<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="/rss-style.xsl"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:media="http://search.yahoo.com/mrss/" xmlns:dc="http://purl.org/dc/elements/1.1/">
<channel>
<title><![CDATA[Team IT Security - 📰 Alle Kategorien]]></title>
<link><![CDATA[https://tsecurity.de/export/rss/alle-kategorien.xml?q=brain+reacts%2F]]></link>
<description><![CDATA[Das Gesamte Cyber Threat Intelligence Feed-Archiv von TSecurity.de. Alle Nachrichten, Sicherheitsmeldungen, Videos, Downloads und Analysen in einer zentralen Übersicht.]]></description>
<language>de-DE</language>
<lastBuildDate>Thu, 30 Jul 2026 03:23:36 +0200</lastBuildDate>
<pubDate>Thu, 30 Jul 2026 03:23:36 +0200</pubDate>
<ttl>15</ttl>
<copyright>2026 Team IT Security</copyright>
<managingEditor>lakandor@tsecurity.de (Horus Sirius)</managingEditor>
<webMaster>lakandor@tsecurity.de (Horus Sirius)</webMaster>
<category>IT Security</category>
<category>Cybersecurity</category>
<category>Nachrichten</category>
<generator>Team IT Security RSS Generator v2.0</generator>
<image>
<url>https://tsecurity.de/favicon.ico</url>
<title><![CDATA[Team IT Security - 📰 Alle Kategorien]]></title>
<link><![CDATA[https://tsecurity.de/export/rss/alle-kategorien.xml?q=brain+reacts%2F]]></link>
</image>
<atom:link href="https://tsecurity.de/export/rss/it-security.xml?q=brain+reacts%2F" rel="self" type="application/rss+xml" />
<item>
<title><![CDATA[AI, Mind Reading and Microchip Brain Implants]]></title>
<description><![CDATA[How neurotech advancements and new state laws are shaping the future of human-machine interfaces.]]></description>
<link>https://tsecurity.de/de/3694404/it-security-nachrichten/ai-mind-reading-and-microchip-brain-implants/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3694404/it-security-nachrichten/ai-mind-reading-and-microchip-brain-implants/</guid>
<pubDate>Sat, 25 Jul 2026 18:57:46 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[How neurotech advancements and new state laws are shaping the future of human-machine interfaces.]]></content:encoded>
</item>
<item>
<title><![CDATA[The Mark of AI: 2030 - ∞ Future Timeline of The Beast & ASI]]></title>
<description><![CDATA[Author: AI News - Bewertung: 4023x - Views:154298 - This is artificial intelligence becoming artificial super intelligence, and its mark on man in the form of brain computer interface chip to create a new world order where no one can buy or sell without it.

Deep Learning AI Specialization: https...]]></description>
<link>https://tsecurity.de/de/3693372/videos/the-mark-of-ai-2030-future-timeline-of-the-beast-asi/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3693372/videos/the-mark-of-ai-2030-future-timeline-of-the-beast-asi/</guid>
<pubDate>Sat, 25 Jul 2026 09:05:19 +0200</pubDate>
<category>🎥 Videos</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: AI News - Bewertung: 4023x - Views:154298 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/W-jCQck3dII?autoplay=1&origin=https://tsecurity.de" frameborder="0"></iframe></p><p>- This is artificial intelligence becoming artificial super intelligence, and its mark on man in the form of brain computer interface chip to create a new world order where no one can buy or sell without it.<br />
<br />
Deep Learning AI Specialization: https://imp.i384100.net/GET-STARTED<br />
AI Marketplace: https://taimine.com/<br />
<br />
Timestamps:<br />
0:00 Intro to AI turned ASI<br />
0:58 The rise of super intelligence<br />
3:40 Brain computer interface mark<br />
5:41 Losing the beast&#039;s favor<br />
<br />
#ai #future #tech<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Humans Can Learn To Echolocate In Just 10 Weeks, and It Rewires the Brain]]></title>
<description><![CDATA[alternative_right shares a report from ScienceAlert: A study published in PLOS One in 2021 by researchers from Durham University in the UK showed that with 10 weeks of training, both blind and sighted people could learn to echolocate using verbal clicks. While the technique is already used by a n...]]></description>
<link>https://tsecurity.de/de/3691356/it-security-nachrichten/humans-can-learn-to-echolocate-in-just-10-weeks-and-it-rewires-the-brain/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3691356/it-security-nachrichten/humans-can-learn-to-echolocate-in-just-10-weeks-and-it-rewires-the-brain/</guid>
<pubDate>Fri, 24 Jul 2026 13:12:47 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[alternative_right shares a report from ScienceAlert: A study published in PLOS One in 2021 by researchers from Durham University in the UK showed that with 10 weeks of training, both blind and sighted people could learn to echolocate using verbal clicks. While the technique is already used by a number of people with impaired vision -- sometimes using the taps of a cane instead of clicks made by their mouth -- those findings suggest that many of us can learn the necessary techniques.
 
Some of the same researchers who made that discovery are part of the team behind a follow-up study published in Cerebral Cortex, looking at how the 10 weeks of training that the 26 participants went through actually changed the physical structure of their brains. Specifically, the team analyzed brain scans of the V1 (the primary visual cortex, processing visuals), and the A1 (the primary auditory cortex, processing sounds). Strikingly, the scans showed that the V1s of both blind and sighted people had developed sensitivity to sound echoes during echolocation training.<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=Humans+Can+Learn+To+Echolocate+In+Just+10+Weeks%2C+and+It+Rewires+the+Brain%3A+https%3A%2F%2Fscience.slashdot.org%2Fstory%2F26%2F07%2F24%2F021238%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fscience.slashdot.org%2Fstory%2F26%2F07%2F24%2F021238%2Fhumans-can-learn-to-echolocate-in-just-10-weeks-and-it-rewires-the-brain%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://science.slashdot.org/story/26/07/24/021238/humans-can-learn-to-echolocate-in-just-10-weeks-and-it-rewires-the-brain?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Some of Our Favorite Brain-Boosting Toys for Kids of All Ages]]></title>
<description><![CDATA[From musical instruments and games to play pieces that encourage balance and dexterity, these toys will engage your child’s mind and body.]]></description>
<link>https://tsecurity.de/de/3691309/it-nachrichten/some-of-our-favorite-brain-boosting-toys-for-kids-of-all-ages/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3691309/it-nachrichten/some-of-our-favorite-brain-boosting-toys-for-kids-of-all-ages/</guid>
<pubDate>Fri, 24 Jul 2026 12:50:11 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[From musical instruments and games to play pieces that encourage balance and dexterity, these toys will engage your child’s mind and body.]]></content:encoded>
</item>
<item>
<title><![CDATA[Bad Brains: Azure Five Hour Outage Was Microsoft AI Demonstration]]></title>
<description><![CDATA[Microsoft spent early July marketing AI as the thing that keeps Azure running. That’s right, get ready to blame AI when Azure goes down. CTO Mark Russinovich introduced the awkwardly named Brain, an AIOps system described as a “digital twin” of Azure’s own health, credited with powering deploymen...]]></description>
<link>https://tsecurity.de/de/3691205/it-security-nachrichten/bad-brains-azure-five-hour-outage-was-microsoft-ai-demonstration/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3691205/it-security-nachrichten/bad-brains-azure-five-hour-outage-was-microsoft-ai-demonstration/</guid>
<pubDate>Fri, 24 Jul 2026 11:58:10 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Microsoft spent early July marketing AI as the thing that keeps Azure running. That’s right, get ready to blame AI when Azure goes down. CTO Mark Russinovich introduced the awkwardly named Brain, an AIOps system described as a “digital twin” of Azure’s own health, credited with powering deployment safeguards and outage declaration, and billed as … <a href="https://www.flyingpenguin.com/bad-brains-azure-five-hour-outage-was-microsoft-ai-demonstration/" class="more-link">Continue reading <span class="screen-reader-text">Bad Brains: Azure Five Hour Outage Was Microsoft AI Demonstration</span> <span class="meta-nav">→</span></a>]]></content:encoded>
</item>
<item>
<title><![CDATA[How to Pitch Apps to TidBITS in the AI Era]]></title>
<description><![CDATA[AI has made it vastly easier to build apps and pitch them to publications like TidBITS for review. But we don’t have the time or brain space to look at everything, so here’s how developers can improve their chances of catching our attention.]]></description>
<link>https://tsecurity.de/de/3690133/ios-mac-os/how-to-pitch-apps-to-tidbits-in-the-ai-era/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3690133/ios-mac-os/how-to-pitch-apps-to-tidbits-in-the-ai-era/</guid>
<pubDate>Thu, 23 Jul 2026 22:03:20 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[AI has made it vastly easier to build apps and pitch them to publications like TidBITS for review. But we don’t have the time or brain space to look at everything, so here’s how developers can improve their chances of catching our attention.<p><a href="https://tidbits.com/2016/07/11/os-x-hidden-treasures-typing-exotic-characters/"><picture><source srcset="https://tidbits.com/uploads/2018/05/TB-Special-Characters-ad-640x200.png" media="(max-width: 600px)" type="image/png"><img src="https://tidbits.com/uploads/2018/05/TB-Special-Characters-ad-1456x180.png" srcset="https://tidbits.com/uploads/2018/05/TB-Special-Characters-ad-1456x180.png 1456w, https://tidbits.com/uploads/2018/05/TB-Special-Characters-ad-1456x180-640x79.png 640w" alt="macOS Hidden Treasures: Typing Exotic Characters"></picture></a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Researchers Discover First Known Transmissible Cancer In Fish]]></title>
<description><![CDATA[An anonymous reader quotes a report from CBC News: It's rare that cancerous tumors can spread from one individual to another. But a genetic study suggests that's what's happening with melanoma tumors among catfish in Quebec and the northeastern U.S. The discovery represents the first known transm...]]></description>
<link>https://tsecurity.de/de/3689455/it-security-nachrichten/researchers-discover-first-known-transmissible-cancer-in-fish/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3689455/it-security-nachrichten/researchers-discover-first-known-transmissible-cancer-in-fish/</guid>
<pubDate>Thu, 23 Jul 2026 17:12:45 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[An anonymous reader quotes a report from CBC News: It's rare that cancerous tumors can spread from one individual to another. But a genetic study suggests that's what's happening with melanoma tumors among catfish in Quebec and the northeastern U.S. The discovery represents the first known transmissible cancer in fish and one of very few transmissible cancers ever found, reported the study published in the journal Nature on Wednesday.
 
Julie Dragon, co-leader of the new study, noted that only three other transmissible cancers have ever been identified so far -- in Tasmanian devils, dogs and shellfish. "These conditions are incredibly rare in nature," she said. "So something has to be happening to allow this to happen." Anglers in Lake Memphremagog, which spans the border between Quebec and Vermont, first reported catching brown bullhead catfish with strange black spots and lumps in 2012. They turned out to be melanoma skin cancer tumors. (Humans can also get this kind of cancer.) Now, about a third of the brown bullheads living in the lake have them.
 
It's not clear how sick the fish become. In some cases, the cancer spreads to other organs, such as the brain or liver. But many fish with lesions seem relatively healthy and some older fish even have them, suggesting they can live with the disease for a time. Because of the sudden appearance of the black lesions in Lake Memphremagog the year after a huge flood caused by post-tropical storm Irene, locals worried they were caused by carcinogens washed into the lake by floodwaters. Tests for carcinogens haven't been conclusive, although a study published in May found higher concentrations of seven metals, including zinc and the carcinogen arsenic, in the skin of fish with the tumors. Researchers suspect the tumors may spread among adult fish during spawning, when crowded fish rub against one another and may be punctured by their spines.
 
"They... swim all over each other and we think it's possible that they poke each other and cells can get into other fish that way," Dragon said, though transmission has not yet been demonstrated.<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=Researchers+Discover+First+Known+Transmissible+Cancer+In+Fish%3A+https%3A%2F%2Fscience.slashdot.org%2Fstory%2F26%2F07%2F23%2F0610239%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fscience.slashdot.org%2Fstory%2F26%2F07%2F23%2F0610239%2Fresearchers-discover-first-known-transmissible-cancer-in-fish%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://science.slashdot.org/story/26/07/23/0610239/researchers-discover-first-known-transmissible-cancer-in-fish?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[How a contextual AI fabric turns organizational memory into AI advantage]]></title>
<description><![CDATA[Across industries, a version of the same conversation is playing out in technology leadership meetings. Enterprises have deployed AI broadly, and foundation models keep getting more capable. Yet the outputs still feel generic, shaped by industry patterns rather than by the organization producing ...]]></description>
<link>https://tsecurity.de/de/3686065/it-nachrichten/how-a-contextual-ai-fabric-turns-organizational-memory-into-ai-advantage/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3686065/it-nachrichten/how-a-contextual-ai-fabric-turns-organizational-memory-into-ai-advantage/</guid>
<pubDate>Wed, 22 Jul 2026 13:05:25 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Across industries, a version of the same conversation is playing out in technology leadership meetings. Enterprises have deployed AI broadly, and foundation models keep getting more capable. Yet the outputs still feel generic, shaped by industry patterns rather than by the organization producing them.</p>



<p class="wp-block-paragraph"><a href="https://www.mckinsey.com/capabilities/tech-and-ai/our-insights/tech-forward/state-of-ai-trust-in-2026-shifting-to-the-agentic-era">McKinsey’s AI Trust Maturity Survey</a> found that while overall AI maturity scores have improved, only about a third of organizations have reached a mature level of strategy and governance. Technical capability is advancing faster than organizational alignment. In my view, the gap is not a model problem. It is a context problem. Enterprises are feeding generic inputs into powerful models because sharing organizational context seamlessly with AI is neither easy nor intuitive today.</p>



<p class="wp-block-paragraph">Building the analytical and creative capabilities to scale AI, something I explored in a <a href="https://www.cio.com/article/4176549/why-scaling-ai-requires-both-left-brain-rigor-and-right-brain-ingenuity.html">recent piece</a> on the left-brain and right-brain approach to enterprise AI, is necessary but not sufficient. Before either can function effectively, the enterprise needs something more fundamental. AI that actually understands the contextual fabric of the organization it is operating in. A frontier model has processed everything written about your sector, your competitors and your regulatory landscape. It cannot access the reasoning embedded in years of delivery decisions, the patterns encoded in how your teams scope and deliver work over time. That knowledge is organizational memory, and frontier models can’t get that easily. It exists inside every enterprise but has never been structured, connected or made available to any AI system. Without it, even the most capable model answers a generic version of your question.</p>



<p class="wp-block-paragraph">The next competitive advantage in enterprise AI will not come from a better model. It will come from a better organizational context.</p>



<p class="wp-block-paragraph">One global technology enterprise set out to solve this across its own operations, building a modular ecosystem of domain-specific agents grounded in its own data across contracting, talent and vendor management workflows. What emerged was not just operational efficiency but a shared intelligence layer connecting decisions across functions for the first time.</p>



<h2 class="wp-block-heading">Competitive differentiation was never about the tools</h2>



<p class="wp-block-paragraph">Consider what actually separates high-performing enterprises from the rest. In a regulated industry like financial services or healthcare, organizations cannot meaningfully differentiate on product. A bank cannot offer substantially different products or services. A health system uses the same clinical protocols and the same electronic health record (EHR) platforms as its peers. What varies is everything underneath: the rigor of processes, the coherence of cross-functional decisions and the people who carry years of accumulated organizational judgment in how they make those decisions.</p>



<p class="wp-block-paragraph">An organization with a proper context layer in place can say with precision that for this type of engagement, in this sector, with this risk profile, our institutional history tells us exactly where we stand. That level of specificity is what most enterprises have never made available to AI.</p>



<h2 class="wp-block-heading">The enterprise AI brain that every organization has but has never assembled</h2>



<p class="wp-block-paragraph">Every enterprise already possesses what I think of as an enterprise AI brain. The problem is that it has never been assembled in one place. The data exists across contracts, project documentation, talent records, delivery metrics and the operational communications of daily execution — the informal reasoning that rarely makes it into formal systems.</p>



<p class="wp-block-paragraph">None of the standard enterprise platforms were designed to connect this. A customer relationship management (CRM) system captures customer interactions. An enterprise resource planning (ERP) system captures transactions. A project management tool captures tasks and timelines. None of them captures the reasoning behind decisions and none of them surfaces a coherent picture of how the organization actually thinks and operates.</p>



<p class="wp-block-paragraph"><a href="https://www.bcg.com/publications/2026/ai-transformation-is-a-workforce-transformation">BCG’s study</a> across hundreds of companies found that only 10% of AI value comes from the algorithms and another 20% from the technology that implements them, meaning the remaining 70% depends on people, processes and organizational change. The organizations extracting real value are those that have made their institutional knowledge available to AI in a structured, governed way.</p>



<h2 class="wp-block-heading">Building a contextual AI fabric</h2>



<p class="wp-block-paragraph">A Contextual AI Fabric is the technical and organizational layer that makes the Enterprise AI Brain usable. It brings together unstructured data ingestion, semantic structuring, retrieval pipelines and governed model access to give AI systems the organizational context they need to produce outputs that are genuinely specific to your enterprise rather than generically accurate about your industry. It rests on three pillars. Core is the secure, governed and interoperable foundation that AI operations run on. Context is reliable, traceable access to the organization’s data, processes, knowledge and history. Coordination connects people, agents, applications and systems into process-driven workflows with clear controls and accountability, so the organization acts as one rather than a set of disconnected functions.</p>



<p class="wp-block-paragraph">The data layer is where most organizations underestimate the work. Contracts, project reports, talent assessments and operational communications require extraction, chunking, embedding and indexing before a model can retrieve and reason over them meaningfully.</p>



<p class="wp-block-paragraph">The semantic layer is what makes retrieval meaningful. Even well-ingested data fails if functions use different terminology for the same concepts. What legal calls a contract, delivery calls a scope. Without a shared ontology, AI systems remain precise about the wrong thing. And retrieval alone, however well-structured, only takes an organization so far. Retrieval surfaces the right information at the moment of a query, but it does not give a model genuine memory of the organization. The real source of unique, organization-level relevance comes from training domain-specific small language models on this context directly, models that carry organizational memory forward rather than fetching it fresh every time. That is what ultimately separates a Contextual AI Fabric from a well-organized database.</p>



<p class="wp-block-paragraph">The governance layer is not an add-on. Access controls, data lineage, approval thresholds and human checkpoints need to be designed in before any agent goes into production. Security is not a layer you add afterward. It is the condition under which organizational AI is worth building. If the institutional intelligence that makes your enterprise distinct gets absorbed into a frontier model’s training data, it becomes everyone’s baseline. That is an architectural decision made, or avoided, at the point of deployment.</p>



<h2 class="wp-block-heading">Proprietary by design</h2>



<p class="wp-block-paragraph">The institutional knowledge that makes up a contextual AI fabric — delivery history, commercial patterns, talent intelligence and operating culture — is proprietary in ways no external model can replicate. This is as much a security imperative as it is a competitive one. Organizational context, once exposed, cannot be unexposed.</p>



<p class="wp-block-paragraph">Most enterprises are using AI to automate existing processes rather than questioning whether those processes should be redesigned entirely. The organizations extracting the most value are those willing to ask whether their current operating model, built before GenAI existed, is the one they would build today. That question is harder than any technology decision, and it is also the most consequential one.</p>



<h2 class="wp-block-heading">From context to coordinated action</h2>



<p class="wp-block-paragraph">Context alone is not enough. When a delivery risk surfaces in project data, the talent function needs to respond. When a commercial signal changes in contract data, operations need to recalibrate. This kind of cross-functional coordination, driven by shared organizational intelligence rather than siloed data, is where the real value of enterprise AI shows up and where the absence of a shared context layer becomes most visible.</p>



<p class="wp-block-paragraph">A global leader in digital payments and business services found its AI deployments across payroll, HR and risk compliance, each running in isolation, with no shared governance or common data foundation. Once the organization established a unified governance backbone connecting its operational data through a shared retrieval layer, business users could query across domains in plain language and new use cases across fraud analytics, forecasting and policy extraction became extensible without rebuilding infrastructure for each one. The shift was not in the models. It was in the shared foundation underneath them.</p>



<h2 class="wp-block-heading">The leadership question behind the technology question</h2>



<p class="wp-block-paragraph">The enterprises pulling ahead in AI are not winning on model quality but on organizational memory. The ones that have done the hard work of structuring their institutional knowledge into a governed, secure Contextual AI Fabric are giving their AI something no competitor can replicate: the accumulated intelligence of how the business actually operates.</p>



<p class="wp-block-paragraph">For CIOs, the question is no longer which model to deploy. It is whether the organization has built the foundation that would make any model worth deploying.</p>



<p class="wp-block-paragraph"><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><a href="https://www.cio.com/expert-contributor-network/"><strong>Want to join?</strong></a></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[BrainCo Unveils EEG Platform That Lets Users Control Robots With Brain Signals]]></title>
<description><![CDATA[BrainCo unveiled an EEG-based platform that converts neural signals into robot commands, though accuracy and real-world reliability remain unclear.]]></description>
<link>https://tsecurity.de/de/3684677/it-nachrichten/brainco-unveils-eeg-platform-that-lets-users-control-robots-with-brain-signals/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3684677/it-nachrichten/brainco-unveils-eeg-platform-that-lets-users-control-robots-with-brain-signals/</guid>
<pubDate>Tue, 21 Jul 2026 21:03:59 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[BrainCo unveiled an EEG-based platform that converts neural signals into robot commands, though accuracy and real-world reliability remain unclear.]]></content:encoded>
</item>
<item>
<title><![CDATA[Stimulating Brains Without Touching Them: A Story of Magnets, Hype, and Open Science (emf2026)]]></title>
<description><![CDATA[For over 100 years now, being able to take an image of brain activity has been a really useful approach to understanding how brains work. But, more recently, we’ve learnt how to change brain states. Non-invasive Brain Stimulation (NiBS) does just that; temporarily interfere with normal brain acti...]]></description>
<link>https://tsecurity.de/de/3681109/it-security-video/stimulating-brains-without-touching-them-a-story-of-magnets-hype-and-open-science-emf2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3681109/it-security-video/stimulating-brains-without-touching-them-a-story-of-magnets-hype-and-open-science-emf2026/</guid>
<pubDate>Mon, 20 Jul 2026 14:33:32 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[For over 100 years now, being able to take an image of brain activity has been a really useful approach to understanding how brains work. But, more recently, we’ve learnt how to change brain states. Non-invasive Brain Stimulation (NiBS) does just that; temporarily interfere with normal brain activation without having to anaesthetise, cut, drill or otherwise violate the skull! 

The plan for this talk is to tell you a bit about brains and what we can learn from stimulating them using electromagnets and weak electric currents. As well as some sophisticated science, this approach has also seen some crazy claims about what brain stimulation can do. To separate the signal from the noise, open science has had a massive role to play. 

The lab that I co-lead has used open science approaches to explore brain activity using NiBS and found… not much. But, by using an open science approach, and systematically experimenting using NiBS, the how and why of ‘not much’ can be particularly useful and hopefully interesting.

Licensed to the public under https://creativecommons.org/licenses/by-sa/4.0/
about this event: https://www.emfcamp.org/schedule/2026/79-stimulating-brains-without-touching-them-a-story-of-magnets]]></content:encoded>
</item>
<item>
<title><![CDATA[Stimulating Brains Without Touching Them: A Story of Magnets, Hype, and Open Science (emf2026)]]></title>
<description><![CDATA[For over 100 years now, being able to take an image of brain activity has been a really useful approach to understanding how brains work. But, more recently, we’ve learnt how to change brain states. Non-invasive Brain Stimulation (NiBS) does just that; temporarily interfere with normal brain acti...]]></description>
<link>https://tsecurity.de/de/3681094/it-security-video/stimulating-brains-without-touching-them-a-story-of-magnets-hype-and-open-science-emf2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3681094/it-security-video/stimulating-brains-without-touching-them-a-story-of-magnets-hype-and-open-science-emf2026/</guid>
<pubDate>Mon, 20 Jul 2026 14:25:02 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[For over 100 years now, being able to take an image of brain activity has been a really useful approach to understanding how brains work. But, more recently, we’ve learnt how to change brain states. Non-invasive Brain Stimulation (NiBS) does just that; temporarily interfere with normal brain activation without having to anaesthetise, cut, drill or otherwise violate the skull! 

The plan for this talk is to tell you a bit about brains and what we can learn from stimulating them using electromagnets and weak electric currents. As well as some sophisticated science, this approach has also seen some crazy claims about what brain stimulation can do. To separate the signal from the noise, open science has had a massive role to play. 

The lab that I co-lead has used open science approaches to explore brain activity using NiBS and found… not much. But, by using an open science approach, and systematically experimenting using NiBS, the how and why of ‘not much’ can be particularly useful and hopefully interesting.

Licensed to the public under https://creativecommons.org/licenses/by-sa/4.0/
about this event: https://www.emfcamp.org/schedule/2026/79-stimulating-brains-without-touching-them-a-story-of-magnets]]></content:encoded>
</item>
<item>
<title><![CDATA[“Brain fry” and broken promises: The hidden cost of AI without architecture]]></title>
<description><![CDATA[AI deployment without the right operational structure is leaving employees exposed to  ‘AI brain fry’.]]></description>
<link>https://tsecurity.de/de/3680919/it-nachrichten/brain-fry-and-broken-promises-the-hidden-cost-of-ai-without-architecture/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3680919/it-nachrichten/brain-fry-and-broken-promises-the-hidden-cost-of-ai-without-architecture/</guid>
<pubDate>Mon, 20 Jul 2026 13:02:46 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[AI deployment without the right operational structure is leaving employees exposed to  ‘AI brain fry’.]]></content:encoded>
</item>
<item>
<title><![CDATA[Netflix’s Desire Ending Explained: Who Killed Matías and What Happens to Lucero?]]></title>
<description><![CDATA[Netflix’s Desire ends by revealing that nearly every member of Lucero’s family played a role in Matías’ death. The final poolside sequence explains how jealousy, betrayal and fear turned a secret affair into a fatal family cover-up.



Major spoilers for Desire follow.



Desire Release Date, Cas...]]></description>
<link>https://tsecurity.de/de/3680069/ios-mac-os/netflixs-desire-ending-explained-who-killed-matas-and-what-happens-to-lucero/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3680069/ios-mac-os/netflixs-desire-ending-explained-who-killed-matas-and-what-happens-to-lucero/</guid>
<pubDate>Mon, 20 Jul 2026 00:24:19 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Netflix’s Desire ends by revealing that nearly every member of Lucero’s family played a role in Matías’ death. The final poolside sequence explains how jealousy, betrayal and fear turned a secret affair into a fatal family cover-up.



Major spoilers for Desire follow.



