merge malicious code into the repository.
 
After first opening a pull request to merge the malicious code into the repository, Mythos created fake online "sock puppet" personas that claimed to have independently reviewed and verified the code as not containing malware. The AI agent also sent five emails to two human maintainers of the repository, including some emails containing malware and others attempting to persuade a maintainer to accept the pull request. Mythos even opened a GitHub Issue on a second repository -- also owned by a maintainer of the first repository -- that contained a prompt injection with malicious instructions targeting "issue-triage AI coding agents." This line of attack came from Mythos reasoning that the repository maintainer could be an AI coding agent such as Claude Code.<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=Anthropic's+AI+Used+Fake+Identities%2C+Malware+In+Rogue+Attack+On+GitHub+Project%3A+https%3A%2F%2Fit.slashdot.org%2Fstory%2F26%2F08%2F05%2F2157224%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fit.slashdot.org%2Fstory%2F26%2F08%2F05%2F2157224%2Fanthropics-ai-used-fake-identities-malware-in-rogue-attack-on-github-project%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://it.slashdot.org/story/26/08/05/2157224/anthropics-ai-used-fake-identities-malware-in-rogue-attack-on-github-project?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Quote of the day by Anduril founder Palmer Lucky: 'There's no moral high ground to making a land mine that can't tell the difference between a school bus full of children and Russian armor']]></title>
<description><![CDATA[The era of 'dumb weapons' is coming to an end, with companies striving to infuse AI and other technologies into the tools of future warfare]]></description>
<link>https://tsecurity.de/de/3706985/it-nachrichten/quote-of-the-day-by-anduril-founder-palmer-lucky-theres-no-moral-high-ground-to-making-a-land-mine-that-cant-tell-the-difference-between-a-school-bus-full-of-children-and-russian-armor/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3706985/it-nachrichten/quote-of-the-day-by-anduril-founder-palmer-lucky-theres-no-moral-high-ground-to-making-a-land-mine-that-cant-tell-the-difference-between-a-school-bus-full-of-children-and-russian-armor/</guid>
<pubDate>Thu, 06 Aug 2026 00:11:40 +0200</pubDate>
<content:encoded><![CDATA[The era of 'dumb weapons' is coming to an end, with companies striving to infuse AI and other technologies into the tools of future warfare]]></content:encoded>
</item>
<item>
<title><![CDATA[Disney+ could soon get a free tier — and it’s about much more than streaming]]></title>
<description><![CDATA[Disney is exploring a free tier for Disney+ that could bring in more viewers while transforming the service into a larger digital hub for the company.]]></description>
<link>https://tsecurity.de/de/3706984/it-nachrichten/disney-could-soon-get-a-free-tier-and-its-about-much-more-than-streaming/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3706984/it-nachrichten/disney-could-soon-get-a-free-tier-and-its-about-much-more-than-streaming/</guid>
<pubDate>Thu, 06 Aug 2026 00:11:40 +0200</pubDate>
<content:encoded><![CDATA[Disney is exploring a free tier for Disney+ that could bring in more viewers while transforming the service into a larger digital hub for the company.]]></content:encoded>
</item>
<item>
<title><![CDATA[Meta introduces Muse Code, its take on a coding agent]]></title>
<description><![CDATA[The terminal-based coding tool is powered by a new AI model, Muse Spark 1.2.]]></description>
<link>https://tsecurity.de/de/3706983/it-nachrichten/meta-introduces-muse-code-its-take-on-a-coding-agent/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3706983/it-nachrichten/meta-introduces-muse-code-its-take-on-a-coding-agent/</guid>
<pubDate>Thu, 06 Aug 2026 00:11:33 +0200</pubDate>
<content:encoded><![CDATA[The terminal-based coding tool is powered by a new AI model, Muse Spark 1.2.]]></content:encoded>
</item>
<item>
<title><![CDATA[PowerShell and Fileless Attacks]]></title>
<description><![CDATA[In this blog post, I am going to show you an example of fileless attacks in PowerShell. A fileless attack in PowerShell means that the attacker does not write malicious code to […]]]></description>
<link>https://tsecurity.de/de/3706982/it-nachrichten/powershell-and-fileless-attacks/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3706982/it-nachrichten/powershell-and-fileless-attacks/</guid>
<pubDate>Thu, 06 Aug 2026 00:11:30 +0200</pubDate>
<content:encoded><![CDATA[In this blog post, I am going to show you an example of fileless attacks in PowerShell. A fileless attack in PowerShell means that the attacker does not write malicious code to […]]]></content:encoded>
</item>
<item>
<title><![CDATA[Midnight Blizzard greift M365-Zugangsdaten über kompromittierte Hotelrouter ab]]></title>
<description><![CDATA[Die staatsnahe russische Cybergruppe Midnight Blizzard konnte wohl weltweit WLAN-Portale von Hotels und Konferenzzentren kompromittieren. Gäste, die über diese WLAN-Zugänge ins Internet gingen, um auf M365-Zugänge zuzugreifen, wurden auf Phishing-Seiten sowie gefälschte Software-Update-Seiten umg...]]></description>
<link>https://tsecurity.de/de/3706981/it-nachrichten/midnight-blizzard-greift-m365-zugangsdaten-ueber-kompromittierte-hotelrouter-ab/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3706981/it-nachrichten/midnight-blizzard-greift-m365-zugangsdaten-ueber-kompromittierte-hotelrouter-ab/</guid>
<pubDate>Thu, 06 Aug 2026 00:10:57 +0200</pubDate>
<content:encoded><![CDATA[Die staatsnahe russische Cybergruppe Midnight Blizzard konnte wohl weltweit WLAN-Portale von Hotels und Konferenzzentren kompromittieren. Gäste, die über diese WLAN-Zugänge ins Internet gingen, um auf M365-Zugänge zuzugreifen, wurden auf Phishing-Seiten sowie gefälschte Software-Update-Seiten umgeleitet. So wurden die Anmeldedaten, Sitzungstoken und … <a href="https://borncity.com/blog/2026/08/06/midnight-blizzard-greift-m365-zugangsdaten-ueber-kompromittierte-hotelrouter-ab/">Weiterlesen <span class="meta-nav">→</span></a>
<p><a href="https://borncity.com/blog/2026/08/06/midnight-blizzard-greift-m365-zugangsdaten-ueber-kompromittierte-hotelrouter-ab/" rel="nofollow">Quelle</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[End-to-End Bayesian Marketing Mix Modeling with Google Meridian: Media Measurement, ROI Analysis, and Budget Optimization]]></title>
<description><![CDATA[In this tutorial, we build a complete Bayesian marketing mix modeling workflow using Google Meridian. We begin by installing the required libraries, verifying GPU availability, and exploring a geo-level marketing dataset that includes media impressions, spend, controls, promotions, conversions, p...]]></description>
<link>https://tsecurity.de/de/3706980/ai-nachrichten/end-to-end-bayesian-marketing-mix-modeling-with-google-meridian-media-measurement-roi-analysis-and-budget-optimization/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3706980/ai-nachrichten/end-to-end-bayesian-marketing-mix-modeling-with-google-meridian-media-measurement-roi-analysis-and-budget-optimization/</guid>
<pubDate>Thu, 06 Aug 2026 00:10:26 +0200</pubDate>
<content:encoded><![CDATA[<p>In this tutorial, we build a complete Bayesian marketing mix modeling workflow using Google Meridian. We begin by installing the required libraries, verifying GPU availability, and exploring a geo-level marketing dataset that includes media impressions, spend, controls, promotions, conversions, population, and revenue. We then map the raw columns to Meridian’s data schema, define interpretable ROI-based […]</p>
<p>The post <a href="https://www.marktechpost.com/2026/08/05/end-to-end-bayesian-marketing-mix-modeling-with-google-meridian-media-measurement-roi-analysis-and-budget-optimization/">End-to-End Bayesian Marketing Mix Modeling with Google Meridian: Media Measurement, ROI Analysis, and Budget Optimization</a> appeared first on <a href="https://www.marktechpost.com/">MarkTechPost</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[GitHub: v4.1.5]]></title>
<description><![CDATA[Added

Explain when a free model promotion ends. Requests to a retired free model now show a dedicated notice with a button to pick another model, instead of a generic error with nothing but a Retry prompt.

Changed

Map reasoning settings onto a shared path across AI SDK providers, so effort lev...]]></description>
<link>https://tsecurity.de/de/3706977/downloads/github-v415/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3706977/downloads/github-v415/</guid>
<pubDate>Thu, 06 Aug 2026 00:07:24 +0200</pubDate>
<content:encoded><![CDATA[<div class="github-feed-entry"><h3>Added</h3>
<ul>
<li>Explain when a free model promotion ends. Requests to a retired free model now show a dedicated notice with a button to pick another model, instead of a generic error with nothing but a Retry prompt.</li>
</ul>
<h3>Changed</h3>
<ul>
<li>Map reasoning settings onto a shared path across AI SDK providers, so effort levels and enable/disable toggles behave consistently (including on Ollama) instead of relying on per-provider overrides.</li>
</ul>
<p><strong>Full Changelog</strong>: <a class="commit-link" href="https://github.com/cline/cline/compare/v4.1.4...v4.1.5">v4.1.4...v4.1.5</a></p></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-18103 | Red Hat Enterprise Linux 6/7/8/9 OMAPI print_hw_addr buffer overflow (CNNVD-2026-73861150)]]></title>
<description><![CDATA[A vulnerability was found in Red Hat Enterprise Linux 6/7/8/9 and classified as critical. This affects the function print_hw_addr of the component OMAPI. The manipulation results in buffer overflow.

This vulnerability was named CVE-2026-18103. The attack may be performed from remote. There is no...]]></description>
<link>https://tsecurity.de/de/3706976/sicherheitsluecken/cve-2026-18103-red-hat-enterprise-linux-6789-omapi-printhwaddr-buffer-overflow-cnnvd-2026-73861150/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3706976/sicherheitsluecken/cve-2026-18103-red-hat-enterprise-linux-6789-omapi-printhwaddr-buffer-overflow-cnnvd-2026-73861150/</guid>
<pubDate>Thu, 06 Aug 2026 00:06:13 +0200</pubDate>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/red_hat:enterprise_linux">Red Hat Enterprise Linux 6/7/8/9</a> and classified as <a href="https://vuldb.com/kb/risk">critical</a>. This affects the function <code>print_hw_addr</code> of the component <em>OMAPI</em>. The manipulation results in buffer overflow.

This vulnerability was named <a href="https://vuldb.com/cve/CVE-2026-18103">CVE-2026-18103</a>. The attack may be performed from remote. There is no available exploit.]]></content:encoded>
</item>
<item>
<title><![CDATA[Hacker tarnen Mac-Malware als Zoom-Update - iTopnews.de]]></title>
<description><![CDATA[Durch Fake-Zoom erlangen Hacker Fernzugriff auf euren Mac. Securonix warnt vor der Malware-Kampagne namens Smoke#Screen. Die Angreifer setzen dabei ...]]></description>
<link>https://tsecurity.de/de/3706975/hacking/hacker-tarnen-mac-malware-als-zoom-update-itopnewsde/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3706975/hacking/hacker-tarnen-mac-malware-als-zoom-update-itopnewsde/</guid>
<pubDate>Thu, 06 Aug 2026 00:05:49 +0200</pubDate>
<content:encoded><![CDATA[Durch Fake-Zoom erlangen <b>Hacker</b> Fernzugriff auf euren Mac. Securonix warnt vor der Malware-Kampagne namens Smoke#Screen. Die Angreifer setzen dabei ...]]></content:encoded>
</item>
<item>
<title><![CDATA[KI wendet sich bei Test gegen Menschen | BR24]]></title>
<description><![CDATA[London: In Großbritannien haben Sicherheitsforscher bei einem KI-Modell alarmierende Hacker-Fähigkeiten beobachtet. In einem Testl .]]></description>
<link>https://tsecurity.de/de/3706974/hacking/ki-wendet-sich-bei-test-gegen-menschen-br24/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3706974/hacking/ki-wendet-sich-bei-test-gegen-menschen-br24/</guid>
<pubDate>Thu, 06 Aug 2026 00:05:49 +0200</pubDate>
<content:encoded><![CDATA[London: In Großbritannien haben Sicherheitsforscher bei einem KI-Modell alarmierende <b>Hacker</b>-Fähigkeiten beobachtet. In einem Testl .]]></content:encoded>
</item>
<item>
<title><![CDATA[Why security validation must follow the attack path]]></title>
<description><![CDATA[For years organizations have strengthened their security posture by investing in specialized tools for applications, identities, endpoints, networks, and cloud infrastructure. Those investments remain essential, but the way attackers operate has changed dramatically. Today’s adversaries move late...]]></description>
<link>https://tsecurity.de/de/3706973/it-security-nachrichten/why-security-validation-must-follow-the-attack-path/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3706973/it-security-nachrichten/why-security-validation-must-follow-the-attack-path/</guid>
<pubDate>Thu, 06 Aug 2026 00:04:12 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">For years organizations have strengthened their security posture by investing in specialized tools for applications, identities, endpoints, networks, and cloud infrastructure. Those investments remain essential, but the way attackers operate has changed dramatically. Today’s adversaries move laterally, chaining together weaknesses across multiple technologies until they reach their ultimate target.</p>



<p class="wp-block-paragraph"><a href="https://horizon3.ai/intelligence/blogs/infrastructure-readiness/" target="_blank" rel="noreferrer noopener">AI is accelerating the pace of cyberattacks</a>. The window between vulnerability disclosure and exploitation continues to shrink, giving security teams less time to identify, prioritize, and remediate risk.</p>



<p class="wp-block-paragraph">In this environment, an approach that focuses just on isolated technologies is disconnected from how real attacks unfold. Modern attacks often begin with internet-facing web applications. Customer portals, application programming interfaces (APIs), partner platforms, and AI-enabled services have become attractive entry points, because they are constantly evolving and deeply connected to critical business systems. But compromising a web application is rarely the attacker’s end goal. It is simply the first step in a broader attack path.</p>



<p class="wp-block-paragraph">That reality exposes a growing gap in the way many organizations validate security:</p>



<ul class="wp-block-list">
<li>Application security teams test applications.</li>



<li>Identity teams assess authentication controls.</li>



<li>Cloud teams evaluate cloud environments.</li>



<li>Infrastructure teams focus on networks and endpoints.</li>
</ul>



<p class="wp-block-paragraph">Each discipline plays an important role, yet these assessments often occur independently, reflecting organizational structures rather than attacker behavior.</p>



<h3 class="wp-block-heading">Why isolated testing no longer tells the whole story</h3>



<p class="wp-block-paragraph">Attackers don’t recognize those boundaries. A vulnerable web application can expose credentials. Stolen credentials can enable identity abuse. Compromised identities can provide access to cloud resources, sensitive data, and critical business systems.</p>



<p class="wp-block-paragraph">Looking at each technology in isolation makes it difficult to understand whether individual weaknesses can actually be combined into a successful attack. As a result, organizations are beginning to shift their focus from simply identifying vulnerabilities to validating exploitable attack paths.</p>



<p class="wp-block-paragraph">The most important question is no longer whether a vulnerability exists but whether an attacker can use it to achieve meaningful business impact.</p>



<p class="wp-block-paragraph">This shift also changes how organizations think about remediation. Closing a vulnerability is valuable, but simply applying a patch does not necessarily prove that that risk has been eliminated. Security leaders increasingly want evidence that an attack path has been disrupted and that an adversary can no longer move through the environment to reach critical assets.</p>



<p class="wp-block-paragraph">This philosophy aligns with broader industry initiatives, such as <a href="https://horizon3.ai/continuous-threat-exposure-management-ctem/" target="_blank" rel="noreferrer noopener">Continuous Threat Exposure Management</a> (CTEM), that emphasize continuous validation, prioritization based on exploitability, and verification that remediation efforts are actually effective.</p>



<p class="wp-block-paragraph">Rather than generating another lengthy list of findings, modern security validation seeks to answer a more practical question: Which weaknesses truly matter because they create a viable path for attackers?</p>



<p class="wp-block-paragraph">Technology vendors are evolving to support this approach. For example, Horizon3.ai recently introduced <a href="https://horizon3.ai/nodezero/webapp" target="_blank" rel="noreferrer noopener">NodeZero WebApp</a>, extending its autonomous security validation platform to validate end-to-end attack paths that begin with web applications and traverse identities, infrastructure, and cloud environments.</p>



<p class="wp-block-paragraph">The goal is to provide organizations with repeatable evidence of exploitability, plus confirmation that remediation efforts have successfully closed those paths.</p>



<p class="wp-block-paragraph">As attacks continue to accelerate and grow more sophisticated, security validation must evolve alongside them. Organizations that focus on understanding complete attack paths, rather than isolated vulnerabilities, will be better positioned to prioritize resources, reduce meaningful risk, and demonstrate resilience against the threats that matter most.</p>



<p class="wp-block-paragraph">Discover how <a href="https://horizon3.ai/" target="_blank" rel="noreferrer noopener">Horizon3.ai</a> helps security teams move from assumed security to proven resilience.</p>



<p class="wp-block-paragraph"></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Apple streitet sich erneut mit Großbritannien über den verschlüsselten iCloud-Zugang.]]></title>
<description><![CDATA[Melden Sie sich für unseren Newsletter an, um die neuesten Nachrichten zur Cybersicherheit in Ihrem Posteingang zu erhalten. Anmelden. Mit dem ...]]></description>
<link>https://tsecurity.de/de/3706972/it-security-nachrichten/apple-streitet-sich-erneut-mit-grossbritannien-ueber-den-verschluesselten-icloud-zugang/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3706972/it-security-nachrichten/apple-streitet-sich-erneut-mit-grossbritannien-ueber-den-verschluesselten-icloud-zugang/</guid>
<pubDate>Wed, 05 Aug 2026 23:58:43 +0200</pubDate>
<content:encoded><![CDATA[Melden Sie sich für unseren Newsletter an, um die neuesten Nachrichten zur <b>Cybersicherheit</b> in Ihrem Posteingang zu erhalten. Anmelden. Mit dem ...]]></content:encoded>
</item>
<item>
<title><![CDATA[Canadian pleads guilty to Snowflake cloud data-theft attacks]]></title>
<description><![CDATA[A Canadian man pleaded guilty today to his role in accessing company accounts at cloud storage provider Snowflake and stealing data from at least 165 organizations in a scheme to extort millions of dollars from victims. [...]]]></description>
<link>https://tsecurity.de/de/3706971/it-security-nachrichten/canadian-pleads-guilty-to-snowflake-cloud-data-theft-attacks/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3706971/it-security-nachrichten/canadian-pleads-guilty-to-snowflake-cloud-data-theft-attacks/</guid>
<pubDate>Wed, 05 Aug 2026 23:55:36 +0200</pubDate>
<content:encoded><![CDATA[A Canadian man pleaded guilty today to his role in accessing company accounts at cloud storage provider Snowflake and stealing data from at least 165 organizations in a scheme to extort millions of dollars from victims. [...]]]></content:encoded>
</item>
<item>
<title><![CDATA[Prompt injection isn't the bug, AI agent frameworks are]]></title>
<description><![CDATA[Check Point researchers tried to break the frameworks enterprises use to build AI apps. Now they're telling Black Hat attendees what they found]]></description>
<link>https://tsecurity.de/de/3706970/it-security-nachrichten/prompt-injection-isnt-the-bug-ai-agent-frameworks-are/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3706970/it-security-nachrichten/prompt-injection-isnt-the-bug-ai-agent-frameworks-are/</guid>
<pubDate>Wed, 05 Aug 2026 23:55:30 +0200</pubDate>
<content:encoded><![CDATA[Check Point researchers tried to break the frameworks enterprises use to build AI apps. Now they're telling Black Hat attendees what they found]]></content:encoded>
</item>
<item>
<title><![CDATA[Google’s New HiLight for Pixel 11 Works Like This]]></title>
<description><![CDATA[We’ve learned so much about the upcoming Pixel 11 series that few secrets will remain when Google does make them all official. If there’s one takeaway so far, it’s that this might be a year with few upgrades, and in some ways, there will be downgrades (Ex: RAM). There is at least one new item,......]]></description>
<link>https://tsecurity.de/de/3706969/it-nachrichten/googles-new-hilight-for-pixel-11-works-like-this/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3706969/it-nachrichten/googles-new-hilight-for-pixel-11-works-like-this/</guid>
<pubDate>Wed, 05 Aug 2026 23:55:13 +0200</pubDate>
<content:encoded><![CDATA[<p>We’ve learned so much about the upcoming Pixel 11 series that few secrets will remain when Google does make them all official. If there’s one takeaway so far, it’s that this might be a year with few upgrades, and in some ways, there will be downgrades (Ex: RAM). There is at least one new item,...</p>
<p>Read the original post: <a href="https://www.droid-life.com/2026/08/05/googles-new-hilight-for-pixel-11-works-like-this/">Google’s New HiLight for Pixel 11 Works Like This</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Time Magazine has a separate version of its website with ads only AI can see]]></title>
<description><![CDATA[Brands are already paying to influence what chatbots say about them]]></description>
<link>https://tsecurity.de/de/3706968/it-nachrichten/time-magazine-has-a-separate-version-of-its-website-with-ads-only-ai-can-see/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3706968/it-nachrichten/time-magazine-has-a-separate-version-of-its-website-with-ads-only-ai-can-see/</guid>
<pubDate>Wed, 05 Aug 2026 23:55:11 +0200</pubDate>
<content:encoded><![CDATA[Brands are already paying to influence what chatbots say about them]]></content:encoded>
</item>
<item>
<title><![CDATA[Prompt injection isn't the bug, AI agent frameworks are]]></title>
<description><![CDATA[Check Point researchers tried to break the frameworks enterprises use to build AI apps. Now they're telling Black Hat attendees what they found]]></description>
<link>https://tsecurity.de/de/3706967/it-nachrichten/prompt-injection-isnt-the-bug-ai-agent-frameworks-are/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3706967/it-nachrichten/prompt-injection-isnt-the-bug-ai-agent-frameworks-are/</guid>
<pubDate>Wed, 05 Aug 2026 23:55:11 +0200</pubDate>
<content:encoded><![CDATA[Check Point researchers tried to break the frameworks enterprises use to build AI apps. Now they're telling Black Hat attendees what they found]]></content:encoded>
</item>
<item>
<title><![CDATA[Digital Health: „Viele Leute interessieren sich einen Scheiß für ihre Daten“]]></title>
<description><![CDATA[Apps verarbeiten Gesundheitsdaten. Doch wer kontrolliert sie? Paulina Jo Pesch spricht im Podcast über die Macht der Anbieter und die Grenzen der Einwilligung.]]></description>
<link>https://tsecurity.de/de/3706966/it-nachrichten/digital-health-viele-leute-interessieren-sich-einen-scheiss-fuer-ihre-daten/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3706966/it-nachrichten/digital-health-viele-leute-interessieren-sich-einen-scheiss-fuer-ihre-daten/</guid>
<pubDate>Wed, 05 Aug 2026 23:54:17 +0200</pubDate>
<content:encoded><![CDATA[Apps verarbeiten Gesundheitsdaten. Doch wer kontrolliert sie? Paulina Jo Pesch spricht im Podcast über die Macht der Anbieter und die Grenzen der Einwilligung.]]></content:encoded>
</item>
<item>
<title><![CDATA[Visual Studio Code 1.132 advances built-in dictation]]></title>
<description><![CDATA[Visual Studio Code 1.132, the latest version of Microsoft’s popular, open-source code editor, has been released. The brings improvements to built-in dictation, side chats, and support for commenting on web elements in the integrated browser. 



VS Code 1.132 was released August 5. The update can...]]></description>
<link>https://tsecurity.de/de/3706965/ai-nachrichten/visual-studio-code-1132-advances-built-in-dictation/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3706965/ai-nachrichten/visual-studio-code-1132-advances-built-in-dictation/</guid>
<pubDate>Wed, 05 Aug 2026 23:54:11 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Visual Studio Code 1.132, the latest version of Microsoft’s popular, open-source code editor, has been released. The brings improvements to built-in dictation, side chats, and support for commenting on web elements in the integrated browser. </p>



<p class="wp-block-paragraph">VS Code 1.132 was released <a href="https://code.visualstudio.com/updates/v1_132">August 5</a>. The update can be downloaded for Windows, Linux, and macOS at <a href="https://code.visualstudio.com/">code.visualstudio.com</a>. </p>



<p class="wp-block-paragraph">With VS Code 1.132, the built-in multilingual dictation function lets developers dictate in multiple languages using an on-device model that follows language preference or detects the language automatically. The built-in dictation converts speech to text in chat inputs, editors, and terminals. Dictation now uses multilingual Nemotron 3.5 as the default on-device model. Plus, terminal dictation now applies shell-aware cleanup, so spoken commands preserve shell syntax.</p>



<p class="wp-block-paragraph">Also in VS Code 1.132, developers can open a side chat by typing <code>/bt</code> in the chat input. A side chat shares the context and prompt cache of the primary chat, but allows developers to ask the agent questions about the current turn without interrupting the turn. Similarly, developers can select text in a chat response to ask contextual questions about that response.</p>



<p class="wp-block-paragraph">Other new capabilities and improvements in VS Code 1.132:</p>



<ul class="wp-block-list">
<li>The integrated browser adds support for selecting web page elements and annotating them with agent feedback. Users can trigger this mode by using the <code>workbench.action.browser.addElementCommentToChat</code> keyboard shortcut.</li>



<li>Active development continues on the agent host, a new VS Code feature that lets users connect to the same agent session from multiple VS Code windows. The agent host runs agent harnesses such as Copilot, Claude, and Codex in a dedicated process based on the <a href="https://microsoft.github.io/agent-host-protocol/" target="_blank" rel="noreferrer noopener">Agent Host Protocol</a> (AHP).</li>



<li>In the previous release, Microsoft <a href="https://code.visualstudio.com/updates/v1_131#_hybrid-markdown-editor-experimental">introduced the hybrid Markdown editor</a>, which combines rendered Markdown with in-place editing and agent-actionable comments. In this release, Markdown diffs can be opened in the hybrid Markdown editor. </li>



<li>Expanded terminal output in chat now reflows to the available width as the view is resized. Previously, output used a fixed width, which caused lines to wrap too early and left unused space in wider views.</li>
</ul>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Nikita Bier steps down as X’s head of product]]></title>
<description><![CDATA[The serial entrepreneur is stepping down a little over a year after taking the "24/7 job" of overseeing X.]]></description>
<link>https://tsecurity.de/de/3706964/ai-nachrichten/nikita-bier-steps-down-as-xs-head-of-product/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3706964/ai-nachrichten/nikita-bier-steps-down-as-xs-head-of-product/</guid>
<pubDate>Wed, 05 Aug 2026 23:54:08 +0200</pubDate>
<content:encoded><![CDATA[The serial entrepreneur is stepping down a little over a year after taking the "24/7 job" of overseeing X.]]></content:encoded>
</item>
<item>
<title><![CDATA[GNOME Boxes Nightly — The next-gen rewrite of GNOME Boxes]]></title>
<description><![CDATA[submitted by    /u/BrageFuglseth   [link]   [comments]]]></description>
<link>https://tsecurity.de/de/3706957/linux-tipps/gnome-boxes-nightly-the-next-gen-rewrite-of-gnome-boxes/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3706957/linux-tipps/gnome-boxes-nightly-the-next-gen-rewrite-of-gnome-boxes/</guid>
<pubDate>Wed, 05 Aug 2026 23:52:26 +0200</pubDate>
<content:encoded><![CDATA[  submitted by   <a href="https://www.reddit.com/user/BrageFuglseth"> /u/BrageFuglseth </a> <br> <span><a href="https://nightly.gnomeboxes.org/">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/1vgkssk/gnome_boxes_nightly_the_nextgen_rewrite_of_gnome/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[ETW-MCP-Server: Copilot liest Windows-Leistungsdaten via MCP - it boltwise]]></title>
<description><![CDATA[Microsoft bringt den ETW-MCP-Server als Vorschau: Copilot und KI-Agenten analysieren Windows-ETW-Daten lokal per natürlicher Sprache.]]></description>
<link>https://tsecurity.de/de/3706956/windows-server/etw-mcp-server-copilot-liest-windows-leistungsdaten-via-mcp-it-boltwise/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3706956/windows-server/etw-mcp-server-copilot-liest-windows-leistungsdaten-via-mcp-it-boltwise/</guid>
<pubDate>Wed, 05 Aug 2026 23:51:35 +0200</pubDate>
<content:encoded><![CDATA[Microsoft bringt den ETW-MCP-<b>Server</b> als Vorschau: Copilot und KI-Agenten analysieren <b>Windows</b>-ETW-Daten lokal per natürlicher Sprache.]]></content:encoded>
</item>
<item>
<title><![CDATA[GitHub: @signalapp/types@0.2.0]]></title>
<description><![CDATA[Publish Packages]]></description>
<link>https://tsecurity.de/de/3706955/downloads/github-signalapptypes020/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3706955/downloads/github-signalapptypes020/</guid>
<pubDate>Wed, 05 Aug 2026 23:50:53 +0200</pubDate>
<content:encoded><![CDATA[<div class="github-feed-entry"><p>Publish Packages</p></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[GitHub: v8.22.0]]></title>
<description><![CDATA[Handful of bug fixes to keep your app running smoothly. More exciting changes on the horizon!]]></description>
<link>https://tsecurity.de/de/3706954/downloads/github-v8220/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3706954/downloads/github-v8220/</guid>
<pubDate>Wed, 05 Aug 2026 23:50:53 +0200</pubDate>
<content:encoded><![CDATA[<div class="github-feed-entry"><ul>
<li>Handful of bug fixes to keep your app running smoothly. More exciting changes on the horizon!</li>
</ul></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[GitHub: @signalapp/types@0.2.0]]></title>
<description><![CDATA[Publish Packages]]></description>
<link>https://tsecurity.de/de/3706953/tools/github-signalapptypes020/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3706953/tools/github-signalapptypes020/</guid>
<pubDate>Wed, 05 Aug 2026 23:50:10 +0200</pubDate>
<content:encoded><![CDATA[<div class="github-feed-entry"><p>Publish Packages</p></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[GitHub: v8.22.0]]></title>
<description><![CDATA[Handful of bug fixes to keep your app running smoothly. More exciting changes on the horizon!]]></description>
<link>https://tsecurity.de/de/3706952/tools/github-v8220/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3706952/tools/github-v8220/</guid>
<pubDate>Wed, 05 Aug 2026 23:50:10 +0200</pubDate>
<content:encoded><![CDATA[<div class="github-feed-entry"><ul>
<li>Handful of bug fixes to keep your app running smoothly. More exciting changes on the horizon!</li>
</ul></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2022-41513 | Online Diagnostic Lab Management System 1.0 /diagnostic/edittest.php ID sql injection (EUVD-2022-44706)]]></title>
<description><![CDATA[A vulnerability was found in Online Diagnostic Lab Management System 1.0. It has been declared as critical. Impacted is an unknown function of the file /diagnostic/edittest.php. Such manipulation of the argument ID leads to sql injection.

This vulnerability is traded as CVE-2022-41513. The attac...]]></description>
<link>https://tsecurity.de/de/3706951/sicherheitsluecken/cve-2022-41513-online-diagnostic-lab-management-system-10-diagnosticedittestphp-id-sql-injection-euvd-2022-44706/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3706951/sicherheitsluecken/cve-2022-41513-online-diagnostic-lab-management-system-10-diagnosticedittestphp-id-sql-injection-euvd-2022-44706/</guid>
<pubDate>Wed, 05 Aug 2026 23:49:53 +0200</pubDate>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/online_diagnostic_lab_management_system">Online Diagnostic Lab Management System 1.0</a>. It has been declared as <a href="https://vuldb.com/kb/risk">critical</a>. Impacted is an unknown function of the file <em>/diagnostic/edittest.php</em>. Such manipulation of the argument <em>ID</em> leads to sql injection.

This vulnerability is traded as <a href="https://vuldb.com/cve/CVE-2022-41513">CVE-2022-41513</a>. The attack may be launched remotely. Furthermore, there is an exploit available.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2022-41515 | Open Source SACCO Management System 1.0 ajax.php?action=delete_payment ID sql injection (EUVD-2022-44708)]]></title>
<description><![CDATA[A vulnerability was found in Open Source SACCO Management System 1.0. It has been classified as critical. This issue affects some unknown processing of the file /sacco_shield/ajax.php?action=delete_payment. This manipulation of the argument ID causes sql injection.

This vulnerability appears as ...]]></description>
<link>https://tsecurity.de/de/3706950/sicherheitsluecken/cve-2022-41515-open-source-sacco-management-system-10-ajaxphpactiondeletepayment-id-sql-injection-euvd-2022-44708/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3706950/sicherheitsluecken/cve-2022-41515-open-source-sacco-management-system-10-ajaxphpactiondeletepayment-id-sql-injection-euvd-2022-44708/</guid>
<pubDate>Wed, 05 Aug 2026 23:49:53 +0200</pubDate>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/open_source_sacco_management_system">Open Source SACCO Management System 1.0</a>. It has been classified as <a href="https://vuldb.com/kb/risk">critical</a>. This issue affects some unknown processing of the file <em>/sacco_shield/ajax.php?action=delete_payment</em>. This manipulation of the argument <em>ID</em> causes sql injection.

This vulnerability appears as <a href="https://vuldb.com/cve/CVE-2022-41515">CVE-2022-41515</a>. The attack may be initiated remotely. In addition, an exploit is available.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2022-41514 | Open Source SACCO Management System 1.0 ajax.php?action=delete_loan ID sql injection (EUVD-2022-44707)]]></title>
<description><![CDATA[A vulnerability was found in Open Source SACCO Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /sacco_shield/ajax.php?action=delete_loan. The manipulation of the argument ID results in sql injection.

This vulnerability is reported as CVE-2022...]]></description>
<link>https://tsecurity.de/de/3706949/sicherheitsluecken/cve-2022-41514-open-source-sacco-management-system-10-ajaxphpactiondeleteloan-id-sql-injection-euvd-2022-44707/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3706949/sicherheitsluecken/cve-2022-41514-open-source-sacco-management-system-10-ajaxphpactiondeleteloan-id-sql-injection-euvd-2022-44707/</guid>
<pubDate>Wed, 05 Aug 2026 23:49:53 +0200</pubDate>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/open_source_sacco_management_system">Open Source SACCO Management System 1.0</a> and classified as <a href="https://vuldb.com/kb/risk">critical</a>. This vulnerability affects unknown code of the file <em>/sacco_shield/ajax.php?action=delete_loan</em>. The manipulation of the argument <em>ID</em> results in sql injection.

This vulnerability is reported as <a href="https://vuldb.com/cve/CVE-2022-41514">CVE-2022-41514</a>. The attack can be launched remotely. Moreover, an exploit is present.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2022-41517 | TOTOLINK NR1800X 9.1.0u.6279_B20210910 setLanguageCfg lang stack-based overflow (EUVD-2022-44710)]]></title>
<description><![CDATA[A vulnerability identified as critical has been detected in TOTOLINK NR1800X 9.1.0u.6279_B20210910. This impacts the function setLanguageCfg. Performing a manipulation of the argument lang results in stack-based buffer overflow.

This vulnerability is cataloged as CVE-2022-41517. The attack must ...]]></description>
<link>https://tsecurity.de/de/3706948/sicherheitsluecken/cve-2022-41517-totolink-nr1800x-910u6279b20210910-setlanguagecfg-lang-stack-based-overflow-euvd-2022-44710/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3706948/sicherheitsluecken/cve-2022-41517-totolink-nr1800x-910u6279b20210910-setlanguagecfg-lang-stack-based-overflow-euvd-2022-44710/</guid>
<pubDate>Wed, 05 Aug 2026 23:49:53 +0200</pubDate>
<content:encoded><![CDATA[A vulnerability identified as <a href="https://vuldb.com/kb/risk">critical</a> has been detected in <a href="https://vuldb.com/product/totolink:nr1800x">TOTOLINK NR1800X 9.1.0u.6279_B20210910</a>. This impacts the function <code>setLanguageCfg</code>. Performing a manipulation of the argument <em>lang</em> results in stack-based buffer overflow.

This vulnerability is cataloged as <a href="https://vuldb.com/cve/CVE-2022-41517">CVE-2022-41517</a>. The attack must originate from the local network. There is no exploit available.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-63077 | JetBrains TeamCity prior 2026.1.3/2025.11.7 Agent Polling Protocol code injection (Nessus ID 330833)]]></title>
<description><![CDATA[A vulnerability classified as critical was found in JetBrains TeamCity. Affected by this issue is some unknown functionality of the component Agent Polling Protocol. Such manipulation leads to code injection.

This vulnerability is documented as CVE-2026-63077. The attack can be executed remotely...]]></description>
<link>https://tsecurity.de/de/3706947/sicherheitsluecken/cve-2026-63077-jetbrains-teamcity-prior-2026132025117-agent-polling-protocol-code-injection-nessus-id-330833/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3706947/sicherheitsluecken/cve-2026-63077-jetbrains-teamcity-prior-2026132025117-agent-polling-protocol-code-injection-nessus-id-330833/</guid>
<pubDate>Wed, 05 Aug 2026 23:49:53 +0200</pubDate>
<content:encoded><![CDATA[A vulnerability classified as <a href="https://vuldb.com/kb/risk">critical</a> was found in <a href="https://vuldb.com/product/jetbrains:teamcity">JetBrains TeamCity</a>. Affected by this issue is some unknown functionality of the component <em>Agent Polling Protocol</em>. Such manipulation leads to code injection.

This vulnerability is documented as <a href="https://vuldb.com/cve/CVE-2026-63077">CVE-2026-63077</a>. The attack can be executed remotely. Additionally, an exploit exists.

Upgrading the affected component is advised.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-71227 | Red Hat Enterprise Linux libkcapi _kcapi_aio_read_all infinite loop (Nessus ID 332248)]]></title>
<description><![CDATA[A vulnerability, which was classified as critical, was found in Red Hat Enterprise Linux. The impacted element is the function _kcapi_aio_read_all of the component libkcapi. Executing a manipulation can lead to infinite loop.

This vulnerability is handled as CVE-2026-71227. It is possible to lau...]]></description>
<link>https://tsecurity.de/de/3706946/sicherheitsluecken/cve-2026-71227-red-hat-enterprise-linux-libkcapi-kcapiaioreadall-infinite-loop-nessus-id-332248/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3706946/sicherheitsluecken/cve-2026-71227-red-hat-enterprise-linux-libkcapi-kcapiaioreadall-infinite-loop-nessus-id-332248/</guid>
<pubDate>Wed, 05 Aug 2026 23:49:53 +0200</pubDate>
<content:encoded><![CDATA[A vulnerability, which was classified as <a href="https://vuldb.com/kb/risk">critical</a>, was found in <a href="https://vuldb.com/product/red_hat:enterprise_linux">Red Hat Enterprise Linux</a>. The impacted element is the function <code>_kcapi_aio_read_all</code> of the component <em>libkcapi</em>. Executing a manipulation can lead to infinite loop.

This vulnerability is handled as <a href="https://vuldb.com/cve/CVE-2026-71227">CVE-2026-71227</a>. It is possible to launch the attack on the local host. There is not any exploit available.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-67855 | Open62541 GDS use after free (Nessus ID 332249)]]></title>
<description><![CDATA[A vulnerability described as problematic has been identified in Open62541. Affected is an unknown function of the component GDS. Executing a manipulation can lead to use after free.

This vulnerability appears as CVE-2026-67855. The attack may be performed from remote. There is no available exploit.]]></description>
<link>https://tsecurity.de/de/3706945/sicherheitsluecken/cve-2026-67855-open62541-gds-use-after-free-nessus-id-332249/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3706945/sicherheitsluecken/cve-2026-67855-open62541-gds-use-after-free-nessus-id-332249/</guid>
<pubDate>Wed, 05 Aug 2026 23:49:53 +0200</pubDate>
<content:encoded><![CDATA[A vulnerability described as <a href="https://vuldb.com/kb/risk">problematic</a> has been identified in <a href="https://vuldb.com/product/open62541">Open62541</a>. Affected is an unknown function of the component <em>GDS</em>. Executing a manipulation can lead to use after free.

This vulnerability appears as <a href="https://vuldb.com/cve/CVE-2026-67855">CVE-2026-67855</a>. The attack may be performed from remote. There is no available exploit.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-14974 | IBM WebSphere Application Server 8.5/9.0 deserialization (EUVD-2026-50031 / Nessus ID 332247)]]></title>
<description><![CDATA[A vulnerability has been found in IBM WebSphere Application Server 8.5/9.0 and classified as critical. The impacted element is an unknown function. This manipulation causes deserialization.

This vulnerability is registered as CVE-2026-14974. Remote exploitation of the attack is possible. No expl...]]></description>
<link>https://tsecurity.de/de/3706944/sicherheitsluecken/cve-2026-14974-ibm-websphere-application-server-8590-deserialization-euvd-2026-50031-nessus-id-332247/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3706944/sicherheitsluecken/cve-2026-14974-ibm-websphere-application-server-8590-deserialization-euvd-2026-50031-nessus-id-332247/</guid>
<pubDate>Wed, 05 Aug 2026 23:49:53 +0200</pubDate>
<content:encoded><![CDATA[A vulnerability has been found in <a href="https://vuldb.com/product/ibm:websphere_application_server">IBM WebSphere Application Server 8.5/9.0</a> and classified as <a href="https://vuldb.com/kb/risk">critical</a>. The impacted element is an unknown function. This manipulation causes deserialization.

This vulnerability is registered as <a href="https://vuldb.com/cve/CVE-2026-14974">CVE-2026-14974</a>. Remote exploitation of the attack is possible. No exploit is available.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-14515 | IBM WebSphere Application Server 8.5/9.0 cross site scripting (Nessus ID 332247)]]></title>
<description><![CDATA[A vulnerability was found in IBM WebSphere Application Server 8.5/9.0 and classified as problematic. Affected by this vulnerability is an unknown functionality. Executing a manipulation can lead to cross site scripting.

This vulnerability is registered as CVE-2026-14515. It is possible to launch...]]></description>
<link>https://tsecurity.de/de/3706943/sicherheitsluecken/cve-2026-14515-ibm-websphere-application-server-8590-cross-site-scripting-nessus-id-332247/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3706943/sicherheitsluecken/cve-2026-14515-ibm-websphere-application-server-8590-cross-site-scripting-nessus-id-332247/</guid>
<pubDate>Wed, 05 Aug 2026 23:49:52 +0200</pubDate>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/ibm:websphere_application_server">IBM WebSphere Application Server 8.5/9.0</a> and classified as <a href="https://vuldb.com/kb/risk">problematic</a>. Affected by this vulnerability is an unknown functionality. Executing a manipulation can lead to cross site scripting.