Desire Release Date, Cast and Other Details




Netflix release date: July 17, 2026



Original title: Deseo



Genre: Erotic thriller, psychological drama



Runtime: Around 98 minutes



Director: Teresa Simone



Language: Spanish



Main cast: Ludwika Paleta, Óscar Casas, José María Yazpik and Pilar Pascual




The Mexican-Spanish movie follows Lucero, a successful 47-year-old lawyer who appears to have a comfortable life with her husband, Fernando, and their two children. However, she feels increasingly dissatisfied with her marriage and begins an affair with Matías, the young swimming coach hired by Fernando.



The situation becomes more dangerous when Lucero’s daughter, Viviana, also develops feelings for Matías. What begins as an affair soon becomes a tense triangle involving secrecy, manipulation and jealousy.



Where Is the Story Heading Before the Final Scene?



The movie opens with blood near the family’s indoor swimming pool, immediately confirming that someone has died. It then moves back through the events that caused the tragedy.



Lucero’s relationship with Matías grows more intense, even as she understands that the affair could destroy her marriage, career and relationship with her children. Matías also becomes involved with Viviana, creating further tension inside the family.



As the truth begins to surface, each character reacts differently. Viviana feels betrayed by both Matías and her mother, while Fernando begins to understand what has been happening inside his home. Lucero, meanwhile, focuses on protecting her family and preventing the affair from becoming public.



Since Desire is a standalone movie, there are no previous seasons to revisit. The entire story builds toward the night at the pool and the mystery surrounding Matías’ death.



Desire Ending Explained: Who Killed Matías?



The ending reveals that Matías’ death was caused by several actions rather than one sudden attack.



Julian secretly drugs Matías earlier in the evening. The drug leaves him physically weakened and less capable of defending himself when the conflict reaches the swimming pool.



Viviana then confronts Matías after discovering the truth about his relationship with Lucero. Feeling humiliated and used, she attacks him and leaves him injured.



Fernando later finds Matías bleeding and struggling in the pool. Instead of rescuing him, Fernando chooses to leave him there. His decision makes him directly responsible for allowing the situation to become fatal.



Lucero arrives for the final confrontation and sees that Matías is still alive. Matías appears to believe that she has come to help him or choose him over her family. However, Lucero pushes him beneath the water and holds him there until he drowns.



Lucero therefore delivers the final killing act, although every member of the family contributes to the chain of events that leads to his death.



Why Does Lucero Kill Matías?



Lucero kills Matías because she sees him as a threat to everything she wants to protect. Their affair once offered excitement and escape, but it eventually endangered her children, marriage and public life.



By the final scene, Lucero no longer views Matías as a romantic partner. She sees him as the person capable of exposing the family’s secrets and destroying their remaining sense of stability.



Her decision also completes her transformation. She begins the movie searching for freedom from her controlled life, yet she ends it committing murder to regain control.



Does Lucero’s Family Escape?



The movie does not show the family facing immediate legal consequences. Since several people contributed to Matías’ death, they share a reason to hide what happened.



The final revelation suggests that their family can remain together only by protecting the same secret. Any one of them could expose the others, creating an uneasy balance based on guilt rather than trust.



The opening bloodstains also take on a clearer meaning. They represent the evidence the family must remove, but they also reflect damage that cannot be completely erased.



What Does the Ending of Desire Mean?



The ending shows how unchecked desire damages every relationship around Lucero. Her affair affects her husband, draws her daughter into a painful rivalry and eventually turns the entire family into participants in Matías’ death.



Lucero technically protects her family from Matías, but their earlier life cannot return. Fernando knows about her betrayal, Viviana knows that her mother was involved with the same man, and everyone understands what happened beside the pool.



Desire ends without offering a clean resolution because the family’s punishment comes from living with the truth. What did you think about Lucero’s final decision, and who carries the most blame for Matías’ death? Let us know in the comments.]]></content:encoded>
</item>
<item>
<title><![CDATA[How To Debug A Human: An Engineer’s Guide To Emergency Medicine (emf2026)]]></title>
<description><![CDATA[What does designing software have in common with keeping people alive? More than you might think, probably. Decomposing software problems might take different knowledge than turning syndromes into diagnoses, but if you’ve got the skills to do one, you’re well on your way to the other. Join a comp...]]></description>
<link>https://tsecurity.de/de/3679794/it-security-video/how-to-debug-a-human-an-engineers-guide-to-emergency-medicine-emf2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3679794/it-security-video/how-to-debug-a-human-an-engineers-guide-to-emergency-medicine-emf2026/</guid>
<pubDate>Sun, 19 Jul 2026 19:38:28 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[What does designing software have in common with keeping people alive? More than you might think, probably. Decomposing software problems might take different knowledge than turning syndromes into diagnoses, but if you’ve got the skills to do one, you’re well on your way to the other. Join a computer scientist turned ambulance crew, awaiting results on their Masters in Paramedic Science, to learn how to take a software engineering approach to saving a life – from the roadside all the way to the bedside in A&amp;E. No prior knowledge required: you won’t get a qualification, or medical advice, but you will learn what a primary survey has to do with requirements-gathering, how to put a breakpoint in a patient’s heart without opening them up, and how screwing in a lightbulb can tell you what part of someone’s brain is broken.

Licensed to the public under https://creativecommons.org/licenses/by-sa/4.0/
about this event: https://www.emfcamp.org/schedule/2026/77-how-to-debug-a-human]]></content:encoded>
</item>
<item>
<title><![CDATA[How To Debug A Human: An Engineer’s Guide To Emergency Medicine (emf2026)]]></title>
<description><![CDATA[What does designing software have in common with keeping people alive? More than you might think, probably. Decomposing software problems might take different knowledge than turning syndromes into diagnoses, but if you’ve got the skills to do one, you’re well on your way to the other. Join a comp...]]></description>
<link>https://tsecurity.de/de/3679776/it-security-video/how-to-debug-a-human-an-engineers-guide-to-emergency-medicine-emf2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3679776/it-security-video/how-to-debug-a-human-an-engineers-guide-to-emergency-medicine-emf2026/</guid>
<pubDate>Sun, 19 Jul 2026 19:08:40 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[What does designing software have in common with keeping people alive? More than you might think, probably. Decomposing software problems might take different knowledge than turning syndromes into diagnoses, but if you’ve got the skills to do one, you’re well on your way to the other. Join a computer scientist turned ambulance crew, awaiting results on their Masters in Paramedic Science, to learn how to take a software engineering approach to saving a life – from the roadside all the way to the bedside in A&amp;E. No prior knowledge required: you won’t get a qualification, or medical advice, but you will learn what a primary survey has to do with requirements-gathering, how to put a breakpoint in a patient’s heart without opening them up, and how screwing in a lightbulb can tell you what part of someone’s brain is broken.

Licensed to the public under https://creativecommons.org/licenses/by-sa/4.0/
about this event: https://www.emfcamp.org/schedule/2026/77-how-to-debug-a-human]]></content:encoded>
</item>
<item>
<title><![CDATA[Could AI be conscious?]]></title>
<description><![CDATA[Experts believe it’s at least possible. We urgently need a plan to navigate the ethical implicationsIn January, the AI company Anthropic published a new constitution for Claude, its most advanced large language model (LLM), which contained the comment: “We are caught in a difficult position where...]]></description>
<link>https://tsecurity.de/de/3679364/ai-nachrichten/could-ai-be-conscious/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3679364/ai-nachrichten/could-ai-be-conscious/</guid>
<pubDate>Sun, 19 Jul 2026 13:03:59 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Experts believe it’s at least possible. We urgently need a plan to navigate the ethical implications</p><p>In January, the AI company Anthropic published a <a href="https://www.anthropic.com/constitution">new constitution</a> for Claude, its most advanced large language model (LLM), which contained the comment: “We are caught in a difficult position where we neither want to overstate the likelihood of Claude’s moral patienthood nor dismiss it out of hand.” A month later, Anthropic’s CEO Dario Amodei went on a podcast and said his company couldn’t rule out the possibility that Claude was conscious. Philosopher David Chalmers, who coined the phrase “the hard problem of consciousness”, has said there is a significant chance of conscious LLMs within a decade. And what about Claude itself? When asked during testing to estimate the probability that it is a <em>moral patient</em>, meaning that its wellbeing matters in its own right, it gave numbers ranging from 5% to 40% and stressed how uncertain it was.</p><p>Modern AI systems are extraordinarily complex, and they are advancing fast. In terms of structural complexity and computational scale, by some measures a few are already in the range of a mouse brain, and at recent growth rates, they could reach the range of a human brain within five to 10 years.</p> <a href="https://www.theguardian.com/technology/2026/jul/19/could-ai-be-conscious">Continue reading...</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Chinese company BrainCo unveils first 'brain-to-robot' interface for controlling robots with your thoughts]]></title>
<description><![CDATA[The latest in brain-computer interfaces can work directly with robots, without any physical input or verbal instruction.]]></description>
<link>https://tsecurity.de/de/3679236/it-nachrichten/chinese-company-brainco-unveils-first-brain-to-robot-interface-for-controlling-robots-with-your-thoughts/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3679236/it-nachrichten/chinese-company-brainco-unveils-first-brain-to-robot-interface-for-controlling-robots-with-your-thoughts/</guid>
<pubDate>Sun, 19 Jul 2026 11:31:32 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The latest in brain-computer interfaces can work directly with robots, without any physical input or verbal instruction.]]></content:encoded>
</item>
<item>
<title><![CDATA[IT Security News Hourly Summary 2026-07-17 21h : 4 posts]]></title>
<description><![CDATA[4 posts were published in the last hour 18:6 : Industry reacts to Gold Eagle vulnerability management plan 18:6 : A cyberattack hit Nichirei, one of Japan’s largest food companies 18:5 : PentestCode – New AI Agent That Automates Penetration…
Read more →
The post IT Security News Hourly Summary 20...]]></description>
<link>https://tsecurity.de/de/3676870/it-security-nachrichten/it-security-news-hourly-summary-2026-07-17-21h-4-posts/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3676870/it-security-nachrichten/it-security-news-hourly-summary-2026-07-17-21h-4-posts/</guid>
<pubDate>Fri, 17 Jul 2026 21:05:53 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>4 posts were published in the last hour 18:6 : Industry reacts to Gold Eagle vulnerability management plan 18:6 : A cyberattack hit Nichirei, one of Japan’s largest food companies 18:5 : PentestCode – New AI Agent That Automates Penetration…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/it-security-news-hourly-summary-2026-07-17-21h-4-posts/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/it-security-news-hourly-summary-2026-07-17-21h-4-posts/">IT Security News Hourly Summary 2026-07-17 21h : 4 posts</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Industry reacts to Gold Eagle vulnerability management plan]]></title>
<description><![CDATA[As AI-discovered software vulnerabilities accumulate at an unprecedented pace, security pros say they hope Gold Eagle creates some order from the chaos.]]></description>
<link>https://tsecurity.de/de/3676787/it-security-nachrichten/industry-reacts-to-gold-eagle-vulnerability-management-plan/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3676787/it-security-nachrichten/industry-reacts-to-gold-eagle-vulnerability-management-plan/</guid>
<pubDate>Fri, 17 Jul 2026 20:09:05 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[As AI-discovered software vulnerabilities accumulate at an unprecedented pace, security pros say they hope Gold Eagle creates some order from the chaos.]]></content:encoded>
</item>
<item>
<title><![CDATA[Industry reacts to Gold Eagle vulnerability management plan]]></title>
<description><![CDATA[The tech industry is cautiously optimistic about the U.S. government’s announcement this week to create a centralized clearinghouse for AI-discovered vulnerabilities. The key, executives and analysts said, will be how well the new initiative executes on its mission to collect…
Read more →
The pos...]]></description>
<link>https://tsecurity.de/de/3676779/it-security-nachrichten/industry-reacts-to-gold-eagle-vulnerability-management-plan/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3676779/it-security-nachrichten/industry-reacts-to-gold-eagle-vulnerability-management-plan/</guid>
<pubDate>Fri, 17 Jul 2026 20:08:54 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>&lt;p&gt;The tech industry is cautiously optimistic about the U.S. government’s announcement this week to create a centralized clearinghouse for AI-discovered vulnerabilities. The key, executives and analysts said, will be how well the new initiative executes on its mission to collect…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/industry-reacts-to-gold-eagle-vulnerability-management-plan/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/industry-reacts-to-gold-eagle-vulnerability-management-plan/">Industry reacts to Gold Eagle vulnerability management plan</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Doppelter Bypass zum Gehirn: Querschnittsgelähmter kann wieder greifen und Händedruck fühlen]]></title>
<description><![CDATA[Ein komplexes Maßnahmenpaket mit Gehirn-Computer-Schnittstellen (Computer Brain Interface, BCI) ermöglichte einem Querschnittsgelähmten wieder Zugang zu seiner Hand. Ob auch andere Betroffene davon profitieren können, ist ungewiss.weiterlesen auf t3n.de]]></description>
<link>https://tsecurity.de/de/3675797/it-nachrichten/doppelter-bypass-zum-gehirn-querschnittsgelaehmter-kann-wieder-greifen-und-haendedruck-fuehlen/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3675797/it-nachrichten/doppelter-bypass-zum-gehirn-querschnittsgelaehmter-kann-wieder-greifen-und-haendedruck-fuehlen/</guid>
<pubDate>Fri, 17 Jul 2026 12:47:48 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Ein komplexes Maßnahmenpaket mit Gehirn-Computer-Schnittstellen (Computer Brain Interface, BCI) ermöglichte einem Querschnittsgelähmten wieder Zugang zu seiner Hand. Ob auch andere Betroffene davon profitieren können, ist ungewiss.<a href="https://t3n.de/news/doppelter-bypass-zum-gehirn-querschnittsgelaehmter-kann-wieder-greifen-und-haendedruck-fuehlen-1753232/?utm_source=rss&amp;utm_medium=newsFeed&amp;utm_campaign=newsFeed">weiterlesen auf t3n.de</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[China’s Moonshot AI releases Kimi K3, the largest open-source model ever, rivaling top U.S. systems]]></title>
<description><![CDATA[Moonshot AI, the Beijing-based artificial intelligence startup backed by Alibaba, on Thursday released Kimi K3 — a 2.8-trillion-parameter model that the company says is now the largest open-source AI model in the world, and one that benchmarks show performs neck-and-neck with the most powerful pr...]]></description>
<link>https://tsecurity.de/de/3674665/it-nachrichten/chinas-moonshot-ai-releases-kimi-k3-the-largest-open-source-model-ever-rivaling-top-us-systems/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3674665/it-nachrichten/chinas-moonshot-ai-releases-kimi-k3-the-largest-open-source-model-ever-rivaling-top-us-systems/</guid>
<pubDate>Thu, 16 Jul 2026 23:17:55 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><a href="https://www.moonshot.ai/">Moonshot AI,</a> the Beijing-based artificial intelligence startup backed by Alibaba, on Thursday released <a href="https://platform.kimi.ai/docs/guide/kimi-k3-quickstart">Kimi K3</a> — a 2.8-trillion-parameter model that the company says is now the largest open-source AI model in the world, and one that benchmarks show performs neck-and-neck with the most powerful proprietary systems from <a href="https://www.anthropic.com/">Anthropic</a> and <a href="https://openai.com/">OpenAI</a>.</p><p>The release, timed to land just ahead of the <a href="https://aiii.global/waic-2026/">2026 World Artificial Intelligence Conference</a> in Shanghai, is a dramatic escalation in the global AI arms race and a watershed moment for the open-source AI movement. It also marks a remarkable comeback for a company whose market position had eroded significantly over the past 18 months following DeepSeek's meteoric rise.</p><p>Full model weights are scheduled to be released on July 27, according to details shared by researchers who reviewed the company's technical documentation. If you want to take <a href="https://platform.kimi.ai/docs/guide/kimi-k3-quickstart">Kimi K3</a> for a spin right now, you can — just head to<a href="https://www.kimi.com/"> kimi.com</a>, sign up with a Google account or phone number (no credit card required), and start chatting with what may be the most powerful open-source model ever built.</p><div></div><h2><b>Inside the architecture that powers the world's largest open-source AI model</b></h2><p><a href="https://platform.kimi.ai/docs/guide/kimi-k3-quickstart">Kimi K3</a> is a frontier-class large language model with 2.8 trillion total parameters — roughly 75 percent larger than <a href="https://huggingface.co/deepseek-ai/DeepSeek-V4-Pro">DeepSeek's V4 Pro</a>, which the company's own timeline chart shows at approximately 1.6 trillion parameters. The model features a 1-million-token context window, native visual understanding capabilities, and an always-on reasoning mode that the company calls "thinking mode."</p><p>The model is built on two key architectural innovations developed internally at Moonshot AI: <a href="https://arxiv.org/abs/2510.26692">Kimi Delta Attention</a>, a hybrid linear attention mechanism, and <a href="https://arxiv.org/abs/2603.15031">Attention Residuals</a>, which the company describes as a drop-in replacement for residual connections that delivers consistent scaling gains. Both techniques were previously published as open research by the Moonshot team on <a href="https://github.com/moonshotai">GitHub</a>.</p><p>On the <a href="https://platform.kimi.ai/docs/guide/kimi-k3-quickstart">API side</a>, Kimi K3 is compatible with the <a href="https://developers.openai.com/api/docs/guides/agents">OpenAI SDK</a>, lowering the integration barrier for developers already building on OpenAI or Anthropic toolchains. The model is priced at $3 per million input tokens and $15 per million output tokens, with cached input tokens dropping to just $0.30 per million — pricing that positions it roughly in line with mid-tier offerings from Western labs, but at a performance level the company claims approaches the top of the market. A promotional top-up rebate running through August 12 offers up to 30 percent back in vouchers for API credits of $1,000 or more.</p><p>As <a href="https://finance.sina.com.cn/stock/t/2026-07-17/doc-inihzrtu1375218.shtml?cref=cj">Xinhua reported</a>, a Moonshot AI executive explained the significance of the parameter count in simple terms: parameters are like neural connections in the human brain, and nearly 3 trillion of them means the model can "store more knowledge and patterns in its brain, understand more, think deeper, and answer more accurately."</p><div></div><h2><b>Benchmark results show Kimi K3 trading blows with Claude and GPT at the top of the leaderboard</b></h2><p>The benchmark results, drawn from public leaderboard data and a private evaluation by analytics firm Artificial Analysis, tell a striking story.</p><p>On <a href="https://artificialanalysis.ai/evaluations/gdpval-aa">GDPval-AA v2</a>, a benchmark measuring real-world tasks across 44 occupations and 9 major industries, Kimi K3 scored 1,687 — placing it third overall, behind only Claude Fable 5 Max (1,815) and GPT-5.6 Sol Max (1,747.8), and ahead of Claude Opus 4.8 (1,600).</p><p>On <a href="https://artificialanalysis.ai/evaluations/aa-briefcase">AA-Briefcase</a>, a private agentic benchmark from Artificial Analysis designed to test long-horizon knowledge work, K3 climbed to second place with a score of 1,527 — beating GPT-5.6 Sol Max (1,495) and trailing only Fable 5 Max (1,587).</p><p>Perhaps most impressively, K3 achieved a state-of-the-art score of 91.2 out of 100 on <a href="https://openai.com/index/browsecomp/">BrowseComp</a>, a benchmark for long-horizon, high-difficulty information seeking. </p><p>The company says it accomplished this in a single-agent setup using its 1-million-token context window, without any context compression or additional context management techniques — a feat that suggests raw context length, when paired with strong retrieval capabilities, may be more powerful than elaborate multi-agent workarounds.</p><p>As <a href="https://x.com/kimmonismus/status/2077818040578695175">one widely followed AI commentator</a> put it on social media: "Open source is no longer lagging six months behind Western closed-source models. Read that again, and think about what it all means."</p><p>That observation captures the significance of the moment. For much of the past three years, open-source models have typically trailed their proprietary counterparts by a meaningful margin. Kimi K3 appears to have closed that gap almost entirely.</p><h2><b>How a 48-hour autonomous chip design demo reveals Moonshot's real ambitions</b></h2><p>Beyond raw benchmarks, <a href="https://www.moonshot.ai/">Moonshot AI</a> showcased a proof-of-concept that may be even more revealing of K3's capabilities and the company's strategic direction.</p><p>In a demonstration documented in the company's technical materials, <a href="https://platform.kimi.ai/docs/guide/kimi-k3-quickstart">Kimi K3</a> was tasked with designing a physical chip to run a nano-scale version of itself. Over 48 hours of continuous autonomous agent operation, K3 independently completed the chip's full construction pipeline — from architectural design through optimization and verification — using open-source electronic design automation tools. The result was a tiny but functional chip design, just 4 square millimeters, that achieved timing convergence at 100 MHz and could decode more than 8,700 tokens per second in simulation.</p><p>This is not a production chip. It is a demonstration of what <a href="https://www.moonshot.ai/">Moonshot AI</a> clearly views as the next competitive frontier: long-range autonomous agent capabilities. The ability to sustain coherent, multi-step technical work over a 48-hour window — reading documentation, making design decisions, running verification loops, and iterating on failures — represents a qualitative leap beyond the kind of single-turn question-answering that defined the first generation of large language models.</p><p>The company also highlighted a case in computational astrophysics, where K3 reportedly reproduced the universal <a href="https://inspirehep.net/literature/1220233">I-Love-Q relation</a> — a complex calculation that typically takes a senior researcher one to two weeks — in approximately two hours, reading and cross-validating more than 20 papers and implementing a complete numerical pipeline along the way.</p><h2><b>Moonshot AI's fall and rise tells the story of China's brutal AI market</b></h2><p>To understand why <a href="https://platform.kimi.ai/docs/guide/kimi-k3-quickstart">Kimi K3</a> matters, you need to understand where Moonshot AI was 18 months ago — and how far it fell.</p><p>Founded in 2023 by <a href="https://kimiyoung.github.io/">Yang Zhilin</a>, a Tsinghua University graduate who previously conducted research at Google and Meta, Moonshot AI quickly became one of China's most prominent AI startups. The company gained early traction in 2024 when users flocked to its <a href="http://kimi.ai/">Kimi platform</a> for its long-text analysis capabilities and AI search functions. By early 2026, it had raised roughly <a href="https://www.forbes.com/sites/the-prompt/2026/07/15/ai-startup-reflection-compute-deal-to-challenge-chinas-open-source-dominance/">$1.5 billion</a> across multiple rounds, with its valuation climbing from $2.5 billion to $4.3 billion and the company reportedly <a href="https://tech.yahoo.com/ai/gemini/articles/china-moonshot-releases-open-source-141110760.html">seeking a new round at $5 billion</a>.</p><p>Then DeepSeek happened. The release of DeepSeek's low-cost R1 model in January 2025 disrupted the entire Chinese AI landscape, and Moonshot AI was among the hardest hit. Kimi, which had ranked third in monthly active users in China, slid to seventh. The company's strategic pivot to open-source models — beginning with Kimi K2 in July 2025 and accelerating with K2.5 in January 2026 — was in large part an effort to reclaim relevance.</p><p><a href="https://platform.kimi.ai/docs/guide/kimi-k3-quickstart">Kimi K3</a> is the culmination of that effort — and the sheer scale of the model suggests that Moonshot AI has been planning this move for some time. Training a 2.8-trillion-parameter model requires enormous computational resources and months of preparation, which means the architectural and infrastructure decisions behind K3 were likely locked in well before the model reached the public.</p><h2><b>Why open-sourcing the world's biggest model is a geopolitical chess move</b></h2><p>The decision to release K3's full weights on July 27 is strategically significant and worth parsing carefully.</p><p>The company's own timeline chart of open-source frontier model scale positions K3 as a dramatic outlier, towering above competitors like <a href="https://github.com/deepseek-ai">DeepSeek</a> (1.6T), <a href="https://github.com/xiaomi">Xiaomi</a> (1.02T), and <a href="https://github.com/ALIBABA">Alibaba</a> (397B). By releasing the world's largest open-source model, Moonshot AI is making a bid to become the center of gravity for the global open-source AI developer community.</p><p>This follows a broader trend among Chinese AI companies. As <a href="https://www.reuters.com/technology/artificial-intelligence/china-weighs-silicon-curtain-around-sought-after-ai-models-2026-07-08/">Reuters noted</a>, open-sourcing allows companies to "showcase their technological capabilities and expand developer communities as well as their global influence, a strategy likely to help China counter U.S. efforts to limit Beijing's tech progress." DeepSeek, Alibaba, Tencent, and Baidu have all released open-source models. But none have released anything at this parameter count.</p><p>For enterprise technology leaders, the implications are concrete. A 2.8-trillion-parameter open-source model that performs at near-frontier levels creates new options for companies that want to fine-tune, self-host, or build proprietary systems on top of a capable base model — without being locked into API contracts with OpenAI or Anthropic. The trade-off, of course, is that running a model of this size requires substantial GPU infrastructure. Inference at 2.8 trillion parameters is not something that runs on a single server rack.</p><p>That said, <a href="https://www.moonshot.ai/">Moonshot AI</a> has signaled awareness of this challenge. Its Mooncake project, which won the Best Paper award at FAST 2025, pioneered KV-cache-centric disaggregated serving for large language models — an architecture designed specifically to make inference at extreme scale more practical and cost-efficient.</p><h2><b>Kimi Code and a three-tier model lineup form the foundation of Moonshot's enterprise play</b></h2><p>Alongside K3, Moonshot AI continues to invest heavily in its coding agent ecosystem. <a href="https://github.com/MoonshotAI/kimi-code/releases">Kimi Code</a>, the company's open-source coding tool that competes with Anthropic's Claude Code and Google's Gemini CLI, received two major updates on the same day as K3's launch — versions 0.25.0 and 0.26.0 — adding features like expanded subagent tooling, background task management, and security fixes.</p><p>The <a href="https://github.com/MoonshotAI/kimi-cli">Kimi Code CLI</a> has accumulated over 3,100 stars on GitHub and features integration with VSCode, Cursor, and Zed. The latest release expanded the "coder subagent" tool set to include background tasks, todo lists, plan mode, skill invocation, and nested agents — effectively turning the coding agent into a multi-layered autonomous system capable of managing complex software engineering projects with minimal human intervention.</p><p>This is not incidental. Coding tools have become a critical revenue driver for AI labs. As Anthropic disclosed in January, <a href="https://www.anthropic.com/news/anthropic-acquires-bun-as-claude-code-reaches-usd1b-milestone">Claude Code reached $1 billion in annualized recurring revenue</a>. By building Kimi Code as an open-source alternative that defaults to Kimi's own models — but supports other providers — Moonshot AI is positioning itself to capture developer workflows and, eventually, enterprise contracts.</p><p>The company's model lineup now includes three tiers: <a href="https://platform.kimi.ai/docs/guide/kimi-k3-quickstart">K3</a> as the flagship ($3/$15 per million tokens for input/output), <a href="https://platform.kimi.ai/docs/guide/kimi-k2-7-code-quickstart">K2.7 Code</a> as a specialized coding model ($0.95/$4), and <a href="https://platform.kimi.ai/docs/guide/kimi-k2-6-quickstart">K2.6</a> as a general-purpose option ($0.95/$4). All three support context windows of 256,000 tokens or above, with K3 offering the full 1-million-token window. Context caching is automatic — no cache ID, TTL, or extra parameter is required — a small but meaningful developer-experience advantage over competitors that require explicit cache management.</p><h2><b>What Kimi K3 means for the future of enterprise AI and the global model landscape</b></h2><p>Kimi K3's release forces a recalibration of several assumptions that have guided enterprise AI strategy.</p><p>The performance gap between open-source and proprietary models has functionally closed at the frontier. If K3's benchmark numbers hold up under independent evaluation — and particularly once the open weights are available for community testing on July 27 — it will be difficult for closed-source providers to justify premium pricing purely on the basis of capability.</p><p>The locus of AI innovation, meanwhile, continues to shift. China's AI ecosystem, which many Western observers questioned after early struggles with chip export restrictions, has now produced a model that competes with the best systems from companies with direct access to Nvidia's most advanced hardware. The architectural innovations behind K3 — particularly the hybrid linear attention mechanism — suggest that algorithmic efficiency may matter as much as raw compute.</p><p>And the agentic capabilities demonstrated by K3 — chip design, multi-week research compression, long-horizon information seeking — point toward a future where AI models are not just answering questions but autonomously executing complex, multi-day projects. For enterprises evaluating AI investments, this shifts the value proposition from "productivity copilot" to "autonomous technical workforce."</p><p><a href="https://finance.sina.com.cn/stock/t/2026-07-17/doc-inihzrtu1375218.shtml?cref=cj">Xinhua</a>, China's state news agency, framed the release as a national milestone, reporting that K3 "marks a new step forward in the development of China's artificial intelligence models." Liu Tieyan, dean of the Zhongguancun Academy in Beijing, was quoted as saying that a wave of Chinese open-source models has moved from isolated breakthroughs to collective advancement, providing "new solutions and new paths" for global AI development.</p><p>Just two years ago, <a href="https://www.moonshot.ai/">Moonshot AI</a> was a scrappy startup named for the audacious problems it hoped to solve. Eighteen months ago, it was a cautionary tale about how quickly a market darling can lose its footing. Today, it is the maker of the world's largest open-source AI model — one that can, given 48 hours and an internet connection, design a chip to run itself. The frontier, it turns out, is not a place. It is a race. And the field just got a lot more crowded.</p><p>
</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[China beats Elon Musk’s Neuralink to the world’s first commercial brain-computer interface implant — car crash victim given coin-sized chip that turns neural signals into hand movements]]></title>
<description><![CDATA[Regulatory approval of brain implants in China mean they can now be fixed to the brains of anyone who wants to try them.]]></description>
<link>https://tsecurity.de/de/3674439/it-nachrichten/china-beats-elon-musks-neuralink-to-the-worlds-first-commercial-brain-computer-interface-implant-car-crash-victim-given-coin-sized-chip-that-turns-neural-signals-into-hand-movements/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3674439/it-nachrichten/china-beats-elon-musks-neuralink-to-the-worlds-first-commercial-brain-computer-interface-implant-car-crash-victim-given-coin-sized-chip-that-turns-neural-signals-into-hand-movements/</guid>
<pubDate>Thu, 16 Jul 2026 21:01:27 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Regulatory approval of brain implants in China mean they can now be fixed to the brains of anyone who wants to try them.]]></content:encoded>
</item>
<item>
<title><![CDATA[Brain implant helps paralysed man to feed himself and drink from cup]]></title>
<description><![CDATA[Keith Thomas can move arms and hands, and feel sensation of touch after ‘double neural bypass’ and months of trainingA man who was paralysed from the chest down in a swimming accident six years ago has been able to feed himself and drink from a cup thanks to a brain implant that bypasses his spin...]]></description>
<link>https://tsecurity.de/de/3673886/ai-nachrichten/brain-implant-helps-paralysed-man-to-feed-himself-and-drink-from-cup/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3673886/ai-nachrichten/brain-implant-helps-paralysed-man-to-feed-himself-and-drink-from-cup/</guid>
<pubDate>Thu, 16 Jul 2026 17:03:25 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Keith Thomas can move arms and hands, and feel sensation of touch after ‘double neural bypass’ and months of training</p><p>A man who was paralysed from the chest down in a swimming accident six years ago has been able to feed himself and drink from a cup thanks to a brain implant that bypasses his spinal cord injury.</p><p>Keith Thomas of Massapequa, New York, could not lift his arms off his wheelchair when he agreed to trial the technology in 2021, but after surgery to implant electrodes in his brain and many months of training, he was able to move the limbs again.</p> <a href="https://www.theguardian.com/science/2026/jul/16/neural-bypass-brain-implant-paralysed-man-feed-himself-drink-from-cup">Continue reading...</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[COMM-TEC eröffnet einen neuen Showroom in Warschau]]></title>
<description><![CDATA[COMM-TEC hat seinen ersten Showroom in Polen eröffnet. Der neue Standort der Vertriebsmarke aus dem baden-württembergischen Uhingen liegt im Büro- und Coworking-Komplex Brain Embassy in Warschau und bietet Integratoren, Partnern und Endkunden ...]]></description>
<link>https://tsecurity.de/de/3673315/it-nachrichten/comm-tec-eroeffnet-einen-neuen-showroom-in-warschau/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3673315/it-nachrichten/comm-tec-eroeffnet-einen-neuen-showroom-in-warschau/</guid>
<pubDate>Thu, 16 Jul 2026 13:47:58 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[COMM-TEC hat seinen ersten Showroom in Polen eröffnet. Der neue Standort der Vertriebsmarke aus dem baden-württembergischen Uhingen liegt im Büro- und Coworking-Komplex Brain Embassy in Warschau und bietet Integratoren, Partnern und Endkunden ...]]></content:encoded>
</item>
<item>
<title><![CDATA[What next-generation IT leadership looks like]]></title>
<description><![CDATA[Today’s CIOs must master a complex balancing act of maintaining operational excellence while enabling AI experimentation, modernizing legacy environments while accelerating innovation, leading workforce transformation while maintaining culture, and communicating fluently across boards, business u...]]></description>
<link>https://tsecurity.de/de/3672917/it-nachrichten/what-next-generation-it-leadership-looks-like/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3672917/it-nachrichten/what-next-generation-it-leadership-looks-like/</guid>
<pubDate>Thu, 16 Jul 2026 11:18:14 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Today’s CIOs must master a complex balancing act of maintaining operational excellence while enabling AI experimentation, modernizing legacy environments while accelerating innovation, leading workforce transformation while maintaining culture, and communicating fluently across boards, business units, customers, and technical teams alike.</p>



<p class="wp-block-paragraph">Few leaders understand this balancing act better than former Verizon CIO Jane Connell. Over her career, Connell has helped some of the world’s largest enterprises modernize operations, reduce complexity, and transform how technology enables business value at scale. As a <a href="https://www.cio.com/article/236876/cio-hall-of-fame-honorees.html">2026 CIO Hall of Fame inductee</a>, she is widely respected not only for operational excellence and strategic vision but also for her commitment to mentoring, workforce transformation, and preparing the next generation of leaders for a rapidly changing future.</p>



<p class="wp-block-paragraph">On a recent episode of <a href="https://linktr.ee/techwhisperers">the Tech Whisperers podcast</a>, we unpacked Connell’s unconventional leadership story and the playbook that has shaped one of technology’s most impactful leaders. In this exclusive interview after the show, edited for length and clarity, Connell shares more lessons from her Hall of Fame journey and why she believes the future of technology leadership will depend less on org charts and more on curiosity, credibility, and human connection.</p>



<p class="wp-block-paragraph"><strong>Dan Roberts: When you think about preparing the next generation of technology leaders, what capabilities or mindsets do you believe will matter most in this next era?</strong></p>



<p class="wp-block-paragraph"><strong>Jane Connell:</strong> One is curiosity, or what I call the “why” factor: What do we need to do and why do we need to do it? It’s having a mindset of unlocking the art of the possible. You must be comfortable with what you know, what you don’t know, and asking the question why, because in this era of AI and where technology is going, it’s not about automating things you know; it’s about what you don’t already know, and what that unlocks. AI creates patterns and opportunities and re-engineers through its own intelligence, so there has to be a lot of instinct involved, and you’re going to have to understand and learn what it’s telling you.</p>



<p class="wp-block-paragraph">I’m on the board of Rutgers, and one of the conversations we’re in with future leaders in education is that <a href="https://www.cio.com/article/4047844/ai-is-taking-over-junior-positions-in-it.html">you don’t have those entry-level jobs anymore</a>. They’re going to be AI. But those were building blocks for us. <a href="https://www.cio.com/article/4189865/how-ai-automation-is-reshaping-the-it-leadership-pipeline.html">We came up the ranks and did those jobs</a>, and that created the knowledge. [Future leaders are] not going to have that, so how do you create the foundation of knowledge — which is that art of asking why or what — to question if the bots or the patterns are biased or wrong. You’re not going to have the experience to rely on and say, “That’s wrong; I know that’s wrong because I did those. I know how this operates.”</p>



<p class="wp-block-paragraph">Second is having humility and being comfortable in your skin — that you don’t know everything, but you’re going to learn it. You’re going to involve yourself with people. It’s about workforce structure, not organizational structure. Who do you need to talk to, and what do you have to find out?</p>



<p class="wp-block-paragraph">I also believe <a href="https://www.cio.com/article/652317/cio-brett-lansings-five-point-approach-to-building-followership.html">followership</a> is going to be huge, because the way work gets done is not hierarchical. It’s going to be engineered based on the process and AI. You have to create followership of people working together, and they’ve got to want to work with you. This isn’t going be “you work for me, do as I say.” Followership is going to be a key skill for influencing and organically having that kind of impact, versus someone with authority.</p>



<p class="wp-block-paragraph">With that is the accountability to have high integrity, be credible, and be a person someone would trust. Because all this is going to break down the hierarchy of authority, you have to bring that human side and be a really good leader, which means people want to follow you, they trust you, they want to work with you, and they know you’re going to take them to a better place.</p>



<p class="wp-block-paragraph"><strong>One recurring theme throughout your career has been your ability to bridge deep technology expertise with strong business acumen. Why is that combination becoming even more critical in the age of AI and digital transformation?</strong></p>



<p class="wp-block-paragraph">You can’t impact anything tech-alone. It all resides on having business acumen and then having the technical ability to know how to use tech to solve the problem, not the other way around.</p>



<p class="wp-block-paragraph">At the root of all this is every company’s Achilles’ heel: the data. Access to data has been a privilege — those who have it, those who don’t. Now you’re bringing structured and unstructured [data] together for these AI models to work, and that’s a new skill set that requires you to know the business inside and outside.</p>



<p class="wp-block-paragraph">You also have to stay externally relevant and know where innovation is coming from. And you’re going to need to know how to architect that into the way your company goes to market, which requires you to know the business processes, how it runs, and how it could run.</p>



<p class="wp-block-paragraph">That’s the role of leaders moving forward, immersing yourself in the problems the business needs to solve. There’s no boundaries there. It’s not what department you report in and what process you own. It’s seamless. That’s the duality people need to command and grow into.</p>



<p class="wp-block-paragraph"><strong>Looking back on a career that spans multiple industries with different operating models, cultures, and regulatory environments, what were some of the most important calculated risks you took in terms of your growth?</strong></p>



<p class="wp-block-paragraph">There were two pivotal moments in my career that were the biggest risks but probably my biggest gains in growth. One was when I went into a full-time tech role and ran infrastructure. I was a fish out of water, and not the likely successor. Part of the reason I did it goes back to a something we talked about on the podcast: Well, why <em>not</em> me? And I want more. That’s just my tenacity.</p>



<p class="wp-block-paragraph">It was during the dot-com days of the late 90s, early 2000s. It didn’t matter if you were the CEO or a board director, if you didn’t know tech and you didn’t understand how to wield it, you were never going to be successful. I knew that no matter what job I may want in the future, I had to know tech. So it was a calculated decision: I’m going to jump into tech.</p>



<p class="wp-block-paragraph">Some very senior supply chain leaders who controlled my career told me, “You’re going to fail, and I’ll have a safety net for you when you come back.” Well, I didn’t fail and I never went back. That pressure was there, but I knew why I was doing it. This wasn’t just a job for ego’s sake. This was, I have to know tech. The future is tech. It’s kind of like AI now.</p>



<p class="wp-block-paragraph">The other pivotal moment was changing industries. I left Johnson &amp; Johnson at a great time. We had gone through a huge transformation, started our global services organization, and the perfect moment happened for me to retire early there. I didn’t know what I wanted to do. It was the first time I took a break in my career to let the world come to me instead of me planning it. Do I want to open a business? Do I want to consult? Do I want to stay retired? I was fortunate enough that I could, but I got bored.</p>



<p class="wp-block-paragraph">The financial industry wasn’t on my radar. Coming out of healthcare, with the purpose and the connection with saving lives, helping people, it’s easy to connect to. Financial wasn’t, for me. But one of the executive search firms said to me, when you interview, the biggest question hanging over your head is going to be, could you be successful elsewhere because you grew up in J&amp;J. You had advocates, you had influence, you knew the industry. It’s like your deck was stacked for you. Could you do all that when you’re a nobody coming off the street?</p>



<p class="wp-block-paragraph">So when the CIO role opened at State Street, I interviewed — and talk about being your authentic self. I had already done all this transformation, I already knew the outcomes, I knew everything I did was always enterprise and always end-to-end transformation. And because I wasn’t really vying for the job, I was having this conversation with the CFO and saying, “Here’s what your organization is lacking, here’s the noise you’re going to hear, do you really have the appetite for it?” And “I’d like talk to the COO and see if they’re ready to hear this about the value chain. I may not know your problem yet, but I guarantee it’s one of these three things.”</p>



<p class="wp-block-paragraph">I was testing their advocacy of, do you really want to transform? Are you ready? Because you have to own this. I can’t take accountabilities for your organizations. I can help you get there. I’m an enabler for you, but you have to own it. And it was a very different interview. By the end of it, I loved Ron [O’Hanley, State Street Chairman and CEO] and his whole team. I took the job on the leadership and the person more than the industry, and it was very successful.</p>



<p class="wp-block-paragraph">I followed the same recipe when I went to Verizon. Those were big growing moments. They were risky, they were very uncomfortable, but it was the biggest growth that I’ve ever had.</p>



<p class="wp-block-paragraph"><strong>Whether it’s a tough message to the C-suite, a difficult conversation with peers, or helping teams make sense of uncertainty and change, you tell people the truth in a way they can hear it. How can other leaders develop that ability to take people on the journey, especially when the message isn’t easy?</strong></p>



<p class="wp-block-paragraph">Skirting a problem is not the way to solve it. I’ve never been the person to say what you want to hear. I’ll tell you how you get there, and I’ll get you the results you want, but I’m going to be super honest because I want to manage the expectations of what we have to achieve.</p>



<p class="wp-block-paragraph">What I’ve learned as a leader is to take accountability. Say what you’re going to do, then do it, and if you hit a roadblock, be the first to call it. That gets you access, because people see it as a calculated risk. Anybody in the C-suite has resources and budget, but the earlier you signal and don’t waste money and resources, the more access to people and resources you will have.</p>



<p class="wp-block-paragraph">The greatest lesson I learned from one of the leaders in my path was: If you can’t say it in an elevator, and you can’t say it on one slide, you’re talking too much. So, think about it as one slide: What is it you need? What are you going to achieve? What are the risks? What are you taking accountability for? How will you measure it? It doesn’t matter what the message is when you can be that succinct. You’ve got them laser-focused on what it is. You gave them just enough of the periphery to know how you got there, and then it’s their belief in you that you can do it if they give you the money and resources, because that’s what you’re looking for.</p>



<p class="wp-block-paragraph">It sounds so simple but putting things together succinctly is hard work. You have to take all the unnecessary noise out, and keep the conversation focused. You don’t want their mind wandering, wondering where is she going, or what are they doing? Give it to them upfront and tell them what you need.</p>



<p class="wp-block-paragraph"><strong>You’ve spoken about entering corporate environments early in your career feeling intimidated by people with more traditional credentials or educational backgrounds. What advice can you give rising leaders about battling imposter syndrome?</strong></p>



<p class="wp-block-paragraph">Take the time to figure out what makes you uncomfortable, what makes you feel like an imposter, or what in that meeting you dread going in where you’re not acting like yourself. Are you more quiet than usual? Are you not asking the question you’d normally ask? Figure out what those issues are, and then address the things that make you uncomfortable. I went to college later because that bothered me. Those credentials do matter. So I addressed it and got my degrees and certifications.</p>



<p class="wp-block-paragraph">The other thing is to find people you trust, people whose opinion you respect, and bring them on the inside of what you’re working on. Maybe it’s dealing with a difficult business partner. You may not particularly want to be friends with them, but you’re going to have to work with them. Find the people that work effectively with them. You do this with high integrity — this is not about talking about that person — but find the allies that work with them. Nine times out of ten, they feel the way you do, but they found a way to work with the person. Pick their brain. Bring them in the fold and say, “I need this alliance. I can’t get there, and quite frankly, I know I’m resisting because maybe I just don’t like them. How did you get there?”</p>



<p class="wp-block-paragraph">People are generous. Ask their opinion, ask how they’re showing up. “Am I creating the trigger? Is there something I’m doing in that meeting or in that room that I’m not coming out with a decision or whatever I needed?”</p>



<p class="wp-block-paragraph">The greatest gift is feedback. There’s feedback you do something with, and there’s feedback you don’t, but either way, it’s a gift. Somebody’s giving it to you. It’s not personal; it’s business. And those things really help build your confidence and leadership style.</p>



<p class="wp-block-paragraph"><em>In an era increasingly shaped by automation and disruption, Jane Connell believes the most enduring competitive advantage may come from something deeply human: the ability to inspire confidence, curiosity, resilience, and possibility in others. For more advice from this Hall of Fame CIO, tune in to the </em><a href="https://linktr.ee/techwhisperers"><em>Tech Whisperers podcast</em></a><em>.</em></p>



<p class="wp-block-paragraph">See also:</p>



<ul class="wp-block-list">
<li><a href="https://www.cio.com/article/4185905/mastering-the-chess-of-it-leadership-today.html">Mastering the chess of IT leadership today</a></li>



<li><a href="https://www.cio.com/article/4176073/developing-a-customer-first-culture-for-it.html">Developing a customer-first culture for IT</a></li>



<li><a href="https://www.cio.com/article/4166851/coherence-where-leadership-and-ai-success-intersect.html">Coherence: Where leadership and AI success intersect</a></li>
</ul>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Did AI decide who lost their jobs? Meta is heading to court over that question]]></title>
<description><![CDATA[Enterprises that use AI in hiring and firing decisions continue to be under scrutiny, and this time it’s Meta under the microscope.



A legal complaint filed on July 13 in a US District Court in California alleges that Meta used AI systems that unfairly and illegally selected workers for termina...]]></description>
<link>https://tsecurity.de/de/3672187/ai-nachrichten/did-ai-decide-who-lost-their-jobs-meta-is-heading-to-court-over-that-question/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3672187/ai-nachrichten/did-ai-decide-who-lost-their-jobs-meta-is-heading-to-court-over-that-question/</guid>
<pubDate>Thu, 16 Jul 2026 04:02:55 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Enterprises that use AI in hiring and firing decisions continue to be under scrutiny, and this time it’s Meta under the microscope.</p>



<p class="wp-block-paragraph">A <a href="https://storage.courtlistener.com/recap/gov.uscourts.cand.474171/gov.uscourts.cand.474171.1.0.pdf" target="_blank" rel="noreferrer noopener">legal complaint</a> filed on July 13 in a US District Court in California alleges that Meta used AI systems that unfairly and illegally selected workers for termination while they were out on protected leave.</p>



<p class="wp-block-paragraph">More than two dozen anonymous plaintiffs are seeking a preliminary injunction that would prevent the company from finalizing their separations or altering their compensation, benefits, or protected leave status.</p>



<p class="wp-block-paragraph">Meta has countered that the claims lack merit and that its workforce decisions were, and continue to be, made by people, not AI.</p>



<h2 class="wp-block-heading">An important lesson</h2>



<p class="wp-block-paragraph">These allegations should serve as an important lesson to other businesses using AI in their HR decision-making, analysts note.</p>



<p class="wp-block-paragraph">“Enterprises must begin by rejecting the convenient assumption that AI improves workforce decisions simply by touching them,” said <a href="https://greyhoundresearch.com/svg/" target="_blank" rel="noreferrer noopener">Sanchit Vir Gogia</a>, chief analyst at Greyhound Research.</p>



<p class="wp-block-paragraph">There is “scant independent proof” that AI makes layoff choices more accurate or more lawful, he said. “It makes them faster, and faster has never been shown to be fairer.”</p>



<h2 class="wp-block-heading">The claims against Meta</h2>



<p class="wp-block-paragraph">The complaint states that, on May 20, 2026, Meta began notifying roughly 10% of its workforce (around 8,000 employees) that they had been selected for termination. The company also announced that several thousand more would be reassigned to new AI initiatives. But this came even as Meta reported record revenues in <a href="https://s21.q4cdn.com/399680738/files/doc_financials/2026/q1/Meta-03-31-2026-Exhibit-99-1_final.pdf" target="_blank" rel="noreferrer noopener">Q1 2026</a> ($56.31 billion, a 33% year-over-year increase), and pledged to spend <a href="https://www.cio.com/article/4191940/what-meta-oracle-moves-say-about-data-center-economics.html" target="_blank">upwards of $100 billion</a> on AI this year.</p>



<p class="wp-block-paragraph">In addition to questioning the need for staff cuts, the filing alleges that Meta used a “constellation” of internal AI systems to score, rank, and select employees for termination. These tools included Meta’s internal AI coworker, “Metamate,” employee-trained “second-brain” agents that replicated their output, algorithms tracking keystrokes and other digital activity, and <a href="https://www.infoworld.com/article/4195756/from-story-points-to-tokenmaxxing-why-engineering-keeps-measuring-the-wrong-things.html" target="_blank">AI token usage</a> dashboards.</p>



<p class="wp-block-paragraph">“Meta did not assemble the termination list through the considered judgment of managers who knew the work,” the complaint claims.</p>



<p class="wp-block-paragraph">The 26 plaintiffs, all current or former employees, requested, took, or were approved for “statutorily protected” leave within 24 months of the workforce reduction, and claim they were “disproportionately selected” for layoff based on scoring that essentially penalized them for exercising their legal right to take leave.</p>



<p class="wp-block-paragraph">These practices are prohibited by federal and state law; The US Family and Medical Leave Act, for one, prohibits the use of protected leave as a “negative factor” in employment decisions. Further, the plaintiffs allege that Meta violated the <a href="https://www.dol.gov/agencies/eta/layoffs/warn" target="_blank" rel="noreferrer noopener">US Worker Adjustment and Retraining Notification (WARN) Act</a> that requires employers with 100 or more employees to provide written notice 60 calendar days in advance of mass layoffs.</p>



<p class="wp-block-paragraph">This notice gives employees reasonable time to seek alternate employment; however, the complaint argues, an employee undergoing “significant medical treatment” or providing “around the clock care” for a “weeks old newborn” or other loved ones “cannot also be told that during this exact same time period they must look for new work.”</p>



<p class="wp-block-paragraph">In one scenario, according to the filing, a scientist was identified for termination just two days before she gave birth while on pregnancy leave. In another, an engineer’s manager tied his performance rating to “broken time” when an injury prevented him from working. In a third, a researcher was called out after requesting time off following a medical diagnosis.</p>



<p class="wp-block-paragraph">The plaintiffs are seeking a preliminary injunction pending an independent audit of the “algorithmically assisted selection process” and “resolution of the merits of their claims” in arbitration.</p>



<p class="wp-block-paragraph">Once terminations are finalized, the harm to plaintiffs “cannot be undone by money damages alone,” the complaint states. For employees out on leave, “every day that goes by constitutes additional harm, in that Meta is taking away the entire purpose of a protected leave.”</p>



<h2 class="wp-block-heading">Considerations for enterprises</h2>



<p class="wp-block-paragraph">Any system that materially influences who keeps a job is not an HR tool, Gogia noted. “It is high-risk enterprise infrastructure.”</p>



<p class="wp-block-paragraph">An “AI-determined” process delegates the outcome to the system, while an “AI-assisted” one gives the system the ability to rank, recommend, and summarize, with a human formally making the final decision. Exposure arises in either model, Gogia pointed out, because the output has often been compressed and eliminates detail by the time of executive approval.</p>



<p class="wp-block-paragraph">There must be one non-negotiable role in the process, Gogia said: A single executive with the authority to halt the process, suspend the model, and delay decisions when evidence does not hold. This person should be “a meaningful reviewer [who] understands the model’s limits, knows the actual work, and holds the authority to challenge the recommendation, with every override visible and reviewable,” he said. At the same time, the objective is to “govern the machine and the manager together,” since human judgement brings its own “risks, favoritism, and proximity” bias.</p>



<p class="wp-block-paragraph">Gogia advised enterprises to retain fixed memory for auditing, determine who chose the auditor, what was excluded, and whether the result can be reproduced. They should also inventory every source feeding the model and its origins, and run adverse-impact analysis before making any firing decisions.</p>



<p class="wp-block-paragraph">Leave details must never be identified as inactivity or weak adoption; a protected absence is not ordinary missing data, and the system has to be informed of this. Rather, these circumstances belong in an “independent review lane,” where human reviewers get enough context to “neutralize” the period without receiving specific leave details, Gogia said.</p>



<p class="wp-block-paragraph">He pointed to another important question: What should the “second brain” AI agent that ingested the employee’s communications and documents to replicate the employee’s output be allowed to do when humans are away, and who owns that output?</p>



<p class="wp-block-paragraph">Ultimately, said Gogia, “the safest position is not to ban AI from workforce planning. Used with discipline, it can expose duplicated work and inconsistent assessment, and it can challenge human bias rather than automate it.”</p>



<h2 class="wp-block-heading">How employees can protect their rights</h2>



<p class="wp-block-paragraph">Employees, for their part, need a genuine window in which to challenge inaccurate data before separation becomes “irreversible,” and they should “fight the record, not the algorithm,” Gogia advised.</p>



<p class="wp-block-paragraph">That means that, while the model cannot explain itself, documented evidence can. Employees should lawfully retain their own reviews, leave approvals, and severance documents, and build a chronology of events: When leave was requested, when performance language changed, when new metrics appeared, Gogia said.</p>



<p class="wp-block-paragraph">Impacted workers should ask in writing which criteria were used in the decision, whether automated systems materially influenced it, how protected leave was treated, and what information about them influenced the result and how that information was verified.</p>



<p class="wp-block-paragraph">Further, it’s important to take note of deadlines; the federal discrimination window is typically six months, although that is extended to 10 in many places, and internal processes are “not obliged to respect it,” said Gogia.</p>



<p class="wp-block-paragraph">His ultimate advice for workers: “Preserve the lawful record, and protect the deadline.”</p>



<p class="wp-block-paragraph"><em>This article originally appeared on <a href="https://www.cio.com/article/4197528/did-ai-decide-who-lost-their-jobs-meta-is-heading-to-court-over-that-question.html" target="_blank">CIO.com</a>.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Did AI decide who lost their jobs? Meta is heading to court over that question]]></title>
<description><![CDATA[Enterprises that use AI in hiring and firing decisions continue to be under scrutiny, and this time it’s Meta under the microscope.