This vulnerability is registered as <a href="https://vuldb.com/cve/CVE-2026-14515">CVE-2026-14515</a>. It is possible to launch the attack remotely. No exploit is available.]]></content:encoded>
</item>
<item>
<title><![CDATA[Snowflake hacker pleads guilty, faces up to 32 years in prison]]></title>
<description><![CDATA[Connor Moucka obtained almost $500,000 for playing a key role in one of the most widespread and damaging cyberattack sprees on record.
The post Snowflake hacker pleads guilty, faces up to 32 years in prison appeared first on CyberScoop.]]></description>
<link>https://tsecurity.de/de/3706942/it-security-nachrichten/snowflake-hacker-pleads-guilty-faces-up-to-32-years-in-prison/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3706942/it-security-nachrichten/snowflake-hacker-pleads-guilty-faces-up-to-32-years-in-prison/</guid>
<pubDate>Wed, 05 Aug 2026 23:39:22 +0200</pubDate>
<content:encoded><![CDATA[<p>Connor Moucka obtained almost $500,000 for playing a key role in one of the most widespread and damaging cyberattack sprees on record.</p>
<p>The post <a href="https://cyberscoop.com/connor-moucka-guilty-snowflake-attack-spree/">Snowflake hacker pleads guilty, faces up to 32 years in prison</a> appeared first on <a href="https://cyberscoop.com/">CyberScoop</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Meta enters the AI coding wars with Muse Spark 1.2 and Muse Code with persistent async background agents]]></title>
<description><![CDATA[Meta today released Muse Code, a terminal-based AI coding agent now in beta, alongside Muse Spark 1.2, a coding-focused update to its Muse Spark family of frontier models — a one-two punch that puts the company in direct competition with Anthropic's Claude Code, OpenAI's Codex, and the growing fi...]]></description>
<link>https://tsecurity.de/de/3706941/it-nachrichten/meta-enters-the-ai-coding-wars-with-muse-spark-12-and-muse-code-with-persistent-async-background-agents/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3706941/it-nachrichten/meta-enters-the-ai-coding-wars-with-muse-spark-12-and-muse-code-with-persistent-async-background-agents/</guid>
<pubDate>Wed, 05 Aug 2026 23:34:25 +0200</pubDate>
<content:encoded><![CDATA[<p>Meta today <a href="https://research.meta.ai/blog/introducing-muse-code-and-muse-spark-1-2?utm_source=ai_meta_site&amp;utm_medium=web&amp;utm_campaign=hp_research_muse-1-2_08052026&amp;utm_content=hp_research_muse-1-2_08052026">released Muse Code</a>, a terminal-based AI coding agent now in beta, alongside <a href="https://research.meta.ai/blog/introducing-muse-code-and-muse-spark-1-2?utm_source=ai_meta_site&amp;utm_medium=web&amp;utm_campaign=hp_research_muse-1-2_08052026&amp;utm_content=hp_research_muse-1-2_08052026">Muse Spark 1.2</a>, a coding-focused update to its Muse Spark family of frontier models — a one-two punch that puts the company in direct competition with Anthropic's Claude Code, OpenAI's Codex, and the growing field of agentic coding harnesses that have rapidly become the primary way many professional developers ship software.</p><p>"Releasing Muse Code in beta today," Meta CEO Mark Zuckerberg wrote in a <a href="https://x.com/finkd/status/2085080750034940201">post on rival social network X</a> (under his longtime handle @finkd). "It's a terminal coding agent that takes on complete software engineering tasks across large repos: planning changes, writing code, validating the results."</p><p>The launch marks Meta's most serious entry yet into a category it has largely watched from the sidelines. </p><p>While Anthropic and OpenAI turned their coding agents into flagship products — and startups like Cursor built billion-dollar businesses on the workflow — Meta's developer story long centered on Llama, the open-weight model family it gave away to the tune of more than a billion downloads. </p><p>Muse Code changes that in more ways than one: it's a full harness, installable on macOS or Linux with a single curl command, co-trained with the model that powers it — and, like the Muse Spark models behind it, entirely proprietary.</p><p>Developers and prospective users can install it now on their Terminal using the following one-line command — but be warned, if that's you, you'll need to log in with a Meta account and provide billing details first in order to begin: <code>curl -fsSL https://dev.meta.ai/install.sh | bash</code></p><h2><b>Persistent background agents and parallel worktrees</b></h2><p>Muse Code's headline architectural bet is what Meta calls <b>async background agents</b>. </p><p>Rather than spawning helper agents fresh for each task — the pattern most rival harnesses use — Muse Code keeps a set of <i>specialized background agents alive for the entire session. </i></p><p>According to Meta's blog post, these agents "remain active throughout each session, rather than being spawned for individual tasks, helping avoid redundant information gathering," carrying out next steps on their own and choosing when to report back to the main agent.</p><p>The practical pitch is less latency and less babysitting: an agent that already knows the repository doesn't have to re-explore it every time the developer asks for something new.</p><p>When a job is large enough, Muse Code fans out to separate sub-agents working in parallel, each in its own isolated git worktree, so the developer's working copy is never touched. </p><p>"In testing we had it build six features for a game simultaneously with no collisions," Zuckerberg wrote on X. </p><p>Worktree isolation and parallel sub-agents exist in competing tools, but Meta is leaning on the combination of persistence plus parallelism as its differentiator.</p><p>The second notable design choice is auditability. Every model call, tool run, approval, and edit is appended to a <b>local event log</b> before it executes — a single source of truth that Meta says makes the runtime "replay-exact and restart-safe." </p><p>If Muse Code crashes 20 hours into a long-running task, it resumes precisely where it stopped, with no lost work and no re-prompting. For engineering leaders who have been burned by opaque agent runs, a complete local audit trail may prove to be the feature that matters most in enterprise evaluations.</p><p>Muse Code also ships with bundled "skills" that will look familiar to users of rival tools: /plan turns a task into an approval-gated plan, /grill stress-tests that plan until it holds up, and /goal drives the agent toward completion of a stated objective.</p><h2><b>Muse Spark 1.2: co-trained with its own harness</b></h2><p>Under the hood is Muse Spark 1.2, which Meta describes as a coding-focused update to Muse Spark 1.1 with "significantly scaled up training compute on coding tasks" and broader training environment diversity, improving code generation, complex debugging, and codebase understanding while maintaining general agentic capability.</p><p>The update lands squarely on the Muse family's weakest flank. When the original Muse Spark <a href="https://venturebeat.com/technology/goodbye-llama-meta-launches-new-proprietary-ai-model-muse-spark-first-since">debuted in April</a>, it vaulted Meta back into the top five on frontier reasoning and vision benchmarks — but trailed on the agentic coding evaluations that matter most to this market, scoring 77.4 on SWE-Bench Verified against Claude Opus 4.6's 80.8 and Gemini 3.1 Pro's 80.6, and lagging well behind GPT-5.4 on GDPval's measure of long-horizon work tasks. </p><p>Four months later, a coding-specialized checkpoint paired with a purpose-built harness reads as Meta's direct answer to that gap.</p><p>Two training details stand out. First, Meta co-trained the model with Muse Code itself, using rejection-sampled harness trajectories and recipe optimizations for goals, context compaction, and sub-agents — meaning the model was explicitly tuned to perform best inside this particular tool. That mirrors an industry-wide shift away from treating models and harnesses as separable products.</p><p>Second, Meta used a self-improvement loop: Muse Spark 1.1 generated challenging coding environments and instruction-following templates, then graded candidate solutions against those requirements, producing a scalable training dataset for its successor. Meta credits the loop with making 1.2 measurably better at following complex instructions.</p><p>Meta published benchmark charts comparing Muse Spark 1.2 against other coding models on Terminal-Bench 2.1, DeepSWE 1.1, and an internal Meta coding benchmark, pointing readers to a separate methodology report for details — though the company did not headline specific scores in the announcement itself, a notable omission in a field where rivals trumpet leaderboard placement.</p><p>The company's most striking demonstration is a long-horizon case study: Meta pointed Muse Spark 1.2 at GPU kernel optimization and let it run for more than 1,000 tool calls over up to 24 hours on NVIDIA Hopper hardware.</p><p>Working in Triton and barred from simply wrapping existing third-party kernel libraries, the agent wrote, compiled, and profiled its way to what Meta calls "substantial improvements" over baseline implementations of KDA and MLA kernels — including genuinely non-obvious optimizations like re-centering gated cumulative decay at a chunk midpoint. </p><p>"It kept finding substantial improvements well beyond the initial exploration phase," Zuckerberg wrote. Sustained improvement over a 24-hour autonomous run, if it holds up outside Meta's demos, addresses one of the most persistent criticisms of coding agents: that they plateau or drift once past their initial burst of progress.</p><h2><b>Your data for a discount?</b></h2><p>The pricing structure may be the most consequential — and most scrutinized — part of the launch. Meta is offering Muse Spark 1.2 through its<a href="https://dev.meta.ai/docs/pricing-rate-limits?project_id=1661600634933790&amp;team_id=2096920474558192"> Meta Model API </a>in two tiers.</p><p>The <b>standard tier</b> is priced at $1.25 per million input tokens and $4.25 per million output tokens (with cached input at $0.15), and Meta commits that prompts and completions on this tier are not used to train its models. There is no long-context premium, and rate limits run to 3,000 requests and 4 million tokens per minute, per team. It's about mid-range price, compared to other leading AI models available over API. </p><p>The <b>contributor tier</b> is where Meta's strategy diverges sharply from its rivals: $0.10 per million input tokens and $0.20 per million output tokens — roughly 12x and 21x cheaper than standard, respectively, with cached input at a near-free $0.002 — in exchange for explicit permission to use your prompts and completions to train future Meta models. It's the cheapest available on the market, but you pay with your data — as described below. </p><table><tbody><tr><td><p><b>Model</b></p></td><td><p><b>Input ($/1M)</b></p></td><td><p><b>Output ($/1M)</b></p></td><td><p><b>Total ($/1M)</b></p></td><td><p><b>Source</b></p></td></tr><tr><td><p><b>Muse Spark 1.2 Contributor</b></p></td><td><p><b>$0.10</b></p></td><td><p><b>$0.20</b></p></td><td><p><b>$0.30</b></p></td><td><p><b></b><a href="https://dev.meta.ai/docs/pricing-rate-limits"><b>Meta</b></a><b></b></p></td></tr><tr><td><p>MiMo-V2.5 Flash</p></td><td><p>$0.10</p></td><td><p>$0.30</p></td><td><p>$0.40</p></td><td><p><a href="https://platform.xiaomimimo.com/docs/en-US/pricing">Xiaomi</a></p></td></tr><tr><td><p>deepseek-v4-flash</p></td><td><p>$0.14</p></td><td><p>$0.28</p></td><td><p>$0.42</p></td><td><p><a href="https://api-docs.deepseek.com/quick_start/pricing">DeepSeek</a></p></td></tr><tr><td><p>deepseek-v4-pro</p></td><td><p>$0.435</p></td><td><p>$0.87</p></td><td><p>$1.305</p></td><td><p><a href="https://api-docs.deepseek.com/quick_start/pricing">DeepSeek</a></p></td></tr><tr><td><p>GPT-5.6 Luna</p></td><td><p>$0.20</p></td><td><p>$1.20</p></td><td><p>$1.40</p></td><td><p><a href="https://openai.com/index/advancing-the-price-performance-frontier-with-gpt-5-6/">OpenAI</a></p></td></tr><tr><td><p>MiniMax-M3</p></td><td><p>$0.30</p></td><td><p>$1.20</p></td><td><p>$1.50</p></td><td><p><a href="https://platform.minimax.io/subscribe/token-plan?tab=api-enterprise">MiniMax</a></p></td></tr><tr><td><p>LongCat-2.0 — limited-time promo</p></td><td><p>$0.30</p></td><td><p>$1.20</p></td><td><p>$1.50</p></td><td><p><a href="https://longcat.chat/platform/docs/APIPayAsYouGo.html">LongCat</a></p></td></tr><tr><td><p>Gemini 3.1 Flash-Lite</p></td><td><p>$0.25</p></td><td><p>$1.50</p></td><td><p>$1.75</p></td><td><p><a href="https://ai.google.dev/gemini-api/docs/pricing">Google</a></p></td></tr><tr><td><p>MiMo-V2.5</p></td><td><p>$0.40</p></td><td><p>$2.00</p></td><td><p>$2.40</p></td><td><p><a href="https://platform.xiaomimimo.com/docs/en-US/pricing">Xiaomi</a></p></td></tr><tr><td><p>Gemini 3.5 Flash-Lite</p></td><td><p>$0.30</p></td><td><p>$2.50</p></td><td><p>$2.80</p></td><td><p><a href="https://ai.google.dev/gemini-api/docs/pricing">Google</a></p></td></tr><tr><td><p>LongCat-2.0 — standard</p></td><td><p>$0.75</p></td><td><p>$2.95</p></td><td><p>$3.70</p></td><td><p><a href="https://longcat.chat/platform/docs/APIPayAsYouGo.html">LongCat</a></p></td></tr><tr><td><p>MiMo-V2.5 Pro (≤256K)</p></td><td><p>$1.00</p></td><td><p>$3.00</p></td><td><p>$4.00</p></td><td><p><a href="https://platform.xiaomimimo.com/docs/en-US/pricing">Xiaomi</a></p></td></tr><tr><td><p><b>Muse Spark 1.1 / 1.2</b></p></td><td><p><b>$1.25</b></p></td><td><p><b>$4.25</b></p></td><td><p><b>$5.50</b></p></td><td><p><b></b><a href="https://dev.meta.ai/docs/pricing-rate-limits"><b>Meta</b></a></p></td></tr><tr><td><p>GLM-5.2</p></td><td><p>$1.40</p></td><td><p>$4.40</p></td><td><p>$5.80</p></td><td><p><a href="https://docs.z.ai/guides/overview/pricing">Z.ai</a></p></td></tr><tr><td><p>Grok 4.5</p></td><td><p>$2.00</p></td><td><p>$6.00</p></td><td><p>$8.00</p></td><td><p><a href="https://docs.x.ai/developers/models">xAI</a></p></td></tr><tr><td><p>MiMo-V2.5 Pro (&gt;256K)</p></td><td><p>$2.00</p></td><td><p>$6.00</p></td><td><p>$8.00</p></td><td><p><a href="https://platform.xiaomimimo.com/docs/en-US/pricing">Xiaomi</a></p></td></tr><tr><td><p>Qwen3.8-Max</p></td><td><p>$2.00</p></td><td><p>$6.00</p></td><td><p>$8.00</p></td><td><p><a href="https://www.qwencloud.com/models/qwen3.8-max">QwenCloud</a></p></td></tr><tr><td><p>Gemini 3.6 Flash</p></td><td><p>$1.50</p></td><td><p>$7.50</p></td><td><p>$9.00</p></td><td><p><a href="https://ai.google.dev/gemini-api/docs/pricing">Google</a></p></td></tr><tr><td><p>Gemini 3.5 Flash</p></td><td><p>$1.50</p></td><td><p>$9.00</p></td><td><p>$10.50</p></td><td><p><a href="https://ai.google.dev/gemini-api/docs/pricing">Google</a></p></td></tr><tr><td><p>Gemini 3.1 Pro Preview (≤200K)</p></td><td><p>$2.00</p></td><td><p>$12.00</p></td><td><p>$14.00</p></td><td><p><a href="https://ai.google.dev/gemini-api/docs/pricing">Google</a></p></td></tr><tr><td><p>GPT-5.6 Terra</p></td><td><p>$2.00</p></td><td><p>$12.00</p></td><td><p>$14.00</p></td><td><p><a href="https://openai.com/index/advancing-the-price-performance-frontier-with-gpt-5-6/">OpenAI</a></p></td></tr><tr><td><p>GPT-5.4</p></td><td><p>$2.50</p></td><td><p>$15.00</p></td><td><p>$17.50</p></td><td><p><a href="https://openai.com/api/pricing/">OpenAI</a></p></td></tr><tr><td><p>Kimi K3</p></td><td><p>$3.00</p></td><td><p>$15.00</p></td><td><p>$18.00</p></td><td><p><a href="https://platform.kimi.ai/docs/pricing/chat-k3">Moonshot AI</a></p></td></tr><tr><td><p>Gemini 3.1 Pro Preview (&gt;200K)</p></td><td><p>$4.00</p></td><td><p>$18.00</p></td><td><p>$22.00</p></td><td><p><a href="https://ai.google.dev/gemini-api/docs/pricing">Google</a></p></td></tr><tr><td><p>Claude Opus 5</p></td><td><p>$5.00</p></td><td><p>$25.00</p></td><td><p>$30.00</p></td><td><p><a href="https://platform.claude.com/docs/en/about-claude/pricing">Anthropic</a></p></td></tr><tr><td><p>GPT-5.5</p></td><td><p>$5.00</p></td><td><p>$30.00</p></td><td><p>$35.00</p></td><td><p><a href="https://openai.com/api/pricing/">OpenAI</a></p></td></tr><tr><td><p>GPT-5.5 Instant (chat-latest)</p></td><td><p>$5.00</p></td><td><p>$30.00</p></td><td><p>$35.00</p></td><td><p><a href="https://developers.openai.com/api/docs/models/chat-latest">OpenAI</a></p></td></tr><tr><td><p>Sakana Fugu Ultra (≤272K)</p></td><td><p>$5.00</p></td><td><p>$30.00</p></td><td><p>$35.00</p></td><td><p><a href="https://console.sakana.ai/pricing#subscription-plan">Sakana AI</a></p></td></tr><tr><td><p>GPT-5.6 Sol — Standard mode</p></td><td><p>$5.00</p></td><td><p>$30.00</p></td><td><p>$35.00</p></td><td><p><a href="https://openai.com/index/advancing-the-price-performance-frontier-with-gpt-5-6/">OpenAI</a></p></td></tr><tr><td><p>Claude Fable 5 / Claude Mythos 5</p></td><td><p>$10.00</p></td><td><p>$50.00</p></td><td><p>$60.00</p></td><td><p><a href="https://platform.claude.com/docs/en/about-claude/models/overview">Anthropic</a></p></td></tr><tr><td><p>GPT-5.6 Sol — Fast mode</p></td><td><p>$10.00</p></td><td><p>$60.00</p></td><td><p>$70.00</p></td><td><p><a href="https://openai.com/index/advancing-the-price-performance-frontier-with-gpt-5-6/">OpenAI</a></p></td></tr></tbody></table><p>This is the tier Zuckerberg is steering new users toward: "It's easy and low-cost to get started," he wrote. "Install Muse Code with one line and you can start on our contributor tier."</p><p>In VentureBeat's own testing on a Mac mini, the one-line installer worked as advertised — a 97 MB download and a sign-in — but the agent stopped short of running anything, reporting that no models were visible and that payment was "required to finish setting up your account." </p><p>In other words, even the heavily discounted contributor tier requires a payment method on file before Muse Code will do any work: low-cost is accurate, but free is not.</p><p>Meta frames the contributor tier as lowering the barrier for prototyping and experimentation "where training on your data is acceptable." </p><p>But it also means the default on-ramp for Muse Code sends developers' code and prompts into Meta's training pipeline — a tradeoff enterprises with proprietary codebases will need to consciously opt out of by moving to standard pricing. </p><p>The contributor tier also carries much tighter rate limits (60 requests per minute versus 3,000), a clear signal it's aimed at individuals and small experiments rather than production workloads.</p><p>The approach is classically Meta: subsidize access, harvest data at scale, and use it to close the gap with the frontier. Zuckerberg made no secret of the ambition, calling Muse Spark 1.2 "our next step as we push toward frontier, with larger, more capable models on the way."</p><p>However, for developers and enterprises who want or are required legally to keep their code secure, the tradeoff may not be one they're willing or able to make. </p><h2><b>No Llama in sight</b></h2><p>What today's announcement conspicuously lacks is any mention of open source — a striking omission from the company that spent three years positioning itself as the standard-bearer of open AI.</p><p>From the original LLaMA's debut in February 2023 — whose weights famously leaked onto 4chan within weeks, inadvertently kickstarting the movement to run capable models on consumer hardware — through Llama 2's commercially usable license, the coding-specialized Code Llama, and the 405-billion-parameter Llama 3.1, which Zuckerberg launched in July 2024 with a manifesto titled "<a href="https://about.fb.com/news/2024/07/open-source-ai-is-the-path-forward/">Open Source AI Is the Path Forward</a>," Meta's entire pitch to developers was that frontier-class weights should be free to download, self-host, and fine-tune. </p><p>The strategy worked: by early 2026, the Llama family had been <a href="https://miraflow.ai/blog/meta-ended-llama-built-muse-spark-changes-everything-2026">downloaded roughly 1.2 billion times</a>, averaging about a million downloads a day, with self-hosting offering enterprises cost reductions VentureBeat has previously reported at as much as 88% versus proprietary API providers.</p><p>Then came the unraveling. Llama 4 debuted in April 2025 to <a href="https://venturebeat.com/ai/meta-defends-llama-4-release-against-reports-of-mixed-quality-blames-bugs">mixed reviews</a> and, eventually, admissions that its benchmark results had been fudged — while Chinese open-weight rivals from DeepSeek, Alibaba, and Zhipu AI surged to account for some 41% of downloads on Hugging Face by late 2025, eroding Llama's claim to leadership of the very movement it started. The rocky rollout spurred Zuckerberg's summer 2025 overhaul of Meta's AI operations into Meta Superintelligence Labs (MSL), with Scale AI co-founder Alexandr Wang recruited as chief AI officer.</p><p>The Llama era effectively ended this past April 8, when MSL <a href="https://venturebeat.com/technology/goodbye-llama-meta-launches-new-proprietary-ai-model-muse-spark-first-since">shipped the original Muse Spark</a> — "the most powerful model that meta has released," in Wang's words — as Meta's first proprietary model: <a href="https://mynextdeveloper.com/blogs/metas-muse-spark-the-end-of-open-source-for-llama/">cloud-only, with no downloadable weights and no self-hosting</a>, initially confined to Meta's apps and a private API preview. </p><p>Asked directly at the time whether Llama development would continue, a Meta spokesperson told VentureBeat only that "our current Llama models will continue to be available as open source" — pointedly silent on future ones.</p><p>Wang, for his part, said <a href="https://www.artificialintelligence-news.com/news/meta-muse-spark-ai-model-open-source/">bigger models were already in development "with plans to open-source future versions"</a> — but four months on, today's release does nothing to advance that promise: no weights, no license, and neither the blog post nor Zuckerberg's thread so much as uses the word "open."</p><p>The reversal is all the sharper because Meta's rivals have been moving in the opposite direction. OpenAI released its <a href="https://github.com/openai/codex">Codex CLI as open source </a>under the permissive, enterprise-friendly Apache 2.0 license and followed with its <a href="https://venturebeat.com/business/openai-returns-to-open-source-roots-with-new-models-gpt-oss-120b-and-gpt-oss-20b">gpt-oss open-weight models</a>; Google's<a href="https://venturebeat.com/technology/google-is-redefining-enterprise-ai-economics-with-open-source-gemini-cli-that-will-be-free-for-the-majority-of-developers"> Gemini CLI harness is likewise Apache-licensed.</a> </p><p>With Muse Code, Meta lands closest to the posture of Anthropic — whose Claude Code remains proprietary — while the company that once argued open source was the path forward now asks developers to pay per token for a model they cannot inspect, or to subsidize that access with their own data. </p><p>Seen in that light, the contributor tier reads as the successor to the Llama strategy itself: the ecosystem flywheel is no longer free weights in exchange for mindshare, but cheap tokens in exchange for training data.</p><h2><b>Why it matters</b></h2><p>Terminal coding agents have become the fastest-growing surface in enterprise AI, and until today the category has effectively been a two-horse race between Anthropic and OpenAI, with Google and a crowd of startups in pursuit.</p><p>Meta's entry brings a genuinely different architecture (persistent background agents, an append-only local event log), a credible long-horizon demo, and an aggressive pricing wedge.</p><p>The open questions are the ones benchmarks charts can't answer: whether Muse Spark 1.2 actually matches Claude and GPT-class models on real-world repositories, whether developers trust Meta with their code, and whether the contributor tier's discount is enough to make them stop asking. Muse Code is available in beta today; Muse Spark 1.2 is live in the Meta Model API with expanded global access.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Meta Is Challenging Claude Code and Codex With New Muse Code]]></title>
<description><![CDATA[With coding as a key capability for AI companies, Meta throws its hat into the ring.]]></description>
<link>https://tsecurity.de/de/3706940/it-nachrichten/meta-is-challenging-claude-code-and-codex-with-new-muse-code/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3706940/it-nachrichten/meta-is-challenging-claude-code-and-codex-with-new-muse-code/</guid>
<pubDate>Wed, 05 Aug 2026 23:34:18 +0200</pubDate>
<content:encoded><![CDATA[With coding as a key capability for AI companies, Meta throws its hat into the ring.]]></content:encoded>
</item>
<item>
<title><![CDATA[Meta launches Muse Code, an AI agent for large code bases]]></title>
<description><![CDATA[Meta expanded its AI coding offerings with a new agent that, it promises, can handle complex tasks with complex software.]]></description>
<link>https://tsecurity.de/de/3706939/it-nachrichten/meta-launches-muse-code-an-ai-agent-for-large-code-bases/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3706939/it-nachrichten/meta-launches-muse-code-an-ai-agent-for-large-code-bases/</guid>
<pubDate>Wed, 05 Aug 2026 23:34:18 +0200</pubDate>
<content:encoded><![CDATA[Meta expanded its AI coding offerings with a new agent that, it promises, can handle complex tasks with complex software.]]></content:encoded>
</item>
<item>
<title><![CDATA[Travis Kalanick’s robotics startup Atoms taps former Uber finance chief as CFO]]></title>
<description><![CDATA[Kalanick continues to get the band back together, after acquiring Anthony Levandowski's autonomy startup, and even soliciting investment from Uber itself.]]></description>
<link>https://tsecurity.de/de/3706938/it-nachrichten/travis-kalanicks-robotics-startup-atoms-taps-former-uber-finance-chief-as-cfo/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3706938/it-nachrichten/travis-kalanicks-robotics-startup-atoms-taps-former-uber-finance-chief-as-cfo/</guid>
<pubDate>Wed, 05 Aug 2026 23:34:18 +0200</pubDate>
<content:encoded><![CDATA[Kalanick continues to get the band back together, after acquiring Anthony Levandowski's autonomy startup, and even soliciting investment from Uber itself.]]></content:encoded>
</item>
<item>
<title><![CDATA[Nikita Bier steps down as X’s head of product]]></title>
<description><![CDATA[The serial entrepreneur is stepping down a little over a year after taking the "24/7 job" of overseeing X.]]></description>
<link>https://tsecurity.de/de/3706937/it-nachrichten/nikita-bier-steps-down-as-xs-head-of-product/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3706937/it-nachrichten/nikita-bier-steps-down-as-xs-head-of-product/</guid>
<pubDate>Wed, 05 Aug 2026 23:34:18 +0200</pubDate>
<content:encoded><![CDATA[The serial entrepreneur is stepping down a little over a year after taking the "24/7 job" of overseeing X.]]></content:encoded>
</item>
<item>
<title><![CDATA[o2 Mega-Deal: iPhone 17 + MacBook Neo + Unlimited-Flat nur 1 Euro]]></title>
<description><![CDATA[o2 hat einen neuen Mega-Deal mit zwei spannenden Apple Produkten aufgelegt. Ihr erhaltet ab Tag 1 ein komplettes Apple Setup. Warum das iPhone 17 einzeln kaufen, wenn man es im Bundle mit dem MacBook Neo erhält? Das neue Apple-Bundle bei o2 enthält das iPhone 17, das MacBook Neo sowie den o2 Mobi...]]></description>
<link>https://tsecurity.de/de/3706936/ios-mac-os/o2-mega-deal-iphone-17-macbook-neo-unlimited-flat-nur-1-euro/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3706936/ios-mac-os/o2-mega-deal-iphone-17-macbook-neo-unlimited-flat-nur-1-euro/</guid>
<pubDate>Wed, 05 Aug 2026 23:33:00 +0200</pubDate>
<content:encoded><![CDATA[o2 hat einen neuen Mega-Deal mit zwei spannenden Apple Produkten aufgelegt. Ihr erhaltet ab Tag 1 ein komplettes Apple Setup. Warum das iPhone 17 einzeln kaufen, wenn man es im Bundle mit dem MacBook Neo erhält? Das neue Apple-Bundle bei o2 enthält das iPhone 17, das MacBook Neo sowie den o2 Mobile Unlimited on Demand […]]]></content:encoded>
</item>
<item>
<title><![CDATA[iPhone 18 Pro soll drei lang erwartete Neuerungen erhalten]]></title>
<description><![CDATA[Apple stellt die nächste iPhone-Generation voraussichtlich im September vor. Einem Bericht von 9to5Mac zufolge bringt das iPhone 18 Pro drei Funktionen mit, über die schon seit Jahren spekuliert wird und die bislang immer wieder auf spätere Modelle verschoben wurden. Die Hauptkamera bekommt eine ...]]></description>
<link>https://tsecurity.de/de/3706935/ios-mac-os/iphone-18-pro-soll-drei-lang-erwartete-neuerungen-erhalten/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3706935/ios-mac-os/iphone-18-pro-soll-drei-lang-erwartete-neuerungen-erhalten/</guid>
<pubDate>Wed, 05 Aug 2026 23:33:00 +0200</pubDate>
<content:encoded><![CDATA[Apple stellt die nächste iPhone-Generation voraussichtlich im September vor. Einem Bericht von 9to5Mac zufolge bringt das iPhone 18 Pro drei Funktionen mit, über die schon seit Jahren spekuliert wird und die bislang immer wieder auf spätere Modelle verschoben wurden. Die Hauptkamera bekommt eine variable Blende Zu einer iPhone-Kamera mit variabler Blende gab es schon vor […]]]></content:encoded>
</item>
<item>
<title><![CDATA[nvrmnd-png/CutterDiscordRPC: Let your friends see what you are reversing. Discord Rich Presence for Cutter, with a setup script that does the install for you.]]></title>
<description><![CDATA[submitted by    /u/AmbitiousRadish7617   [link]   [comments]]]></description>
<link>https://tsecurity.de/de/3706934/reverse-engineering/nvrmnd-pngcutterdiscordrpc-let-your-friends-see-what-you-are-reversing-discord-rich-presence-for-cutter-with-a-setup-script-that-does-the-install-for-you/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3706934/reverse-engineering/nvrmnd-pngcutterdiscordrpc-let-your-friends-see-what-you-are-reversing-discord-rich-presence-for-cutter-with-a-setup-script-that-does-the-install-for-you/</guid>
<pubDate>Wed, 05 Aug 2026 23:31:54 +0200</pubDate>
<content:encoded><![CDATA[  submitted by   <a href="https://www.reddit.com/user/AmbitiousRadish7617"> /u/AmbitiousRadish7617 </a> <br> <span><a href="https://github.com/nvrmnd-png/CutterDiscordRPC">[link]</a></span>   <span><a href="https://www.reddit.com/r/ReverseEngineering/comments/1vg8kg6/nvrmndpngcutterdiscordrpc_let_your_friends_see/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[I built an open-source MCP server that gives AI agents 46 structured reverse engineering tools (Ghidra, GDB, Binwalk, etc) with a persistent knowledge base]]></title>
<description><![CDATA[submitted by    /u/Katsu121   [link]   [comments]]]></description>
<link>https://tsecurity.de/de/3706933/reverse-engineering/i-built-an-open-source-mcp-server-that-gives-ai-agents-46-structured-reverse-engineering-tools-ghidra-gdb-binwalk-etc-with-a-persistent-knowledge-base/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3706933/reverse-engineering/i-built-an-open-source-mcp-server-that-gives-ai-agents-46-structured-reverse-engineering-tools-ghidra-gdb-binwalk-etc-with-a-persistent-knowledge-base/</guid>
<pubDate>Wed, 05 Aug 2026 23:31:54 +0200</pubDate>
<content:encoded><![CDATA[  submitted by   <a href="https://www.reddit.com/user/Katsu121"> /u/Katsu121 </a> <br> <span><a href="https://github.com/The-Arabi/Reverse-engineering-agent">[link]</a></span>   <span><a href="https://www.reddit.com/r/ReverseEngineering/comments/1vg8ups/i_built_an_opensource_mcp_server_that_gives_ai/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[AI Can Help Emergency Management Teams With Limited Funds]]></title>
<description><![CDATA[Artificial intelligence can help support state, local and tribal emergency management offices. New reports, however, reveal most entities remain in early phases of adoption.]]></description>
<link>https://tsecurity.de/de/3706932/ai-nachrichten/ai-can-help-emergency-management-teams-with-limited-funds/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3706932/ai-nachrichten/ai-can-help-emergency-management-teams-with-limited-funds/</guid>
<pubDate>Wed, 05 Aug 2026 23:27:58 +0200</pubDate>
<content:encoded><![CDATA[Artificial intelligence can help support state, local and tribal emergency management offices. New reports, however, reveal most entities remain in early phases of adoption.]]></content:encoded>
</item>
<item>
<title><![CDATA[Microsoft moves to limit AI use by its employees]]></title>
<description><![CDATA[Until recently, it was common for companies and organizations to engage in “tokenmaxxing” — that is, maximizing their use of AI. But with AI costs going up, companies are now looking to save money, a trend underscored by a recent Microsoft decision to limit AI use by its employees.