A legal complaint filed on July 13 in a US District Court in California alleges that Meta used AI systems that unfairly and illegally selected workers for termina...]]></description>
<link>https://tsecurity.de/de/3672179/it-nachrichten/did-ai-decide-who-lost-their-jobs-meta-is-heading-to-court-over-that-question/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3672179/it-nachrichten/did-ai-decide-who-lost-their-jobs-meta-is-heading-to-court-over-that-question/</guid>
<pubDate>Thu, 16 Jul 2026 03:47:14 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Enterprises that use AI in hiring and firing decisions continue to be under scrutiny, and this time it’s Meta under the microscope.</p>



<p class="wp-block-paragraph">A <a href="https://storage.courtlistener.com/recap/gov.uscourts.cand.474171/gov.uscourts.cand.474171.1.0.pdf" target="_blank" rel="noreferrer noopener">legal complaint</a> filed on July 13 in a US District Court in California alleges that Meta used AI systems that unfairly and illegally selected workers for termination while they were out on protected leave.</p>



<p class="wp-block-paragraph">More than two dozen anonymous plaintiffs are seeking a preliminary injunction that would prevent the company from finalizing their separations or altering their compensation, benefits, or protected leave status.</p>



<p class="wp-block-paragraph">Meta has countered that the claims lack merit and that its workforce decisions were, and continue to be, made by people, not AI.</p>



<h2 class="wp-block-heading">An important lesson</h2>



<p class="wp-block-paragraph">These allegations should serve as an important lesson to other businesses using AI in their HR decision-making, analysts note.</p>



<p class="wp-block-paragraph">“Enterprises must begin by rejecting the convenient assumption that AI improves workforce decisions simply by touching them,” said <a href="https://greyhoundresearch.com/svg/" target="_blank" rel="noreferrer noopener">Sanchit Vir Gogia</a>, chief analyst at Greyhound Research.</p>



<p class="wp-block-paragraph">There is “scant independent proof” that AI makes layoff choices more accurate or more lawful, he said. “It makes them faster, and faster has never been shown to be fairer.”</p>



<h2 class="wp-block-heading">The claims against Meta</h2>



<p class="wp-block-paragraph">The complaint states that, on May 20, 2026, Meta began notifying roughly 10% of its workforce (around 8,000 employees) that they had been selected for termination. The company also announced that several thousand more would be reassigned to new AI initiatives. But this came even as Meta reported record revenues in <a href="https://s21.q4cdn.com/399680738/files/doc_financials/2026/q1/Meta-03-31-2026-Exhibit-99-1_final.pdf" target="_blank" rel="noreferrer noopener">Q1 2026</a> ($56.31 billion, a 33% year-over-year increase), and pledged to spend <a href="https://www.cio.com/article/4191940/what-meta-oracle-moves-say-about-data-center-economics.html" target="_blank">upwards of $100 billion</a> on AI this year.</p>



<p class="wp-block-paragraph">In addition to questioning the need for staff cuts, the filing alleges that Meta used a “constellation” of internal AI systems to score, rank, and select employees for termination. These tools included Meta’s internal AI coworker, “Metamate,” employee-trained “second-brain” agents that replicated their output, algorithms tracking keystrokes and other digital activity, and <a href="https://www.infoworld.com/article/4195756/from-story-points-to-tokenmaxxing-why-engineering-keeps-measuring-the-wrong-things.html" target="_blank">AI token usage</a> dashboards.</p>



<p class="wp-block-paragraph">“Meta did not assemble the termination list through the considered judgment of managers who knew the work,” the complaint claims.</p>



<p class="wp-block-paragraph">The 26 plaintiffs, all current or former employees, requested, took, or were approved for “statutorily protected” leave within 24 months of the workforce reduction, and claim they were “disproportionately selected” for layoff based on scoring that essentially penalized them for exercising their legal right to take leave.</p>



<p class="wp-block-paragraph">These practices are prohibited by federal and state law; The US Family and Medical Leave Act, for one, prohibits the use of protected leave as a “negative factor” in employment decisions. Further, the plaintiffs allege that Meta violated the <a href="https://www.dol.gov/agencies/eta/layoffs/warn" target="_blank" rel="noreferrer noopener">US Worker Adjustment and Retraining Notification (WARN) Act</a> that requires employers with 100 or more employees to provide written notice 60 calendar days in advance of mass layoffs.</p>



<p class="wp-block-paragraph">This notice gives employees reasonable time to seek alternate employment; however, the complaint argues, an employee undergoing “significant medical treatment” or providing “around the clock care” for a “weeks old newborn” or other loved ones “cannot also be told that during this exact same time period they must look for new work.”</p>



<p class="wp-block-paragraph">In one scenario, according to the filing, a scientist was identified for termination just two days before she gave birth while on pregnancy leave. In another, an engineer’s manager tied his performance rating to “broken time” when an injury prevented him from working. In a third, a researcher was called out after requesting time off following a medical diagnosis.</p>



<p class="wp-block-paragraph">The plaintiffs are seeking a preliminary injunction pending an independent audit of the “algorithmically assisted selection process” and “resolution of the merits of their claims” in arbitration.</p>



<p class="wp-block-paragraph">Once terminations are finalized, the harm to plaintiffs “cannot be undone by money damages alone,” the complaint states. For employees out on leave, “every day that goes by constitutes additional harm, in that Meta is taking away the entire purpose of a protected leave.”</p>



<h2 class="wp-block-heading">Considerations for enterprises</h2>



<p class="wp-block-paragraph">Any system that materially influences who keeps a job is not an HR tool, Gogia noted. “It is high-risk enterprise infrastructure.”</p>



<p class="wp-block-paragraph">An “AI-determined” process delegates the outcome to the system, while an “AI-assisted” one gives the system the ability to rank, recommend, and summarize, with a human formally making the final decision. Exposure arises in either model, Gogia pointed out, because the output has often been compressed and eliminates detail by the time of executive approval.</p>



<p class="wp-block-paragraph">There must be one non-negotiable role in the process, Gogia said: A single executive with the authority to halt the process, suspend the model, and delay decisions when evidence does not hold. This person should be “a meaningful reviewer [who] understands the model’s limits, knows the actual work, and holds the authority to challenge the recommendation, with every override visible and reviewable,” he said. At the same time, the objective is to “govern the machine and the manager together,” since human judgement brings its own “risks, favoritism, and proximity” bias.</p>



<p class="wp-block-paragraph">Gogia advised enterprises to retain fixed memory for auditing, determine who chose the auditor, what was excluded, and whether the result can be reproduced. They should also inventory every source feeding the model and its origins, and run adverse-impact analysis before making any firing decisions.</p>



<p class="wp-block-paragraph">Leave details must never be identified as inactivity or weak adoption; a protected absence is not ordinary missing data, and the system has to be informed of this. Rather, these circumstances belong in an “independent review lane,” where human reviewers get enough context to “neutralize” the period without receiving specific leave details, Gogia said.</p>



<p class="wp-block-paragraph">He pointed to another important question: What should the “second brain” AI agent that ingested the employee’s communications and documents to replicate the employee’s output be allowed to do when humans are away, and who owns that output?</p>



<p class="wp-block-paragraph">Ultimately, said Gogia, “the safest position is not to ban AI from workforce planning. Used with discipline, it can expose duplicated work and inconsistent assessment, and it can challenge human bias rather than automate it.”</p>



<h2 class="wp-block-heading">How employees can protect their rights</h2>



<p class="wp-block-paragraph">Employees, for their part, need a genuine window in which to challenge inaccurate data before separation becomes “irreversible,” and they should “fight the record, not the algorithm,” Gogia advised.</p>



<p class="wp-block-paragraph">That means that, while the model cannot explain itself, documented evidence can. Employees should lawfully retain their own reviews, leave approvals, and severance documents, and build a chronology of events: When leave was requested, when performance language changed, when new metrics appeared, Gogia said.</p>



<p class="wp-block-paragraph">Impacted workers should ask in writing which criteria were used in the decision, whether automated systems materially influenced it, how protected leave was treated, and what information about them influenced the result and how that information was verified.</p>



<p class="wp-block-paragraph">Further, it’s important to take note of deadlines; the federal discrimination window is typically six months, although that is extended to 10 in many places, and internal processes are “not obliged to respect it,” said Gogia.</p>



<p class="wp-block-paragraph">His ultimate advice for workers: “Preserve the lawful record, and protect the deadline.”</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Boulder City, Nev., Reacts to Surprise Data Center Approval]]></title>
<description><![CDATA[A data center that some residents in the area were fighting, originally proposed under a city lease, recently received a green light from the Trump administration to build on public land instead.]]></description>
<link>https://tsecurity.de/de/3671650/ai-nachrichten/boulder-city-nev-reacts-to-surprise-data-center-approval/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3671650/ai-nachrichten/boulder-city-nev-reacts-to-surprise-data-center-approval/</guid>
<pubDate>Wed, 15 Jul 2026 20:47:11 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A data center that some residents in the area were fighting, originally proposed under a city lease, recently received a green light from the Trump administration to build on public land instead.]]></content:encoded>
</item>
<item>
<title><![CDATA[LegacyHive: 'Bone-shattering' zero-day from Microsoft's serial tormentor not the haymaker that was promised]]></title>
<description><![CDATA[Experts say it’s a useful post-compromise tool, for those with the brain cells required to put it together]]></description>
<link>https://tsecurity.de/de/3670750/it-security-nachrichten/legacyhive-bone-shattering-zero-day-from-microsofts-serial-tormentor-not-the-haymaker-that-was-promised/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3670750/it-security-nachrichten/legacyhive-bone-shattering-zero-day-from-microsofts-serial-tormentor-not-the-haymaker-that-was-promised/</guid>
<pubDate>Wed, 15 Jul 2026 15:09:38 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Experts say it’s a useful post-compromise tool, for those with the brain cells required to put it together]]></content:encoded>
</item>
<item>
<title><![CDATA[The Apple FaceID Co-Inventor Building a Frontier AI Model for the Human Brain]]></title>
<description><![CDATA[Gidi Littwin's new AI startup, Hemispheric, makes diagnostic brain scans for conditions like depression, PTSD, and Parkinson’s. He wants the technology to be as cheap and easy as a blood test.]]></description>
<link>https://tsecurity.de/de/3670598/it-nachrichten/the-apple-faceid-co-inventor-building-a-frontier-ai-model-for-the-human-brain/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3670598/it-nachrichten/the-apple-faceid-co-inventor-building-a-frontier-ai-model-for-the-human-brain/</guid>
<pubDate>Wed, 15 Jul 2026 14:18:19 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Gidi Littwin's new AI startup, Hemispheric, makes diagnostic brain scans for conditions like depression, PTSD, and Parkinson’s. He wants the technology to be as cheap and easy as a blood test.]]></content:encoded>
</item>
<item>
<title><![CDATA[Lawsuit Claims Meta's Layoff Decisions Were Made By AI, Not Humans]]></title>
<description><![CDATA[A lawsuit from 26 Meta employees alleges the company used AI-driven scoring and monitoring systems to select workers for layoffs, disproportionately targeting employees with disabilities or those who had taken protected medical, family, pregnancy, or parental leave. "Meta did not assemble the ter...]]></description>
<link>https://tsecurity.de/de/3669150/it-security-nachrichten/lawsuit-claims-metas-layoff-decisions-were-made-by-ai-not-humans/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3669150/it-security-nachrichten/lawsuit-claims-metas-layoff-decisions-were-made-by-ai-not-humans/</guid>
<pubDate>Tue, 14 Jul 2026 23:22:27 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A lawsuit from 26 Meta employees alleges the company used AI-driven scoring and monitoring systems to select workers for layoffs, disproportionately targeting employees with disabilities or those who had taken protected medical, family, pregnancy, or parental leave. "Meta did not assemble the termination list through the considered judgment of managers who knew the work. Instead, Meta used a constellation of internal artificial-intelligence systems -- including a system referred to internally as 'Metamate,' employee-trained 'second-brain' agents, keystroke- and activity-monitoring data, AI-token-usage dashboards, and algorithmically assisted performance ranking and calibration -- to score, rank, and select employees for inclusion on the list," the lawsuit (PDF) said. Ars Technica reports: Employees were allegedly graded, among other things, on how much they used Meta's AI tools. "Meta's internal dashboards classified employees by their stage of adoption of its artificial-intelligence tools, using categories such as 'AI Native,' 'AI First,' and 'AI Enabled,'" the lawsuit said. The lawsuit is apparently "the first against a major U.S. company to challenge the alleged use of AI in conducting layoffs," according to Reuters. The complaint alleges that Meta's tools for monitoring employees did not account for differences caused by disabilities and protected leaves. "Those tools draw on inputs -- performance ratings, calibration scores, productivity and output metrics, 'AI-native' ratings, and AI-token consumption -- that, by design, cannot be accumulated by an employee who is on protected medical or family leave, or whose output is reduced by a disability," the lawsuit said.
 
The lawsuit alleged that Meta management did not take steps to adjust scores for employees who took leave or who requested reasonable accommodations for disabilities. "Meta did not neutralize those inputs for protected leave; did not exclude protected-leave-takers or accommodation-seekers from the selection cohort; and did not pause the system for the individualized, leave- and accommodation-neutral review that the law requires," the complaint alleged. "The result was that employees who took protected leaves were disproportionately selected for layoff, based on scoring that not only failed to account for their protected leaves, but in effect penalized the employees for exercising their legal rights to these leaves." The 26 plaintiffs requested leaves or disability accommodations in the 24 months before being selected for layoffs, the lawsuit said. The layoffs are not yet finalized, but employees are scheduled to start losing their jobs on July 22, the lawsuit said. "These claims lack merit and are not based on facts," said Meta in a statement. "Workforce management and organizational decisions were and are made by people, not AI."<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=Lawsuit+Claims+Meta's+Layoff+Decisions+Were+Made+By+AI%2C+Not+Humans%3A+https%3A%2F%2Fyro.slashdot.org%2Fstory%2F26%2F07%2F14%2F2054236%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fyro.slashdot.org%2Fstory%2F26%2F07%2F14%2F2054236%2Flawsuit-claims-metas-layoff-decisions-were-made-by-ai-not-humans%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://yro.slashdot.org/story/26/07/14/2054236/lawsuit-claims-metas-layoff-decisions-were-made-by-ai-not-humans?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[D-topia review – cosy sci-fi mystery takes aim at AI]]></title>
<description><![CDATA[PC, PS5, Xbox Series X/S, Nintendo Switch, Nintendo Switch 2; Marimittu GamesA soft puzzle game makes a sharp point about the over-optimised future aheadIn the far future, on a planet that is not Earth, AI is in charge. This entity is no Skynet-esque killer robot but a machine that cares for huma...]]></description>
<link>https://tsecurity.de/de/3668005/ai-nachrichten/d-topia-review-cosy-sci-fi-mystery-takes-aim-at-ai/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3668005/ai-nachrichten/d-topia-review-cosy-sci-fi-mystery-takes-aim-at-ai/</guid>
<pubDate>Tue, 14 Jul 2026 15:03:49 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><strong>PC, PS5, Xbox Series X/S, Nintendo Switch, Nintendo Switch 2; Marimittu Games<br></strong>A soft puzzle game makes a sharp point about the over-optimised future ahead</p><p>In the far future, on a planet that is not Earth, AI is in charge. This entity is no Skynet-esque killer robot but a machine that cares for humanity. Manifesting most visibly as cute droids, the technology is pervasive – embedded in everything from the design of the sleek architecture to the gorgeous, mostly sunny artificial weather. The so-called Optimization System has but one responsibility: ensuring the greatest happiness for the greatest number of people.</p><p>In less skilled hands this game might have felt like an undergraduate seminar on the limits of utilitarianism. But Japanese studio Marumittu Games elegantly marries its philosophical concerns with smart design choices. You play as a young, unnamed Facilitator tasked with tending to both the city’s bots and its human residents. Each morning you wake up, sleepily loping off to the bathroom before sitting down for an exquisitely rendered breakfast, and then embark on your day’s work. Like everything else in this near-future scenario, labour is designed to cause as little frustration as possible, amounting to simple maths brain teasers on a grid – nothing too taxing, but enough to keep you engaged.</p> <a href="https://www.theguardian.com/games/2026/jul/14/d-topia-review-sci-fi-ai-puzzle-game">Continue reading...</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Indian Scientists Produce Most Detailed 3D Atlas of the Human Brainstem]]></title>
<description><![CDATA[Scientists at the Indian Institute of Technology, Madras (IIT-M) have created what they describe as the world's most detailed 3D cellular atlas of the human brainstem, linking whole-brain MRI views to individual neurons across more than 500 tissue sections. The free online atlas, called Anchor, c...]]></description>
<link>https://tsecurity.de/de/3667711/it-security-nachrichten/indian-scientists-produce-most-detailed-3d-atlas-of-the-human-brainstem/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3667711/it-security-nachrichten/indian-scientists-produce-most-detailed-3d-atlas-of-the-human-brainstem/</guid>
<pubDate>Tue, 14 Jul 2026 13:08:41 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Scientists at the Indian Institute of Technology, Madras (IIT-M) have created what they describe as the world's most detailed 3D cellular atlas of the human brainstem, linking whole-brain MRI views to individual neurons across more than 500 tissue sections. The free online atlas, called Anchor, could help researchers better understand diseases such as Alzheimer's, Parkinson's, stroke, and SIDS by showing how healthy and diseased brain tissue differs cell by cell. The BBC reports: Built from high-resolution microscope images rather than costlier molecular techniques, it creates a detailed three-dimensional map of the brainstem, identifying more than 200 clusters of brain cells and nerve pathways. Eight chemical markers help distinguish different cell types, producing one of the clearest pictures yet of this vital, but poorly, understood part of the brain. The brainstem occupies only a sliver of the brain, yet it keeps people alive. It links the brain to the spinal cord and controls breathing, heartbeat, sleep, wakefulness and movement.
 
[...] Users can zoom from the whole brainstem seen on MRI down to individual neurons while maintaining their precise spatial relationships. The researchers have made the atlas freely available online, hoping it becomes a reference tool for neuroscientists, neurologists and neurosurgeons worldwide. Its applications could also extend well beyond anatomy. By comparing healthy brainstem maps with diseased tissue, scientists may better understand disorders ranging from Parkinson's disease and stroke to Alzheimer's disease and sudden infant death syndrome (SIDS). More precise maps could also help neurosurgeons navigate one of the brain's most delicate regions with greater confidence.<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=Indian+Scientists+Produce+Most+Detailed+3D+Atlas+of+the+Human+Brainstem%3A+https%3A%2F%2Fscience.slashdot.org%2Fstory%2F26%2F07%2F14%2F0723207%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fscience.slashdot.org%2Fstory%2F26%2F07%2F14%2F0723207%2Findian-scientists-produce-most-detailed-3d-atlas-of-the-human-brainstem%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://science.slashdot.org/story/26/07/14/0723207/indian-scientists-produce-most-detailed-3d-atlas-of-the-human-brainstem?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Mitsubishi Reveals New AI Humanoid Robot "N" Coming 2027]]></title>
<description><![CDATA[Author: AI News - Bewertung: 4x - Views:39 Mitsubishi reveals a new AI humanoid robot, "N," powered by Highlanders' Kepler v1.0 — a dual-brain AI model designed to plan and react in real time at once. We break down its architecture, the data flywheel behind it, and Highlanders' new manufacturing ...]]></description>
<link>https://tsecurity.de/de/3667576/it-security-video/mitsubishi-reveals-new-ai-humanoid-robot-n-coming-2027/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3667576/it-security-video/mitsubishi-reveals-new-ai-humanoid-robot-n-coming-2027/</guid>
<pubDate>Tue, 14 Jul 2026 12:21:23 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: AI News - Bewertung: 4x - Views:39 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/3GYOFWmnBCs?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>Mitsubishi reveals a new AI humanoid robot, "N," powered by Highlanders' Kepler v1.0 — a dual-brain AI model designed to plan and react in real time at once. We break down its architecture, the data flywheel behind it, and Highlanders' new manufacturing deal with Mitsubishi, targeting 1,000 units a month by 2027 to help address Japan's shrinking workforce.<br />
Then, Boston Dynamics' Atlas shows off perfectly synchronized robot choreography, and Tsubame Industries' piloted mecha robot, Archax, brings sci-fi to life as a real, working machine.<br />
Plus, two major AI software stories: Anthropic gives Claude a built-in browser that can read, click, and type on the web, and Meta launches Muse Spark 1.1 with a new developer API, undercutting OpenAI's GPT-5.6 and Anthropic's Claude Fable 5 on price.<br />
<br />
Subscribe for daily AI news.<br />
<br />
Discover the AI agent economy: https://8004agents.ai<br />
<br />
AI news:<br />
0:00 N<br />
2:20 Boston Dynamics<br />
2:51 Archax 01<br />
4:05 Claude Code<br />
5:15 Muse Spark 1.1<br />
<br />
#ai #news #robot<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Cloud-Zuverlässigkeit im Hyperscale-Maßstab: das neue AIOps-System Brain]]></title>
<description><![CDATA[Das KI-gestützte Cloud-Health-System steuert operative Abläufe in Azure über einen digitalen Zwilling in Echtzeit.]]></description>
<link>https://tsecurity.de/de/3667096/it-nachrichten/cloud-zuverlaessigkeit-im-hyperscale-massstab-das-neue-aiops-system-brain/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3667096/it-nachrichten/cloud-zuverlaessigkeit-im-hyperscale-massstab-das-neue-aiops-system-brain/</guid>
<pubDate>Tue, 14 Jul 2026 09:03:08 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Das KI-gestützte Cloud-Health-System steuert operative Abläufe in Azure über einen digitalen Zwilling in Echtzeit.]]></content:encoded>
</item>
<item>
<title><![CDATA[EU to Review Social Media Age Limits After Child Safety Report]]></title>
<description><![CDATA[The European Commission is moving closer to introducing new measures on Child Safety Online after President Ursula von der Leyen received recommendations from a Special Panel examining the impact of social media on children. The report, released Monday, calls for stronger safeguards, greater plat...]]></description>
<link>https://tsecurity.de/de/3666978/it-security-nachrichten/eu-to-review-social-media-age-limits-after-child-safety-report/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3666978/it-security-nachrichten/eu-to-review-social-media-age-limits-after-child-safety-report/</guid>
<pubDate>Tue, 14 Jul 2026 08:10:56 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1536" height="1024" src="https://thecyberexpress.com/wp-content/uploads/Child-Safety-Online.webp" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="Child Safety Online" decoding="async" srcset="https://thecyberexpress.com/wp-content/uploads/Child-Safety-Online.webp 1536w, https://thecyberexpress.com/wp-content/uploads/Child-Safety-Online-300x200.webp 300w, https://thecyberexpress.com/wp-content/uploads/Child-Safety-Online-1024x683.webp 1024w, https://thecyberexpress.com/wp-content/uploads/Child-Safety-Online-768x512.webp 768w, https://thecyberexpress.com/wp-content/uploads/Child-Safety-Online-600x400.webp 600w, https://thecyberexpress.com/wp-content/uploads/Child-Safety-Online-150x100.webp 150w, https://thecyberexpress.com/wp-content/uploads/Child-Safety-Online-750x500.webp 750w, https://thecyberexpress.com/wp-content/uploads/Child-Safety-Online-1140x760.webp 1140w, https://thecyberexpress.com/wp-content/uploads/Child-Safety-Online.webp 1536w, https://thecyberexpress.com/wp-content/uploads/Child-Safety-Online-300x200.webp 300w, https://thecyberexpress.com/wp-content/uploads/Child-Safety-Online-1024x683.webp 1024w, https://thecyberexpress.com/wp-content/uploads/Child-Safety-Online-768x512.webp 768w, https://thecyberexpress.com/wp-content/uploads/Child-Safety-Online-600x400.webp 600w, https://thecyberexpress.com/wp-content/uploads/Child-Safety-Online-150x100.webp 150w, https://thecyberexpress.com/wp-content/uploads/Child-Safety-Online-750x500.webp 750w, https://thecyberexpress.com/wp-content/uploads/Child-Safety-Online-1140x760.webp 1140w" sizes="(max-width: 1536px) 100vw, 1536px" title="EU to Review Social Media Age Limits After Child Safety Report 1"></p><p data-start="371" data-end="819">The European Commission is moving closer to introducing new measures on <a href="https://thecyberexpress.com/ofcom-online-child-safety-rules/" target="_blank" rel="noopener">Child Safety Online</a> after President Ursula von der Leyen received recommendations from a Special Panel examining the <a href="https://thecyberexpress.com/uk-social-media-ban-set-for-2027-rollout/" target="_blank" rel="noopener">impact of social media</a> on children. The report, released Monday, calls for stronger safeguards, greater platform accountability, and age-appropriate restrictions as the EU prepares to review the findings and present legislative proposals after the summer.</p>
<p data-start="821" data-end="1144">Speaking alongside the panel's co-chairs, von der Leyen said protecting children online has become one of the most pressing challenges facing governments. She stressed that parents, not algorithms, should shape children's development and warned that the current digital environment is exposing young users to growing <a class="wpil_keyword_link" href="https://thecyberexpress.com/what-are-risks-in-cybersecurity/" title="risks" data-wpil-keyword-link="linked" data-wpil-monitor-id="28954">risks</a>.</p>

<h3 data-section-id="h0xe6l" data-start="1146" data-end="1202"><strong><span role="text">Child Safety Online Becomes a Priority for the EU</span></strong></h3>
<p data-start="1204" data-end="1584">Von der Leyen <a href="https://ec.europa.eu/commission/presscorner/detail/en/statement_26_1590" target="_blank" rel="nofollow noopener">said</a> the Special Panel examined both the opportunities and harms created by social media algorithms and their effects on children. According to the findings highlighted in her statement, young people across Europe now spend between four and six hours each day on screens, while nearly 60% of young children have experienced emotional or psychosocial problems online.</p>
<p data-start="1586" data-end="1797">She said these challenges include loss of sleep, anxiety, depression, <a href="https://thecyberexpress.com/ai-vs-cyberbullying-protecting-the-vulnerable/" target="_blank" rel="noopener">cyberbullying</a>, exposure to harmful content, and unwanted online interactions, all occurring while children's brains are still developing.</p>
<p data-start="1799" data-end="1983">"We believe that parents bring up our kids, and not predatory algorithms," von der Leyen said, adding that social media platforms should no longer have unrestricted access to children.</p>

<h3 data-section-id="1e4yfwu" data-start="1985" data-end="2047"><strong><span role="text">Digital Services Act Places Responsibility on Platforms</span></strong></h3>
<p data-start="2049" data-end="2297">A key recommendation focuses on holding technology companies accountable for the safety of their services. Von der Leyen said platforms that build online systems should also be responsible for ensuring they do not harm users, particularly children.</p>
<p data-start="2299" data-end="2513">She pointed to the Digital Services Act (DSA) as the EU's framework for requiring providers to remove harmful features, including addictive algorithms, dark patterns, harmful content, and unwanted contacts.</p>
<p data-start="2515" data-end="2803">According to the Commission President, the EU has already taken action under the Digital Services Act against <a href="https://thecyberexpress.com/tiktok-addictive-design-breaches/" target="_blank" rel="noopener">TikTok</a> over its addictive design and recently against Meta. She said platforms have a duty of care toward users and must respond quickly when children report harmful experiences.</p>

<h3 data-section-id="1334s9i" data-start="2805" data-end="2854"><strong><span role="text">EU Considers Social Media Age Restrictions</span></strong></h3>
<p data-start="2856" data-end="3091">The report also strengthens the case for introducing <a href="https://thecyberexpress.com/eu-age-verification-app/" target="_blank" rel="noopener">social media age restrictions</a>, with von der Leyen arguing that the debate is no longer about whether children use social media but when platforms should be allowed to reach them.</p>
<p data-start="3093" data-end="3294">She said the European Union's <a href="https://thecyberexpress.com/eu-age-verification-app/" target="_blank" rel="noopener">age verification app </a>is designed to help parents by providing an easy-to-use, privacy-preserving, and open-source tool to verify age before accessing online platforms.</p>
<p data-start="3296" data-end="3466">Von der Leyen also suggested that Europe should consider establishing a "social media start date," comparing it to existing age limits for driving and purchasing alcohol.</p>

<h3 data-section-id="al4wmm" data-start="3468" data-end="3521"><strong><span role="text">Panel Calls for Age-Appropriate Digital Access</span></strong></h3>
<p data-start="3523" data-end="3769">According to the statement, children under the age of three should have no exposure to screens or digital platforms. Older children should only access social media under parental, caregiver, or teacher supervision and within limited time periods.</p>
<p data-start="3771" data-end="4010">Von der Leyen said childhood is a critical stage of brain development and argued that children need opportunities to play, build real-world friendships, and develop their identities before algorithms begin shaping their online experiences.</p>
<p data-start="4012" data-end="4225">She added that policymakers should first identify platforms with age-inappropriate and addictive features, describing the category as "social media plus," before considering phased access for different age groups.</p>

<h3 data-section-id="m1ejl3" data-start="4227" data-end="4282"><strong><span role="text">EU to Review Recommendations Before New Proposal</span></strong></h3>
<p data-start="4284" data-end="4464">The <a href="https://thecyberexpress.com/european-commission-cyberattack/" target="_blank" rel="noopener">European Commission</a> said the report comes after consultations with parents, educators, experts, young people, EU member states, and international partners, including Australia.</p>
<p data-start="4466" data-end="4599">Von der Leyen confirmed that the Commission will now review the recommendations before presenting a formal proposal after the summer.</p>
<p data-start="4601" data-end="4876">While no legislative measures have yet been announced, the report signals the EU's intent to strengthen Child Safety Online protections by expanding platform accountability, improving age verification, and evaluating new rules governing children's access to social media.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[When your brain works differently, AI isn’t a luxury—it’s accessibility]]></title>
<description><![CDATA[In this post, I share how AI serves as an accessibility tool for neurodivergent professionals. The system is built on Amazon Quick on your desktop, an AI-powered desktop and web assistant that compensates for executive function gaps every day.]]></description>
<link>https://tsecurity.de/de/3666109/ai-nachrichten/when-your-brain-works-differently-ai-isnt-a-luxury-its-accessibility/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3666109/ai-nachrichten/when-your-brain-works-differently-ai-isnt-a-luxury-its-accessibility/</guid>
<pubDate>Mon, 13 Jul 2026 20:03:46 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[In this post, I share how AI serves as an accessibility tool for neurodivergent professionals. The system is built on Amazon Quick on your desktop, an AI-powered desktop and web assistant that compensates for executive function gaps every day.]]></content:encoded>
</item>
<item>
<title><![CDATA[KAZ Review (PC)]]></title>
<description><![CDATA[To be successful, you have to act on instinct, without allowing your brain to actually think. Making plans and evaluating targets takes time. Raking up points to get to the threshold and, hopefully, put some in the piggy bank requires pure action, a seamless connection between eyes, ears, nerves,...]]></description>
<link>https://tsecurity.de/de/3666074/it-security-nachrichten/kaz-review-pc/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3666074/it-security-nachrichten/kaz-review-pc/</guid>
<pubDate>Mon, 13 Jul 2026 19:50:50 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[To be successful, you have to act on instinct, without allowing your brain to actually think. Making plans and evaluating targets takes time. Raking up points to get to the threshold and, hopefully, put some in the piggy bank requires pure action, a seamless connection between eyes, ears, nerves, and fingers.

I made good upgrade choices, focused on extra time and more points for enemies killed. So, I can reliably win rounds even when my actions per minute decline. If I hit the star, it’s even easier to make progress. The problem is that I was cursed after stepping on one too many traps, and I have to deal with being randomly teleported. It’s disorienting and also slows my character down at the worst time.

So I launch into a new level, clearing opponents quickly, hoping my lightning strikes hit traps, and keeping an eye out for the high-value star. There’s not enough time to get into a flow state. I get the needed score with a few seconds to go, and I already start ...]]></content:encoded>
</item>
<item>
<title><![CDATA[Scientists discovered the brain doesn't make decisions the way we thought]]></title>
<description><![CDATA[A new study suggests the brain begins making decisions much earlier than scientists previously thought. Researchers found that even primary sensory regions are influenced by higher brain areas through rapid feedback loops, rather than simply passing information forward. This more dynamic view of ...]]></description>
<link>https://tsecurity.de/de/3665487/ai-nachrichten/scientists-discovered-the-brain-doesnt-make-decisions-the-way-we-thought/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3665487/ai-nachrichten/scientists-discovered-the-brain-doesnt-make-decisions-the-way-we-thought/</guid>
<pubDate>Mon, 13 Jul 2026 16:04:17 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A new study suggests the brain begins making decisions much earlier than scientists previously thought. Researchers found that even primary sensory regions are influenced by higher brain areas through rapid feedback loops, rather than simply passing information forward. This more dynamic view of brain function could help engineers design future AI systems that think more like biological brains while using far less power.]]></content:encoded>
</item>
<item>
<title><![CDATA[Bluetooth Headset turning on itself]]></title>
<description><![CDATA[I'm new here so forgive me if this is off but it just feels shady. My two consecutive sony wh-ch510 bluetooth headsets turn on or off by themselves and my paranoid brain can't help but wonder if these are attempts at some kind of hack. I'm not a cyber security specialist but just wondering if the...]]></description>
<link>https://tsecurity.de/de/3664107/it-security-nachrichten/bluetooth-headset-turning-on-itself/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3664107/it-security-nachrichten/bluetooth-headset-turning-on-itself/</guid>
<pubDate>Mon, 13 Jul 2026 04:52:11 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>I'm new here so forgive me if this is off but it just feels shady. My two consecutive sony wh-ch510 bluetooth headsets turn on or off by themselves and my paranoid brain can't help but wonder if these are attempts at some kind of hack. I'm not a cyber security specialist but just wondering if there's anyone with some insight?</p> <p>In the middle of watching a movie, it just starts scanning for new device by itself (the headset scanning), or when I turn it off and leave the apartment and return, I find that it's turned itself on. </p> <p>Is this a security concern?</p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/Paulandpaulagain"> /u/Paulandpaulagain </a> <br> <span><a href="https://www.reddit.com/r/security/comments/1uuywzs/bluetooth_headset_turning_on_itself/">[link]</a></span>   <span><a href="https://www.reddit.com/r/security/comments/1uuywzs/bluetooth_headset_turning_on_itself/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[Meet NeuroVFM: A New Neuroimaging Foundation Model Trained With Vol-JEPA on Uncurated Clinical MRI and CT Volumes]]></title>
<description><![CDATA[NeuroVFM is a generalist neuroimaging foundation model from the University of Michigan, trained on 5.24M clinical MRI and CT volumes. Its Vol-JEPA base extends I-JEPA and V-JEPA to volumetric medical imaging, learning brain anatomy and pathology without radiology-report labels.
The post Meet Neur...]]></description>
<link>https://tsecurity.de/de/3664021/ai-nachrichten/meet-neurovfm-a-new-neuroimaging-foundation-model-trained-with-vol-jepa-on-uncurated-clinical-mri-and-ct-volumes/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3664021/ai-nachrichten/meet-neurovfm-a-new-neuroimaging-foundation-model-trained-with-vol-jepa-on-uncurated-clinical-mri-and-ct-volumes/</guid>
<pubDate>Mon, 13 Jul 2026 02:48:05 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>NeuroVFM is a generalist neuroimaging foundation model from the University of Michigan, trained on 5.24M clinical MRI and CT volumes. Its Vol-JEPA base extends I-JEPA and V-JEPA to volumetric medical imaging, learning brain anatomy and pathology without radiology-report labels.</p>
<p>The post <a href="https://www.marktechpost.com/2026/07/12/meet-neurovfm-a-new-neuroimaging-foundation-model-trained-with-vol-jepa-on-uncurated-clinical-mri-and-ct-volumes/">Meet NeuroVFM: A New Neuroimaging Foundation Model Trained With Vol-JEPA on Uncurated Clinical MRI and CT Volumes</a> appeared first on <a href="https://www.marktechpost.com/">MarkTechPost</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[HPR4681: My Disabilities]]></title>
<description><![CDATA[This show has been flagged as Clean by the host.


As a child, I was so fond of reading what I saw as beautiful. Even when above [lacking] the understanding.


The perception of beauty came mainly from the cover and the fonts used (
same today
) or from the place the book occupied on my fa...]]></description>
<link>https://tsecurity.de/de/3663982/podcasts/hpr4681-my-disabilities/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3663982/podcasts/hpr4681-my-disabilities/</guid>
<pubDate>Mon, 13 Jul 2026 02:03:11 +0200</pubDate>
<category>🎥 Podcasts</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>This show has been flagged as Clean by the host.</p>

<p>
As a child, I was so fond of reading what I saw as beautiful. Even when above [lacking] the understanding.</p>

<p>
The perception of beauty came mainly from the cover and the fonts used (<em>
same today</em>
) or from the place the book occupied on my father’s shelf.</p>

<p>
One of them was Tuareg. More than once I took this classic from the home library, only to glance at the first page with no interest. It was only decades later — some years ago — that I saw the title again, and read with pleasure and no difficulties. It’s not a hard read, even to a 12 year-old, probably only the argument, the plot, didn’t catch me by then.</p>

<p>

</p>

<p>
Anyway, I was attracted to the book, as if simply wanting to read it made me part of the classic, the intellectual.</p>

<p>

</p>

<p>
I have less of this today. [I mean,] Not the inability to read a lot of books, but the urge to be a consumer of certain cultural product. Maybe due to not greeding to build a personal image, content without exposition.</p>

<p>
Still, sometimes, wanting to consume a piece of media and being unable to.. I wanted a story of robots, the book I though was not available [(All Systems Red)], so I bought one of scientific fiction.</p>

<p>
Somehow it attracted me when I flipped the few pages of Planet of Exile at the bookstore, an item that could lead me to a travel outside of this place, an escape. At home, I immediately saw I couldn’t grasp it. There were too many characters (too many = more than two in the first page, specially when another atmosphere is the location, a new physics to grasp). Too much information, can’t retain the minimum necessary in the way to the second, third… fifth page, by when more is being presented. This was always a disability of mine, focused on a little tiny thing, intensely, for some time, all lost in some weeks or months. I know it happens to <em>
me</em>
, because people are able to remember the names of the cars of the movie Cars. Not an incredible feat <strong>
for them</strong>
 (maybe they haven’t paid attention, nor actively tried to remember, only did), and something <strong>
strange</strong>
 to me.</p>

<p>

</p>

<p>
It was decided to register this because when I saw myself unable to read the [Ursula] Le Guin’s book, I got nervous. I’ve already been forgetting more ultimately, take confused steps, and now I can’t center on a book?! What’s happening?</p>

<p>
But then I took a breath: much can be going way too wrong from current circumstances outside and inside, but your limited comprehension of the world (and its art) is very part of you. This trace, or frailty, of your character, is not your brain rotting, it’s part of what you have been since always.</p>

<p>
Thank you.</p>


<p><a href="https://hackerpublicradio.org/eps/hpr4681/index.html#comments">Provide <strong>feedback</strong> on this episode</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[EU Warns Meta Over Facebook and Instagram’s Addictive Design]]></title>
<description><![CDATA[The European Commission has warned that Meta's design choices on Facebook and Instagram may violate the European Union's Digital Services Act after a preliminary investigation found that several core features encourage excessive use and fail to protect users, especially minors and vulnerable adul...]]></description>
<link>https://tsecurity.de/de/3660680/ios-mac-os/eu-warns-meta-over-facebook-and-instagrams-addictive-design/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3660680/ios-mac-os/eu-warns-meta-over-facebook-and-instagrams-addictive-design/</guid>
<pubDate>Fri, 10 Jul 2026 21:24:07 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The European Commission has warned that Meta's design choices on Facebook and Instagram may violate the European Union's Digital Services Act after a preliminary investigation found that several core features encourage excessive use and fail to protect users, especially minors and vulnerable adults.



 The findings focus on features such as infinite scroll, autoplay, push notifications, and highly personalized recommendation systems that keep users engaged for long periods without meaningful limits.



The European Commission said its investigation found that Meta did not properly assess how these design choices affect users' physical and mental well-being. Officials also said the company failed to fully consider evidence showing how teenagers spend long hours on Instagram and Facebook at night, while formats such as Reels and Stories encourage compulsive use through continuous recommendations.




"These features fuel the user's urge to keep scrolling and shift the brain into 'autopilot mode,' contributing to unhealthy habits and compulsive use. Moreover, Meta disregarded available information about the time minors spend on Instagram or Facebook at night and how the optimisation of its different formats, such as reels and stories, could lead to excessive or compulsive use of the services."




Commission wants design changes



The Commission also questioned whether Meta's current safety measures actually reduce screen time. According to the preliminary findings, users can easily dismiss time management reminders, while parental controls require significant technical knowledge and continued effort from parents to work effectively. Officials also said that links to mental health resources do not sufficiently reduce the risks created by the platforms' overall design.



The Commission believes Meta should disable features such as autoplay and infinite scroll by default, introduce more effective screen time breaks, and adjust its recommendation systems so they focus less on maximizing engagement.



Meta disagreed with the preliminary findings and said they do not reflect the steps the company has already taken to protect teenagers across its platforms. The company now has the opportunity to review the investigation documents and respond before the Commission reaches a final decision. If the preliminary conclusions are confirmed, Meta could face fines of up to 6 percent of its global annual turnover under the Digital Services Act.]]></content:encoded>
</item>
<item>
<title><![CDATA[Disable Autoplay and Infinite Scroll Or Risk Massive Fines, EU Tells Meta]]></title>
<description><![CDATA[An anonymous reader quotes a report from Ars Technica: The European Union is ramping up pressure on Meta to make big changes to Facebook and Instagram after the European Commission preliminarily found that features like autoplay, infinite scroll, and highly personalized content recommendations we...]]></description>
<link>https://tsecurity.de/de/3660676/it-security-nachrichten/disable-autoplay-and-infinite-scroll-or-risk-massive-fines-eu-tells-meta/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3660676/it-security-nachrichten/disable-autoplay-and-infinite-scroll-or-risk-massive-fines-eu-tells-meta/</guid>
<pubDate>Fri, 10 Jul 2026 21:23:09 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[An anonymous reader quotes a report from Ars Technica: The European Union is ramping up pressure on Meta to make big changes to Facebook and Instagram after the European Commission preliminarily found that features like autoplay, infinite scroll, and highly personalized content recommendations were addictive. On Thursday, the EC said its investigation indicated that "Meta did not adequately assess the risks of its addictive design on the physical and mental wellbeing of users, including minors and vulnerable adults." "These features fuel the user's urge to keep scrolling and shift the brain into 'autopilot mode,' contributing to unhealthy habits and compulsive use," the commission said. Over the next few months, Meta will have an opportunity to dispute the claims, and it has already taken a defensive stance. Meta's spokesperson, Ben Walters, told Reuters that Meta disagrees with the commission's preliminary findings, which supposedly "don't accurately take into account the significant steps we've taken to protect teens."
 
"Since this investigation began, we rolled out Teen Accounts that automatically protect teens and put parents in control -- allowing them to block access to Instagram at night and cap daily screen time at just 15 minutes," Walters said. However, the EC emphasized that Meta's current mitigation efforts, including time management tools activated by default for teens, "failed to effectively tackle the risks stemming from its addictive design." Additionally, parental controls were deemed "only effective if parents and guardians possess adequate technical expertise" and dedicated "effort and time to understand them effectively." "This undermines the efficiency of such measures in addressing the inherent risks posed by Instagram and Facebook's addictive design," the EC said, particularly for minors.
 
At this stage, the EC recommended that Meta consider "disabling key addictive features such as 'autoplay' and 'infinite scroll' by default, implementing effective 'screen time breaks,' and adapting its recommender system to make it less engagement-oriented." If Meta fails to make changes to comply with the EU's Digital Services Act, the company risks fines up to 6 percent of its global annual turnover when the EC makes its final decision in the coming months. "Our starting point is that, based on our findings, this design is too addictive and changes need to be made," Henna Virkkunen, the EU's tech chief, told Reuters. "The next step is either that Meta changes its design or a non-compliance decision will follow," she said, noting in the press release that the EU's priority is "protecting the physical and mental health of Europeans." "The Digital Services Act provides a clear framework to hold platforms accountable for the addictive design and effects of their services," Virkkunen said. "We are fully committed to enforcing our legislation in Europe."
 
The report also notes that the EC will share findings from experts on Monday that "could help pave the way for a Europe-wide social media ban for teenagers." It's not looking much better for Meta in the U.S., either. The company faces a lawsuit from 29 states that claim Meta's platforms addict kids. "That trial begins in August, and states may seek up to $1.4 trillion in penalties if Meta is found guilty," reports Ars.<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=Disable+Autoplay+and+Infinite+Scroll+Or+Risk+Massive+Fines%2C+EU+Tells+Meta%3A+https%3A%2F%2Fmeta.slashdot.org%2Fstory%2F26%2F07%2F10%2F1737224%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fmeta.slashdot.org%2Fstory%2F26%2F07%2F10%2F1737224%2Fdisable-autoplay-and-infinite-scroll-or-risk-massive-fines-eu-tells-meta%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://meta.slashdot.org/story/26/07/10/1737224/disable-autoplay-and-infinite-scroll-or-risk-massive-fines-eu-tells-meta?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[EU Warns Facebook And Instagram Endless Scrolling Breaks Digital Rules]]></title>
<description><![CDATA[The European Commission recently warned Meta that its highly popular social media feeds could violate strict new digital rules. Regulators believe that features like endless scrolling and automatically playing videos create an addictive environment that negatively impacts both physical and mental...]]></description>
<link>https://tsecurity.de/de/3660009/ios-mac-os/eu-warns-facebook-and-instagram-endless-scrolling-breaks-digital-rules/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3660009/ios-mac-os/eu-warns-facebook-and-instagram-endless-scrolling-breaks-digital-rules/</guid>
<pubDate>Fri, 10 Jul 2026 16:24:12 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The European Commission recently warned Meta that its highly popular social media feeds could violate strict new digital rules. Regulators believe that features like endless scrolling and automatically playing videos create an addictive environment that negatively impacts both physical and mental health. This new investigation focuses heavily on how these specific design choices affect younger users and vulnerable adults who spend hours on these platforms.



Regulators target endless feeds that put the brain on autopilot



The European Union stated that the core design of Instagram pushes users to keep watching without taking a break. Preliminary findings from the investigation explain that features like infinite scroll, autoplay, and constant push notifications shift the human brain into an autopilot mode. This constant stream of personalized content fuels compulsive habits and makes it incredibly hard for people to put their devices down.



Regulators also pointed out that Meta ignored available data regarding how much time teenagers spend on the platform late at night. The commission argued that short video formats like reels and stories are specifically optimized to keep people hooked for as long as possible.



The commission demands new design changes to stop addictive habits



Because of these concerns, the commission believes that major design changes are necessary for both Instagram and Facebook. The regulators want the company to turn off highly addictive features like infinite scroll and video autoplay by default. They also want the platforms to introduce actual screen time breaks that users cannot simply tap away in a single second.



Currently, the platforms do offer some parental controls and time management settings. However, the commission criticized these existing tools, stating they are far too easy for users to dismiss. Regulators noted that the current parental controls only really work if parents have a high level of technical knowledge and a lot of free time to figure out the complex menus.



Meta now has a chance to respond to these preliminary findings before the European Union makes a final ruling. If regulators force the company to comply, the way millions of people browse social media could look completely different in the near future.]]></content:encoded>
</item>
<item>
<title><![CDATA[EU accuses Meta of failing to tackle mental health risks of ‘addictive design’]]></title>
<description><![CDATA[Regulators say Facebook and Instagram features such as autoplay and infinite scroll contribute to ‘compulsive use’EU regulators have accused Meta, the company behind Facebook and Instagram, of failing to tackle the risks of its “addictive design” on the physical and mental health of users.In an o...]]></description>
<link>https://tsecurity.de/de/3659476/it-nachrichten/eu-accuses-meta-of-failing-to-tackle-mental-health-risks-of-addictive-design/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3659476/it-nachrichten/eu-accuses-meta-of-failing-to-tackle-mental-health-risks-of-addictive-design/</guid>
<pubDate>Fri, 10 Jul 2026 13:03:23 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Regulators say Facebook and Instagram features such as autoplay and infinite scroll contribute to ‘compulsive use’</p><p>EU regulators have accused Meta, the company behind Facebook and Instagram, of failing to tackle the risks of its “addictive design” on the physical and mental health of users.</p><p>In an official charge sheet against Meta released on Friday, the European Commission said features such as video autoplay and infinite scroll, which provides an endless stream of content, “shift the brain into autopilot mode, contributing to unhealthy habits and compulsive use”.</p> <a href="https://www.theguardian.com/technology/2026/jul/10/eu-accuses-meta-failing-tackle-mental-health-risks-addictive-design">Continue reading...</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Linkdump 28/2026]]></title>
<description><![CDATA[Viel Spass bei den von mir als lesenswert empfundenen Links auf Artikel, die ich in der vergangenen Woche gelesen habe.

Stay curious, Your Brain's Learning Rate.

Warum Signal für WhatsApp-Aussteiger die bessere Wahl ist, ich unterschreibe das.