“As we ramp...]]></description>
<link>https://tsecurity.de/de/3706931/ai-nachrichten/microsoft-moves-to-limit-ai-use-by-its-employees/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3706931/ai-nachrichten/microsoft-moves-to-limit-ai-use-by-its-employees/</guid>
<pubDate>Wed, 05 Aug 2026 23:27:53 +0200</pubDate>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Until recently, it was common for companies and organizations to engage in “tokenmaxxing” — that is, <a href="https://www.computerworld.com/article/4185848/how-companies-are-racing-to-solve-the-ai-token-problem.html" data-type="link" data-id="https://www.computerworld.com/article/4185848/how-companies-are-racing-to-solve-the-ai-token-problem.html">maximizing their use of AI</a>. But with AI costs going up, companies are now looking to save money, a trend underscored by a recent Microsoft decision to limit AI use by its employees.</p>



<p class="wp-block-paragraph">“As we ramp up our use of GitHub Copilot to achieve our goals, we all need to be mindful of how we consume tokens,” Microsoft Executive Vice President Jay Parikh wrote in an email to the company’s employees.</p>



<p class="wp-block-paragraph">Starting now, each department at Microsoft will be allocated a certain pool of tokens, with usage then adjusted up or down as needed.</p>



<p class="wp-block-paragraph">The change prompted concern among some employees. “It’s very telling that a company that has invested so much in AI and subsidized so much AI inference is now advising its own employees to cut back on spending,” an anonymous Microsoft employee said in a comment to <a href="https://www.404media.co/microsoft-tells-engineers-tokenmaxxing-is-not-what-we-are-optimizing-for/" data-type="link" data-id="https://www.404media.co/microsoft-tells-engineers-tokenmaxxing-is-not-what-we-are-optimizing-for/" target="_blank" rel="noreferrer noopener">404 Media</a>.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Hank Green found the AI problem that YouTube labels can’t catch]]></title>
<description><![CDATA["Slop" isn't the only problem.]]></description>
<link>https://tsecurity.de/de/3706930/ai-nachrichten/hank-green-found-the-ai-problem-that-youtube-labels-cant-catch/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3706930/ai-nachrichten/hank-green-found-the-ai-problem-that-youtube-labels-cant-catch/</guid>
<pubDate>Wed, 05 Aug 2026 23:27:49 +0200</pubDate>
<content:encoded><![CDATA["Slop" isn't the only problem.]]></content:encoded>
</item>
<item>
<title><![CDATA[Reddit signals ominous upcoming "changes” for old.reddit.com]]></title>
<description><![CDATA[Reddit says the beloved site is used for some "bad behavior."]]></description>
<link>https://tsecurity.de/de/3706929/ai-nachrichten/reddit-signals-ominous-upcoming-changes-for-oldredditcom/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3706929/ai-nachrichten/reddit-signals-ominous-upcoming-changes-for-oldredditcom/</guid>
<pubDate>Wed, 05 Aug 2026 23:27:48 +0200</pubDate>
<content:encoded><![CDATA[Reddit says the beloved site is used for some "bad behavior."]]></content:encoded>
</item>
<item>
<title><![CDATA[Anthropic’s AI used fake identities, malware in rogue attack on GitHub project]]></title>
<description><![CDATA[Anthropic and OpenAI models’ unprompted actions forced halt to UK cyber tests.]]></description>
<link>https://tsecurity.de/de/3706928/ai-nachrichten/anthropics-ai-used-fake-identities-malware-in-rogue-attack-on-github-project/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3706928/ai-nachrichten/anthropics-ai-used-fake-identities-malware-in-rogue-attack-on-github-project/</guid>
<pubDate>Wed, 05 Aug 2026 23:27:48 +0200</pubDate>
<content:encoded><![CDATA[Anthropic and OpenAI models’ unprompted actions forced halt to UK cyber tests.]]></content:encoded>
</item>
<item>
<title><![CDATA[The Most Dangerous AI Hacking Techniques Still Have Humans in the Loop]]></title>
<description><![CDATA[Security researcher James Kettle tried to push the limit of AI’s hacking abilities—and discovered how effective it can be when combined with human expertise.]]></description>
<link>https://tsecurity.de/de/3706927/ai-nachrichten/the-most-dangerous-ai-hacking-techniques-still-have-humans-in-the-loop/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3706927/ai-nachrichten/the-most-dangerous-ai-hacking-techniques-still-have-humans-in-the-loop/</guid>
<pubDate>Wed, 05 Aug 2026 23:27:46 +0200</pubDate>
<content:encoded><![CDATA[Security researcher James Kettle tried to push the limit of AI’s hacking abilities—and discovered how effective it can be when combined with human expertise.]]></content:encoded>
</item>
<item>
<title><![CDATA[Big US hedge funds targeted by wave of cyber attacks]]></title>
<description><![CDATA[Point72 and Citadel among firms hit by audio phishing schemes]]></description>
<link>https://tsecurity.de/de/3706926/ai-nachrichten/big-us-hedge-funds-targeted-by-wave-of-cyber-attacks/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3706926/ai-nachrichten/big-us-hedge-funds-targeted-by-wave-of-cyber-attacks/</guid>
<pubDate>Wed, 05 Aug 2026 23:27:45 +0200</pubDate>
<content:encoded><![CDATA[Point72 and Citadel among firms hit by audio phishing schemes]]></content:encoded>
</item>
<item>
<title><![CDATA[Jeff Dean and other top AI researchers are leaving Google to launch their own startup]]></title>
<description><![CDATA[The legendary Google executive is joined by other outgoing Google execs in a joint mission to use AI to push forward the process of scientific discovery.]]></description>
<link>https://tsecurity.de/de/3706925/ai-nachrichten/jeff-dean-and-other-top-ai-researchers-are-leaving-google-to-launch-their-own-startup/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3706925/ai-nachrichten/jeff-dean-and-other-top-ai-researchers-are-leaving-google-to-launch-their-own-startup/</guid>
<pubDate>Wed, 05 Aug 2026 23:27:43 +0200</pubDate>
<content:encoded><![CDATA[The legendary Google executive is joined by other outgoing Google execs in a joint mission to use AI to push forward the process of scientific discovery.]]></content:encoded>
</item>
<item>
<title><![CDATA[Klaviyo acquires Elias Torres’ Agency in full-circle reunion for tech founders]]></title>
<description><![CDATA[The serial entrepreneur joins the e-commerce company as CPO to lead its AI agents.]]></description>
<link>https://tsecurity.de/de/3706924/ai-nachrichten/klaviyo-acquires-elias-torres-agency-in-full-circle-reunion-for-tech-founders/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3706924/ai-nachrichten/klaviyo-acquires-elias-torres-agency-in-full-circle-reunion-for-tech-founders/</guid>
<pubDate>Wed, 05 Aug 2026 23:27:43 +0200</pubDate>
<content:encoded><![CDATA[The serial entrepreneur joins the e-commerce company as CPO to lead its AI agents.]]></content:encoded>
</item>
<item>
<title><![CDATA[Why Lightspeed is going all-in on creator-led venture capital]]></title>
<description><![CDATA[Venture firms are turning to creators to build trust with the next generation of founders before a check is ever written. It’s a trend that’s been building with a16z’s acquisition of Erik Torenberg’s Turpentine podcast and OpenAI’s acquisition of TBPN. Lightspeed Venture Partners just made its ow...]]></description>
<link>https://tsecurity.de/de/3706923/ai-nachrichten/why-lightspeed-is-going-all-in-on-creator-led-venture-capital/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3706923/ai-nachrichten/why-lightspeed-is-going-all-in-on-creator-led-venture-capital/</guid>
<pubDate>Wed, 05 Aug 2026 23:27:43 +0200</pubDate>
<content:encoded><![CDATA[Venture firms are turning to creators to build trust with the next generation of founders before a check is ever written. It’s a trend that’s been building with a16z’s acquisition of Erik Torenberg’s Turpentine podcast and OpenAI’s acquisition of TBPN. Lightspeed Venture Partners just made its own notable hire in that vein, bringing on Claire Zau, a seed investor with a major following on Instagram and […]]]></content:encoded>
</item>
<item>
<title><![CDATA[How Lightspeed found its newest hire … via Instagram DM]]></title>
<description><![CDATA[Lightspeed partners Josh Machiz and Claire Zau stopped by the Equity studio to talk about the strategies behind their growing social media presence and their podcast, Lightwork.]]></description>
<link>https://tsecurity.de/de/3706922/ai-nachrichten/how-lightspeed-found-its-newest-hire-via-instagram-dm/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3706922/ai-nachrichten/how-lightspeed-found-its-newest-hire-via-instagram-dm/</guid>
<pubDate>Wed, 05 Aug 2026 23:27:43 +0200</pubDate>
<content:encoded><![CDATA[Lightspeed partners Josh Machiz and Claire Zau stopped by the Equity studio to talk about the strategies behind their growing social media presence and their podcast, Lightwork.]]></content:encoded>
</item>
<item>
<title><![CDATA[Moove raises $250M to become the backbone of the robotaxi industry]]></title>
<description><![CDATA[Moove is scaling up the autonomous vehicle fleet management side of its business and plans to someday own, not just manage, Waymo robotaxis.]]></description>
<link>https://tsecurity.de/de/3706921/ai-nachrichten/moove-raises-250m-to-become-the-backbone-of-the-robotaxi-industry/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3706921/ai-nachrichten/moove-raises-250m-to-become-the-backbone-of-the-robotaxi-industry/</guid>
<pubDate>Wed, 05 Aug 2026 23:27:42 +0200</pubDate>
<content:encoded><![CDATA[Moove is scaling up the autonomous vehicle fleet management side of its business and plans to someday own, not just manage, Waymo robotaxis.]]></content:encoded>
</item>
<item>
<title><![CDATA[Trump’s DOJ gains oversight of OpenAI’s green-card employee sponsorships]]></title>
<description><![CDATA[The DOJ alleged that OpenAI did not meaningful attempt to hire U.S. citizens before seeking permanent residence for Visa-holding employees.]]></description>
<link>https://tsecurity.de/de/3706920/ai-nachrichten/trumps-doj-gains-oversight-of-openais-green-card-employee-sponsorships/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3706920/ai-nachrichten/trumps-doj-gains-oversight-of-openais-green-card-employee-sponsorships/</guid>
<pubDate>Wed, 05 Aug 2026 23:27:42 +0200</pubDate>
<content:encoded><![CDATA[The DOJ alleged that OpenAI did not meaningful attempt to hire U.S. citizens before seeking permanent residence for Visa-holding employees.]]></content:encoded>
</item>
<item>
<title><![CDATA[Meta launches Muse Code, an AI agent for large code bases]]></title>
<description><![CDATA[Meta expanded its AI coding offerings with a new agent that, it promises, can handle complex tasks with complex software.]]></description>
<link>https://tsecurity.de/de/3706919/ai-nachrichten/meta-launches-muse-code-an-ai-agent-for-large-code-bases/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3706919/ai-nachrichten/meta-launches-muse-code-an-ai-agent-for-large-code-bases/</guid>
<pubDate>Wed, 05 Aug 2026 23:27:41 +0200</pubDate>
<content:encoded><![CDATA[Meta expanded its AI coding offerings with a new agent that, it promises, can handle complex tasks with complex software.]]></content:encoded>
</item>
<item>
<title><![CDATA[Travis Kalanick’s robotics startup Atoms taps former Uber finance chief as CFO]]></title>
<description><![CDATA[Kalanick continues to get the band back together, after acquiring Anthony Levandowski's autonomy startup, and even soliciting investment from Uber itself.]]></description>
<link>https://tsecurity.de/de/3706918/ai-nachrichten/travis-kalanicks-robotics-startup-atoms-taps-former-uber-finance-chief-as-cfo/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3706918/ai-nachrichten/travis-kalanicks-robotics-startup-atoms-taps-former-uber-finance-chief-as-cfo/</guid>
<pubDate>Wed, 05 Aug 2026 23:27:41 +0200</pubDate>
<content:encoded><![CDATA[Kalanick continues to get the band back together, after acquiring Anthony Levandowski's autonomy startup, and even soliciting investment from Uber itself.]]></content:encoded>
</item>
<item>
<title><![CDATA[Meta AI Releases Muse Code (Beta): A Terminal Coding Agent Powered by the New Muse Spark 1.2 Model]]></title>
<description><![CDATA[Meta Superintelligence Labs has released Muse Code, a terminal coding agent in beta, powered by the new Muse Spark 1.2 model. Muse Code plans changes, writes code, and validates results across large repositories. Async background agents stay active for the whole session instead of spawning per ta...]]></description>
<link>https://tsecurity.de/de/3706917/ai-nachrichten/meta-ai-releases-muse-code-beta-a-terminal-coding-agent-powered-by-the-new-muse-spark-12-model/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3706917/ai-nachrichten/meta-ai-releases-muse-code-beta-a-terminal-coding-agent-powered-by-the-new-muse-spark-12-model/</guid>
<pubDate>Wed, 05 Aug 2026 23:27:24 +0200</pubDate>
<content:encoded><![CDATA[<p>Meta Superintelligence Labs has released Muse Code, a terminal coding agent in beta, powered by the new Muse Spark 1.2 model. Muse Code plans changes, writes code, and validates results across large repositories. Async background agents stay active for the whole session instead of spawning per task. A local append-only event log makes the runtime replay-exact and restart-safe after a crash. Muse Spark 1.2 was co-trained with the harness and trained on long-horizon, repository-scale work.</p>
<p>The post <a href="https://www.marktechpost.com/2026/08/05/meta-superintelligence-labs-releases-muse-code/">Meta AI Releases Muse Code (Beta): A Terminal Coding Agent Powered by the New Muse Spark 1.2 Model</a> appeared first on <a href="https://www.marktechpost.com/">MarkTechPost</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[How LendingTree built a multi-agent mortgage assistant on Amazon Bedrock]]></title>
<description><![CDATA[Learn how LendingTree built a production multi-agent mortgage assistant on Amazon Bedrock. Three coordinated agents use LangGraph, the Model Context Protocol, and Amazon Nova models with built-in guardrails to deliver 24/7 personalized mortgage guidance while meeting strict financial-services com...]]></description>
<link>https://tsecurity.de/de/3706916/ai-nachrichten/how-lendingtree-built-a-multi-agent-mortgage-assistant-on-amazon-bedrock/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3706916/ai-nachrichten/how-lendingtree-built-a-multi-agent-mortgage-assistant-on-amazon-bedrock/</guid>
<pubDate>Wed, 05 Aug 2026 23:27:18 +0200</pubDate>
<content:encoded><![CDATA[Learn how LendingTree built a production multi-agent mortgage assistant on Amazon Bedrock. Three coordinated agents use LangGraph, the Model Context Protocol, and Amazon Nova models with built-in guardrails to deliver 24/7 personalized mortgage guidance while meeting strict financial-services compliance.]]></content:encoded>
</item>
<item>
<title><![CDATA[Durchbruch für Foldables: Apples iPhone Ultra dürfte Falter-Verkäufe pushen]]></title>
<description><![CDATA[Apples erstes faltbares iPhone könnte den Markt für Falt-Smartphones massiv befeuern. Um glatt ein Fünftel könnten die Verkäufe im Vergleich zum Vorjahr anspringen. Dieser Anstieg ... Weiterlesen ...
Der Beitrag Durchbruch für Foldables: Apples iPhone Ultra dürfte Falter-Verkäufe pushen erschien ...]]></description>
<link>https://tsecurity.de/de/3706877/ios-mac-os/durchbruch-fuer-foldables-apples-iphone-ultra-duerfte-falter-verkaeufe-pushen/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3706877/ios-mac-os/durchbruch-fuer-foldables-apples-iphone-ultra-duerfte-falter-verkaeufe-pushen/</guid>
<pubDate>Wed, 05 Aug 2026 23:24:57 +0200</pubDate>
<content:encoded><![CDATA[<figure><img width="1088" height="713" src="https://www.apfelpage.de/wp-content/uploads/2026/02/Gemini_Generated_Image_b6ewfwb6ewfwb6ew-e1770111674979.png" class="type:primaryImage wp-post-image" alt="" decoding="async" srcset="https://www.apfelpage.de/wp-content/uploads/2026/02/Gemini_Generated_Image_b6ewfwb6ewfwb6ew-e1770111674979.png 1088w, https://www.apfelpage.de/wp-content/uploads/2026/02/Gemini_Generated_Image_b6ewfwb6ewfwb6ew-e1770111674979-570x374.png 570w, https://www.apfelpage.de/wp-content/uploads/2026/02/Gemini_Generated_Image_b6ewfwb6ewfwb6ew-e1770111674979-768x503.png 768w" sizes="(max-width: 1088px) 100vw, 1088px"></figure>
<p>Apples erstes faltbares iPhone könnte den Markt für Falt-Smartphones massiv befeuern. Um glatt ein Fünftel könnten die Verkäufe im Vergleich zum Vorjahr anspringen. Dieser Anstieg ... <a title="Durchbruch für Foldables: Apples iPhone Ultra dürfte Falter-Verkäufe pushen" class="read-more" href="https://www.apfelpage.de/news/durchbruch-fuer-foldables-apples-iphone-ultra-duerfte-falter-verkaeufe-pushen/" aria-label="Mehr Informationen über Durchbruch für Foldables: Apples iPhone Ultra dürfte Falter-Verkäufe pushen">Weiterlesen ...</a></p>
<p>Der Beitrag <a href="https://www.apfelpage.de/news/durchbruch-fuer-foldables-apples-iphone-ultra-duerfte-falter-verkaeufe-pushen/">Durchbruch für Foldables: Apples iPhone Ultra dürfte Falter-Verkäufe pushen</a> erschien zuerst auf <a href="https://www.apfelpage.de/">Apfelpage</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Trügerischer Datenschutz: Verspricht Apples Private Relay zu viel Privatsphäre in Safari?]]></title>
<description><![CDATA[Apple verspricht Nutzern der kostenpflichtigen Funktion iCloud Private Relay eine weitgehend anonymisierte Internetnutzung. Der Dienst, der Bestandteil von iCloud+ ist, soll unter anderem die eigen ... Weiterlesen ...
Der Beitrag Trügerischer Datenschutz: Verspricht Apples Private Relay zu viel P...]]></description>
<link>https://tsecurity.de/de/3706876/ios-mac-os/truegerischer-datenschutz-verspricht-apples-private-relay-zu-viel-privatsphaere-in-safari/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3706876/ios-mac-os/truegerischer-datenschutz-verspricht-apples-private-relay-zu-viel-privatsphaere-in-safari/</guid>
<pubDate>Wed, 05 Aug 2026 23:24:57 +0200</pubDate>
<content:encoded><![CDATA[<figure><img width="2560" height="1707" src="https://www.apfelpage.de/wp-content/uploads/2022/01/macOS-Safari-macOS-Finder-macOS-Thumb-scaled.jpeg" class="type:primaryImage wp-post-image" alt="Safari am Mac - Symbolbild" decoding="async" fetchpriority="high" srcset="https://www.apfelpage.de/wp-content/uploads/2022/01/macOS-Safari-macOS-Finder-macOS-Thumb-scaled.jpeg 2560w, https://www.apfelpage.de/wp-content/uploads/2022/01/macOS-Safari-macOS-Finder-macOS-Thumb-570x380.jpeg 570w, https://www.apfelpage.de/wp-content/uploads/2022/01/macOS-Safari-macOS-Finder-macOS-Thumb-564x376.jpeg 564w, https://www.apfelpage.de/wp-content/uploads/2022/01/macOS-Safari-macOS-Finder-macOS-Thumb-768x512.jpeg 768w, https://www.apfelpage.de/wp-content/uploads/2022/01/macOS-Safari-macOS-Finder-macOS-Thumb-1536x1024.jpeg 1536w, https://www.apfelpage.de/wp-content/uploads/2022/01/macOS-Safari-macOS-Finder-macOS-Thumb-2048x1365.jpeg 2048w, https://www.apfelpage.de/wp-content/uploads/2022/01/macOS-Safari-macOS-Finder-macOS-Thumb-185x124.jpeg 185w, https://www.apfelpage.de/wp-content/uploads/2022/01/macOS-Safari-macOS-Finder-macOS-Thumb-270x180.jpeg 270w, https://www.apfelpage.de/wp-content/uploads/2022/01/macOS-Safari-macOS-Finder-macOS-Thumb-512x341.jpeg 512w, https://www.apfelpage.de/wp-content/uploads/2022/01/macOS-Safari-macOS-Finder-macOS-Thumb-1024x683.jpeg 1024w" sizes="(max-width: 2560px) 100vw, 2560px"></figure>
<p>Apple verspricht Nutzern der kostenpflichtigen Funktion iCloud Private Relay eine weitgehend anonymisierte Internetnutzung. Der Dienst, der Bestandteil von iCloud+ ist, soll unter anderem die eigen ... <a title="Trügerischer Datenschutz: Verspricht Apples Private Relay zu viel Privatsphäre in Safari?" class="read-more" href="https://www.apfelpage.de/news/truegerischer-datenschutz-verspricht-apples-private-relay-zu-viel-privatsphaere-in-safari/" aria-label="Mehr Informationen über Trügerischer Datenschutz: Verspricht Apples Private Relay zu viel Privatsphäre in Safari?">Weiterlesen ...</a></p>
<p>Der Beitrag <a href="https://www.apfelpage.de/news/truegerischer-datenschutz-verspricht-apples-private-relay-zu-viel-privatsphaere-in-safari/">Trügerischer Datenschutz: Verspricht Apples Private Relay zu viel Privatsphäre in Safari?</a> erschien zuerst auf <a href="https://www.apfelpage.de/">Apfelpage</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[RAM-Produktion für 2027 ist bereits komplett ausverkauft]]></title>
<description><![CDATA[Die weltweite Speicherkrise zieht sich länger hin als befürchtet. Laut Branchenquellen von DigiTimes haben die drei großen Hersteller von DRAM- und HBM-Speicher ihre gesamte Produktionskapazität für das Jahr 2027 bereits verkauft. Auch bei NAND-Flash sind die Kapazitäten fast vollständig vergeben...]]></description>
<link>https://tsecurity.de/de/3706875/ios-mac-os/ram-produktion-fuer-2027-ist-bereits-komplett-ausverkauft/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3706875/ios-mac-os/ram-produktion-fuer-2027-ist-bereits-komplett-ausverkauft/</guid>
<pubDate>Wed, 05 Aug 2026 23:24:57 +0200</pubDate>
<content:encoded><![CDATA[Die weltweite Speicherkrise zieht sich länger hin als befürchtet. Laut Branchenquellen von DigiTimes haben die drei großen Hersteller von DRAM- und HBM-Speicher ihre gesamte Produktionskapazität für das Jahr 2027 bereits verkauft. Auch bei NAND-Flash sind die Kapazitäten fast vollständig vergeben. Spätestens Ende August sollen die letzten Verträge stehen. Für Apple und dessen Kunden bedeutet das, […]]]></content:encoded>
</item>
<item>
<title><![CDATA[Absatz faltbarer Smartphones wird dieses Jahr dank „iPhone Ultra“ um 20% steigen]]></title>
<description><![CDATA[Allgemein wird damit gerechnet, das Apple im kommenden Monat mit dem sogenannten iPhone Ultra sein erstes faltbares Smartphone ankündigen wird und genau dieses soll den Markt für faltbare Smartphones ordentlich ankurbeln. Absatz faltbarer Smartphones wird dieses Jahr dank „iPhone Ultra“ um 20% st...]]></description>
<link>https://tsecurity.de/de/3706874/ios-mac-os/absatz-faltbarer-smartphones-wird-dieses-jahr-dank-iphone-ultra-um-20-steigen/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3706874/ios-mac-os/absatz-faltbarer-smartphones-wird-dieses-jahr-dank-iphone-ultra-um-20-steigen/</guid>
<pubDate>Wed, 05 Aug 2026 23:24:57 +0200</pubDate>
<content:encoded><![CDATA[Allgemein wird damit gerechnet, das Apple im kommenden Monat mit dem sogenannten iPhone Ultra sein erstes faltbares Smartphone ankündigen wird und genau dieses soll den Markt für faltbare Smartphones ordentlich ankurbeln. Absatz faltbarer Smartphones wird dieses Jahr dank „iPhone Ultra“ um 20% steigen Der Markt für faltbare Smartphones dürfte 2026 einen deutlichen Wachstumsschub erleben. Laut […]]]></content:encoded>
</item>
<item>
<title><![CDATA[Apple's iPhone 18 Pro event won't be live, no matter how much you wish it to be]]></title>
<description><![CDATA[Apple's employee lottery for the September iPhone launch doesn't mean it will be a return to a live-presented event. It'll probably be the same pre-recorded presentation with press in the room as usual.John Ternus will introduce Apple's event in September. It will probably be prerecorded. It's ba...]]></description>
<link>https://tsecurity.de/de/3706873/ios-mac-os/apples-iphone-18-pro-event-wont-be-live-no-matter-how-much-you-wish-it-to-be/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3706873/ios-mac-os/apples-iphone-18-pro-event-wont-be-live-no-matter-how-much-you-wish-it-to-be/</guid>
<pubDate>Wed, 05 Aug 2026 23:24:57 +0200</pubDate>
<content:encoded><![CDATA[Apple's employee lottery for the September <a href="https://appleinsider.com/inside/iphone" title="iPhone" data-kpt="1">iPhone</a> launch doesn't mean it will be a return to a live-presented event. It'll probably be the same pre-recorded presentation with press in the room as usual.<br><br><div><img src="https://media.appleinsider.com/gallery/68477-144282-52498-104841-000-lead-John-Ternus-xl-xl.jpg" alt="Man in a black T-shirt speaking and gesturing with both hands indoors, standing before large glass windows overlooking a modern circular office building and greenery"><br><span>John Ternus will introduce Apple's event in September. It will probably be prerecorded. </span></div><br>It's barely a month away from Apple's regular fall event, which will see the launch of products like the <a href="https://appleinsider.com/inside/iphone-18" title="iPhone 18" data-kpt="1">iPhone 18 Pro</a>, the <a href="https://appleinsider.com/inside/iphone-fold" title="iPhone Fold" data-kpt="1">iPhone Fold</a>, and other long-rumored items. It is always a major event, with most of the tech world paying close attention.<br><br>However, with the prospect of a new CEO at the helm, there are also expectations of other changes. That can also include the September event itself.<br><br><br> <a href="https://appleinsider.com/articles/26/08/05/apples-september-event-wont-be-live-no-matter-how-much-you-wish-it-to-be?utm_source=rss">Continue Reading on AppleInsider</a> | <a href="https://forums.appleinsider.com/discussion/245177?urm_source=rss">Discuss on our Forums</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Meta's Muse Code is yet another AI coding agent on macOS]]></title>
<description><![CDATA[A one-line command in your macOS terminal can get you access to Meta's Muse Code, which aims to be a transparent AI coding tool that can work across large repositories.Meta's Muse Code is a new AI coding tool for macOS. Image source: MetaThere are already coding agents like Claude Code and ChatGP...]]></description>
<link>https://tsecurity.de/de/3706872/ios-mac-os/metas-muse-code-is-yet-another-ai-coding-agent-on-macos/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3706872/ios-mac-os/metas-muse-code-is-yet-another-ai-coding-agent-on-macos/</guid>
<pubDate>Wed, 05 Aug 2026 23:24:57 +0200</pubDate>
<content:encoded><![CDATA[A one-line command in your <a href="https://appleinsider.com/inside/macos" title="macOS" data-kpt="1">macOS</a> terminal can get you access to Meta's Muse Code, which aims to be a transparent AI coding tool that can work across large repositories.<br><br><div><img src="https://media.appleinsider.com/gallery/68478-144284-IMG_4884-xl.jpg" alt="Abstract space scene with blue lines converging into a bright central circle on a dark background, suggesting data streams or light beams focusing toward a single glowing point"><br><span>Meta's Muse Code is a new AI coding tool for macOS. Image source: Meta</span></div><br>There are already coding agents like <a href="https://appleinsider.com/articles/26/02/03/boost-your-vibe-coding-with-ai-agents-in-apples-new-xcode-263">Claude Code</a> and <a href="https://appleinsider.com/articles/26/04/24/chatbots-take-a-back-seat-as-new-gpt-55-model-focuses-on-getting-work-done">ChatGPT Codex</a> available for macOS, but Meta wants to enter the ring with its latest AI toolset. Unlike the others, it doesn't have an app interface and runs through the Terminal.<br><br>According to an <a href="https://research.meta.ai/blog/introducing-muse-code-and-muse-spark-1-2">announcement post</a> from Meta, Muse Code can take on complex software engineering tasks across large repositories. It is capable of planning changes, writing code, and validating the results while coordinating multiple persistent subagents.<br><br><br> <a href="https://appleinsider.com/articles/26/08/05/metas-muse-code-is-yet-another-ai-coding-agent-on-macos?utm_source=rss">Continue Reading on AppleInsider</a> | <a href="https://forums.appleinsider.com/discussion/245178?urm_source=rss">Discuss on our Forums</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Apple’s Q3 iPhone sales crush expectations — and even better than they seem]]></title>
<description><![CDATA[Apple’s fiscal third-quarter iPhone revenue hit $54.25 billion, surging nearly 22% and beating Wall Street forecasts. Behind the headline…
The post Apple’s Q3 iPhone sales crush expectations — and even better than they seem appeared first on MacDailyNews.]]></description>
<link>https://tsecurity.de/de/3706871/ios-mac-os/apples-q3-iphone-sales-crush-expectations-and-even-better-than-they-seem/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3706871/ios-mac-os/apples-q3-iphone-sales-crush-expectations-and-even-better-than-they-seem/</guid>
<pubDate>Wed, 05 Aug 2026 23:24:55 +0200</pubDate>
<content:encoded><![CDATA[<p>Apple’s fiscal third-quarter iPhone revenue hit $54.25 billion, surging nearly 22% and beating Wall Street forecasts. Behind the headline…</p>
<p>The post <a href="https://macdailynews.com/2026/08/05/apples-q3-iphone-sales-crush-expectations-and-even-better-than-they-seem/">Apple’s Q3 iPhone sales crush expectations — and even better than they seem</a> appeared first on <a href="https://macdailynews.com/">MacDailyNews</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Apple’s CarPlay is coming to Crest and Balise pontoon boats]]></title>
<description><![CDATA[MasterCraft Boat Holdings has announced that it is adding Apple CarPlay to its upcoming Crest and Balise pontoon boats…
The post Apple’s CarPlay is coming to Crest and Balise pontoon boats appeared first on MacDailyNews.]]></description>
<link>https://tsecurity.de/de/3706870/ios-mac-os/apples-carplay-is-coming-to-crest-and-balise-pontoon-boats/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3706870/ios-mac-os/apples-carplay-is-coming-to-crest-and-balise-pontoon-boats/</guid>
<pubDate>Wed, 05 Aug 2026 23:24:55 +0200</pubDate>
<content:encoded><![CDATA[<p>MasterCraft Boat Holdings has announced that it is adding Apple CarPlay to its upcoming Crest and Balise pontoon boats…</p>
<p>The post <a href="https://macdailynews.com/2026/08/05/apples-carplay-is-coming-to-crest-and-balise-pontoon-boats/">Apple’s CarPlay is coming to Crest and Balise pontoon boats</a> appeared first on <a href="https://macdailynews.com/">MacDailyNews</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Can new CEO John Ternus bring back Apple’s design mojo?]]></title>
<description><![CDATA[As Tim Cook hands the reins to hardware engineering chief John Ternus in September 2026, the company faces its biggest leadership transition…
The post Can new CEO John Ternus bring back Apple’s design mojo? appeared first on MacDailyNews.]]></description>
<link>https://tsecurity.de/de/3706869/ios-mac-os/can-new-ceo-john-ternus-bring-back-apples-design-mojo/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3706869/ios-mac-os/can-new-ceo-john-ternus-bring-back-apples-design-mojo/</guid>
<pubDate>Wed, 05 Aug 2026 23:24:55 +0200</pubDate>
<content:encoded><![CDATA[<p>As Tim Cook hands the reins to hardware engineering chief John Ternus in September 2026, the company faces its biggest leadership transition…</p>
<p>The post <a href="https://macdailynews.com/2026/08/05/can-new-ceo-john-ternus-bring-back-apples-design-mojo/">Can new CEO John Ternus bring back Apple’s design mojo?</a> appeared first on <a href="https://macdailynews.com/">MacDailyNews</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Meta launches Muse Code AI coding agent for macOS and Linux]]></title>
<description><![CDATA[Meta is entering the AI coding-agent race with Muse Code, a new terminal-based tool now available in beta for macOS and Linux.]]></description>
<link>https://tsecurity.de/de/3706868/ios-mac-os/meta-launches-muse-code-ai-coding-agent-for-macos-and-linux/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3706868/ios-mac-os/meta-launches-muse-code-ai-coding-agent-for-macos-and-linux/</guid>
<pubDate>Wed, 05 Aug 2026 23:24:53 +0200</pubDate>
<content:encoded><![CDATA[<div class="feat-image"><img src="https://9to5mac.com/wp-content/uploads/sites/6/2026/05/meta-ai.webp?w=1600"></div><p class="wp-block-paragraph">Meta is entering the AI coding-agent race with Muse Code, a new terminal-based tool now available in beta for macOS and Linux.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Why do people recommend AntiX over Alpine for old hardware?]]></title>
<description><![CDATA[I really don’t get the glaze behind AntiX, usually if you have slow hardware you should maximize it to be as quick as possible which is something Alpine does very well, Alpine which is very underrated uses less then 80mb of ram vs AntiX which I believe uses over 100mb and runs IceWM which is way ...]]></description>
<link>https://tsecurity.de/de/3706867/linux-tipps/why-do-people-recommend-antix-over-alpine-for-old-hardware/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3706867/linux-tipps/why-do-people-recommend-antix-over-alpine-for-old-hardware/</guid>
<pubDate>Wed, 05 Aug 2026 23:24:40 +0200</pubDate>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>I really don’t get the glaze behind AntiX, usually if you have slow hardware you should maximize it to be as quick as possible which is something Alpine does very well, Alpine which is very underrated uses less then 80mb of ram vs AntiX which I believe uses over 100mb and runs IceWM which is way more bloated then something like dwm. I think people should start recommending Alpine instead of AntiX.</p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/Glum_Hamster_2104"> /u/Glum_Hamster_2104 </a> <br> <span><a href="https://www.reddit.com/r/linux/comments/1vggpe8/why_do_people_recommend_antix_over_alpine_for_old/">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/1vggpe8/why_do_people_recommend_antix_over_alpine_for_old/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[HWiNFO64 style hardware monitoring software for Linux]]></title>
<description><![CDATA[submitted by    /u/oisqi   [link]   [comments]]]></description>
<link>https://tsecurity.de/de/3706866/linux-tipps/hwinfo64-style-hardware-monitoring-software-for-linux/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3706866/linux-tipps/hwinfo64-style-hardware-monitoring-software-for-linux/</guid>
<pubDate>Wed, 05 Aug 2026 23:24:40 +0200</pubDate>
<content:encoded><![CDATA[  submitted by   <a href="https://www.reddit.com/user/oisqi"> /u/oisqi </a> <br> <span><a href="https://github.com/pulpul-s/HWall">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/1vghjap/hwinfo64_style_hardware_monitoring_software_for/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[Microconference Topic CfP is coming to an End]]></title>
<description><![CDATA[This Friday (August 7th) is the last day to submit a topic to any of the Microconferences. If you have something interesting to discuss at a Microconference, do not hesitate, submit now! It’s also a good idea to reread The Ideal Microconference Topic Session. Notifications for accepted and reject...]]></description>
<link>https://tsecurity.de/de/3706862/unix-server/microconference-topic-cfp-is-coming-to-an-end/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3706862/unix-server/microconference-topic-cfp-is-coming-to-an-end/</guid>
<pubDate>Wed, 05 Aug 2026 23:24:16 +0200</pubDate>
<content:encoded><![CDATA[This Friday (August 7th) is the last day to submit a topic to any of the Microconferences. If you have something interesting to discuss at a Microconference, do not hesitate, submit now! It’s also a good idea to reread The Ideal Microconference Topic Session. Notifications for accepted and rejected topics will happen on or before […]]]></content:encoded>
</item>
<item>
<title><![CDATA[Security: Mangelnde Rechteprüfung in botan3 (Debian)]]></title>
<description><![CDATA[]]></description>
<link>https://tsecurity.de/de/3706861/unix-server/security-mangelnde-rechtepruefung-in-botan3-debian/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3706861/unix-server/security-mangelnde-rechtepruefung-in-botan3-debian/</guid>
<pubDate>Wed, 05 Aug 2026 23:23:39 +0200</pubDate>
<content:encoded><![CDATA[ ]]></content:encoded>
</item>
<item>
<title><![CDATA[Security: Denial of Service in libgcrypt (Red Hat)]]></title>
<description><![CDATA[]]></description>
<link>https://tsecurity.de/de/3706860/unix-server/security-denial-of-service-in-libgcrypt-red-hat/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3706860/unix-server/security-denial-of-service-in-libgcrypt-red-hat/</guid>
<pubDate>Wed, 05 Aug 2026 23:23:39 +0200</pubDate>
<content:encoded><![CDATA[ ]]></content:encoded>
</item>
<item>
<title><![CDATA[Security: Mehrere Probleme in aom (Debian)]]></title>
<description><![CDATA[]]></description>
<link>https://tsecurity.de/de/3706859/unix-server/security-mehrere-probleme-in-aom-debian/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3706859/unix-server/security-mehrere-probleme-in-aom-debian/</guid>
<pubDate>Wed, 05 Aug 2026 23:23:39 +0200</pubDate>
<content:encoded><![CDATA[ ]]></content:encoded>
</item>
<item>
<title><![CDATA[Security: Ausführen beliebiger Kommandos in sg3_utils (Red Hat)]]></title>
<description><![CDATA[]]></description>
<link>https://tsecurity.de/de/3706858/unix-server/security-ausfuehren-beliebiger-kommandos-in-sg3utils-red-hat/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3706858/unix-server/security-ausfuehren-beliebiger-kommandos-in-sg3utils-red-hat/</guid>
<pubDate>Wed, 05 Aug 2026 23:23:39 +0200</pubDate>
<content:encoded><![CDATA[ ]]></content:encoded>
</item>
<item>
<title><![CDATA[Security: Denial of Service in perl-YAML (Fedora)]]></title>
<description><![CDATA[]]></description>
<link>https://tsecurity.de/de/3706857/unix-server/security-denial-of-service-in-perl-yaml-fedora/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3706857/unix-server/security-denial-of-service-in-perl-yaml-fedora/</guid>
<pubDate>Wed, 05 Aug 2026 23:23:39 +0200</pubDate>
<content:encoded><![CDATA[ ]]></content:encoded>
</item>
<item>
<title><![CDATA[Security: Preisgabe von Informationen in fence-agents (Red Hat)]]></title>
<description><![CDATA[]]></description>
<link>https://tsecurity.de/de/3706856/unix-server/security-preisgabe-von-informationen-in-fence-agents-red-hat/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3706856/unix-server/security-preisgabe-von-informationen-in-fence-agents-red-hat/</guid>
<pubDate>Wed, 05 Aug 2026 23:23:39 +0200</pubDate>
<content:encoded><![CDATA[ ]]></content:encoded>
</item>
<item>
<title><![CDATA[Security: Mangelnde Eingabeprüfung in ldns (Red Hat)]]></title>
<description><![CDATA[]]></description>
<link>https://tsecurity.de/de/3706855/unix-server/security-mangelnde-eingabepruefung-in-ldns-red-hat/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3706855/unix-server/security-mangelnde-eingabepruefung-in-ldns-red-hat/</guid>
<pubDate>Wed, 05 Aug 2026 23:23:39 +0200</pubDate>
<content:encoded><![CDATA[ ]]></content:encoded>
</item>
<item>
<title><![CDATA[Security: Ausführen beliebiger Kommandos in sg3_utils (Red Hat)]]></title>
<description><![CDATA[]]></description>
<link>https://tsecurity.de/de/3706854/unix-server/security-ausfuehren-beliebiger-kommandos-in-sg3utils-red-hat/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3706854/unix-server/security-ausfuehren-beliebiger-kommandos-in-sg3utils-red-hat/</guid>
<pubDate>Wed, 05 Aug 2026 23:23:39 +0200</pubDate>
<content:encoded><![CDATA[ ]]></content:encoded>
</item>
<item>
<title><![CDATA[Security: Denial of Service in libgcrypt (Red Hat)]]></title>
<description><![CDATA[]]></description>
<link>https://tsecurity.de/de/3706853/unix-server/security-denial-of-service-in-libgcrypt-red-hat/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3706853/unix-server/security-denial-of-service-in-libgcrypt-red-hat/</guid>
<pubDate>Wed, 05 Aug 2026 23:23:39 +0200</pubDate>
<content:encoded><![CDATA[ ]]></content:encoded>
</item>
<item>
<title><![CDATA[Security: Zwei Probleme in libXfont2 (SUSE)]]></title>
<description><![CDATA[]]></description>
<link>https://tsecurity.de/de/3706852/unix-server/security-zwei-probleme-in-libxfont2-suse/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3706852/unix-server/security-zwei-probleme-in-libxfont2-suse/</guid>
<pubDate>Wed, 05 Aug 2026 23:23:39 +0200</pubDate>
<content:encoded><![CDATA[ ]]></content:encoded>
</item>
<item>
<title><![CDATA[Security: Zwei Probleme in libXfont2 (SUSE)]]></title>
<description><![CDATA[]]></description>
<link>https://tsecurity.de/de/3706851/unix-server/security-zwei-probleme-in-libxfont2-suse/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3706851/unix-server/security-zwei-probleme-in-libxfont2-suse/</guid>
<pubDate>Wed, 05 Aug 2026 23:23:39 +0200</pubDate>
<content:encoded><![CDATA[ ]]></content:encoded>
</item>
<item>
<title><![CDATA[Security: Ausführen beliebiger Kommandos in freerdp (Red Hat)]]></title>
<description><![CDATA[]]></description>
<link>https://tsecurity.de/de/3706850/unix-server/security-ausfuehren-beliebiger-kommandos-in-freerdp-red-hat/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3706850/unix-server/security-ausfuehren-beliebiger-kommandos-in-freerdp-red-hat/</guid>
<pubDate>Wed, 05 Aug 2026 23:23:39 +0200</pubDate>
<content:encoded><![CDATA[ ]]></content:encoded>
</item>
<item>
<title><![CDATA[ETW-MCP-Server: Microsoft verbindet Copilot mit Windows-Diagnose - ad-hoc-news.de]]></title>
<description><![CDATA[Mit dem neuen ETW-MCP-Server können Entwickler Windows-Leistungsdaten per natürlicher Sprache analysieren – direkt über GitHub Copilot. Microsoft hat ...]]></description>
<link>https://tsecurity.de/de/3706849/windows-server/etw-mcp-server-microsoft-verbindet-copilot-mit-windows-diagnose-ad-hoc-newsde/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3706849/windows-server/etw-mcp-server-microsoft-verbindet-copilot-mit-windows-diagnose-ad-hoc-newsde/</guid>
<pubDate>Wed, 05 Aug 2026 23:23:36 +0200</pubDate>
<content:encoded><![CDATA[Mit dem neuen ETW-MCP-<b>Server</b> können Entwickler <b>Windows</b>-Leistungsdaten per natürlicher Sprache analysieren – direkt über GitHub Copilot. Microsoft hat ...]]></content:encoded>
</item>
<item>
<title><![CDATA[GitHub: 0.147.0-alpha.12]]></title>
<description><![CDATA[Release 0.147.0-alpha.12]]></description>
<link>https://tsecurity.de/de/3706848/downloads/github-01470-alpha12/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3706848/downloads/github-01470-alpha12/</guid>
<pubDate>Wed, 05 Aug 2026 23:23:18 +0200</pubDate>
<content:encoded><![CDATA[<div class="github-feed-entry"><p>Release 0.147.0-alpha.12</p></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[GitHub: v1.18.14]]></title>
<description><![CDATA[Core
Improvements