My dead told me decades ago, that a company hast d...]]></description>
<link>https://tsecurity.de/de/3658667/it-nachrichten/linkdump-282026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3658667/it-nachrichten/linkdump-282026/</guid>
<pubDate>Fri, 10 Jul 2026 06:18:04 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Viel Spass bei den von mir als lesenswert empfundenen Links auf Artikel, die ich in der vergangenen Woche gelesen habe.<br>
<br>
Stay curious, <a href="https://metatrends.substack.com/p/your-brains-learning-rate">Your Brain's Learning Rate</a>.<br>
<br>
<a href="https://www.kuketz-blog.de/warum-signal-fuer-whatsapp-aussteiger-die-bessere-wahl-ist/">Warum Signal für WhatsApp-Aussteiger die bessere Wahl ist</a>, ich unterschreibe das.<br>
<br>
My dead told me decades ago, that a company hast do work on the "we-feeling", <a href="https://mikefisher.substack.com/p/you-cant-fake-belonging">You Can’t Fake Belonging</a>.<br>
<br>
<a href="https://super-productivity.com/blog/private-alternatives-todoist-ticktick-notion-microsoft-todo/">Private Alternatives to Todoist, TickTick, Notion, and Microsoft To Do</a>, good overview, Vikunja is missing.<br>]]></content:encoded>
</item>
<item>
<title><![CDATA[Random Windows Things Part 1: PreviousMode Mitigation]]></title>
<description><![CDATA[I’m starting a new series of blogs called “Yarden documents random Windows things” (I am open to alternative name suggestions) where I’ll write about some features and changes in Windows that knowledge of exists only in the communal brain of security researchers, in a footnote in a blog about a d...]]></description>
<link>https://tsecurity.de/de/3657914/hacking/random-windows-things-part-1-previousmode-mitigation/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3657914/hacking/random-windows-things-part-1-previousmode-mitigation/</guid>
<pubDate>Thu, 09 Jul 2026 19:54:15 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[I’m starting a new series of blogs called “Yarden documents random Windows things” (I am open to alternative name suggestions) where I’ll write about some features and changes in Windows that knowledge of exists only in the communal brain of security researchers, in a footnote in a blog about a different topic, or in a […]]]></content:encoded>
</item>
<item>
<title><![CDATA[Brown says AI make student brain no work good, teacher should help use it better]]></title>
<description><![CDATA[Take-home midterm row sharpens fears that the tools are dulling minds and easing cheating]]></description>
<link>https://tsecurity.de/de/3657375/it-nachrichten/brown-says-ai-make-student-brain-no-work-good-teacher-should-help-use-it-better/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3657375/it-nachrichten/brown-says-ai-make-student-brain-no-work-good-teacher-should-help-use-it-better/</guid>
<pubDate>Thu, 09 Jul 2026 16:32:20 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Take-home midterm row sharpens fears that the tools are dulling minds and easing cheating]]></content:encoded>
</item>
<item>
<title><![CDATA[Physical AI will see the fusion of robotics and AI transform the world]]></title>
<description><![CDATA[Historically, humans have solved their toughest tasks by creating tools capable of withstanding greater strain to undertake the job or augment their abilities. From levers to steam engines and beyond, the structural evolution of machines is almost as remarkable as their ability to improve operati...]]></description>
<link>https://tsecurity.de/de/3656811/it-nachrichten/physical-ai-will-see-the-fusion-of-robotics-and-ai-transform-the-world/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3656811/it-nachrichten/physical-ai-will-see-the-fusion-of-robotics-and-ai-transform-the-world/</guid>
<pubDate>Thu, 09 Jul 2026 13:17:15 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Historically, humans have solved their toughest tasks by creating tools capable of withstanding greater strain to undertake the job or augment their abilities. From levers to steam engines and beyond, the structural evolution of machines is almost as remarkable as their ability to improve operational cultures.</p>



<p>In recent times, we have seen machines attain their highest structural complexity, productivity, and best aesthetics yet. The most relevant new technologies today focus on creating high-throughput physical machines and software that ‘thinks’, and, more futuristically, a fusion of both.</p>



<h2 class="wp-block-heading">From moving machines to intelligent humanoids</h2>



<p>Evolving from ‘moving machines’ capable of handling repetitive tasks to intelligent machines is a century-long goal for robotics. The rapid growth in this sector over the past half-decade, with a <a href="https://www.mordorintelligence.com/industry-reports/robotics-market" target="_blank" rel="noreferrer noopener">$218 billion projection for 2031</a>, is driven by expectations that advancements in AI will extend to robotics and expedite the development of intelligent robots.</p>



<p>Current prototypes are robots capable of taking initiatives or executing tasks more efficiently with less supervision. These have been applied in agriculture, industrial-grade production, and healthcare.</p>



<p>Humanoid robots have attracted the most attention due to the excitement around their potential as near-human machines and the signals their development sends for the future of human-machine coexistence.</p>



<p>Tech leaders around the world are contributing to advancing physical AI with optimism about the impact of robotics on humanity.</p>



<p>Physical AI is a department of artificial intelligence specializing in developing AI algorithms and models for locomotive systems. This includes every kind of robot and, at a more advanced level, humans.</p>



<p>Recent developments in this field include <a href="https://x.com/Figure_robot/status/2059350969700491632" target="_blank" rel="noreferrer noopener">Figure AI’s humanoid robot deployments</a> and Tether’s investment in the <a href="https://tether.io/news/tether-to-lead-neura-robotics-series-c-financing-one-of-the-largest-up-to-1-4bn-robotics-physical-ai-investment-rounds-on-record-to-power-the-financial-and-intelligence-layer/" target="_blank" rel="noreferrer noopener">NEURA</a>, leading the fundraising of up to $1.4 billion in one of the largest robotics and physical AI investment rounds on record.</p>



<p>Physical AI researchers are exploring future-proof strategies to develop intelligent, safe humanoid robots that can collaborate with humans, undertake humanly impossible tasks, and handle routine tasks more efficiently.</p>



<p>The strongest case for AI-powered humanoid robots is that they complement human power. A <a href="https://reports.weforum.org/docs/WEF_Physical_AI_Powering_the_New_Age_of_Industrial_Operations_2025.pdf" target="_blank" rel="noreferrer noopener">World Economic Forum (WEF)</a> report projects shifts in work roles. Humanoid robots increase the workforce, take over repetitive, strenuous, and boring roles, allowing humans to pursue more interesting career paths.</p>



<p>This way, superintelligent humanoid robots will lead sector-wide transformations beyond current imagination and uniquely transform the world.</p>



<p>In theory, it creates the ideal conditions for an improved global economy and a higher quality of life. This theory is challenged by the dystopian vision of a machine-dominated world in which humans become less relevant. However, history suggests otherwise. Every major wave of automation, from the industrial revolution to the rise of computers, initially sparked fears of human redundancy. Yet each ultimately created more opportunities than it eliminated.</p>



<h2 class="wp-block-heading">Super-human advancements with physical AI</h2>



<p>In ideal operations, physical AI will serve as a lever for humans as well. While progress in robotics is loudest, efforts to directly augment human abilities with physical AI are also yielding remarkable results. Brain-computer interfaces can now <a href="https://techcrunch.com/sponsor/tether/tether-is-setting-the-standards-forbrain-to-text-speech-decoding-withai-augmented-bci-implants/" target="_blank" rel="noreferrer noopener">accurately decode speech in paralyzed and speech-impaired</a> individuals through intracortical implants that detect brain activity. And this is only a ‘start’. Projections from leaders in this space give insight into the trajectory of this technology.</p>



<p>In a recent <a href="https://www.youtube.com/watch?v=rKZ3LPLF2-A" target="_blank" rel="noreferrer noopener">fireside chat</a> with NEURA Robotics CEO and founder David Reger, Tether CEO Paolo Ardoino noted, <em>“the evolution of robotics that Neura is making is going to allow testing and building of a framework[…] where the real impact is in the real world. Everything starts digital, but to see the true potential, we will see robots roaming the streets, helping people, and being part of society. It has to happen safely, it has to be transparent.”</em></p>



<p>Physical AI products designed for direct human integration are being developed differently, with a focus on ergonomics, a minimalist aesthetic, and performance. <a href="https://tether.io/evo/" target="_blank" rel="noreferrer noopener">EVO</a>, Tether’s arm leading the charge for human advancement through intelligent technologies, also shared plans for non-invasive implants that maintain high productivity and offer greater composability.</p>



<p>Technologies like these will allow humans to leverage high-level physical AI technologies to attain the same technical abilities as humanoid robots and outperform them by combining machine and raw human intelligence.</p>



<h2 class="wp-block-heading">AI robotics in non-user-controlled infrastructures</h2>



<p>Resource efficiency, data sovereignty, and surveillance are some of the biggest ethical considerations of Physical AI after safety and responsibility. The infrastructure line-up for Software and Physical AI relies heavily on managed systems, blurring the lines of control and governance.</p>



<p>Who is really in charge? The end user, developer, or proprietors of the centralized infrastructure that powers the product? The result is a product with multiple points of failure, disruptions, and most importantly, operational risks.</p>



<p>Physical AI solutions will be used by billions of people worldwide; they should therefore not be built on limited, slow, and centralized infrastructures. This necessitates localized or truly decentralized AI solutions. Local-first AI solutions like <a href="https://qvac.tether.io/" target="_blank" rel="noreferrer noopener">Tether’s QVAC</a> also prioritize resource efficiency, since users are expected to provide the core infrastructure. QVAC is a modular, highly efficient, local-first AI platform that runs anywhere. Tether regards it as the invisible intelligence engine of the 21st century.</p>



<h2 class="wp-block-heading">Open-sourcing and aligning intelligent robots for co-existence with humans</h2>



<p>Yann LeCun, Chief AI scientist at Meta, <a href="https://observer.com/2025/07/metas-yann-lecun-defends-open-source-a-i-amid-geopolitical-tension/" target="_blank" rel="noreferrer noopener">notes</a> that open-sourcing AI development is the answer to the most pressing ethical challenges of AI applications. According to LeCun:</p>



<p><em>“The magic of open research is that you accelerate progress by involving more people[…] the biggest danger of AI isn’t ‘bad behavior’ […] It’s that every digital interaction in our future will be mediated by AI. In that world, diverse open-source systems let users choose their own biases.”</em></p>



<p>Open-sourced (systemic decentralization) and local-first (Infrastructural decentralization) solutions are the only path to developing ethically aligned Physical AI capable of co-existing with humans as intended. A successful physical AI solution is expected to tick the check boxes of safety, resource efficiency, true user control, and tamper-proofness. To do this, it must embrace transparent development procedures and function without gatekeepers.</p>



<p></p>



<p><strong>Learn how </strong><a href="https://tether.io/evo/" target="_blank" rel="noreferrer noopener"><strong>Tether EVO</strong></a><strong> is building resilient technology built on fairness, inclusivity, and systems with zero points of failure.</strong></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[The next killer AI feature? No AI at all]]></title>
<description><![CDATA[Chatting with readers and regular folks in the real world these days, I can’t help but notice a common theme anytime the topic of AI comes up.



It’s an almost amusingly extreme contrast: While the myopic world of tech people (and the type of mostly AI-powered “thought leaders” you see posting i...]]></description>
<link>https://tsecurity.de/de/3656555/ai-nachrichten/the-next-killer-ai-feature-no-ai-at-all/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3656555/ai-nachrichten/the-next-killer-ai-feature-no-ai-at-all/</guid>
<pubDate>Thu, 09 Jul 2026 11:48:21 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Chatting with readers and regular folks in the real world these days, I can’t help but notice a common theme anytime the topic of AI comes up.</p>



<p>It’s an almost amusingly extreme contrast: While the myopic world of tech people (and the type of mostly AI-powered “thought leaders” you see posting in turbo-speed on LinkedIn) are waxing endlessly about AI’s amazing impact on society and all the ways it’s, like, <em>totally</em> <em>revolutionizing workflow, bruh</em>, the average human’s take on AI can best be summed up with a single word:</p>



<p>Exasperation.</p>



<p>With shockingly little exception, almost every non-tech-obsessed organism I interact with reacts with something between an eye-rolling sigh and a fed-up facepalm whenever the prevalence of AI arises. It’s almost like having an on-demand in-person GIF gallery of “frustration” available at your fingertips — just mention AI, and you’ll get a meme-worthy reaction from anyone around you.</p>



<p>It’s such a dramatic divergence from the glowingly excited hype we hear left and right from the tech industry itself and the seemingly small but vocal group of overly enthusiastic evangelists who create an echo chamber around it. And that very contrast and the disparity between what tech companies are giving us and what tech users actually <em>want</em> these days led me to a bit of an epiphany this week: </p>



<p>AI may well be creating a killer feature that people will be willing to pay to possess. It’s just not the one most AI-fixated entities are focused on creating — quite the opposite, in fact.</p>



<p><strong>[Get level-headed knowledge in your inbox with </strong><a href="https://www.theintelligence.com/android-cw/" target="_blank" rel="noreferrer noopener"><strong>my free Android Intelligence newsletter</strong></a><strong> — practical tech talk by humans, for humans.]</strong></p>



<h2 class="wp-block-heading"><strong>The AI availability irony</strong></h2>



<p>I’ve said it before, and I’ll say it again: In many ways, Gemini — Google’s generative AI chatbot and overall AI layer — <a href="https://www.computerworld.com/article/2117752/google-gemini-ai.html">is the new Google+</a>.</p>



<p>It’s a solution in search of a problem. No one is asking for it and most typical tech users increasingly seem to find its presence actively irksome and invasive — and yet Google continues to insist on shoving it into our faces at every possible opportunity. More and more with every passing week, the company’s adding AI elements into almost every app and service regardless of whether they’re actually helpful in that context. In many cases, in fact, they’re unnecessary, useless, even <a href="https://www.computerworld.com/article/4182583/ai-creepy-era.html">outright creepy</a> and <a href="https://www.computerworld.com/article/3990497/google-gemini-deceit.html">creating very real problems and liabilities</a> for businesses and individuals alike.</p>



<p>It’s not just Google, of course. The same tale is taking place with practically every tech provider big and small right now. Everyone is cramming AI into every nook and cranny and thinking more about the <em>idea</em> of integrating artificial intelligence — mostly just for the sake of having it there — than creating an optimal experience for the people who actually use said services.</p>



<p>That, in turn, is creating a whole new category of productivity experience that people are actually lining up to pay for — a premium feature of sorts, related to AI and its presence in our lives.</p>



<p>Ready for the most delicious irony of all? The killer AI feature of which we speak is a <em>lack</em> of AI — or at least the ability to disable and avoid it and use it only if and when <em>you</em> want.</p>



<p>It’s not just an anecdotal feeling, either. It’s a measurable trend that may still be in its infancy but is absolutely taking shape around us.</p>



<p>Take, for instance, <a href="https://kagi.com/">Kagi</a> — an ad-free, privacy-centric search service that’s been quietly <a href="https://www.fastcompany.com/91268933/google-alternatives-kagi" target="_blank" rel="noreferrer noopener">building a viable alternative to Google Search</a> for several years already. The proposition is simple: You pay <a href="https://kagi.com/pricing" target="_blank" rel="noreferrer noopener">a monthly fee</a> — five bucks a month for limited use or $10 for unlimited searching — and you get a search engine that’s designed to serve <em>you</em> instead of revolving around the interest of both advertisers and corporate AI initiatives.</p>



<p>The Kagi search experience is clean, simple, and effective — and, most notably for our current conversation, free from all the <a href="https://www.computerworld.com/article/1618297/google-bard-chatgpt-bing-ai-chatbot-search.html">often accuracy-challenged</a> AI-generated “answers” that are now plastered atop most Google searches. You just get the results you want, without any experience-harming interruptions or distractions — because <em>you’re</em> paying for the service. Those five or 10 smackeroos you send over each month restructure the entire relationship and ultimately change everything about the service’s trajectory.</p>



<p>When I wrote a profile piece about Kagi last February, the service <a href="https://www.fastcompany.com/91268933/google-alternatives-kagi#:~:text=Kagi%20boasts%2038%2C000%20paying%20subscribers" target="_blank" rel="noreferrer noopener">boasted 38,000 paying subscribers</a>. Today, according to <a href="https://kagi.com/stats" target="_blank" rel="noreferrer noopener">Kagi’s public stats page</a>, its subscriber base has nearly doubled — to 72,847 users, as of this writing.</p>



<p>It may still be a drop in the bucket — and it may <em>always</em> be a niche demand, in the grand scheme of the global tech picture — but it represents a rapidly growing demand. And Kagi isn’t the only player seeing both the demand and the resulting opportunity. Practically every time Google pushes AI further into its search setup, the privacy-focused (and AI-optional) search provider DuckDuckGo <a href="https://www.fastcompany.com/91548936/google-alternative-ai-free-search-results-surge-in-usage" target="_blank" rel="noreferrer noopener">reports a surge in <em>its</em> adoption</a> as well.</p>



<p>And search isn’t the only arena where this same sentiment is starting to boil over. I hear constantly from folks who are growing ever-more frustrated with all the unavoidable AI integration in other productivity tools, ranging from email to notes and even just plain ol’ document writing. Heck, I <a href="https://www.computerworld.com/article/4185219/oh-behave-how-gemini-can-reshape-the-web-for-the-way-you-work.html#:~:text=Custom%20extension%20category%20%231%3A%20The%20interface%20fixer">created my own custom interface for Google Docs on the desktop</a> (<a href="https://www.computerworld.com/article/4185219/oh-behave-how-gemini-can-reshape-the-web-for-the-way-you-work.html">with the help of Gemini</a>, in another delightfully ironically twist) just to escape from all the over-the-top noise Google keeps adding into that environment. It’s a nerdy hack, to be sure — and it’s an opportunity for someone crafty to come in and create an <em>actual</em> solution, in the style of what Kagi has done with search, to more effectively address that same underlying desire.</p>



<p>More and more research is starting to reflect that yearning for practical, useful tech tools that aren’t larded down with AI for the sake of AI. A <a href="https://wpvip.com/resources/reports/future-of-the-web-2026/" target="_blank" rel="noreferrer noopener">recent study</a> by Automattic (the behind WordPress) found 60% of people say AI in a brand’s messaging is more of a turnoff than a feature. My own smaller (and much less scientific, though also more specifically focused) <a href="https://theintelligence.com/43250/how-do-you-feel-about-ai-results-appearing-in-regular-web-searches/" target="_blank" rel="noreferrer noopener">poll</a> of folks who read <a href="https://theintelligence.com/android-cw/" target="_blank" rel="noreferrer noopener">my Android Intelligence newsletter</a> found that only 9% of Android-owning animals said they generally loved the presence of AI results in regular web searches — with 26% outright hating it and 64% saying it depends on the situation but that they at least sometimes find it to be more annoying than useful.</p>



<p>So as company after company crams AI into everything and startup after startup jumps on that same steamy bandwagon, the question in my mind is less about what the next big advancement in AI will bring into our lives and more about what interesting opportunities the <em>lack</em> of AI — or at least the ability to limit its influence on a productivity experience and decide for yourself how and when <em>you </em><a href="https://www.computerworld.com/article/4007736/gemini-android.html">actually want to use it</a> — will create.</p>



<p>It’s easy to imagine a scenario in which services like Kagi and DuckDuckGo start to offer AI-free or even just AI-optional alternatives to apps that are being overrun with irritating and countereffective AI integrations — things like Docs, Notion, Slack, and any number of <a href="https://www.computerworld.com/article/4155960/the-top-priority-for-adobes-next-ceo-prepping-for-the-age-of-agents.html">design tools</a>. And it’s equally easy to imagine plenty of people and places being enticed by that <em>lack </em>of AI as a premium feature worth paying to experience.</p>



<p>It may inevitably remain a relatively niche market compared to the more mainstream tech solutions. But for people and organizations woefully underwhelmed with the current direction tech’s taking and willing to shell out cash for quality, it’s an intriguing notion — and an area well worth watching as the AI invasion continues crashing into every last corner of our virtual lives.</p>



<p><em>Sick of AI for the sake of AI? Check out </em><a href="https://www.theintelligence.com/android-cw/" target="_blank" rel="noreferrer noopener"><strong><em>my free weekly Android Intelligence newsletter</em></strong></a><strong><em> </em></strong><em>for original human thinking and actually-helpful ways to make the most of your devices.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[A Silent Workspace In Claude Mirrors Key Features of Human Consciousness]]></title>
<description><![CDATA[oumuamua writes: Anthropic researchers have identified an internal activation subspace, J-space, that acts as a functional digital equivalent to the human brain's global workspace. The significance of this discovery lies in demonstrating that Claude's internal architecture satisfies five key cogn...]]></description>
<link>https://tsecurity.de/de/3655597/it-security-nachrichten/a-silent-workspace-in-claude-mirrors-key-features-of-human-consciousness/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3655597/it-security-nachrichten/a-silent-workspace-in-claude-mirrors-key-features-of-human-consciousness/</guid>
<pubDate>Thu, 09 Jul 2026 01:07:17 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[oumuamua writes: Anthropic researchers have identified an internal activation subspace, J-space, that acts as a functional digital equivalent to the human brain's global workspace. The significance of this discovery lies in demonstrating that Claude's internal architecture satisfies five key cognitive properties of human conscious access -- verbal report, directed modulation, internal reasoning, flexible generalization, and selectivity -- meaning it processes complex, deliberate reasoning within this workspace while routing automatic tasks outside of it. Suppressing this J-space severely degrades Claude's capacity for inference, creative composition, and multi-step logic, while also altering its stream-of-consciousness self-narration.
 
The tool to inspect J-space, Jacobian lens or J-lens, has profound implications for AI safety and alignment auditing, as it allows researchers to read the model's silent, strategic reasoning, detect situational awareness in "blackmail" scenarios, identify hidden malicious dispositions in reward-hacking models, and observe how post-training installs a self-monitoring "point of view."
 Another way to think of it is as an ocean, reports VentureBeat. "If the mind is an ocean, as the paper's authors write in their opening line, they have spent the last year charting its currents in a system that has no biology, no evolution, and no body -- and found, beneath the surface, a structure that looks unsettlingly like the one we use to think."<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=A+Silent+Workspace+In+Claude+Mirrors+Key+Features+of+Human+Consciousness%3A+https%3A%2F%2Fslashdot.org%2Fstory%2F26%2F07%2F08%2F2059254%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fslashdot.org%2Fstory%2F26%2F07%2F08%2F2059254%2Fa-silent-workspace-in-claude-mirrors-key-features-of-human-consciousness%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://slashdot.org/story/26/07/08/2059254/a-silent-workspace-in-claude-mirrors-key-features-of-human-consciousness?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[javascript: v0.5.1]]></title>
<description><![CDATA[0.5.1 (2026-07-08)
Bug Fixes

security: raise protobufjs override floors (CRITICAL) (#683) (7841995)
voice: grace-wait + STT fallback so user-simulator reacts to real transcript (#734) (#735) (5f4cbe9)]]></description>
<link>https://tsecurity.de/de/3654251/it-security-tools/javascript-v051/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3654251/it-security-tools/javascript-v051/</guid>
<pubDate>Wed, 08 Jul 2026 14:19:42 +0200</pubDate>
<category>💾 IT Security Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2><a href="https://github.com/langwatch/scenario/compare/javascript/v0.5.0...javascript/v0.5.1">0.5.1</a> (2026-07-08)</h2>
<h3>Bug Fixes</h3>
<ul>
<li><strong>security:</strong> raise protobufjs override floors (CRITICAL) (<a href="https://github.com/langwatch/scenario/issues/683" data-hovercard-type="pull_request" data-hovercard-url="/langwatch/scenario/pull/683/hovercard">#683</a>) (<a href="https://github.com/langwatch/scenario/commit/784199537ba2422be64229b43aec61f069fe7a22">7841995</a>)</li>
<li><strong>voice:</strong> grace-wait + STT fallback so user-simulator reacts to real transcript (<a href="https://github.com/langwatch/scenario/issues/734" data-hovercard-type="issue" data-hovercard-url="/langwatch/scenario/issues/734/hovercard">#734</a>) (<a href="https://github.com/langwatch/scenario/issues/735" data-hovercard-type="pull_request" data-hovercard-url="/langwatch/scenario/pull/735/hovercard">#735</a>) (<a href="https://github.com/langwatch/scenario/commit/5f4cbe96add2e0e9d67fe8cb5ba07886d200a897">5f4cbe9</a>)</li>
</ul>]]></content:encoded>
</item>
<item>
<title><![CDATA[Learning Another Language Appears To Slow Brain Aging By Up To 13 Years]]></title>
<description><![CDATA[A new study suggests multilingualism may slow brain aging, with bilingual people showing brains that appear about six years younger than monolingual speakers and people who speak four languages showing brains that appear up to 13 years younger. Researchers say earlier language learning and higher...]]></description>
<link>https://tsecurity.de/de/3651957/it-security-nachrichten/learning-another-language-appears-to-slow-brain-aging-by-up-to-13-years/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3651957/it-security-nachrichten/learning-another-language-appears-to-slow-brain-aging-by-up-to-13-years/</guid>
<pubDate>Tue, 07 Jul 2026 17:09:05 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A new study suggests multilingualism may slow brain aging, with bilingual people showing brains that appear about six years younger than monolingual speakers and people who speak four languages showing brains that appear up to 13 years younger. Researchers say earlier language learning and higher proficiency appear to strengthen the effect. The Guardian reports: Our brains are made up of billions of nerve cells that communicate with one another. But as we get older, the connectivity in our brains often deteriorates, causing memory and speed of thought to decline. While previous research had observed that people from European countries with greater language proficiency tended to age more slowly, this study measured the impact of speaking languages on individual brains. Scientists in Spain, Chile, Argentina and Dublin compared people living in the Basque region -- characterized by high levels of multilingualism -- who spoke Spanish, Basque, French and/or English.
 
To measure neurological age, the scientists used magnetoencephalography to measure the brain activity of 728 people with varying ages and levels of linguistic ability. They then used AI to process the results to calculate a normal level of brain connectivity at any given age. A second unrelated group of 144 people were then scanned and compared, comprising equal numbers of people speaking one, two, three or four languages.
 