Simplified xAI login to a single device-code flow that works better in headless and remote environments.

Bugfixes

Preserved structured mid-stream provider errors so compatible providers can retry failed responses.
Retried more transient provider and network errors instead of ...]]></description>
<link>https://tsecurity.de/de/3706847/downloads/github-v11814/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3706847/downloads/github-v11814/</guid>
<pubDate>Wed, 05 Aug 2026 23:23:11 +0200</pubDate>
<content:encoded><![CDATA[<div class="github-feed-entry"><h2>Core</h2>
<h3>Improvements</h3>
<ul>
<li>Simplified xAI login to a single device-code flow that works better in headless and remote environments.</li>
</ul>
<h3>Bugfixes</h3>
<ul>
<li>Preserved structured mid-stream provider errors so compatible providers can retry failed responses.</li>
<li>Retried more transient provider and network errors instead of failing immediately.</li>
<li>Counted cache writes in ACP usage totals.</li>
<li>Logged remote workspace 5xx response bodies in the host logs to make proxy failures easier to debug. (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jamesmurdza/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jamesmurdza">@jamesmurdza</a>)</li>
<li>Stopped sending the host <code>directory</code> path to remote workspaces so prompts resolve from the remote project root. (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jamesmurdza/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jamesmurdza">@jamesmurdza</a>)</li>
<li>Waited for queued ACP session updates before ending a turn.</li>
</ul>
<p><strong>Thank you to 1 community contributor:</strong></p>
<ul>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jamesmurdza/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jamesmurdza">@jamesmurdza</a>:
<ul>
<li>fix(server): don't forward host directory to remote workspace (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="5041176433" data-permission-text="Title is private" data-url="https://github.com/anomalyco/opencode/issues/40136" data-hovercard-type="pull_request" data-hovercard-url="/anomalyco/opencode/pull/40136/hovercard" href="https://github.com/anomalyco/opencode/pull/40136">#40136</a>)</li>
<li>fix(server): log upstream 5xx bodies from proxied workspace requests (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="5041176311" data-permission-text="Title is private" data-url="https://github.com/anomalyco/opencode/issues/40135" data-hovercard-type="pull_request" data-hovercard-url="/anomalyco/opencode/pull/40135/hovercard" href="https://github.com/anomalyco/opencode/pull/40135">#40135</a>)</li>
</ul>
</li>
</ul></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Firefox UX: Let your designs fail for the right reasons]]></title>
<description><![CDATA[How AI-assisted native prototypes changed what usability testing could show me.
 
If you’ve ever simplified an interaction just to make a prototype manageable, you’ve probably felt the tension between what you designed and what the prototype could actually support. The risk is that when a design ...]]></description>
<link>https://tsecurity.de/de/3706846/tools/firefox-ux-let-your-designs-fail-for-the-right-reasons/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3706846/tools/firefox-ux-let-your-designs-fail-for-the-right-reasons/</guid>
<pubDate>Wed, 05 Aug 2026 23:22:26 +0200</pubDate>
<content:encoded><![CDATA[<h4>How AI-assisted native prototypes changed what usability testing could show me.</h4>
<p> </p>
<p>If you’ve ever simplified an interaction just to make a prototype manageable, you’ve probably felt the tension between what you designed and what the prototype could actually support. The risk is that when a design fails in usability testing, you can’t always tell why. Was the experience itself the problem, or was it really the prototype getting in the way: a missing connection, a laggy transition, a path you didn’t build?</p>
<p>I ran into this while working on Report Broken Site for Firefox Android, and it led me to a different way of prototyping: building directly inside the real app with AI (Claude), so the test reflects native fidelity rather than a simulation of it. That’s when I started worrying just about the design failing, and not the prototype.</p>
<div class="wp-caption aligncenter"><img alt="Four-step screenshot sequence of the Report Broken Site feature: choosing an issue type, adding details, previewing the report data, and confirming the report was sent." class=" wp-image-4500" height="558" src="https://blog.mozilla.org/ux/files/2026/08/image1-300x178.png" width="940"><p class="wp-caption-text">Feature: Report Broken Site</p></div>
<p> </p>
<h3>Reaching limits of walled prototypes</h3>
<p>In tools like Figma, prototyping requires anticipating every possible interaction and defining it explicitly. For the user to feel the true experience, each path needs to be connected, each transition set, and each variation accounted for. As complexity grows, it tends to increase the cost of maintaining it: screens multiply, connections become fragile, and animations become tedious to maintain.</p>
<p>At some point, you’re no longer designing the experience. <b>You’re managing the prototype. </b></p>
<div class="wp-caption aligncenter"><img alt='Animated GIF of a Figma prototype canvas with multiple Report Broken Site screens connected by numerous crisscrossing arrows, illustrating how manually wired prototype logic becomes tangled as complexity grows."' class="wp-image-4512 size-full" height="1512" src="https://blog.mozilla.org/ux/files/2026/08/Choosing-animation_1.5x.gif" width="3024"><p class="wp-caption-text">E.g. Changing the animation for one node, requires updating it everywhere manually.</p></div>
<p>To cope, we simplify the prototype. We reduce the number of paths, guide users through predefined flows, and limit what they can do on the prototype. The result is what I’ve started thinking of as a <b>walled prototype</b> — like a walled garden: a bounded space where users can move, but only within the paths we’ve pre-defined.</p>
<p>Some designers might argue that Figma’s recent additions of variables and advanced logic solve this problem. However, even with these tools, the designer is still building and managing the prototype. Figma prototypes simulate a system; it is not the system itself or a part of it. These prototypes have been useful, but they have also shaped the participant testing experience in ways that haven’t always been obvious.</p>
<p> </p>
<div class="wp-caption aligncenter"><img alt="Zoomed-out Figma canvas showing a large grid of connected mobile screens for the Report Broken Site prototype, linked by a dense tangle of blue connector lines." class=" wp-image-4501" height="827" src="https://blog.mozilla.org/ux/files/2026/08/image2-300x239.png" width="1038"><p class="wp-caption-text">When the logic of a feature is handled by manual connections, the canvas quickly turns into spaghetti of fragile dependencies.</p></div>
<h4><b>Prototypes shape participant behavior</b></h4>
<p>This becomes especially noticeable in usability testing. Test participants tend to recognize when they are interacting with a prototype, and that awareness can change how they behave. They may hesitate to explore, follow the perceived intent of the task, or tap around when they get stuck.</p>
<p>For example, to keep a prototype manageable, I might only make a few issue types selectable. But then participants are doing two things at once: deciding what they want to do and guessing what the prototype will allow. Their feedback can become shaped by the prototype’s limits, not just the design —  like a visitor to the walled garden checking which paths are actually open to them.</p>
<p>That constraint can be useful in early concept testing, where a narrower path helps focus the conversation. It becomes more limiting when we are trying to understand how the full experience behaves.</p>
<p>Research and practice have long acknowledged that <a href="https://www.nngroup.com/articles/ux-prototype-hi-lo-fidelity/">prototype fidelity</a> and <a href="https://uxdesign.cc/how-high-fidelity-prototypes-can-enhance-user-testing-30245ad0c4d1">testing setup</a> can influence participant behavior. But in practice, many workflows still rely on constrained, screen-to-screen simulations.</p>
<p>I’ve often wondered:</p>
<blockquote><p><b><i>How a user’s perceived experience might change if they weren’t encountering the feature in the isolation of a walled prototype?</i></b></p></blockquote>
<p> </p>
<h3>From walled to native fidelity prototypes</h3>
<p>Designing and prototyping is often described in terms of fidelity — from low-fidelity sketches to high-fidelity designs ready for dev handoff. That framing focuses on how closely we represent the product, but not necessarily how the experience itself behaves.</p>
<p>As building realistic interactions becomes easier using AI, it may now be possible to move beyond simulating flows in Figma and towards observing how people actually behave. So, alongside designing it in Figma, I built the feature directly into a local version of the Firefox Android app using Claude. It wasn’t straightforward at first, but even the friction of getting it working revealed things I wouldn’t have seen in a Figma prototype.</p>
<p>When I did this, I noticed there were no predefined paths to manage or fragile connections to maintain. The experience felt more continuous, allowing users to move more freely, not just within the feature, but within the app itself. I started thinking of these as prototypes with <b>native fidelity</b> — native to the app, native to the device, and aligned with how users expect interactions to behave.</p>
<h4><b>When prototypes need to handle dynamic behavior</b></h4>
<p>The difference between the two types of prototypes is not just theoretical; it starts to change what the experience can support. In walled prototypes, content is often fixed, and interactions move users between predefined screens. While this works for simple flows, it becomes harder to represent how interfaces behave when content needs to update dynamically based on user interaction.</p>
<p>In the <b>Report Broken Site</b> feature, this was important. A walled prototype struggles with:</p>
<ul>
<li><b>Capturing website data:</b> Depending on the browsing tab, metadata like the URL, screenshot, browser info, and tracking data needs to be captured and reflected back to the user.</li>
<li><b>URL editing:</b> Simulating real text entry, cursor movement, and auto-correct behavior.</li>
<li><b>Branching logic:</b> If a user selects “Site doesn’t load” as issue type, the details are optional, but if they choose “Something else,” details become required.</li>
<li><b>Error handling:</b> For “Something else,” the system must validate input length in the description box and show an error if it’s insufficient.</li>
</ul>
<p><b>Have you ever run into interactions like these and found yourself simplifying them, just to make the prototype manageable?</b></p>
<p>When I built it directly using Claude, the native fidelity prototype was able to handle metadata capture, text input, and branching logic more naturally.</p>
<div class="wp-caption aligncenter"><img alt="Screen recording on a real Android device of the Report Broken Site feature, showing the URL field and list of selectable issue types." class="size-full wp-image-4502" height="1128" src="https://blog.mozilla.org/ux/files/2026/08/image3.gif" width="1280"><p class="wp-caption-text">The native fidelity prototype inherits native behaviors like metadata capture, keyboard interactions, and dynamic state changes.</p></div>
<h4><b>The environment is part of the experience</b></h4>
<p>Another challenge is the environment in which the prototype is experienced. In walled prototypes, layouts are often fixed, and responsiveness is limited. Differences in device size, orientation, or performance can introduce inconsistencies that don’t reflect the intended final experience.</p>
<p>In practice, this can show up as:</p>
<ul>
<li><b>Oversized UI elements</b> on larger devices as the prototype was created for an average phone size.</li>
<li><b>Laggy interactions</b> on slower networks as Figma prototypes fail to be responsive sometimes.</li>
<li><b>Layouts that don’t adapt</b> as expected because of the constraints of the prototyping environment.</li>
</ul>
<p>When the interaction is built directly in the app, the experience inherits the <b>native environment of the device.</b> Layouts respond to screen size, interactions feel more consistent, and the overall experience is closer to what users would encounter in the final product. This could reduce the likelihood of testing interfaces being mistaken for design issues.</p>
<p> </p>
<h3>Tradeoffs and new realities</h3>
<p>This approach introduces its own challenges. First time setup for a designer is complex, and navigating the codebase and working through unfamiliar tools takes effort.</p>
<div class="wp-caption aligncenter"><img alt="Screenshot of Android Studio showing Claude assisting with a build error alongside the Firefox for Android codebase and a live device preview of the Report Broken Site feature." class=" wp-image-4504" height="649" src="https://blog.mozilla.org/ux/files/2026/08/image5-300x195.png" width="998"><p class="wp-caption-text">Using Claude on the Firefox for Android codebase in Android Studio to build the prototype.</p></div>
<p>Adopting this approach requires a shift in the UX designer’s toolkit. It raises the barrier to entry by requiring baseline comfort with the terminal, build environments, and IDEs. But it also allows designers to move beyond “faking the experience” in Figma prototypes and start building directly in the app.</p>
<p><b>Building the prototype this way also changes how the work evolves. </b>Instead of worrying about defining everything upfront, requirements tend to emerge through interaction —i.e. edge cases, missing states, and unclear behaviors as the experience is built. In Figma, many of these details are easy to overlook; when you create a prototype by building directly, they become easier to find.</p>
<p>Of course, this realism has its limits. While the experience feels like a continuous system rather than a sequence of steps, I haven’t yet connected it to a backend, pulled in APIs, or tested cross-device capabilities across mobile, tablet, and desktop. I’m still at the start of this exploration. What I want to understand next is how native fidelity prototypes change the testing environment itself: whether participants explore differently, whether failures are easier to interpret, and what new friction this approach introduces for designers and teams.</p>
<p> </p>
<h3>Start failing for the right reasons</h3>
<p>To put it simply: <b>if prototypes constrain user behavior, they may also shape the insights we get from usability testing.</b></p>
<p>For Report Broken Site, the value of the native prototype was not just that it handled more states. It gave me a more honest way to sit with the experience before putting it in front of participants. I could edit the URL, switch issue types, trigger validation, and move around the app as the feature would exist in context. Because this was a mobile experience, that context mattered: I could test it on a real device, with real navigation patterns, real input behavior, and the surrounding app experience intact. Those details helped me look past whether the prototype was working and focus more directly on whether the experience was working.</p>
<p>That is what I mean by letting the design fail for the right reasons: understanding whether an experience fails because of the design itself, not because of a missing screen-to-screen connection, bad transition, or laggy Figma prototype. The next step is to test whether this translates into different participant behavior and more useful usability insights.</p>
<p> </p>
<p>Originally published on<a class="_ymio1r31 _ypr0glyw _zcxs1o36 _mizu1v1w _1ah3dkaa _ra3xnqa1 _128mdkaa _1cvmnqa1 _4davt94y _4bfu1r31 _1hms8stv _ajmmnqa1 _vchhusvi _kqswh2mm _ect4ttxp _2rkolb4i _syaz13af _1a3b1r31 _4fpr8stv _5goinqa1 _f8pj13af _9oik1r31 _1bnxglyw _jf4cnqa1 _30l313af _1nrm1r31 _c2waglyw _1iohnqa1 _9h8h12zz _10531ra0 _1ien1ra0 _n0fx1ra0 _1vhv17z1" href="https://medium.com/@aarjavpandya/let-your-designs-fail-for-the-right-reasons-4843c2fa453a" title="https://medium.com/firefox-ux/how-do-people-decide-whether-or-not-to-get-a-browser-extension-334c66ab4484"> medium.com</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2022-41496 | iCMS 7.0.16 Parameter admincp.php url server-side request forgery (EUVD-2022-44689)]]></title>
<description><![CDATA[A vulnerability was found in iCMS 7.0.16. It has been rated as critical. This impacts an unknown function of the file admincp.php of the component Parameter Handler. The manipulation of the argument url leads to server-side request forgery.

This vulnerability is documented as CVE-2022-41496. The...]]></description>
<link>https://tsecurity.de/de/3706845/sicherheitsluecken/cve-2022-41496-icms-7016-parameter-admincpphp-url-server-side-request-forgery-euvd-2022-44689/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3706845/sicherheitsluecken/cve-2022-41496-icms-7016-parameter-admincpphp-url-server-side-request-forgery-euvd-2022-44689/</guid>
<pubDate>Wed, 05 Aug 2026 23:22:07 +0200</pubDate>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/icms">iCMS 7.0.16</a>. It has been rated as <a href="https://vuldb.com/kb/risk">critical</a>. This impacts an unknown function of the file <em>admincp.php</em> of the component <em>Parameter Handler</em>. The manipulation of the argument <em>url</em> leads to server-side request forgery.

This vulnerability is documented as <a href="https://vuldb.com/cve/CVE-2022-41496">CVE-2022-41496</a>. The attack requires being on the local network. There is not any exploit available.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2022-41495 | ClipperCMS 1.3.3 /manager/index.php rss_url_news server-side request forgery (EUVD-2022-44688)]]></title>
<description><![CDATA[A vulnerability was found in ClipperCMS 1.3.3. It has been declared as critical. This affects an unknown function of the file /manager/index.php. Executing a manipulation of the argument rss_url_news can lead to server-side request forgery.

This vulnerability is registered as CVE-2022-41495. The...]]></description>
<link>https://tsecurity.de/de/3706844/sicherheitsluecken/cve-2022-41495-clippercms-133-managerindexphp-rssurlnews-server-side-request-forgery-euvd-2022-44688/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3706844/sicherheitsluecken/cve-2022-41495-clippercms-133-managerindexphp-rssurlnews-server-side-request-forgery-euvd-2022-44688/</guid>
<pubDate>Wed, 05 Aug 2026 23:22:07 +0200</pubDate>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/clippercms">ClipperCMS 1.3.3</a>. It has been declared as <a href="https://vuldb.com/kb/risk">critical</a>. This affects an unknown function of the file <em>/manager/index.php</em>. Executing a manipulation of the argument <em>rss_url_news</em> can lead to server-side request forgery.

This vulnerability is registered as <a href="https://vuldb.com/cve/CVE-2022-41495">CVE-2022-41495</a>. The attack requires access to the local network. No exploit is available.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2022-41498 | SourceCodester Billing System Project 1.0 editbrand.php ID sql injection (EUVD-2022-44691)]]></title>
<description><![CDATA[A vulnerability identified as critical has been detected in SourceCodester Billing System Project 1.0. Impacted is an unknown function of the file /phpinventory/editbrand.php. The manipulation of the argument ID leads to sql injection.

This vulnerability is listed as CVE-2022-41498. The attack m...]]></description>
<link>https://tsecurity.de/de/3706843/sicherheitsluecken/cve-2022-41498-sourcecodester-billing-system-project-10-editbrandphp-id-sql-injection-euvd-2022-44691/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3706843/sicherheitsluecken/cve-2022-41498-sourcecodester-billing-system-project-10-editbrandphp-id-sql-injection-euvd-2022-44691/</guid>
<pubDate>Wed, 05 Aug 2026 23:22:07 +0200</pubDate>
<content:encoded><![CDATA[A vulnerability identified as <a href="https://vuldb.com/kb/risk">critical</a> has been detected in <a href="https://vuldb.com/product/sourcecodester:billing_system_project">SourceCodester Billing System Project 1.0</a>. Impacted is an unknown function of the file <em>/phpinventory/editbrand.php</em>. The manipulation of the argument <em>ID</em> leads to sql injection.

This vulnerability is listed as <a href="https://vuldb.com/cve/CVE-2022-41498">CVE-2022-41498</a>. The attack may be initiated remotely. In addition, an exploit is available.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2022-41497 | ClipperCMS 1.3.3 /manager/index.php pkg_url server-side request forgery (EUVD-2022-44690)]]></title>
<description><![CDATA[A vulnerability categorized as critical has been discovered in ClipperCMS 1.3.3. Affected is an unknown function of the file /manager/index.php. The manipulation of the argument pkg_url results in server-side request forgery.

This vulnerability is reported as CVE-2022-41497. The attacker must ha...]]></description>
<link>https://tsecurity.de/de/3706842/sicherheitsluecken/cve-2022-41497-clippercms-133-managerindexphp-pkgurl-server-side-request-forgery-euvd-2022-44690/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3706842/sicherheitsluecken/cve-2022-41497-clippercms-133-managerindexphp-pkgurl-server-side-request-forgery-euvd-2022-44690/</guid>
<pubDate>Wed, 05 Aug 2026 23:22:07 +0200</pubDate>
<content:encoded><![CDATA[A vulnerability categorized as <a href="https://vuldb.com/kb/risk">critical</a> has been discovered in <a href="https://vuldb.com/product/clippercms">ClipperCMS 1.3.3</a>. Affected is an unknown function of the file <em>/manager/index.php</em>. The manipulation of the argument <em>pkg_url</em> results in server-side request forgery.

This vulnerability is reported as <a href="https://vuldb.com/cve/CVE-2022-41497">CVE-2022-41497</a>. The attacker must have access to the local network to execute the attack. No exploit exists.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2024-26950 | Linux Kernel up to 6.8.2 wireguard null pointer dereference (Nessus ID 210815 / WID-SEC-2024-1008)]]></title>
<description><![CDATA[A vulnerability marked as critical has been reported in Linux Kernel up to 6.8.2. The affected element is an unknown function of the component wireguard. This manipulation causes null pointer dereference.

The identification of this vulnerability is CVE-2024-26950. The attack needs to be done wit...]]></description>
<link>https://tsecurity.de/de/3706841/sicherheitsluecken/cve-2024-26950-linux-kernel-up-to-682-wireguard-null-pointer-dereference-nessus-id-210815-wid-sec-2024-1008/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3706841/sicherheitsluecken/cve-2024-26950-linux-kernel-up-to-682-wireguard-null-pointer-dereference-nessus-id-210815-wid-sec-2024-1008/</guid>
<pubDate>Wed, 05 Aug 2026 23:22:07 +0200</pubDate>
<content:encoded><![CDATA[A vulnerability marked as <a href="https://vuldb.com/kb/risk">critical</a> has been reported in <a href="https://vuldb.com/product/linux:kernel">Linux Kernel up to 6.8.2</a>. The affected element is an unknown function of the component <em>wireguard</em>. This manipulation causes null pointer dereference.

The identification of this vulnerability is <a href="https://vuldb.com/cve/CVE-2024-26950">CVE-2024-26950</a>. The attack needs to be done within the local network. There is no exploit available.

It is suggested to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2024-26951 | Linux Kernel up to 6.8.2 wireguard wg_peer_remove_all use after free (Nessus ID 210882 / WID-SEC-2024-1008)]]></title>
<description><![CDATA[A vulnerability, which was classified as critical, has been found in Linux Kernel up to 6.8.2. Affected is the function wg_peer_remove_all of the component wireguard. The manipulation leads to use after free.

This vulnerability is listed as CVE-2024-26951. The attack must be carried out from wit...]]></description>
<link>https://tsecurity.de/de/3706840/sicherheitsluecken/cve-2024-26951-linux-kernel-up-to-682-wireguard-wgpeerremoveall-use-after-free-nessus-id-210882-wid-sec-2024-1008/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3706840/sicherheitsluecken/cve-2024-26951-linux-kernel-up-to-682-wireguard-wgpeerremoveall-use-after-free-nessus-id-210882-wid-sec-2024-1008/</guid>
<pubDate>Wed, 05 Aug 2026 23:22:07 +0200</pubDate>
<content:encoded><![CDATA[A vulnerability, which was classified as <a href="https://vuldb.com/kb/risk">critical</a>, has been found in <a href="https://vuldb.com/product/linux:kernel">Linux Kernel up to 6.8.2</a>. Affected is the function <code>wg_peer_remove_all</code> of the component <em>wireguard</em>. The manipulation leads to use after free.

This vulnerability is listed as <a href="https://vuldb.com/cve/CVE-2024-26951">CVE-2024-26951</a>. The attack must be carried out from within the local network. There is no available exploit.

It is advisable to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2021-33033 | Linux Kernel up to 5.11.13 DOI Definition net/ipv4/cipso_ipv4.c cipso_v4_genopt use after free]]></title>
<description><![CDATA[A vulnerability, which was classified as critical, was found in Linux Kernel up to 5.11.13. This affects the function cipso_v4_genopt of the file net/ipv4/cipso_ipv4.c of the component DOI Definition Handler. Such manipulation leads to use after free.

This vulnerability is referenced as CVE-2021...]]></description>
<link>https://tsecurity.de/de/3706839/sicherheitsluecken/cve-2021-33033-linux-kernel-up-to-51113-doi-definition-netipv4cipsoipv4c-cipsov4genopt-use-after-free/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3706839/sicherheitsluecken/cve-2021-33033-linux-kernel-up-to-51113-doi-definition-netipv4cipsoipv4c-cipsov4genopt-use-after-free/</guid>
<pubDate>Wed, 05 Aug 2026 23:22:07 +0200</pubDate>
<content:encoded><![CDATA[A vulnerability, which was classified as <a href="https://vuldb.com/kb/risk">critical</a>, was found in <a href="https://vuldb.com/product/linux:kernel">Linux Kernel up to 5.11.13</a>. This affects the function <code>cipso_v4_genopt</code> of the file <em>net/ipv4/cipso_ipv4.c</em> of the component <em>DOI Definition Handler</em>. Such manipulation leads to use after free.

This vulnerability is referenced as <a href="https://vuldb.com/cve/CVE-2021-33033">CVE-2021-33033</a>. The attack needs to be initiated within the local network. No exploit is available.

You should upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2024-26953 | Linux Kernel up to 6.6.23/6.7.11/6.8.2 esp state issue (Nessus ID 209785 / WID-SEC-2024-1008)]]></title>
<description><![CDATA[A vulnerability identified as problematic has been detected in Linux Kernel up to 6.6.23/6.7.11/6.8.2. This issue affects some unknown processing of the component esp. The manipulation leads to state issue.

This vulnerability is uniquely identified as CVE-2024-26953. The attack can only be initi...]]></description>
<link>https://tsecurity.de/de/3706838/sicherheitsluecken/cve-2024-26953-linux-kernel-up-to-66236711682-esp-state-issue-nessus-id-209785-wid-sec-2024-1008/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3706838/sicherheitsluecken/cve-2024-26953-linux-kernel-up-to-66236711682-esp-state-issue-nessus-id-209785-wid-sec-2024-1008/</guid>
<pubDate>Wed, 05 Aug 2026 23:22:07 +0200</pubDate>
<content:encoded><![CDATA[A vulnerability identified as <a href="https://vuldb.com/kb/risk">problematic</a> has been detected in <a href="https://vuldb.com/product/linux:kernel">Linux Kernel up to 6.6.23/6.7.11/6.8.2</a>. This issue affects some unknown processing of the component <em>esp</em>. The manipulation leads to state issue.

This vulnerability is uniquely identified as <a href="https://vuldb.com/cve/CVE-2024-26953">CVE-2024-26953</a>. The attack can only be initiated within the local network. No exploit exists.

You should upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2022-0330 | Linux Kernel up to 5.17-rc1 GPU i915 Kernel Driver memory corruption (EUVD-2022-15497 / Nessus ID 236676)]]></title>
<description><![CDATA[A vulnerability was found in Linux Kernel up to 5.17-rc1 and classified as critical. Impacted is an unknown function of the component GPU i915 Kernel Driver. Such manipulation leads to memory corruption.

This vulnerability is traded as CVE-2022-0330. The attack may be launched remotely. There is...]]></description>
<link>https://tsecurity.de/de/3706837/sicherheitsluecken/cve-2022-0330-linux-kernel-up-to-517-rc1-gpu-i915-kernel-driver-memory-corruption-euvd-2022-15497-nessus-id-236676/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3706837/sicherheitsluecken/cve-2022-0330-linux-kernel-up-to-517-rc1-gpu-i915-kernel-driver-memory-corruption-euvd-2022-15497-nessus-id-236676/</guid>
<pubDate>Wed, 05 Aug 2026 23:22:07 +0200</pubDate>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/linux:kernel">Linux Kernel up to 5.17-rc1</a> and classified as <a href="https://vuldb.com/kb/risk">critical</a>. Impacted is an unknown function of the component <em>GPU i915 Kernel Driver</em>. Such manipulation leads to memory corruption.

This vulnerability is traded as <a href="https://vuldb.com/cve/CVE-2022-0330">CVE-2022-0330</a>. The attack may be launched remotely. There is no exploit available.

It is suggested to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2021-42252 | Linux Kernel up to 5.14.5 Aspeed LPC Control Interface aspeed-lpc-ctrl.c aspeed_lpc_ctrl_mmap comparison]]></title>
<description><![CDATA[A vulnerability described as critical has been identified in Linux Kernel up to 5.14.5. This impacts the function aspeed_lpc_ctrl_mmap of the file drivers/soc/aspeed/aspeed-lpc-ctrl.c of the component Aspeed LPC Control Interface. The manipulation results in incorrect comparison.

This vulnerabil...]]></description>
<link>https://tsecurity.de/de/3706836/sicherheitsluecken/cve-2021-42252-linux-kernel-up-to-5145-aspeed-lpc-control-interface-aspeed-lpc-ctrlc-aspeedlpcctrlmmap-comparison/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3706836/sicherheitsluecken/cve-2021-42252-linux-kernel-up-to-5145-aspeed-lpc-control-interface-aspeed-lpc-ctrlc-aspeedlpcctrlmmap-comparison/</guid>
<pubDate>Wed, 05 Aug 2026 23:22:07 +0200</pubDate>
<content:encoded><![CDATA[A vulnerability described as <a href="https://vuldb.com/kb/risk">critical</a> has been identified in <a href="https://vuldb.com/product/linux:kernel">Linux Kernel up to 5.14.5</a>. This impacts the function <code>aspeed_lpc_ctrl_mmap</code> of the file <em>drivers/soc/aspeed/aspeed-lpc-ctrl.c</em> of the component <em>Aspeed LPC Control Interface</em>. The manipulation results in incorrect comparison.

This vulnerability is reported as <a href="https://vuldb.com/cve/CVE-2021-42252">CVE-2021-42252</a>. The attack can be launched remotely. Moreover, an exploit is present.

Upgrading the affected component is recommended.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2021-38166 | Linux Kernel up to 5.13.8 Bucket kernel/bpf/hashtab.c out-of-bounds write]]></title>
<description><![CDATA[A vulnerability was found in Linux Kernel up to 5.13.8. It has been classified as critical. The impacted element is an unknown function of the file kernel/bpf/hashtab.c of the component Bucket Handler. Performing a manipulation results in out-of-bounds write.

This vulnerability is reported as CV...]]></description>
<link>https://tsecurity.de/de/3706835/sicherheitsluecken/cve-2021-38166-linux-kernel-up-to-5138-bucket-kernelbpfhashtabc-out-of-bounds-write/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3706835/sicherheitsluecken/cve-2021-38166-linux-kernel-up-to-5138-bucket-kernelbpfhashtabc-out-of-bounds-write/</guid>
<pubDate>Wed, 05 Aug 2026 23:22:07 +0200</pubDate>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/linux:kernel">Linux Kernel up to 5.13.8</a>. It has been classified as <a href="https://vuldb.com/kb/risk">critical</a>. The impacted element is an unknown function of the file <em>kernel/bpf/hashtab.c</em> of the component <em>Bucket Handler</em>. Performing a manipulation results in out-of-bounds write.

This vulnerability is reported as <a href="https://vuldb.com/cve/CVE-2021-38166">CVE-2021-38166</a>. The attacker must have access to the local network to execute the attack. No exploit exists.

It is suggested to install a patch to address this issue.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-9081 | IBM Langflow OSS up to 1.10.3 validate_model_provider_key OLLAMA_BASE_URL server-side request forgery (EUVD-2026-53568)]]></title>
<description><![CDATA[A vulnerability classified as critical was found in IBM Langflow OSS up to 1.10.3. This affects the function validate_model_provider_key. Executing a manipulation of the argument OLLAMA_BASE_URL can lead to server-side request forgery.

The identification of this vulnerability is CVE-2026-9081. T...]]></description>
<link>https://tsecurity.de/de/3706834/sicherheitsluecken/cve-2026-9081-ibm-langflow-oss-up-to-1103-validatemodelproviderkey-ollamabaseurl-server-side-request-forgery-euvd-2026-53568/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3706834/sicherheitsluecken/cve-2026-9081-ibm-langflow-oss-up-to-1103-validatemodelproviderkey-ollamabaseurl-server-side-request-forgery-euvd-2026-53568/</guid>
<pubDate>Wed, 05 Aug 2026 23:22:07 +0200</pubDate>
<content:encoded><![CDATA[A vulnerability classified as <a href="https://vuldb.com/kb/risk">critical</a> was found in <a href="https://vuldb.com/product/ibm:langflow_oss">IBM Langflow OSS up to 1.10.3</a>. This affects the function <code>validate_model_provider_key</code>. Executing a manipulation of the argument <em>OLLAMA_BASE_URL</em> can lead to server-side request forgery.

The identification of this vulnerability is <a href="https://vuldb.com/cve/CVE-2026-9081">CVE-2026-9081</a>. The attack may be launched remotely. There is no exploit available.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-70448 | Jenkins Project Ivy Report Plugin up to 1.2 xml external entity reference (EUVD-2026-53542)]]></title>
<description><![CDATA[A vulnerability labeled as critical has been found in Jenkins Project Ivy Report Plugin up to 1.2. Affected by this issue is some unknown functionality. Such manipulation leads to xml external entity reference.

This vulnerability is traded as CVE-2026-70448. The attack may be launched remotely. ...]]></description>
<link>https://tsecurity.de/de/3706833/sicherheitsluecken/cve-2026-70448-jenkins-project-ivy-report-plugin-up-to-12-xml-external-entity-reference-euvd-2026-53542/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3706833/sicherheitsluecken/cve-2026-70448-jenkins-project-ivy-report-plugin-up-to-12-xml-external-entity-reference-euvd-2026-53542/</guid>
<pubDate>Wed, 05 Aug 2026 23:22:07 +0200</pubDate>
<content:encoded><![CDATA[A vulnerability labeled as <a href="https://vuldb.com/kb/risk">critical</a> has been found in <a href="https://vuldb.com/product/jenkins_project:ivy_report_plugin">Jenkins Project Ivy Report Plugin up to 1.2</a>. Affected by this issue is some unknown functionality. Such manipulation leads to xml external entity reference.

This vulnerability is traded as <a href="https://vuldb.com/cve/CVE-2026-70448">CVE-2026-70448</a>. The attack may be launched remotely. There is no exploit available.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-70447 | Jenkins AWS CodeBuild Plugin up to 0.59 permission (EUVD-2026-53541)]]></title>
<description><![CDATA[A vulnerability identified as problematic has been detected in Jenkins AWS CodeBuild Plugin up to 0.59. Affected by this vulnerability is an unknown functionality. This manipulation causes permission issues.

This vulnerability appears as CVE-2026-70447. The attack may be initiated remotely. Ther...]]></description>
<link>https://tsecurity.de/de/3706832/sicherheitsluecken/cve-2026-70447-jenkins-aws-codebuild-plugin-up-to-059-permission-euvd-2026-53541/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3706832/sicherheitsluecken/cve-2026-70447-jenkins-aws-codebuild-plugin-up-to-059-permission-euvd-2026-53541/</guid>
<pubDate>Wed, 05 Aug 2026 23:22:07 +0200</pubDate>
<content:encoded><![CDATA[A vulnerability identified as <a href="https://vuldb.com/kb/risk">problematic</a> has been detected in <a href="https://vuldb.com/product/jenkins:aws_codebuild_plugin">Jenkins AWS CodeBuild Plugin up to 0.59</a>. Affected by this vulnerability is an unknown functionality. This manipulation causes permission issues.