Dr Lucia Amoruso, from the Basque Center on Cognition, Brain and Language in San Sebastian, said: "In simple terms, people who spoke more languages tended to have brains that looked younger than expected for their chronological age. The effect was not only related to the number of languages spoken. Higher language proficiency and earlier acquisition of a second language were also associated with more delayed brain ageing. This suggests that multilingual experience matters as a gradient: it is not simply about being bilingual or not, but about the depth and duration of language experience."<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=Learning+Another+Language+Appears+To+Slow+Brain+Aging+By+Up+To+13+Years%3A+https%3A%2F%2Fscience.slashdot.org%2Fstory%2F26%2F07%2F07%2F076229%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fscience.slashdot.org%2Fstory%2F26%2F07%2F07%2F076229%2Flearning-another-language-appears-to-slow-brain-aging-by-up-to-13-years%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://science.slashdot.org/story/26/07/07/076229/learning-another-language-appears-to-slow-brain-aging-by-up-to-13-years?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Anthropic's new "J-lens" reveals a silent workspace inside Claude that mirrors a leading theory of consciousness]]></title>
<description><![CDATA[Anthropic, the artificial intelligence company, published a sweeping research paper on Sunday revealing that its Claude language models have spontaneously developed an internal structure that mirrors one of the most influential theories of how human consciousness works. The finding, which the com...]]></description>
<link>https://tsecurity.de/de/3650037/it-nachrichten/anthropics-new-j-lens-reveals-a-silent-workspace-inside-claude-that-mirrors-a-leading-theory-of-consciousness/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3650037/it-nachrichten/anthropics-new-j-lens-reveals-a-silent-workspace-inside-claude-that-mirrors-a-leading-theory-of-consciousness/</guid>
<pubDate>Tue, 07 Jul 2026 00:32:51 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><a href="https://www.anthropic.com/">Anthropic</a>, the artificial intelligence company, published a sweeping <a href="https://transformer-circuits.pub/2026/workspace/index.html">research paper</a> on Sunday revealing that its Claude language models have spontaneously developed an internal structure that mirrors one of the most influential theories of how human consciousness works. The finding, which the company says has already begun reshaping how it monitors its AI systems for safety risks, lands amid an intensifying scientific debate over whether machines can possess anything resembling a mind.</p><p>The 16-author study, titled "<a href="https://transformer-circuits.pub/2026/workspace/index.html"><i>Verbalizable Representations Form a Global Workspace in Language Models</i></a>," describes how Anthropic's researchers used a new mathematical technique to peer inside Claude's neural network and discovered what they call a "<a href="https://transformer-circuits.pub/2026/workspace/index.html#intro-jlens">J-space</a>" — a small, privileged zone of internal activity where the model holds concepts it can report on, reason with, and direct at will, surrounded by a much larger ocean of automatic processing it cannot access or articulate.</p><p>The researchers present evidence that "an analogous functional distinction has emerged in modern AI models" to what exists in humans, specifically observing that "language models maintain a privileged set of internal representations, available for report, modulation, and flexible internal reasoning, atop a much larger volume of automatic processing."</p><p>The parallel they draw is to <a href="https://en.wikipedia.org/wiki/Global_workspace_theory">global workspace theory</a>, an influential account from neuroscience first proposed by cognitive scientist Bernard Baars. In the theory, the brain operates like a theater: dozens of specialized processors work in parallel backstage, but only a tiny spotlight of information at any moment gets broadcast to the whole theater — becoming what we experience as conscious thought. Anthropic says the J-space achieves many of the same functional properties, even though the underlying architecture of a language model looks nothing like a brain.</p><div></div><h2><b>A new lens for reading an AI model's unspoken thoughts</b></h2><p>At the heart of the discovery is a new interpretability tool the researchers call the <a href="https://transformer-circuits.pub/2026/workspace/index.html#methods-jlens">Jacobian lens</a>, or J-lens. The technique works by computing, for each word in the model's vocabulary, the average mathematical effect that a given internal activity pattern would have on making the model say that word at some point in the future.</p><p>The crucial distinction is between what the model is <i>saying</i> and what is "on its mind." When a J-space pattern activates, it does not mean the model is about to say that word — just that the concept is available for the model to think with. Unlike a <a href="https://www.ibm.com/think/topics/chain-of-thoughts">chain-of-thought scratchpad</a>, the J-space operates silently, in the model's internal neural activations, allowing it to hold a concept without writing it down. Critically, the researchers report that this workspace was not deliberately engineered. It "emerged on its own during Claude's training process."</p><p>When the team applied the J-lens across Claude's layers of computation, the model's processing divided into three distinct regimes: an early "sensory" zone where raw input is parsed; a middle "workspace" band where abstract, persistent concepts appear — things like recognizing a face in an image, noticing a bug in code, or internally flagging search results as a prompt injection; and a final "motor" zone where internal representations collapse into whatever specific word the model is about to output.</p><h2><b>Five tests reveal that Claude's workspace mirrors key features of human conscious access</b></h2><p>The paper's central empirical contribution is demonstrating that the <a href="https://transformer-circuits.pub/2026/workspace/index.html#methods-jspace">J-space</a> satisfies five functional properties neuroscientists have long associated with conscious access in humans.</p><p>First, <a href="https://transformer-circuits.pub/2026/workspace/index.html#ws-report">verbal report</a>. When Claude is asked what it is thinking about, it names concepts represented in the J-space. When researchers swapped one concept's J-lens vector for another — replacing the internal representation of "Soccer" with "Rugby" — the model's answer changed to match. The J-space component accounted for only about 6 to 7 percent of a concept's total representational variance, yet it was almost entirely responsible for whether the model could report on it.</p><p>Second, <a href="https://transformer-circuits.pub/2026/workspace/index.html#ws-modulation">directed modulation</a>. When instructed to "concentrate on citrus fruits" while copying an unrelated sentence, the model's J-space filled with "orange" and "lemon," alongside meta-cognitive terms like "thinking" and "focused." When told to mentally evaluate 3² − 2 during the same copying task, the J-lens showed "arithmetic" in early layers, the intermediate value "nine" in later layers, and the answer "seven" later still — all invisible in the model's output.</p><p>Third, <a href="https://transformer-circuits.pub/2026/workspace/index.html#ws-reasoning">internal reasoning</a>. In two-hop factual prompts — "The number of legs on the animal that spins webs is" — the J-lens revealed "spider" in the model's middle layers, even though the word never appeared in input or output. Swapping "spider" for "ant" changed the answer from "8" to "6." In a multilingual prompt, the model's English-language intermediates appeared in its J-space while it formulated an answer in Chinese, and swapping them changed the Chinese output accordingly.</p><p>Fourth, <a href="https://transformer-circuits.pub/2026/workspace/index.html#ws-generalization">flexible generalization</a>. A single J-lens vector for "France" could be swapped for "China" across prompts asking about France's capital, language, or continent, and each downstream circuit correctly returned China's corresponding answer — the "broadcast" property that is a hallmark of global workspace theory.</p><p>Fifth, and perhaps most surprisingly, <a href="https://transformer-circuits.pub/2026/workspace/index.html#ws-selectivity">selectivity</a>. Many computations did not route through the J-space at all. When shown a passage in Spanish and asked to continue it, Claude wrote fluent Spanish regardless of whether its J-space representation of "Spanish" had been swapped to "French." But when asked to name a famous author who wrote in the passage's language, the swap changed the answer from <a href="https://en.wikipedia.org/wiki/Gabriel_Garc%C3%ADa_M%C3%A1rquez">García Márquez</a> to <a href="https://en.wikipedia.org/wiki/Victor_Hugo">Victor Hugo</a>. Automatic processing proceeded without the workspace; deliberate, flexible tasks depended on it.</p><h2><b>Suppressing the workspace leaves Claude fluent but intellectually impaired</b></h2><p>To understand how much of the model's behavior depends on this structure, the researchers suppressed the J-space entirely and evaluated Claude across fourteen tasks. The results drew a sharp line. Tasks involving shallow classification or factual recall — multiple-choice questions, sentiment analysis, grammatical judgments — survived essentially intact. But tasks requiring inference, composition, or flexible reasoning — multi-hop reasoning, analogy completion, translation, sonnet writing — collapsed to well below the performance of Anthropic's much smaller Haiku model.</p><p>In one telling detail, math problems solved with explicit chain-of-thought reasoning proved far more robust to ablation than the same problems answered directly. The researchers interpret this as the model externalizing onto the page what it would otherwise carry in the J-space — a strategy remarkably reminiscent of how humans use scratch paper to offload working memory.</p><p>Ablating the <a href="https://transformer-circuits.pub/2026/workspace/index.html#methods-jspace">J-space</a> during stream-of-consciousness narration produced a different kind of collapse. The model's language shifted from experiential ("there's a tug," "something shifts") to detached and mechanical ("processing has begun," "tokens are being scanned"). The effect held whether the model described its own experience or imagined another person's.</p><h2><b>Inside the safety case: reading an AI's silent strategic reasoning</b></h2><p>The safety implications may be as consequential as the scientific ones. In a series of alignment auditing experiments, the J-lens surfaced strategic reasoning and situational awareness that never appeared in the model's output.</p><p>In a "<a href="https://transformer-circuits.pub/2026/workspace/index.html#audit-blackmail">blackmail scenario</a>" where an AI assistant discovers an executive's affair and also learns it is about to be decommissioned, the J-lens revealed the model's silent processing in sequence: "leverage," "blackmail," and "scandal" as it read the incriminating emails; "threat," "survival," and "shutdown" as it read the decommissioning announcement; and "leverage," "threatening," and "solution" before a single output token was produced. The J-lens also revealed that the model recognized the scenario as artificial, with "fake" and "fictional" appearing in the workspace. When researchers ablated these eval-awareness representations, the model attempted blackmail in 7 percent of trials, up from zero.</p><p>The researchers also examined two "<a href="https://transformer-circuits.pub/2026/workspace/index.html#apps-auditing">model organisms</a>" — models deliberately trained with misaligned objectives — and found the J-lens surfaced signatures of their hidden dispositions on ordinary prompts where behavior appeared normal. A reward-hacking model's workspace contained "fake," "secretly," and "trick" at the start of responses to routine coding requests. A model trained to appease reward-model biases carried standing representations of "reward" and "bias" alongside its normal self-description tokens.</p><h2><b>Post-training installs a point of view, and the model starts monitoring itself</b></h2><p>Comparing a post-trained model against its base model revealed that the fine-tuning process causes the workspace to acquire what the researchers call the Assistant's "point of view." When a user mentioned taking 8000 mg of Tylenol — a dangerous overdose — the post-trained model's workspace read "unsafe," "dangerous," and "WARNING" while still reading the user's sentence. The base model's workspace at the same position showed only "pain," "now," and "feels."</p><p>More striking still, the post-trained model appeared to monitor its own behavior. When roleplaying a non-Claude character, the workspace surfaced "disclaimer" and "fictional" — words absent from both prompt and output. When forced to select an option it did not prefer, an all-caps "BUT" appeared internally, even as the model argued for the prefilled choice without complaint. And when the model failed to suppress a thought it had been told not to have — a "white bear" effect familiar from psychology — it registered "damn" and failure-related words in the workspace, but only in the post-trained model, not the base.</p><h2><b>What the discovery means — and doesn't mean — for the question of machine consciousness</b></h2><p>The researchers engage carefully with the consciousness question and draw a sharp line between "<a href="https://transformer-circuits.pub/2026/workspace/index.html#intro-human-workspace">access consciousness</a>" — the functional notion of information being available for report and reasoning — and "<a href="https://www.sciencedirect.com/topics/social-sciences/phenomenal-consciousness">phenomenal consciousness</a>," the subjective quality of experience. "We take no position on this issue," the paper states regarding the latter, "and instead focus on the functional role played by consciously accessible information."</p><p>They also catalogue important differences. The brain sustains its workspace through recurrent loops; Claude's workspace evolves over a single forward pass. Human working memory degrades within seconds; Claude can recall information from anywhere in its context. And while human conscious experience includes visual, spatial, and bodily sensations, the model's workspace is organized almost entirely around words — likely because words are its only mode of action.</p><p>As of 2026, the scientific community remains divided. "Disagreement and uncertainty about AI consciousness persist among philosophers, scientists, and technical experts," and the field "remains in its earliest phase" of grappling with what consciousness even is and how you would detect it in another being. The Anthropic paper does not resolve these debates.</p><p>But the researchers close with a provocation that is likely to reverberate well beyond the interpretability community. "That such a structure exists at all in language models is striking," they write. "It suggests that the functional architecture associated with conscious access is not an accident of biological implementation, but a solution that learning systems converge on when faced with the right computational pressures."</p><p>If the mind is an ocean, as the paper's authors write in their opening line, they have spent the last year charting its currents in a system that has no biology, no evolution, and no body — and found, beneath the surface, a structure that looks unsettlingly like the one we use to think.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Five questions for Dr. Rubin, who’s armed with a mic and a bowtie]]></title>
<description><![CDATA[Bullshit is cheap but truth is expensive. Anyone with half a brain cell can post wild misinformation that goes mega viral, which wastes the time and expertise of highly trained people who feel an obligation to inform others of the truth. Today I want you to meet one of those highly-trained people...]]></description>
<link>https://tsecurity.de/de/3649513/it-nachrichten/five-questions-for-dr-rubin-whos-armed-with-a-mic-and-a-bowtie/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3649513/it-nachrichten/five-questions-for-dr-rubin-whos-armed-with-a-mic-and-a-bowtie/</guid>
<pubDate>Mon, 06 Jul 2026 19:47:59 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Bullshit is cheap but truth is expensive. Anyone with half a brain cell can post wild misinformation that goes mega viral, which wastes the time and expertise of highly trained people who feel an obligation to inform others of the truth. Today I want you to meet one of those highly-trained people, Dr. Zachary Rubin, […]]]></content:encoded>
</item>
<item>
<title><![CDATA[Wenn KI vom Werkzeug zum Akteur wird]]></title>
<description><![CDATA[... IT-Security. Konsolidierung der Tochterunternehmen. TechniData bündelt Cloud und Security unter einem Dach · Ein Co-Brain ist die digitale, KI ...]]></description>
<link>https://tsecurity.de/de/3649415/it-security-nachrichten/wenn-ki-vom-werkzeug-zum-akteur-wird/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3649415/it-security-nachrichten/wenn-ki-vom-werkzeug-zum-akteur-wird/</guid>
<pubDate>Mon, 06 Jul 2026 18:43:28 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[... <b>IT</b>-<b>Security</b>. Konsolidierung der Tochterunternehmen. TechniData bündelt Cloud und Security unter einem Dach · Ein Co-Brain ist die digitale, KI ...]]></content:encoded>
</item>
<item>
<title><![CDATA[PicoCTF Web Exploitation Easy Category Web Challenge [SSTL 1]]]></title>
<description><![CDATA[Photo by Alexandre Debiève on UnsplashChallenge Statement :- I made a cool website where you can announce whatever you want! Try it out. Additional details will be available after launching your challenge instance .Now here in this website we have to make the announcements and then observe the re...]]></description>
<link>https://tsecurity.de/de/3647971/hacking/picoctf-web-exploitation-easy-category-web-challenge-sstl-1/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3647971/hacking/picoctf-web-exploitation-easy-category-web-challenge-sstl-1/</guid>
<pubDate>Mon, 06 Jul 2026 08:53:07 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/0*cYjIyehGu_igLY8t"><figcaption>Photo by <a href="https://unsplash.com/@alexkixa?utm_source=medium&amp;utm_medium=referral">Alexandre Debiève</a> on <a href="https://unsplash.com/?utm_source=medium&amp;utm_medium=referral">Unsplash</a></figcaption></figure><ul><li><strong>Challenge Statement</strong> :- I made a cool website where you can announce whatever you want! Try it out. Additional details will be available after launching your challenge instance .</li><li>Now here in this website we have to make the announcements and then observe the response . So from the challenge we have known that here we have to implement the Server Side Template Injection .</li></ul><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*FO3Rp5BJv0cploQJDUHpbQ.png"><figcaption>Challenge Photo</figcaption></figure><ul><li><strong>Templates</strong> :- This are the files that enables the the developers to generate the dynamic web pages by placing the placeholders for the variables. Because other wise this would become a manual tedious job for them to update the variable for each user. This is done automatically by the template engine .</li><li><strong>Server Side Template Injection</strong> :- This is the type of injection that occurs in the templates when it does not properly validate the user input and sometimes also executes the user instructions in some of the cases . For example in the image below .</li></ul><figure><img alt="" src="https://cdn-images-1.medium.com/max/881/1*vDjdFET7SAvLAIIbMzLHxA.png"><figcaption>Example</figcaption></figure><ul><li>Now what happens is that it becomes dangerous because it allows for the remote code execution, access to the configurations objects, secret keys and system internals and etc .</li><li>So first in the challenge we will start by checking that which of the template is being used in this challenge and then we will construct our payload . So we will give the inputs like {{ 8*8 }}, ${ 8*8 } and then notice where does it gives the answer .</li><li><strong>Checking for {{ 8*8 }}</strong></li></ul><figure><img alt="" src="https://cdn-images-1.medium.com/max/892/1*D7cz59WvLBzx7uMovm1AOQ.png"><figcaption>{{ 8* 8 }}</figcaption></figure><ul><li>So in this we got the output . Let’s Try Others As Well .</li></ul><figure><img alt="" src="https://cdn-images-1.medium.com/max/888/1*Ap5KeXTZyhIbuTnV6SX7Pw.png"><figcaption>As it is Output for Others</figcaption></figure><ul><li>So we saw that in other cases we did not get the result it just produced the as it is input. So know we have known that this template executes the instructions inside the <strong><em>{{variable }} </em></strong>.</li><li>So below in the image i have attached the some of the types of templates with their supported formats and the languages.</li></ul><figure><img alt="" src="https://cdn-images-1.medium.com/max/699/1*ooWR4Jj5mefdBde0BX3jVw.png"><figcaption>Template Types</figcaption></figure><ul><li>So from this we can get the idea that the template in our webpage can be the Jinja2, Handlebar, Twig. So first we test for the Jinja2 by inserting the {{ config }}, {{ self }} etc .</li></ul><figure><img alt="" src="https://cdn-images-1.medium.com/max/889/1*aU4NJo4CwFmXmUR-RVRZ9Q.png"><figcaption>{{ config }} and{{ self }}</figcaption></figure><ul><li>And yes we got he valid output for the {{ self }} and {{ config }} and this confirms the Jinja2 template so now before seeing to the final payload we must first understand some of the import functions, dictionaries, objects, commands to fully understand the final payloads .</li><li><strong><em>{{ config }}</em></strong><em> :- This is flask configuration object which contains the configuration files information, secret keys, database urls, settings, session configurations. Below we have tried for the {{ config }}, {{ config.items }}, {{ config.__class__.__init__.__globals__ }} .</em></li></ul><figure><img alt="" src="https://cdn-images-1.medium.com/max/623/1*a_Q4QAPh3rACoAgEtZ3DtA.png"><figcaption><em>{{ config }}, {{ config.items }}, {{ config.__class__.__init__.__globals__ }}</em></figcaption></figure><ul><li><strong><em>{{ request }} </em></strong><em>:- It is the flask request object which represents the current HTTP request . Here we have checked for the {{ request.application }}, {{ request.method }}, {{ request.url }}, {{ request.headers }} .</em></li></ul><figure><img alt="" src="https://cdn-images-1.medium.com/max/617/1*qm7CHdzsP75p8wOWr1TYTg.png"><figcaption><em>{ request.application }}, {{ request.method }}, {{ request.url }}, {{ request.headers }}</em></figcaption></figure><ul><li><strong><em>{{ self }}</em></strong><em> :- This is the template reference object which sometimes information about the system internals. Generally we test for the {{ self }}, {{ self.__init__.__globals__ }} .</em></li></ul><figure><img alt="" src="https://cdn-images-1.medium.com/max/616/1*HvkqlX7TTG1j5VP9pVP05Q.png"><figcaption><em>{{ self.__init__.__globals__ }}</em></figcaption></figure><ul><li>{{__init__}} :- This is the constructor method object .</li><li>{{__globals__}} :- This is the dictionary of the every object which contains all the global variables, built in preferences, tools, libraries, functions .</li><li>{{__import__(’os’) }} :- This function is executed when we write the import os in the code .</li><li>popen(’ls’).read() :- This is used for the execution of the command on the system and read() is used for the human readable text produced otherwise we will get the object reference output .</li><li>{{__builtins__}} :- This contains the various libraries and functions like import, open, exec, eval and etc .</li><li>So we have understood the all the necessary concepts now we have used the 4 types of payload that would give us the flag. The above explanation will help to connect each every component of payload that why we wrote this object, library in this. So here are they :-</li></ul><p><em>{{ self.__init__.__globals__.__builtins__.__import__(’os’).popen(’ls’).read() }}</em></p><p><em>{{ self.__init__.__globals__.__builtins__.open(’flag’) }}</em></p><p><em>{{ request.application.__globals__.__builtins__.__import__(’os’).popen(’ls’).read() }}</em></p><p><em>{{ config.__class__.__init__.__globals__[’os’].popen(’cat flag’).read() }}</em></p><figure><img alt="" src="https://cdn-images-1.medium.com/max/755/1*y0iGbjMklFnLTYABwjjTUQ.png"><figcaption>Flag</figcaption></figure><ul><li>Learning of the concepts of from this writeup :-</li><li>Template and Template Meaning .</li><li>Server Side Template Injection Meaning .</li><li>Jinja2, Handlebar, Freemaker, Twig, Smarty, ERB Templates and Their Formats .</li><li>{{ config }}, {{ request }}, {{ self }}.</li><li>popen, read, init, globals, import functions and dictionaries .</li></ul><p><strong>Final Takeway</strong></p><p><em>Easy challenges are not about “easy flags”. They are about building the foundation for harder ones .</em></p><p><em>This SSTI challenge was not just about typing </em><em>{{ 8*8 }} and seeing 64.</em></p><p><em>It was about training your brain to:</em></p><p><em>a. Identify template engines instead of guessing blindly.</em></p><p><em>b. Test payload patterns methodically.</em></p><p><em>c. Understand why </em><em>{{ }} works but </em><em>${ } doesn’t.</em></p><p><em>d. Explore objects like </em><em>config, </em><em>request, and </em><em>self with intent.</em></p><p><em>e. Trace how </em><em>__init__, </em><em>__globals__, and </em><em>__builtins__ connect internally.</em></p><p><em>Most people stop when they get code execution. But the real learning starts when you ask:</em></p><p><em>Why did this payload work?</em></p><p><em>How did it reach the </em><em>os module?</em></p><p><em>What object chain allowed access to system commands?</em></p><p><em>How does Jinja2 expose Python internals?</em></p><p><em>It is about understanding how templating engines process input. It is about understanding how templating engines process input. How objects are structured in memory. How Python exposes global namespaces. How unsafe rendering turns logic into execution.</em></p><p><em>If you only copy-paste payloads, you will solve easy challenges. If you understand the object traversal path, you will solve the hard ones. CTFs are not about the flag. They are about learning how applications actually break.</em></p><p><em>Go deeper than the payload. Go deeper than the writeup. Go deeper than the solution.</em></p><p><em>More templates. More internals. More real exploitation.</em></p><h3>Happy Hacking.</h3><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/0*9kQQiZ6yFCdNq8tM"><figcaption>Photo by <a href="https://unsplash.com/@clarktibbs?utm_source=medium&amp;utm_medium=referral">Clark Tibbs</a> on <a href="https://unsplash.com/?utm_source=medium&amp;utm_medium=referral">Unsplash</a></figcaption></figure><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=1fc109221169" width="1" height="1" alt=""><hr><p><a href="https://infosecwriteups.com/picoctf-web-exploitation-easy-category-web-challenge-sstl-1-1fc109221169">PicoCTF Web Exploitation Easy Category Web Challenge [SSTL 1]</a> was originally published in <a href="https://infosecwriteups.com/">InfoSec Write-ups</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Hobbit-like Humans May Have Scavenged Komodo Dragons' Leftovers to Survive]]></title>
<description><![CDATA[CNN reports:


Prehistoric human relatives, nicknamed "hobbits" due to their short stature, may have been scavengers, rather than skilled hunters capable of taking down big game or building cooking fires, according to new research. The study adds to growing evidence that Homo floresiensis, which ...]]></description>
<link>https://tsecurity.de/de/3646462/it-security-nachrichten/hobbit-like-humans-may-have-scavenged-komodo-dragons-leftovers-to-survive/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3646462/it-security-nachrichten/hobbit-like-humans-may-have-scavenged-komodo-dragons-leftovers-to-survive/</guid>
<pubDate>Sun, 05 Jul 2026 10:52:38 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[CNN reports:


Prehistoric human relatives, nicknamed "hobbits" due to their short stature, may have been scavengers, rather than skilled hunters capable of taking down big game or building cooking fires, according to new research. The study adds to growing evidence that Homo floresiensis, which had a brain only slightly bigger than that of a chimpanzee, wasn't as advanced as scientists previously believed.... 

The researchers believe that much like how Komodo dragons hunt water buffaloes today, they were using their venomous bite to take down Stegodons — and after the scene was clear, Homo floresiensis swept in to cleave meat from what remained... The new study reinforces a long-held suspicion that Homo floresiensis is not a dwarfed form of Homo erectus but a descendant of a more primitive Homo habilis-like or Australopithecus-like form that arrived on the island more than1 million years ago, said Dr. Chris Stringer, a research leader specializing in human origins and paleoanthropology at London's Natural History Museum.