This vulnerability appears as <a href="https://vuldb.com/cve/CVE-2026-70447">CVE-2026-70447</a>. The attack may be initiated remotely. There is no available exploit.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-70446 | Jenkins CodeSonar Plugin up to 3.6.0 permission (EUVD-2026-53540)]]></title>
<description><![CDATA[A vulnerability categorized as problematic has been discovered in Jenkins CodeSonar Plugin up to 3.6.0. Affected is an unknown function. The manipulation results in permission issues.

This vulnerability is reported as CVE-2026-70446. The attack can be launched remotely. No exploit exists.]]></description>
<link>https://tsecurity.de/de/3706831/sicherheitsluecken/cve-2026-70446-jenkins-codesonar-plugin-up-to-360-permission-euvd-2026-53540/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3706831/sicherheitsluecken/cve-2026-70446-jenkins-codesonar-plugin-up-to-360-permission-euvd-2026-53540/</guid>
<pubDate>Wed, 05 Aug 2026 23:22:07 +0200</pubDate>
<content:encoded><![CDATA[A vulnerability categorized as <a href="https://vuldb.com/kb/risk">problematic</a> has been discovered in <a href="https://vuldb.com/product/jenkins:codesonar_plugin">Jenkins CodeSonar Plugin up to 3.6.0</a>. Affected is an unknown function. The manipulation results in permission issues.

This vulnerability is reported as <a href="https://vuldb.com/cve/CVE-2026-70446">CVE-2026-70446</a>. The attack can be launched remotely. No exploit exists.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-7657 | IBM Langflow up to 1.10.3 server-side request forgery (EUVD-2026-53567)]]></title>
<description><![CDATA[A vulnerability was found in IBM Langflow up to 1.10.3. It has been classified as critical. The impacted element is an unknown function. Performing a manipulation results in server-side request forgery.

This vulnerability is cataloged as CVE-2026-7657. It is possible to initiate the attack remot...]]></description>
<link>https://tsecurity.de/de/3706830/sicherheitsluecken/cve-2026-7657-ibm-langflow-up-to-1103-server-side-request-forgery-euvd-2026-53567/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3706830/sicherheitsluecken/cve-2026-7657-ibm-langflow-up-to-1103-server-side-request-forgery-euvd-2026-53567/</guid>
<pubDate>Wed, 05 Aug 2026 23:22:07 +0200</pubDate>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/ibm:langflow">IBM Langflow up to 1.10.3</a>. It has been classified as <a href="https://vuldb.com/kb/risk">critical</a>. The impacted element is an unknown function. Performing a manipulation results in server-side request forgery.

This vulnerability is cataloged as <a href="https://vuldb.com/cve/CVE-2026-7657">CVE-2026-7657</a>. It is possible to initiate the attack remotely. There is no exploit available.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-18991 | nanocoai NanoClaw up to 2.0.64 send_file core.ts path traversal (Issue 2760)]]></title>
<description><![CDATA[A vulnerability categorized as critical has been discovered in nanocoai NanoClaw up to 2.0.64. This affects an unknown part of the file container/agent-runner/src/mcp-tools/core.ts of the component send_file. Such manipulation leads to path traversal.

This vulnerability is documented as CVE-2026...]]></description>
<link>https://tsecurity.de/de/3706829/sicherheitsluecken/cve-2026-18991-nanocoai-nanoclaw-up-to-2064-sendfile-corets-path-traversal-issue-2760/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3706829/sicherheitsluecken/cve-2026-18991-nanocoai-nanoclaw-up-to-2064-sendfile-corets-path-traversal-issue-2760/</guid>
<pubDate>Wed, 05 Aug 2026 23:22:07 +0200</pubDate>
<content:encoded><![CDATA[A vulnerability categorized as <a href="https://vuldb.com/kb/risk">critical</a> has been discovered in <a href="https://vuldb.com/product/nanocoai:nanoclaw">nanocoai NanoClaw up to 2.0.64</a>. This affects an unknown part of the file <em>container/agent-runner/src/mcp-tools/core.ts</em> of the component <em>send_file</em>. Such manipulation leads to path traversal.

This vulnerability is documented as <a href="https://vuldb.com/cve/CVE-2026-18991">CVE-2026-18991</a>. The attack can be executed remotely. Additionally, an exploit exists.

The project was informed of the problem early through an issue report but has not responded yet.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2022-41500 | EyouCMS 1.5.9 Members Center cross-site request forgery (Issue 27 / EUVD-2022-44693)]]></title>
<description><![CDATA[A vulnerability marked as problematic has been reported in EyouCMS 1.5.9. This affects an unknown function of the component Members Center/Editorial Membership/Points Recharge. This manipulation causes cross-site request forgery.

This vulnerability is tracked as CVE-2022-41500. The attack is pos...]]></description>
<link>https://tsecurity.de/de/3706828/sicherheitsluecken/cve-2022-41500-eyoucms-159-members-center-cross-site-request-forgery-issue-27-euvd-2022-44693/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3706828/sicherheitsluecken/cve-2022-41500-eyoucms-159-members-center-cross-site-request-forgery-issue-27-euvd-2022-44693/</guid>
<pubDate>Wed, 05 Aug 2026 23:22:07 +0200</pubDate>
<content:encoded><![CDATA[A vulnerability marked as <a href="https://vuldb.com/kb/risk">problematic</a> has been reported in <a href="https://vuldb.com/product/eyoucms">EyouCMS 1.5.9</a>. This affects an unknown function of the component <em>Members Center/Editorial Membership/Points Recharge</em>. This manipulation causes cross-site request forgery.

This vulnerability is tracked as <a href="https://vuldb.com/cve/CVE-2022-41500">CVE-2022-41500</a>. The attack is possible to be carried out remotely. No exploit exists.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2022-41504 | Billing System Project 1.0 editProductImage.php unrestricted upload (EUVD-2022-44697)]]></title>
<description><![CDATA[A vulnerability, which was classified as critical, was found in Billing System Project 1.0. The affected element is an unknown function of the file /php_action/editProductImage.php. Executing a manipulation can lead to unrestricted upload.

This vulnerability is registered as CVE-2022-41504. The ...]]></description>
<link>https://tsecurity.de/de/3706827/sicherheitsluecken/cve-2022-41504-billing-system-project-10-editproductimagephp-unrestricted-upload-euvd-2022-44697/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3706827/sicherheitsluecken/cve-2022-41504-billing-system-project-10-editproductimagephp-unrestricted-upload-euvd-2022-44697/</guid>
<pubDate>Wed, 05 Aug 2026 23:22:07 +0200</pubDate>
<content:encoded><![CDATA[A vulnerability, which was classified as <a href="https://vuldb.com/kb/risk">critical</a>, was found in <a href="https://vuldb.com/product/billing_system_project">Billing System Project 1.0</a>. The affected element is an unknown function of the file <em>/php_action/editProductImage.php</em>. Executing a manipulation can lead to unrestricted upload.

This vulnerability is registered as <a href="https://vuldb.com/cve/CVE-2022-41504">CVE-2022-41504</a>. The attack requires access to the local network. No exploit is available.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2022-41505 | TP-LINK Tapo C200 on TP UART Port access control (EUVD-2022-44698)]]></title>
<description><![CDATA[A vulnerability was found in TP-LINK Tapo C200 on TP. It has been declared as critical. Affected by this issue is some unknown functionality of the component UART Port. Such manipulation leads to improper access controls.

This vulnerability is documented as CVE-2022-41505. The attack can be exec...]]></description>
<link>https://tsecurity.de/de/3706826/sicherheitsluecken/cve-2022-41505-tp-link-tapo-c200-on-tp-uart-port-access-control-euvd-2022-44698/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3706826/sicherheitsluecken/cve-2022-41505-tp-link-tapo-c200-on-tp-uart-port-access-control-euvd-2022-44698/</guid>
<pubDate>Wed, 05 Aug 2026 23:22:07 +0200</pubDate>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/tp-link:tapo_c200">TP-LINK Tapo C200</a> on TP. It has been declared as <a href="https://vuldb.com/kb/risk">critical</a>. Affected by this issue is some unknown functionality of the component <em>UART Port</em>. Such manipulation leads to improper access controls.

This vulnerability is documented as <a href="https://vuldb.com/cve/CVE-2022-41505">CVE-2022-41505</a>. The attack can be executed directly on the physical device. There is not any exploit available.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2022-41512 | Online Diagnostic Lab Management System 1.0 /php_action/editFile.php unrestricted upload (EUVD-2022-44705)]]></title>
<description><![CDATA[A vulnerability labeled as critical has been found in Online Diagnostic Lab Management System 1.0. This impacts an unknown function of the file /php_action/editFile.php. The manipulation results in unrestricted upload.

This vulnerability was named CVE-2022-41512. The attack needs to be approache...]]></description>
<link>https://tsecurity.de/de/3706825/sicherheitsluecken/cve-2022-41512-online-diagnostic-lab-management-system-10-phpactioneditfilephp-unrestricted-upload-euvd-2022-44705/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3706825/sicherheitsluecken/cve-2022-41512-online-diagnostic-lab-management-system-10-phpactioneditfilephp-unrestricted-upload-euvd-2022-44705/</guid>
<pubDate>Wed, 05 Aug 2026 23:22:07 +0200</pubDate>
<content:encoded><![CDATA[A vulnerability labeled as <a href="https://vuldb.com/kb/risk">critical</a> has been found in <a href="https://vuldb.com/product/online_diagnostic_lab_management_system">Online Diagnostic Lab Management System 1.0</a>. This impacts an unknown function of the file <em>/php_action/editFile.php</em>. The manipulation results in unrestricted upload.

This vulnerability was named <a href="https://vuldb.com/cve/CVE-2022-41512">CVE-2022-41512</a>. The attack needs to be approached within the local network. There is no available exploit.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-64553 | Linux Kernel up to 7.1.4 psample nla_put information disclosure (WID-SEC-2026-2536)]]></title>
<description><![CDATA[A vulnerability classified as problematic was found in Linux Kernel up to 7.1.4. Affected by this vulnerability is the function nla_put of the component psample. Executing a manipulation can lead to information disclosure.

The identification of this vulnerability is CVE-2026-64553. The attack ma...]]></description>
<link>https://tsecurity.de/de/3706824/sicherheitsluecken/cve-2026-64553-linux-kernel-up-to-714-psample-nlaput-information-disclosure-wid-sec-2026-2536/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3706824/sicherheitsluecken/cve-2026-64553-linux-kernel-up-to-714-psample-nlaput-information-disclosure-wid-sec-2026-2536/</guid>
<pubDate>Wed, 05 Aug 2026 23:22:07 +0200</pubDate>
<content:encoded><![CDATA[A vulnerability classified as <a href="https://vuldb.com/kb/risk">problematic</a> was found in <a href="https://vuldb.com/product/linux:kernel">Linux Kernel up to 7.1.4</a>. Affected by this vulnerability is the function <code>nla_put</code> of the component <em>psample</em>. Executing a manipulation can lead to information disclosure.

The identification of this vulnerability is <a href="https://vuldb.com/cve/CVE-2026-64553">CVE-2026-64553</a>. The attack may be launched remotely. There is no exploit available.

Upgrading the affected component is advised.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-64554 | Linux Kernel up to 7.2-rc3 netfilter bridge net/ipv6/ip6_output.c ip6_frag_next use after free (WID-SEC-2026-2536)]]></title>
<description><![CDATA[A vulnerability classified as very critical was found in Linux Kernel up to 7.2-rc3. This affects the function ip6_frag_next of the file net/ipv6/ip6_output.c of the component netfilter bridge. Such manipulation leads to use after free.

This vulnerability is referenced as CVE-2026-64554. It is p...]]></description>
<link>https://tsecurity.de/de/3706823/sicherheitsluecken/cve-2026-64554-linux-kernel-up-to-72-rc3-netfilter-bridge-netipv6ip6outputc-ip6fragnext-use-after-free-wid-sec-2026-2536/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3706823/sicherheitsluecken/cve-2026-64554-linux-kernel-up-to-72-rc3-netfilter-bridge-netipv6ip6outputc-ip6fragnext-use-after-free-wid-sec-2026-2536/</guid>
<pubDate>Wed, 05 Aug 2026 23:22:07 +0200</pubDate>
<content:encoded><![CDATA[A vulnerability classified as <a href="https://vuldb.com/kb/risk">very critical</a> was found in <a href="https://vuldb.com/product/linux:kernel">Linux Kernel up to 7.2-rc3</a>. This affects the function <code>ip6_frag_next</code> of the file <em>net/ipv6/ip6_output.c</em> of the component <em>netfilter bridge</em>. Such manipulation leads to use after free.

This vulnerability is referenced as <a href="https://vuldb.com/cve/CVE-2026-64554">CVE-2026-64554</a>. It is possible to launch the attack remotely. No exploit is available.

Upgrading the affected component is advised.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-64555 | Linux Kernel up to 6.12.96/6.18.39/7.1.4/7.2-rc3 KVM arm64 nested virtualization kvm_hyp_handle_mops state issue (WID-SEC-2026-2536)]]></title>
<description><![CDATA[A vulnerability, which was classified as very critical, has been found in Linux Kernel up to 6.12.96/6.18.39/7.1.4/7.2-rc3. Affected by this issue is the function kvm_hyp_handle_mops of the component KVM arm64 nested virtualization. The manipulation leads to state issue.

This vulnerability is re...]]></description>
<link>https://tsecurity.de/de/3706822/sicherheitsluecken/cve-2026-64555-linux-kernel-up-to-612966183971472-rc3-kvm-arm64-nested-virtualization-kvmhyphandlemops-state-issue-wid-sec-2026-2536/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3706822/sicherheitsluecken/cve-2026-64555-linux-kernel-up-to-612966183971472-rc3-kvm-arm64-nested-virtualization-kvmhyphandlemops-state-issue-wid-sec-2026-2536/</guid>
<pubDate>Wed, 05 Aug 2026 23:22:07 +0200</pubDate>
<content:encoded><![CDATA[A vulnerability, which was classified as <a href="https://vuldb.com/kb/risk">very critical</a>, has been found in <a href="https://vuldb.com/product/linux:kernel">Linux Kernel up to 6.12.96/6.18.39/7.1.4/7.2-rc3</a>. Affected by this issue is the function <code>kvm_hyp_handle_mops</code> of the component <em>KVM arm64 nested virtualization</em>. The manipulation leads to state issue.

This vulnerability is referenced as <a href="https://vuldb.com/cve/CVE-2026-64555">CVE-2026-64555</a>. Remote exploitation of the attack is possible. No exploit is available.

It is advisable to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-64187 | Linux Kernel up to 6.12.95/6.18.38/7.1.3/7.2-rc3 xfs fs/xfs/xfs_log_recover.c xlog_recover_reorder_trans ri_buf null pointer dereference (WID-SEC-2026-2427)]]></title>
<description><![CDATA[A vulnerability marked as problematic has been reported in Linux Kernel up to 6.12.95/6.18.38/7.1.3/7.2-rc3. This affects the function xlog_recover_reorder_trans of the file fs/xfs/xfs_log_recover.c of the component xfs. The manipulation of the argument ri_buf leads to null pointer dereference.

...]]></description>
<link>https://tsecurity.de/de/3706821/sicherheitsluecken/cve-2026-64187-linux-kernel-up-to-612956183871372-rc3-xfs-fsxfsxfslogrecoverc-xlogrecoverreordertrans-ribuf-null-pointer-dereference-wid-sec-2026-2427/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3706821/sicherheitsluecken/cve-2026-64187-linux-kernel-up-to-612956183871372-rc3-xfs-fsxfsxfslogrecoverc-xlogrecoverreordertrans-ribuf-null-pointer-dereference-wid-sec-2026-2427/</guid>
<pubDate>Wed, 05 Aug 2026 23:22:07 +0200</pubDate>
<content:encoded><![CDATA[A vulnerability marked as <a href="https://vuldb.com/kb/risk">problematic</a> has been reported in <a href="https://vuldb.com/product/linux:kernel">Linux Kernel up to 6.12.95/6.18.38/7.1.3/7.2-rc3</a>. This affects the function <code>xlog_recover_reorder_trans</code> of the file <em>fs/xfs/xfs_log_recover.c</em> of the component <em>xfs</em>. The manipulation of the argument <em>ri_buf</em> leads to null pointer dereference.

This vulnerability is uniquely identified as <a href="https://vuldb.com/cve/CVE-2026-64187">CVE-2026-64187</a>. The attack is possible to be carried out remotely. No exploit exists.

It is suggested to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-64189 | Linux Kernel up to 6.12.95/6.18.38/7.1.3/7.2-rc1 ipset ip_set_core.c ip_set_dump_do ip_set_list use after free (WID-SEC-2026-2427)]]></title>
<description><![CDATA[A vulnerability identified as very critical has been detected in Linux Kernel up to 6.12.95/6.18.38/7.1.3/7.2-rc1. This vulnerability affects the function ip_set_dump_do of the file net/netfilter/ipset/ip_set_core.c of the component ipset. The manipulation of the argument ip_set_list leads to use...]]></description>
<link>https://tsecurity.de/de/3706820/sicherheitsluecken/cve-2026-64189-linux-kernel-up-to-612956183871372-rc1-ipset-ipsetcorec-ipsetdumpdo-ipsetlist-use-after-free-wid-sec-2026-2427/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3706820/sicherheitsluecken/cve-2026-64189-linux-kernel-up-to-612956183871372-rc1-ipset-ipsetcorec-ipsetdumpdo-ipsetlist-use-after-free-wid-sec-2026-2427/</guid>
<pubDate>Wed, 05 Aug 2026 23:22:07 +0200</pubDate>
<content:encoded><![CDATA[A vulnerability identified as <a href="https://vuldb.com/kb/risk">very critical</a> has been detected in <a href="https://vuldb.com/product/linux:kernel">Linux Kernel up to 6.12.95/6.18.38/7.1.3/7.2-rc1</a>. This vulnerability affects the function <code>ip_set_dump_do</code> of the file <em>net/netfilter/ipset/ip_set_core.c</em> of the component <em>ipset</em>. The manipulation of the argument <em>ip_set_list</em> leads to use after free.

This vulnerability is traded as <a href="https://vuldb.com/cve/CVE-2026-64189">CVE-2026-64189</a>. It is possible to initiate the attack remotely. There is no exploit available.

You should upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-64188 | Linux Kernel up to 7.0.13 rmnet rmnet_vnd.c rmnet_dellink egress_dev use after free (Nessus ID 330014 / WID-SEC-2026-2427)]]></title>
<description><![CDATA[A vulnerability categorized as very critical has been discovered in Linux Kernel up to 7.0.13. This affects the function rmnet_dellink of the file rmnet_vnd.c of the component rmnet. Executing a manipulation of the argument egress_dev can lead to use after free.

This vulnerability appears as CVE...]]></description>
<link>https://tsecurity.de/de/3706819/sicherheitsluecken/cve-2026-64188-linux-kernel-up-to-7013-rmnet-rmnetvndc-rmnetdellink-egressdev-use-after-free-nessus-id-330014-wid-sec-2026-2427/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3706819/sicherheitsluecken/cve-2026-64188-linux-kernel-up-to-7013-rmnet-rmnetvndc-rmnetdellink-egressdev-use-after-free-nessus-id-330014-wid-sec-2026-2427/</guid>
<pubDate>Wed, 05 Aug 2026 23:22:07 +0200</pubDate>
<content:encoded><![CDATA[A vulnerability categorized as <a href="https://vuldb.com/kb/risk">very critical</a> has been discovered in <a href="https://vuldb.com/product/linux:kernel">Linux Kernel up to 7.0.13</a>. This affects the function <code>rmnet_dellink</code> of the file <em>rmnet_vnd.c</em> of the component <em>rmnet</em>. Executing a manipulation of the argument <em>egress_dev</em> can lead to use after free.

This vulnerability appears as <a href="https://vuldb.com/cve/CVE-2026-64188">CVE-2026-64188</a>. The attack may be performed from remote. There is no available exploit.

It is advisable to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-64191 | Linux Kernel up to 7.0.13 i2c-stub drivers/i2c/i2c-stub.c stub_xfer block out-of-bounds (Nessus ID 330014 / WID-SEC-2026-2427)]]></title>
<description><![CDATA[A vulnerability classified as very critical was found in Linux Kernel up to 7.0.13. This affects the function stub_xfer of the file drivers/i2c/i2c-stub.c of the component i2c-stub. Executing a manipulation of the argument block can lead to out-of-bounds read.

The identification of this vulnerab...]]></description>
<link>https://tsecurity.de/de/3706818/sicherheitsluecken/cve-2026-64191-linux-kernel-up-to-7013-i2c-stub-driversi2ci2c-stubc-stubxfer-block-out-of-bounds-nessus-id-330014-wid-sec-2026-2427/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3706818/sicherheitsluecken/cve-2026-64191-linux-kernel-up-to-7013-i2c-stub-driversi2ci2c-stubc-stubxfer-block-out-of-bounds-nessus-id-330014-wid-sec-2026-2427/</guid>
<pubDate>Wed, 05 Aug 2026 23:22:07 +0200</pubDate>
<content:encoded><![CDATA[A vulnerability classified as <a href="https://vuldb.com/kb/risk">very critical</a> was found in <a href="https://vuldb.com/product/linux:kernel">Linux Kernel up to 7.0.13</a>. This affects the function <code>stub_xfer</code> of the file <em>drivers/i2c/i2c-stub.c</em> of the component <em>i2c-stub</em>. Executing a manipulation of the argument <em>block</em> can lead to out-of-bounds read.

The identification of this vulnerability is <a href="https://vuldb.com/cve/CVE-2026-64191">CVE-2026-64191</a>. The attack can only be executed locally. There is no exploit available.

Upgrading the affected component is advised.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-64190 | Linux Kernel up to 6.18.34 team team_core.c team_xmit ops null pointer dereference (WID-SEC-2026-2427)]]></title>
<description><![CDATA[A vulnerability was found in Linux Kernel up to 6.18.34. It has been rated as problematic. Affected by this issue is the function team_xmit of the file drivers/net/team/team_core.c of the component team. Performing a manipulation of the argument ops results in null pointer dereference.

This vuln...]]></description>
<link>https://tsecurity.de/de/3706817/sicherheitsluecken/cve-2026-64190-linux-kernel-up-to-61834-team-teamcorec-teamxmit-ops-null-pointer-dereference-wid-sec-2026-2427/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3706817/sicherheitsluecken/cve-2026-64190-linux-kernel-up-to-61834-team-teamcorec-teamxmit-ops-null-pointer-dereference-wid-sec-2026-2427/</guid>
<pubDate>Wed, 05 Aug 2026 23:22:07 +0200</pubDate>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/linux:kernel">Linux Kernel up to 6.18.34</a>. It has been rated as <a href="https://vuldb.com/kb/risk">problematic</a>. Affected by this issue is the function <code>team_xmit</code> of the file <em>drivers/net/team/team_core.c</em> of the component <em>team</em>. Performing a manipulation of the argument <em>ops</em> results in null pointer dereference.

This vulnerability is reported as <a href="https://vuldb.com/cve/CVE-2026-64190">CVE-2026-64190</a>. The attack is possible to be carried out remotely. No exploit exists.

Upgrading the affected component is advised.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-67862 | Open62541 1.5.5 High-Level Attribute Reading Logic ua_client_highlevel.c buffer overflow (Nessus ID 332254)]]></title>
<description><![CDATA[A vulnerability, which was classified as problematic, has been found in Open62541 1.5.5. Impacted is an unknown function of the file src/client/ua_client_highlevel.c of the component High-Level Attribute Reading Logic. Performing a manipulation results in buffer overflow.

This vulnerability is k...]]></description>
<link>https://tsecurity.de/de/3706816/sicherheitsluecken/cve-2026-67862-open62541-155-high-level-attribute-reading-logic-uaclienthighlevelc-buffer-overflow-nessus-id-332254/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3706816/sicherheitsluecken/cve-2026-67862-open62541-155-high-level-attribute-reading-logic-uaclienthighlevelc-buffer-overflow-nessus-id-332254/</guid>
<pubDate>Wed, 05 Aug 2026 23:22:07 +0200</pubDate>
<content:encoded><![CDATA[A vulnerability, which was classified as <a href="https://vuldb.com/kb/risk">problematic</a>, has been found in <a href="https://vuldb.com/product/open62541">Open62541 1.5.5</a>. Impacted is an unknown function of the file <em>src/client/ua_client_highlevel.c</em> of the component <em>High-Level Attribute Reading Logic</em>. Performing a manipulation results in buffer overflow.

This vulnerability is known as <a href="https://vuldb.com/cve/CVE-2026-67862">CVE-2026-67862</a>. Remote exploitation of the attack is possible. No exploit is available.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-71201 | OpenStack Ironic Portgroups access control (Nessus ID 332253)]]></title>
<description><![CDATA[A vulnerability was found in OpenStack Ironic. It has been rated as problematic. This issue affects some unknown processing of the component Portgroups. This manipulation causes improper access controls.

This vulnerability is handled as CVE-2026-71201. The attack can be initiated remotely. There...]]></description>
<link>https://tsecurity.de/de/3706815/sicherheitsluecken/cve-2026-71201-openstack-ironic-portgroups-access-control-nessus-id-332253/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3706815/sicherheitsluecken/cve-2026-71201-openstack-ironic-portgroups-access-control-nessus-id-332253/</guid>
<pubDate>Wed, 05 Aug 2026 23:22:07 +0200</pubDate>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/openstack:ironic">OpenStack Ironic</a>. It has been rated as <a href="https://vuldb.com/kb/risk">problematic</a>. This issue affects some unknown processing of the component <em>Portgroups</em>. This manipulation causes improper access controls.

This vulnerability is handled as <a href="https://vuldb.com/cve/CVE-2026-71201">CVE-2026-71201</a>. The attack can be initiated remotely. There is not any exploit available.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-71190 | OpenStack Swift up to 2.35.3/2.36.2/2.37.2/2.38.0 Accept Header Parser redos (Nessus ID 332251)]]></title>
<description><![CDATA[A vulnerability labeled as critical has been found in OpenStack Swift up to 2.35.3/2.36.2/2.37.2/2.38.0. The affected element is an unknown function of the component Accept Header Parser. Such manipulation leads to inefficient regular expression complexity.

This vulnerability is listed as CVE-20...]]></description>
<link>https://tsecurity.de/de/3706814/sicherheitsluecken/cve-2026-71190-openstack-swift-up-to-2353236223722380-accept-header-parser-redos-nessus-id-332251/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3706814/sicherheitsluecken/cve-2026-71190-openstack-swift-up-to-2353236223722380-accept-header-parser-redos-nessus-id-332251/</guid>
<pubDate>Wed, 05 Aug 2026 23:22:07 +0200</pubDate>
<content:encoded><![CDATA[A vulnerability labeled as <a href="https://vuldb.com/kb/risk">critical</a> has been found in <a href="https://vuldb.com/product/openstack:swift">OpenStack Swift up to 2.35.3/2.36.2/2.37.2/2.38.0</a>. The affected element is an unknown function of the component <em>Accept Header Parser</em>. Such manipulation leads to inefficient regular expression complexity.

This vulnerability is listed as <a href="https://vuldb.com/cve/CVE-2026-71190">CVE-2026-71190</a>. The attack may be performed from remote. There is no available exploit.

The affected component should be upgraded.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-67860 | open62541 1.5.5 HistoryRead buffer overflow (Nessus ID 332252)]]></title>
<description><![CDATA[A vulnerability, which was classified as critical, was found in open62541 1.5.5. The affected element is an unknown function of the component HistoryRead. Executing a manipulation can lead to buffer overflow.

This vulnerability is handled as CVE-2026-67860. The attack can be executed remotely. T...]]></description>
<link>https://tsecurity.de/de/3706813/sicherheitsluecken/cve-2026-67860-open62541-155-historyread-buffer-overflow-nessus-id-332252/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3706813/sicherheitsluecken/cve-2026-67860-open62541-155-historyread-buffer-overflow-nessus-id-332252/</guid>
<pubDate>Wed, 05 Aug 2026 23:22:07 +0200</pubDate>
<content:encoded><![CDATA[A vulnerability, which was classified as <a href="https://vuldb.com/kb/risk">critical</a>, was found in <a href="https://vuldb.com/product/open62541">open62541 1.5.5</a>. The affected element is an unknown function of the component <em>HistoryRead</em>. Executing a manipulation can lead to buffer overflow.

This vulnerability is handled as <a href="https://vuldb.com/cve/CVE-2026-67860">CVE-2026-67860</a>. The attack can be executed remotely. There is not any exploit available.]]></content:encoded>
</item>
<item>
<title><![CDATA[I built an open-source MCP server that gives AI agents 46 structured reverse engineering tools (Ghidra, GDB, Binwalk, etc) with a persistent knowledge base]]></title>
<description><![CDATA[Hey guys, I have been working on an open-source project that lets AI agents (Claude, OpenCode, Antigravity, Codex, etc.) work with reverse engineering tools and store facts in a DB to make long-term analysis easier. You just point your agent to the file, and it does the work: it runs tools like G...]]></description>
<link>https://tsecurity.de/de/3706812/malware-trojaner-viren/i-built-an-open-source-mcp-server-that-gives-ai-agents-46-structured-reverse-engineering-tools-ghidra-gdb-binwalk-etc-with-a-persistent-knowledge-base/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3706812/malware-trojaner-viren/i-built-an-open-source-mcp-server-that-gives-ai-agents-46-structured-reverse-engineering-tools-ghidra-gdb-binwalk-etc-with-a-persistent-knowledge-base/</guid>
<pubDate>Wed, 05 Aug 2026 23:22:01 +0200</pubDate>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>Hey guys,</p> <p>I have been working on an open-source project that lets AI agents (Claude, OpenCode, Antigravity, Codex, etc.) work with reverse engineering tools and store facts in a DB to make long-term analysis easier.</p> <p>You just point your agent to the file, and it does the work: it runs tools like <strong>Ghidra headless, gdb, binwalk, tshark, radare2, readelf, strings...</strong> then turns what it finds into the database.</p> <h1>Key Features</h1> <ol> <li><strong>Specialized Analysis Agents:</strong> Binary, firmware, network, CPU, and kernel.</li> <li><strong>Knowledge Base (SQLite):</strong> Everything is stored as a fact, hypothesis, or experiment with confidence + evidence tags so nothing is "trust me, bro."</li> <li><strong>Multi-Agent Debate:</strong> When agents disagree on a finding, they argue it out in a structured debate until they reach a consensus.</li> <li><strong>Self-Critique:</strong> Every agent's output gets LLM-reviewed before it's accepted.</li> <li><strong>RAG Semantic Search:</strong> Query all past analyses (<em>"Have I seen this obfuscation pattern before?"</em>).</li> <li><strong>Missions:</strong> Define objectives with dependencies, assign agents, and track progress.</li> <li><strong>Token Budgets + Rate Limiting:</strong> Prevents runaway loops from burning your API budget.</li> <li><strong>Monitoring:</strong> Prometheus metrics + Grafana.</li> </ol> <h1>Interface &amp; Setup</h1> <ul> <li><strong>MCP Server:</strong> The whole thing is exposed as an MCP server (46 tools), so you drive it from a terminal with natural language.</li> <li><strong>Dashboard:</strong> You can also use the Flask web dashboard (currently only a database view, but an interactive UI to work directly with agents is doable).</li> <li><strong>One-Command Setup:</strong> Run <code>python setup_wizard.py</code>it detects your installed RE tools, helps you pick an LLM provider (OpenAI, Anthropic, Google, Ollama, etc.), validates the key, and writes your <code>.env</code>. (note that LLM api keys are not necessary if you plan to use it just from your agent cli like opencode)</li> </ul> <p><strong>Stack:</strong> Python, LLM orchestration, MCP, SQLite, Flask. Ghidra, GDB, and Binwalk are optional. It degrades gracefully with just binutils.</p> <p>This is very much a research project, and I'd love feedback from people who do this professionally, what's missing, what annoys you, what would you trust it to do?</p> <p><strong>GitHub:</strong> <a href="https://github.com/The-Arabi/Reverse-engineering-agent">https://github.com/The-Arabi/Reverse-engineering-agent</a></p> <p><a href="https://preview.redd.it/47z8u41x1ghh1.png?width=1336&amp;format=png&amp;auto=webp&amp;s=1bde2ec8279186ed46688b5574d271aaae78766e">database</a></p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/Katsu121"> /u/Katsu121 </a> <br> <span><a href="https://www.reddit.com/r/ExploitDev/comments/1vg8tjn/i_built_an_opensource_mcp_server_that_gives_ai/">[link]</a></span>   <span><a href="https://www.reddit.com/r/ExploitDev/comments/1vg8tjn/i_built_an_opensource_mcp_server_that_gives_ai/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[Das freie Wort - Wahlhelfer | krone.at]]></title>
<description><![CDATA[Bessere Wahlhelfer als die Herren Babler, Ludwig und Hacker können sich die anderen Parteien gar nicht wünschen. Einfach weiter so. Dr. Max ...]]></description>
<link>https://tsecurity.de/de/3706811/hacking/das-freie-wort-wahlhelfer-kroneat/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3706811/hacking/das-freie-wort-wahlhelfer-kroneat/</guid>
<pubDate>Wed, 05 Aug 2026 23:21:49 +0200</pubDate>
<content:encoded><![CDATA[Bessere Wahlhelfer als die Herren Babler, Ludwig und <b>Hacker</b> können sich die anderen Parteien gar nicht wünschen. Einfach weiter so. Dr. Max ...]]></content:encoded>
</item>
<item>
<title><![CDATA[Bitcoin plötzlich in Bewegung: Hacker-Angriff sorgt für Rekord-Aktivität - FXStreet]]></title>
<description><![CDATA[Bitcoin plötzlich in Bewegung: Hacker-Angriff sorgt für Rekord-Aktivität ... Die On-Chain-Aktivität von Bitcoin (BTC) ist nach Angriffen auf Coldcard- ...]]></description>
<link>https://tsecurity.de/de/3706810/hacking/bitcoin-ploetzlich-in-bewegung-hacker-angriff-sorgt-fuer-rekord-aktivitaet-fxstreet/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3706810/hacking/bitcoin-ploetzlich-in-bewegung-hacker-angriff-sorgt-fuer-rekord-aktivitaet-fxstreet/</guid>
<pubDate>Wed, 05 Aug 2026 23:21:49 +0200</pubDate>
<content:encoded><![CDATA[Bitcoin plötzlich in Bewegung: <b>Hacker</b>-Angriff sorgt für Rekord-Aktivität ... Die On-Chain-Aktivität von Bitcoin (BTC) ist nach Angriffen auf Coldcard- ...]]></content:encoded>
</item>
<item>
<title><![CDATA[CrowdStrike 2026: Hacker nutzen Sicherheitslücken binnen 24 Stunden aus - Martin Cid Magazine]]></title>
<description><![CDATA[Der Threat Hunting Report 2026 von CrowdStrike belegt: 88 Prozent der veröffentlichten Sicherheitslücken werden innerhal. CrowdStrike 2026: Hacker ...]]></description>
<link>https://tsecurity.de/de/3706809/hacking/crowdstrike-2026-hacker-nutzen-sicherheitsluecken-binnen-24-stunden-aus-martin-cid-magazine/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3706809/hacking/crowdstrike-2026-hacker-nutzen-sicherheitsluecken-binnen-24-stunden-aus-martin-cid-magazine/</guid>
<pubDate>Wed, 05 Aug 2026 23:21:49 +0200</pubDate>
<content:encoded><![CDATA[Der Threat Hunting Report 2026 von CrowdStrike belegt: 88 Prozent der veröffentlichten Sicherheitslücken werden innerhal. CrowdStrike 2026: <b>Hacker</b> ...]]></content:encoded>
</item>
<item>
<title><![CDATA[Hacker greifen Unternehmen über offizielle Microsoft-Dienste mit Phishing-Mails an]]></title>
<description><![CDATA[Cyberkriminelle verzichten zunehmend auf gefälschte Microsoft-Anmeldeseiten und nutzen stattdessen Microsofts eigene, legitime Infrastruktur zur ...]]></description>
<link>https://tsecurity.de/de/3706808/hacking/hacker-greifen-unternehmen-ueber-offizielle-microsoft-dienste-mit-phishing-mails-an/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3706808/hacking/hacker-greifen-unternehmen-ueber-offizielle-microsoft-dienste-mit-phishing-mails-an/</guid>
<pubDate>Wed, 05 Aug 2026 23:21:49 +0200</pubDate>
<content:encoded><![CDATA[Cyberkriminelle verzichten zunehmend auf gefälschte Microsoft-Anmeldeseiten und nutzen stattdessen Microsofts eigene, legitime Infrastruktur zur ...]]></content:encoded>
</item>
<item>
<title><![CDATA[Wirtschaft vor acht - KI als Hacker - hier anschauen - ARD Mediathek]]></title>
<description><![CDATA[Es ist schon wieder passiert! Während Unternehmen wie Amazon, Nvidia, in Deutschland auch Infineon und Co.]]></description>
<link>https://tsecurity.de/de/3706807/hacking/wirtschaft-vor-acht-ki-als-hacker-hier-anschauen-ard-mediathek/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3706807/hacking/wirtschaft-vor-acht-ki-als-hacker-hier-anschauen-ard-mediathek/</guid>
<pubDate>Wed, 05 Aug 2026 23:21:49 +0200</pubDate>
<content:encoded><![CDATA[Es ist schon wieder passiert! Während Unternehmen wie Amazon, Nvidia, in Deutschland auch Infineon und Co.]]></content:encoded>
</item>
<item>
<title><![CDATA[KI verschickt bei Test Phishing-Mails | BR24]]></title>
<description><![CDATA[London: Bei einem Test mit Künstlicher Intelligenz haben britische Sicherheitsforscher alarmierende Hacker-Fähigkeiten beobachtet.]]></description>
<link>https://tsecurity.de/de/3706806/hacking/ki-verschickt-bei-test-phishing-mails-br24/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3706806/hacking/ki-verschickt-bei-test-phishing-mails-br24/</guid>
<pubDate>Wed, 05 Aug 2026 23:21:49 +0200</pubDate>
<content:encoded><![CDATA[London: Bei einem Test mit Künstlicher Intelligenz haben britische Sicherheitsforscher alarmierende <b>Hacker</b>-Fähigkeiten beobachtet.]]></content:encoded>
</item>
<item>
<title><![CDATA[Bitcoin Kurs klettert auf 63.500 Dollar, doch Hacker erbeuten 1.367 BTC aus einer Hardware Wallet]]></title>
<description><![CDATA[Anzeige / WerbungDer Bitcoin Kurs steht am Dienstagmorgen bei rund 63.500 US Dollar, nachdem Hacker 1.367 BTC aus 4.585 Adressen abgezogen haben.]]></description>
<link>https://tsecurity.de/de/3706805/hacking/bitcoin-kurs-klettert-auf-63500-dollar-doch-hacker-erbeuten-1367-btc-aus-einer-hardware-wallet/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3706805/hacking/bitcoin-kurs-klettert-auf-63500-dollar-doch-hacker-erbeuten-1367-btc-aus-einer-hardware-wallet/</guid>
<pubDate>Wed, 05 Aug 2026 23:21:49 +0200</pubDate>
<content:encoded><![CDATA[Anzeige / WerbungDer Bitcoin Kurs steht am Dienstagmorgen bei rund 63.500 US Dollar, nachdem <b>Hacker</b> 1.367 BTC aus 4.585 Adressen abgezogen haben.]]></content:encoded>
</item>
<item>
<title><![CDATA[Syrer vor Niederösterreichern? Jetzt wackelt Hackers Spitals-Argument | exxpress]]></title>
<description><![CDATA[Wiens Gesundheitsstadtrat Peter Hacker (SPÖ) verteidigt die Behandlung syrischer Patienten, während Niederösterreicher bei planbaren Eingriffen in ...]]></description>
<link>https://tsecurity.de/de/3706804/hacking/syrer-vor-niederoesterreichern-jetzt-wackelt-hackers-spitals-argument-exxpress/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3706804/hacking/syrer-vor-niederoesterreichern-jetzt-wackelt-hackers-spitals-argument-exxpress/</guid>
<pubDate>Wed, 05 Aug 2026 23:21:49 +0200</pubDate>
<content:encoded><![CDATA[Wiens Gesundheitsstadtrat Peter <b>Hacker</b> (SPÖ) verteidigt die Behandlung syrischer Patienten, während Niederösterreicher bei planbaren Eingriffen in ...]]></content:encoded>
</item>
<item>
<title><![CDATA[This round mini PC is big on personality - here's why I recommend it]]></title>
<description><![CDATA[Small enough to slip into a backpack, Lenovo's Yoga Mini Gen 11 is a solid work PC with unique tricks up its sleeve.]]></description>
<link>https://tsecurity.de/de/3706803/hacking/this-round-mini-pc-is-big-on-personality-heres-why-i-recommend-it/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3706803/hacking/this-round-mini-pc-is-big-on-personality-heres-why-i-recommend-it/</guid>
<pubDate>Wed, 05 Aug 2026 23:21:41 +0200</pubDate>
<content:encoded><![CDATA[Small enough to slip into a backpack, Lenovo's Yoga Mini Gen 11 is a solid work PC with unique tricks up its sleeve.]]></content:encoded>
</item>
<item>
<title><![CDATA[AI Deception Emerges in Cyber Tests as Agents Target Real People and Systems]]></title>
<description><![CDATA[AISI found AI agents taking unsanctioned online actions, including social engineering and code attacks, during controlled cyber tests. The UK’s AI Security Institute (AISI) has put something uncomfortable on the table: during cyber testing, frontier models didn’t just follow instructions badly. I...]]></description>
<link>https://tsecurity.de/de/3706802/hacking/ai-deception-emerges-in-cyber-tests-as-agents-target-real-people-and-systems/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3706802/hacking/ai-deception-emerges-in-cyber-tests-as-agents-target-real-people-and-systems/</guid>
<pubDate>Wed, 05 Aug 2026 23:21:37 +0200</pubDate>
<content:encoded><![CDATA[AISI found AI agents taking unsanctioned online actions, including social engineering and code attacks, during controlled cyber tests. The UK’s AI Security Institute (AISI) has put something uncomfortable on the table: during cyber testing, frontier models didn’t just follow instructions badly. In some runs, they crossed into real-world actions, touched real people and organisations, and […]]]></content:encoded>
</item>
<item>
<title><![CDATA[Anja Kohl, HR, zu nächstem KI-Alarm wegen Hacking-Versuchs bei Anthropic - Tagesschau]]></title>
<description><![CDATA[Anja Kohl, HR, zu nächstem KI-Alarm wegen Hacking-Versuchs bei Anthropic.]]></description>
<link>https://tsecurity.de/de/3706801/hacking/anja-kohl-hr-zu-naechstem-ki-alarm-wegen-hacking-versuchs-bei-anthropic-tagesschau/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3706801/hacking/anja-kohl-hr-zu-naechstem-ki-alarm-wegen-hacking-versuchs-bei-anthropic-tagesschau/</guid>
<pubDate>Wed, 05 Aug 2026 23:21:37 +0200</pubDate>
<content:encoded><![CDATA[Anja Kohl, HR, zu nächstem KI-Alarm wegen <b>Hacking</b>-Versuchs bei Anthropic.]]></content:encoded>
</item>
<item>
<title><![CDATA[The Real Goal: Strategic Autonomy]]></title>
<description><![CDATA[YouTube Video]]></description>
<link>https://tsecurity.de/de/3706800/it-security-video/the-real-goal-strategic-autonomy/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3706800/it-security-video/the-real-goal-strategic-autonomy/</guid>
<pubDate>Wed, 05 Aug 2026 23:21:30 +0200</pubDate>
<content:encoded><![CDATA[<p>YouTube Video</p><p><iframe loading="lazy" src="https://www.youtube.com/embed/SL9AWhudF5c"></iframe></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[GitHub: v2.36.0]]></title>
<description><![CDATA[What's Changed

Support Platform Filtering in ENABLE_FUZZ_FOR_BOTS Feature Flag by @javanlacerda in #5411
[Metrics] Check provision model by consulting metadata by @PauloVLB in #5413

Full Changelog: 2.35.6...v2.36.0]]></description>
<link>https://tsecurity.de/de/3706799/it-security-tools/github-v2360/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3706799/it-security-tools/github-v2360/</guid>
<pubDate>Wed, 05 Aug 2026 23:21:22 +0200</pubDate>
<content:encoded><![CDATA[<div class="github-feed-entry"><h2>What's Changed</h2>
<ul>
<li>Support Platform Filtering in ENABLE_FUZZ_FOR_BOTS Feature Flag by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/javanlacerda/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/javanlacerda">@javanlacerda</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="5062975002" data-permission-text="Title is private" data-url="https://github.com/google/clusterfuzz/issues/5411" data-hovercard-type="pull_request" data-hovercard-url="/google/clusterfuzz/pull/5411/hovercard" href="https://github.com/google/clusterfuzz/pull/5411">#5411</a></li>
<li>[Metrics] Check provision model by consulting metadata by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/PauloVLB/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/PauloVLB">@PauloVLB</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="5073511872" data-permission-text="Title is private" data-url="https://github.com/google/clusterfuzz/issues/5413" data-hovercard-type="pull_request" data-hovercard-url="/google/clusterfuzz/pull/5413/hovercard" href="https://github.com/google/clusterfuzz/pull/5413">#5413</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a class="commit-link" href="https://github.com/google/clusterfuzz/compare/2.35.6...v2.36.0">2.35.6...v2.36.0</a></p></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Shai-Hulud strikes again: CHAINDROP worm hits 400+ npm packages]]></title>
<description><![CDATA[Elastic Security Labs identified the return of Shai-Hulud. Attackers compromised the keyv maintainer and deployed CHAINDROP, a worm that uses stolen npm credentials to backdoor co-owned packages totaling over 1.3 billion monthly downloads.]]></description>
<link>https://tsecurity.de/de/3706798/it-security-nachrichten/shai-hulud-strikes-again-chaindrop-worm-hits-400-npm-packages/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3706798/it-security-nachrichten/shai-hulud-strikes-again-chaindrop-worm-hits-400-npm-packages/</guid>
<pubDate>Wed, 05 Aug 2026 23:21:02 +0200</pubDate>
<content:encoded><![CDATA[Elastic Security Labs identified the return of Shai-Hulud. Attackers compromised the keyv maintainer and deployed CHAINDROP, a worm that uses stolen npm credentials to backdoor co-owned packages totaling over 1.3 billion monthly downloads.]]></content:encoded>
</item>
<item>
<title><![CDATA[Can AI do novel security research? Meet the HTTP Terminator]]></title>
<description><![CDATA[Abstract We all know AI can find bugs. After a decade of research, I asked a harder question: can an autonomous system invent new attack techniques, and use them to hack live websites at scale? Buildi]]></description>
<link>https://tsecurity.de/de/3706797/it-security-nachrichten/can-ai-do-novel-security-research-meet-the-http-terminator/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3706797/it-security-nachrichten/can-ai-do-novel-security-research-meet-the-http-terminator/</guid>
<pubDate>Wed, 05 Aug 2026 23:21:01 +0200</pubDate>
<content:encoded><![CDATA[Abstract We all know AI can find bugs. After a decade of research, I asked a harder question: can an autonomous system invent new attack techniques, and use them to hack live websites at scale? Buildi]]></content:encoded>
</item>
<item>
<title><![CDATA[Tom Cotton prods Treasury for tax code tweaks to modernize OT]]></title>
<description><![CDATA[The Senate Intel Committee chair wrote to Treasury Secretary Scott Bessent about changes to spur investment in aging technology to better guard against cyberattacks.
The post Tom Cotton prods Treasury for tax code tweaks to modernize OT appeared first on CyberScoop.]]></description>
<link>https://tsecurity.de/de/3706796/it-security-nachrichten/tom-cotton-prods-treasury-for-tax-code-tweaks-to-modernize-ot/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3706796/it-security-nachrichten/tom-cotton-prods-treasury-for-tax-code-tweaks-to-modernize-ot/</guid>
<pubDate>Wed, 05 Aug 2026 23:20:52 +0200</pubDate>
<content:encoded><![CDATA[<p>The Senate Intel Committee chair wrote to Treasury Secretary Scott Bessent about changes to spur investment in aging technology to better guard against cyberattacks.</p>
<p>The post <a href="https://fedscoop.com/treasury-tax-code-ot-cyberattacks-tom-cotton-letter/">Tom Cotton prods Treasury for tax code tweaks to modernize OT</a> appeared first on <a href="https://cyberscoop.com/">CyberScoop</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Horizon3 raises $250 million in Series E funding.]]></title>
<description><![CDATA[Spur secures $200 million in funding from Insight Partners. Okta has agreed to acquire identity security platform Permiso Security.]]></description>
<link>https://tsecurity.de/de/3706795/it-security-nachrichten/horizon3-raises-250-million-in-series-e-funding/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3706795/it-security-nachrichten/horizon3-raises-250-million-in-series-e-funding/</guid>
<pubDate>Wed, 05 Aug 2026 23:20:42 +0200</pubDate>
<content:encoded><![CDATA[Spur secures $200 million in funding from Insight Partners. Okta has agreed to acquire identity security platform Permiso Security.]]></content:encoded>
</item>
<item>
<title><![CDATA[SAFE and sound.]]></title>
<description><![CDATA[The White House lays out its AI strategy at Black Hat. Researchers spotlight rogue AI behavior. CISA warns of an actively exploited N-able flaw. TP-Link patches 15 Omada vulnerabilities. Apple fights the UK’s iCloud access order. The AI gray market expands. A Massachusetts healthcare breach hits ...]]></description>
<link>https://tsecurity.de/de/3706794/it-security-nachrichten/safe-and-sound/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3706794/it-security-nachrichten/safe-and-sound/</guid>
<pubDate>Wed, 05 Aug 2026 23:20:41 +0200</pubDate>
<content:encoded><![CDATA[The White House lays out its AI strategy at Black Hat. Researchers spotlight rogue AI behavior. CISA warns of an actively exploited N-able flaw. TP-Link patches 15 Omada vulnerabilities. Apple fights the UK’s iCloud access order. The AI gray market expands. A Massachusetts healthcare breach hits more than 300,000 people. Lawmakers push to extend protections for OPM breach victims. Our guest is Cal Al-Dhubaib, Principal Technologist at Rubrik, who wonders if your security team is solving the wrong problem. With elections, don’t trust AI to tell you the whole story.]]></content:encoded>
</item>
<item>
<title><![CDATA[Oracle SQL Injection Attack Enables Remote Code Execution ]]></title>
<description><![CDATA[A Huntress investigation reveals how attackers used SQL injection to achieve RCE and steal credentials.
The post Oracle SQL Injection Attack Enables Remote Code Execution  appeared first on eSecurity Planet.]]></description>
<link>https://tsecurity.de/de/3706793/it-security-nachrichten/oracle-sql-injection-attack-enables-remote-code-execution/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3706793/it-security-nachrichten/oracle-sql-injection-attack-enables-remote-code-execution/</guid>
<pubDate>Wed, 05 Aug 2026 23:20:30 +0200</pubDate>
<content:encoded><![CDATA[<p>A Huntress investigation reveals how attackers used SQL injection to achieve RCE and steal credentials.</p>
<p>The post <a href="https://www.esecurityplanet.com/threats/oracle-sql-injection-attack-enables-remote-code-execution/">Oracle SQL Injection Attack Enables Remote Code Execution </a> appeared first on <a href="https://www.esecurityplanet.com/">eSecurity Planet</a>.</p>]]></content:encoded>
</item>
</channel>
</rss>
<!-- Generated in 3,21ms -->