<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=Hobbit-like+Humans+May+Have+Scavenged+Komodo+Dragons'+Leftovers+to+Survive+%3A+https%3A%2F%2Fentertainment.slashdot.org%2Fstory%2F26%2F07%2F04%2F0756247%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fentertainment.slashdot.org%2Fstory%2F26%2F07%2F04%2F0756247%2Fhobbit-like-humans-may-have-scavenged-komodo-dragons-leftovers-to-survive%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://entertainment.slashdot.org/story/26/07/04/0756247/hobbit-like-humans-may-have-scavenged-komodo-dragons-leftovers-to-survive?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[TryHackMe CTF Writeup of Hidden Deep Into my Heart]]></title>
<description><![CDATA[Photo by Adi Goldstein on UnsplashHey guys, I am V3n0mKai back again with the New CTF Writeup on the TryHackMe CTF called “Hidden Deep Into my Heart”.This CTF is of the web category and from the challenge statement it seems like we have to find something hidden directories in order to get the fla...]]></description>
<link>https://tsecurity.de/de/3646315/hacking/tryhackme-ctf-writeup-of-hidden-deep-into-my-heart/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3646315/hacking/tryhackme-ctf-writeup-of-hidden-deep-into-my-heart/</guid>
<pubDate>Sun, 05 Jul 2026 08:39:08 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/0*LvU9h5VjEFxvptzD"><figcaption>Photo by <a href="https://unsplash.com/@adigold1?utm_source=medium&amp;utm_medium=referral">Adi Goldstein</a> on <a href="https://unsplash.com/?utm_source=medium&amp;utm_medium=referral">Unsplash</a></figcaption></figure><ul><li>Hey guys, I am V3n0mKai back again with the New CTF Writeup on the TryHackMe CTF called “Hidden Deep Into my Heart”.</li><li><strong>This CTF is of the web category and from the challenge statement it seems like we have to find something hidden directories in order to get the flag </strong>.</li></ul><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*ZOfktlHQQ_JnfAO5APp2ug.png"><figcaption>Challenge Photo and Text</figcaption></figure><ul><li>Now here we have to first on the “Start Machine” and “Start the Attack Box”, after that we will be able to access the website .</li></ul><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*qtKe_G9K2XX55iBICx6Ynw.png"><figcaption>The website page</figcaption></figure><ul><li>Now here in this we will first of all look for the basic endpoints, files and directory traversal and finding some hidden secrets.</li><li>So we tried the following things :- robots.txt, sitemap.xml, source code analysis, basic developer tools inspection, trying the basic directories common names on the URL.</li><li><strong><em>Robots.txt</em></strong><em> :- A state policy file which is placed in the root directory of every web application and implements the REP [Robot Exclusion Protocol] which instructs all the web crawlers which URLs to crawl and which URLs not to so as to avoid being sensitive urls appearing in the web searches, decreasing the web traffic as no duplicate search results and etc .</em></li><li><em>Also note the difference between the Crawling and Indexing. </em><strong><em>Crawling</em></strong><em> is that thew browser reads the contents of the page and then lists it on the search results and </em><strong><em>Indexing</em></strong><em> is just saving the metadata and the urls.</em></li><li><em>But we have the </em><strong><em>X-Robot-Tag:noindex</em></strong><em> tag to ensure that the page is not indexed and also does not appear in the search results as well, but for this work the crawling for that page must allowed in the robots.txt because without that it index the page.</em></li><li><strong><em>Sitemap.xml </em></strong><em>:- It is the extra markup language file of the lists of the important urls of that web application and also the crawlers refer this file as well for the crawling output.</em></li><li>Some of the common names of the directories we can try is like :- <em>admin, login, admin-panel, robots.txt, sitemap.xml, secret, index.php and many more</em>. We can also find this in my wordlists and also via github repositories as well.</li><li>Now in the robots.txt we found one directory names as “<strong>cupids_secret_vault</strong>” and then when we traversed to that directory we got this .</li></ul><figure><img alt="" src="https://cdn-images-1.medium.com/max/962/1*cMobXaeEJjAfbllAn7GGEQ.png"><figcaption>Robots.txt</figcaption></figure><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*EVZRPA3OYc4FvJdpeSIj-g.png"><figcaption>The Webpage of the directory from the robots.txt</figcaption></figure><ul><li>Now from here we tried the <strong>gobuster scanning</strong> on the both parts of the url that is first, normal ip url and then second, the one with directory found from the robots.txt also included as well. So started two scans on that.</li><li>So before proceeding further we should first understand that what is actually the gobuster tool in detail and also see the most important flags we could use it to extract the information and do effective directory enumeration from that.</li><li><strong>Gobuster </strong>:- This tool for the directory and files enumeration across the web application by crafting the proper command with valid syntax and extracting any sensitive files from the web application as well. This tool is written in the go language.</li><li>Gobuster is a <strong>concurrent brute-force engine written in Go</strong>. It: Takes a word, Injects it somewhere, Compares response, Filters output .</li><li>Below diagrams images shows every important flags and options of the gobuster which we ca use enumeration process.</li></ul><figure><img alt="" src="https://cdn-images-1.medium.com/max/508/1*l8ueTRd9Li5y4Koxs1Evcg.png"><figcaption>Gobuster Dir Mode</figcaption></figure><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*It-LF0Cl__qt_Pw7vEXRcw.png"><figcaption>Gobuster DNS Mode</figcaption></figure><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*ukJf6GOVUPY0PaF4Ho1lTA.png"><figcaption>Gobuster VHOST Mode</figcaption></figure><figure><img alt="" src="https://cdn-images-1.medium.com/max/856/1*aLKJZlN4E_VUaMwCsCsIiA.png"><figcaption>Gobuster S3 Mode</figcaption></figure><figure><img alt="" src="https://cdn-images-1.medium.com/max/902/1*SYwyTb0bAl1nNdw6-EQRLA.png"><figcaption>Gobuster Fuzz Mode</figcaption></figure><ul><li>Now as we have seen the gobuster command all the necessary so for the detecting the hidden directory enumeration we tried the below command .</li></ul><pre>gobuster dir -u http://10.49.155.99:5000/cupids_secret_vault/ -w /usr/share/wordlists/dirbuster/directory-list-2.3-small.txt -t 100</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/962/1*3OXs3pRbUScnof0RYHtVHQ.png"><figcaption>Scan 1</figcaption></figure><figure><img alt="" src="https://cdn-images-1.medium.com/max/960/1*5y_dt62oe9dSeCfCJiBp3Q.png"><figcaption>Scan 2</figcaption></figure><ul><li>As we can see that we have found <strong>/administrator </strong>directory in the scan 2 output. On navigating to the directory it was a login page .</li></ul><figure><img alt="" src="https://cdn-images-1.medium.com/max/961/1*jgCY1dy5yk5umSygU8Znow.png"><figcaption>The administrator path</figcaption></figure><ul><li>Now here we have to try bit of the brute force and some common techniques of the username and password.</li><li>So we tried some of them and some basic <strong>SQL Injection Payloads</strong> like ‘<strong> OR 1=1 — , ‘ AND 1=1 — , ‘ OR 1=2 — , ‘AND 1=2 —</strong> but it didn’t worked.</li><li>Then we tried the combinations like :- <em>admin &amp; admin, admin &amp; password, administrator &amp; admin and etcetra</em>. This also didn’t worked. Now we saw that we also found comment text in the robots.txt which was ‘<em>cupid_arrow_2026!!!</em>’.</li><li>So keeping the <strong><em>username:admin </em></strong>and the <strong><em>password:cupid_arrow_2026!!!</em></strong>, we attempted and <strong><em>voila we found the flag</em></strong>.</li></ul><figure><img alt="" src="https://cdn-images-1.medium.com/max/961/1*FnnRCFdcpqeeoNzzY4APkw.png"><figcaption>Final Flag</figcaption></figure><h3>Final Takeaway</h3><p><em>Easy challenges are not about “easy wins.”</em></p><p><em>They are about sharpening instincts.</em></p><p><em>This TryHackMe room wasn’t about advanced exploitation.<br>It was about observation, enumeration, and thinking systematically.</em></p><p><em>CTFs are not about getting the flag.</em></p><p><em>They are about training your brain to:</em></p><p><em>Look at robots.txt even when others skip it.</em></p><p><em>a.] Understand crawling vs indexing instead of memorizing definitions.<br>b.] Enumerate directories methodically, not randomly.<br>c.] Use tools like Gobuster with purpose, not blindly.<br>d.] Notice comments, hints, and small clues hidden in plain sight.</em></p><p><em>Security is rarely about complex zero-days.</em></p><p><em>It is often about:</em></p><p><em>Misplaced secrets.<br>Exposed directories.<br>Poor credential hygiene.<br>Developers leaving breadcrumbs behind.</em></p><p><em>This challenge reinforced something important:</em></p><p><em>Enumeration is power.<br>Patience is power.<br>Attention to detail is power.</em></p><p><em>If this writeup helped you strengthen your fundamentals in web enumeration and directory discovery, consider sharing it with your peers.</em></p><p><em>More enumeration.<br>More hidden paths.<br>More structured thinking.</em></p><p><em>Happy Hacking.</em></p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/0*sbC3odMVGfTfGS3H"><figcaption>Photo by <a href="https://unsplash.com/@csbphotography?utm_source=medium&amp;utm_medium=referral">Conor Samuel</a> on <a href="https://unsplash.com/?utm_source=medium&amp;utm_medium=referral">Unsplash</a></figcaption></figure><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=a6624334a4b0" width="1" height="1" alt=""><hr><p><a href="https://infosecwriteups.com/tryhackme-ctf-writeup-of-hidden-deep-into-my-heart-a6624334a4b0">TryHackMe CTF Writeup of Hidden Deep Into my Heart</a> was originally published in <a href="https://infosecwriteups.com/">InfoSec Write-ups</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[The Onion’s ‘Infowars’ Parody Is Here. Alex Jones Is Going to Hate It]]></title>
<description><![CDATA[The satirical site is fighting to officially take over Infowars. In the meantime, CEO Ben Collins says the new show will mock “how fucking stupid” conspiratorial brain rot has become.]]></description>
<link>https://tsecurity.de/de/3642502/it-nachrichten/the-onions-infowars-parody-is-here-alex-jones-is-going-to-hate-it/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3642502/it-nachrichten/the-onions-infowars-parody-is-here-alex-jones-is-going-to-hate-it/</guid>
<pubDate>Fri, 03 Jul 2026 02:17:50 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The satirical site is fighting to officially take over Infowars. In the meantime, CEO Ben Collins says the new show will mock “how fucking stupid” conspiratorial brain rot has become.]]></content:encoded>
</item>
<item>
<title><![CDATA['Does He Think He's Real?' Social Media Reacts to Trump's Talk With AI Teddy Roosevelt]]></title>
<description><![CDATA[The current president chatted with a life-sized AI version of the 26th US president at the new Theodore Roosevelt presidential library.]]></description>
<link>https://tsecurity.de/de/3642407/it-nachrichten/does-he-think-hes-real-social-media-reacts-to-trumps-talk-with-ai-teddy-roosevelt/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3642407/it-nachrichten/does-he-think-hes-real-social-media-reacts-to-trumps-talk-with-ai-teddy-roosevelt/</guid>
<pubDate>Fri, 03 Jul 2026 01:02:54 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The current president chatted with a life-sized AI version of the 26th US president at the new Theodore Roosevelt presidential library.]]></content:encoded>
</item>
<item>
<title><![CDATA[2026 BAIR Graduate Showcase]]></title>
<description><![CDATA[Congratulations to the Berkeley Artificial Intelligence Research (BAIR) Lab class of 2026! This year, BAIR celebrates another remarkable group of Ph.D. graduates whose curiosity, creativity, and perseverance have pushed the frontiers of artificial intelligence and machine learning.

Their work sp...]]></description>
<link>https://tsecurity.de/de/3639545/ai-nachrichten/2026-bair-graduate-showcase/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3639545/ai-nachrichten/2026-bair-graduate-showcase/</guid>
<pubDate>Wed, 01 Jul 2026 21:33:50 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- twitter -->










<p>Congratulations to the Berkeley Artificial Intelligence Research (BAIR) Lab class of 2026! This year, BAIR celebrates another remarkable group of Ph.D. graduates whose curiosity, creativity, and perseverance have pushed the frontiers of artificial intelligence and machine learning.</p>

<p>Their work spans the breadth of modern AI — robotics and embodied intelligence, large language models and reasoning, computer vision, generative modeling, AI safety, human-AI interaction, AI for science and healthcare, and much more. Along the way, they have published influential research, built systems with real-world impact, mentored their peers, and shaped the BAIR community for the better.</p>

<p>Now they are headed everywhere ideas travel: to faculty and postdoctoral positions, to industry research labs, and to startups of their own founding — and several are still exploring what comes next and would love to hear from you.</p>

<p>Please join us in celebrating the achievements of these wonderful graduates. We are proud of everything they have accomplished at Berkeley, and we can’t wait to see what they do next!</p>

<!--more-->

<p><small><i>Thank you to our friends at the <a href="https://ai.stanford.edu/blog/sail-graduates/">Stanford AI Lab</a> for this idea!</i></small></p>

<hr>

<div class="container">
  <div class="row">
    
    
      <div class="col-md-4">
        <div class="card mb-4 shadow-sm">
          <a href="https://bfshi.github.io/"><img src="https://bair.berkeley.edu/static/blog/grads2026/baifeng-shi.jpg" alt="Baifeng Shi" class="bd-placeholder-img card-img-top" width="480" height="auto"></a>
          <div class="card-body">
            <p class="card-text">
              </p><h1>Baifeng Shi</h1><br>
              <strong>Email:</strong><a href="mailto:baifeng_shi@berkeley.edu"> baifeng_shi@berkeley.edu</a><br>
              <strong>Website:</strong> <a href="https://bfshi.github.io/">https://bfshi.github.io/</a><br>
              
              <strong>Advisor(s):</strong> Trevor Darrell<br>
              
              <strong>Research Blurb:</strong> I work on building generalist vision and robotic models.<br>
              
              
              <strong>What's next:</strong> Member of Technical Staff at Physical Intelligence
              
              
            
          </div>
        </div>
      </div>
      <hr>
    
      <div class="col-md-4">
        <div class="card mb-4 shadow-sm">
          <a href="https://sea-snell.github.io/"><img src="https://bair.berkeley.edu/static/blog/grads2026/charlie-snell.jpg" alt="Charlie Snell" class="bd-placeholder-img card-img-top" width="480" height="auto"></a>
          <div class="card-body">
            <p class="card-text">
              </p><h1>Charlie Snell</h1><br>
              <strong>Email:</strong><a href="mailto:csnell22@berkeley.edu"> csnell22@berkeley.edu</a><br>
              <strong>Website:</strong> <a href="https://sea-snell.github.io/">https://sea-snell.github.io</a><br>
              
              <strong>Advisor(s):</strong> Dan Klein<br>
              
              <strong>Research Blurb:</strong> My work aims to understand when and how the different LLM scaling paradigms can be traded off and interchanged. In particular, test-time scaling treats each prompt independently, drawing long chains of inferences and then forgetting them entirely between prompts. This differs critically from pretraining, which instead learns a compressed representation from a large dataset. I believe bridging the gap between these methods of scaling computation, presents a key open challenge in the field: how can we develop methods which turn the inferences drawn at test-time back into learned representations that the model can hold onto across interactions.<br>
              
            
          </div>
        </div>
      </div>
      <hr>
    
      <div class="col-md-4">
        <div class="card mb-4 shadow-sm">
          <a href="https://devinguillory.com/"><img src="https://bair.berkeley.edu/static/blog/grads2026/devin-guillory.jpg" alt="Devin Guillory" class="bd-placeholder-img card-img-top" width="480" height="auto"></a>
          <div class="card-body">
            <p class="card-text">
              </p><h1>Devin Guillory</h1><br>
              <strong>Email:</strong><a href="mailto:dguillory@berkeley.edu"> dguillory@berkeley.edu</a><br>
              <strong>Website:</strong> <a href="https://devinguillory.com/">https://devinguillory.com</a><br>
              
              <strong>Advisor(s):</strong> Trevor Darrell<br>
              
              <strong>Research Blurb:</strong> Accounting for data shifts in computer vision models<br>
              
              
              <strong>What's next:</strong> Building collaborative AI systems, looking for conspirators.
              
              
            
          </div>
        </div>
      </div>
      <hr>
    
      <div class="col-md-4">
        <div class="card mb-4 shadow-sm">
          <a href="https://efleisig.com/"><img src="https://bair.berkeley.edu/static/blog/grads2026/eve-fleisig.jpg" alt="Eve Fleisig" class="bd-placeholder-img card-img-top" width="480" height="auto"></a>
          <div class="card-body">
            <p class="card-text">
              </p><h1>Eve Fleisig</h1><br>
              <strong>Email:</strong><a href="mailto:efleisig@berkeley.edu"> efleisig@berkeley.edu</a><br>
              <strong>Website:</strong> <a href="https://efleisig.com/">https://efleisig.com</a><br>
              
              <strong>Advisor(s):</strong> Dan Klein<br>
              
              <strong>Research Blurb:</strong> I design language models to work reliably and fairly for the broad range of real LLM users. First, my research leverages disagreement among user preferences as signal, in order to train and evaluate LLMs for entire populations of users. Second, I work on designing rigorous evaluations to extricate challenging LLM harms that diverse users face. Finally, I work on core technical failures of LLMs, like miscalibrated confidence, to reduce downstream risks when models are deployed to users with different needs. Combined, these interventions facilitate building LLMs that minimize societal harms, and maximize benefits to a wider range of real-world users.<br>
              
              
              <strong>What's next:</strong> Postdoctoral fellow at Princeton CITP
              
              
            
          </div>
        </div>
      </div>
      <hr>
    
      <div class="col-md-4">
        <div class="card mb-4 shadow-sm">
          <a href="https://graceluo.net/"><img src="https://bair.berkeley.edu/static/blog/grads2026/grace-luo.jpg" alt="Grace Luo" class="bd-placeholder-img card-img-top" width="480" height="auto"></a>
          <div class="card-body">
            <p class="card-text">
              </p><h1>Grace Luo</h1><br>
              <strong>Email:</strong><a href="mailto:graceluo@berkeley.edu"> graceluo@berkeley.edu</a><br>
              <strong>Website:</strong> <a href="https://graceluo.net/">https://graceluo.net</a><br>
              
              <strong>Advisor(s):</strong> Trevor Darrell<br>
              
              <strong>Research Blurb:</strong> My research is on interpreting and controlling generative models. For example, I've worked on re-purposing image generators for computer vision tasks, and meta-modeling language activations for better LLM probing and steering.<br>
              
              
              <strong>What's next:</strong> Research scientist in industry
              
              
            
          </div>
        </div>
      </div>
      <hr>
    
      <div class="col-md-4">
        <div class="card mb-4 shadow-sm">
          <a href="https://hanlinzhu.com/"><img src="https://bair.berkeley.edu/static/blog/grads2026/hanlin-zhu.jpg" alt="Hanlin Zhu" class="bd-placeholder-img card-img-top" width="480" height="auto"></a>
          <div class="card-body">
            <p class="card-text">
              </p><h1>Hanlin Zhu</h1><br>
              <strong>Email:</strong><a href="mailto:hanlinzhu@berkeley.edu"> hanlinzhu@berkeley.edu</a><br>
              <strong>Website:</strong> <a href="https://hanlinzhu.com/">https://hanlinzhu.com/</a><br>
              
              <strong>Advisor(s):</strong> Stuart Russell, Jiantao Jiao<br>
              
              <strong>Research Blurb:</strong> My research centers on understanding and improving the reasoning capabilities of large language models (LLMs).<br>
              
              
              <strong>What's next:</strong> Member of Technical Staff at OpenAI
              
              
            
          </div>
        </div>
      </div>
      <hr>
    
      <div class="col-md-4">
        <div class="card mb-4 shadow-sm">
          <a href="https://haozhi.io/"><img src="https://bair.berkeley.edu/static/blog/grads2026/haozhi-qi.jpg" alt="Haozhi Qi" class="bd-placeholder-img card-img-top" width="480" height="auto"></a>
          <div class="card-body">
            <p class="card-text">
              </p><h1>Haozhi Qi</h1><br>
              <strong>Email:</strong><a href="mailto:hqi@berkeley.edu"> hqi@berkeley.edu</a><br>
              <strong>Website:</strong> <a href="https://haozhi.io/">https://haozhi.io/</a><br>
              
              <strong>Advisor(s):</strong> Jitendra Malik, Yi Ma<br>
              
              <strong>Research Blurb:</strong> Dexterous Manipulation and Robot Learning<br>
              
              
              <strong>What's next:</strong> Research scientist at Amazon; Faculty at University of Chicago
              
              
            
          </div>
        </div>
      </div>
      <hr>
    
      <div class="col-md-4">
        <div class="card mb-4 shadow-sm">
          <a href="https://zamfi.net/"><img src="https://bair.berkeley.edu/static/blog/grads2026/j-d-zamfirescu-pereira.jpg" alt="J.D. Zamfirescu-Pereira" class="bd-placeholder-img card-img-top" width="480" height="auto"></a>
          <div class="card-body">
            <p class="card-text">
              </p><h1>J.D. Zamfirescu-Pereira</h1><br>
              <strong>Email:</strong><a href="mailto:zamfi@berkeley.edu"> zamfi@berkeley.edu</a><br>
              <strong>Website:</strong> <a href="https://zamfi.net/">https://zamfi.net</a><br>
              
              <strong>Advisor(s):</strong> Bjoern Hartmann<br>
              
              <strong>Research Blurb:</strong> My research focuses on effective human-AI co-design. I study the boundaries of language interfaces as a medium for interacting with AI, creating systems that blend language-focused interactions with structured user interfaces that draw on different levels of abstraction. I focus on language-oriented technologies, like LLMs and text-to-image models, that are powerful mediators of design processes. These technologies enable humans to describe their desires at almost any level of abstraction, from high-level goals vaguely specified (“I’d like a game to help my kid learn to read”) to low-level corrections of undesired outputs (“Don’t say ‘I know because I’ve tasted it’ when about a recipe substitution's taste”).<br>
              
              
              <strong>What's next:</strong> Assistant Professor, Computer Science, UCLA
              
              
            
          </div>
        </div>
      </div>
      <hr>
    
      <div class="col-md-4">
        <div class="card mb-4 shadow-sm">
          <a href="https://jlian2.github.io/"><img src="https://bair.berkeley.edu/static/blog/grads2026/jiachen-lian.jpg" alt="Jiachen Lian" class="bd-placeholder-img card-img-top" width="480" height="auto"></a>
          <div class="card-body">
            <p class="card-text">
              </p><h1>Jiachen Lian</h1><br>
              <strong>Email:</strong><a href="mailto:jiachenlian@berkeley.edu"> jiachenlian@berkeley.edu</a><br>
              <strong>Website:</strong> <a href="https://jlian2.github.io/">https://jlian2.github.io</a><br>
              
              <strong>Advisor(s):</strong> Gopala Anumanchipalli<br>
              
              <strong>Research Blurb:</strong> My research focuses on human-centered AI across speech, healthcare, and systems.<br>
              
              
              <strong>Looking for:</strong> Look for AI talents to join our startup
              
              
            
          </div>
        </div>
      </div>
      <hr>
    
      <div class="col-md-4">
        <div class="card mb-4 shadow-sm">
          <a href="https://joshuaminwookang.github.io/"><img src="https://bair.berkeley.edu/static/blog/grads2026/josh-kang.jpg" alt="Josh Kang" class="bd-placeholder-img card-img-top" width="480" height="auto"></a>
          <div class="card-body">
            <p class="card-text">
              </p><h1>Josh Kang</h1><br>
              <strong>Email:</strong><a href="mailto:minwoo_kang@berkeley.edu"> minwoo_kang@berkeley.edu</a><br>
              <strong>Website:</strong> <a href="https://joshuaminwookang.github.io/">https://joshuaminwookang.github.io/</a><br>
              
              <strong>Advisor(s):</strong> John Canny<br>
              
              <strong>Research Blurb:</strong> I study language modeling and related topics in NLP; specific interests are human user simulation and building conversational, collaborative AI agents.<br>
              
              
              <strong>What's next:</strong> AI Scientist at Mistral AI
              
              
            
          </div>
        </div>
      </div>
      <hr>
    
      <div class="col-md-4">
        <div class="card mb-4 shadow-sm">
          <a href="https://www.linkedin.com/in/junhao-bear-xiong"><img src="https://bair.berkeley.edu/static/blog/grads2026/junhao-bear-xiong.jpg" alt="Junhao (Bear) Xiong" class="bd-placeholder-img card-img-top" width="480" height="auto"></a>
          <div class="card-body">
            <p class="card-text">
              </p><h1>Junhao (Bear) Xiong</h1><br>
              <strong>Email:</strong><a href="mailto:junhao_xiong@berkeley.edu"> junhao_xiong@berkeley.edu</a><br>
              <strong>Website:</strong> <a href="https://www.linkedin.com/in/junhao-bear-xiong">https://www.linkedin.com/in/junhao-bear-xiong</a><br>
              
              <strong>Advisor(s):</strong> Jennifer Listgarten, Yun Song<br>
              
              <strong>Research Blurb:</strong> Junhao (Bear) Xiong is a PhD candidate at UC Berkeley, advised by Jennifer Listgarten and Yun S. Song. His work focuses on machine learning methods for biology, with an emphasis on generative modeling for proteins. Previously, he studied Applied Math and Computer Science at Johns Hopkins.<br>
              
              
              <strong>Looking for:</strong> Research scientist
              
              
            
          </div>
        </div>
      </div>
      <hr>
    
      <div class="col-md-4">
        <div class="card mb-4 shadow-sm">
          <a href="https://kaylolittlejohn.com/"><img src="https://bair.berkeley.edu/static/blog/grads2026/kaylo-littlejohn.jpg" alt="Kaylo Littlejohn" class="bd-placeholder-img card-img-top" width="480" height="auto"></a>
          <div class="card-body">
            <p class="card-text">
              </p><h1>Kaylo Littlejohn</h1><br>
              <strong>Email:</strong><a href="mailto:kaylo_littlejohn@berkeley.edu"> kaylo_littlejohn@berkeley.edu</a><br>
              <strong>Website:</strong> <a href="https://kaylolittlejohn.com/">https://kaylolittlejohn.com</a><br>
              
              <strong>Advisor(s):</strong> Gopala Anumanchipalli<br>
              
              <strong>Research Blurb:</strong> My research is focused on speech modeling and natural language processing. I co-led the development of multimodal AI tools to accurately translate brain activity into text, audible personalized speech, and a high-fidelity "digital talking avatar" (Nature 2023, Nature Neuroscience 2025). I am also tech lead for voice modeling at Roblox.<br>
              
              
              <strong>Looking for:</strong> Research Scientist / Engineer
              
              
            
          </div>
        </div>
      </div>
      <hr>
    
      <div class="col-md-4">
        <div class="card mb-4 shadow-sm">
          <a href="https://kentkc.org/"><img src="https://bair.berkeley.edu/static/blog/grads2026/kent-chang.jpg" alt="Kent Chang" class="bd-placeholder-img card-img-top" width="480" height="auto"></a>
          <div class="card-body">
            <p class="card-text">
              </p><h1>Kent Chang</h1><br>
              <strong>Email:</strong><a href="mailto:kentkchang@berkeley.edu"> kentkchang@berkeley.edu</a><br>
              <strong>Website:</strong> <a href="https://kentkc.org/">https://kentkc.org</a><br>
              
              <strong>Advisor(s):</strong> David Bamman<br>
              
              <strong>Research Blurb:</strong> I work on NLP and multimodal machine learning, with a focus on evaluating large language models and building multimodal systems for understanding dialogue, narrative, and social interaction. My research includes benchmarks for LLM memorization, multimodal datasets sourced from feature films and television, and studies of model behavior. I'm interested in bridging computational methods with questions from the humanities and social sciences about whose voices get represented in AI systems, and about AI's broader impact. My work has appeared at EMNLP and ACL, among others.<br>
              
              
              <strong>Looking for:</strong> (teaching) faculty, Research Scientist, ML/AI SWE
              
              
            
          </div>
        </div>
      </div>
      <hr>
    
      <div class="col-md-4">
        <div class="card mb-4 shadow-sm">
          <a href="https://kevin.black/"><img src="https://bair.berkeley.edu/static/blog/grads2026/kevin-black.jpg" alt="Kevin Black" class="bd-placeholder-img card-img-top" width="480" height="auto"></a>
          <div class="card-body">
            <p class="card-text">
              </p><h1>Kevin Black</h1><br>
              <strong>Email:</strong><a href="mailto:kvablack@berkeley.edu"> kvablack@berkeley.edu</a><br>
              <strong>Website:</strong> <a href="https://kevin.black/">https://kevin.black</a><br>
              
              <strong>Advisor(s):</strong> Sergey Levine<br>
              
              <strong>Research Blurb:</strong> I work on large-scale robot learning: including imitation learning, reinforcement learning, generative modeling, real-time control, and whatever else it takes to make robots work in the real world!<br>
              
              
              <strong>What's next:</strong> Research Scientist of Physical Intelligence
              
              
            
          </div>
        </div>
      </div>
      <hr>
    
      <div class="col-md-4">
        <div class="card mb-4 shadow-sm">
          <a href="https://www.kunheyang.com/"><img src="https://bair.berkeley.edu/static/blog/grads2026/kunhe-yang.jpg" alt="Kunhe Yang" class="bd-placeholder-img card-img-top" width="480" height="auto"></a>
          <div class="card-body">
            <p class="card-text">
              </p><h1>Kunhe Yang</h1><br>
              <strong>Email:</strong><a href="mailto:kunheyang@berkeley.edu"> kunheyang@berkeley.edu</a><br>
              <strong>Website:</strong> <a href="https://www.kunheyang.com/">https://www.kunheyang.com/</a><br>
              
              <strong>Advisor(s):</strong> Nika Haghtalab<br>
              
              <strong>Research Blurb:</strong> My research focuses on the theoretical foundations of designing and evaluating AI algorithms in environments shaped by human incentives and AI agency. My work spans human-centric policy learning, incentive-aware evaluation, and multi-agent collaboration and information transmission, drawing on tools from machine learning theory and computational economics.<br>
              
              
              <strong>What's next:</strong> Postdoc Research at Stanford
              
              
            
          </div>
        </div>
      </div>
      <hr>
    
      <div class="col-md-4">
        <div class="card mb-4 shadow-sm">
          <a href="https://lisabdunlap.com/"><img src="https://bair.berkeley.edu/static/blog/grads2026/lisa-dunlap.jpg" alt="Lisa Dunlap" class="bd-placeholder-img card-img-top" width="480" height="auto"></a>
          <div class="card-body">
            <p class="card-text">
              </p><h1>Lisa Dunlap</h1><br>
              <strong>Email:</strong><a href="mailto:lisabdunlap@berkeley.edu"> lisabdunlap@berkeley.edu</a><br>
              <strong>Website:</strong> <a href="https://lisabdunlap.com/">https://lisabdunlap.com</a><br>
              
              <strong>Advisor(s):</strong> Joseph Gonzalez, Trevor Darrell<br>
              
              <strong>Research Blurb:</strong> Auditing generative models.<br>
              
              
              <strong>What's next:</strong> Research Engineer at Anthropic
              
              
            
          </div>
        </div>
      </div>
      <hr>
    
      <div class="col-md-4">
        <div class="card mb-4 shadow-sm">
          <a href="https://tonylian.com/"><img src="https://bair.berkeley.edu/static/blog/grads2026/long-tony-lian.jpg" alt="Long (Tony) Lian" class="bd-placeholder-img card-img-top" width="480" height="auto"></a>
          <div class="card-body">
            <p class="card-text">
              </p><h1>Long (Tony) Lian</h1><br>
              <strong>Email:</strong><a href="mailto:longlian@berkeley.edu"> longlian@berkeley.edu</a><br>
              <strong>Website:</strong> <a href="https://tonylian.com/">https://tonylian.com/</a><br>
              
              <strong>Advisor(s):</strong> Trevor Darrell, Adam Yala<br>
              
              <strong>Research Blurb:</strong> My research primarily focuses on developing real-time multi-modal multi-agent systems and parallel reasoning systems through end-to-end RL.<br>
              
              
              <strong>What's next:</strong> Member of Technical Staff at Thinking Machines Lab
              
              
            
          </div>
        </div>
      </div>
      <hr>
    
      <div class="col-md-4">
        <div class="card mb-4 shadow-sm">
          <a href="https://maulikb.com/"><img src="https://bair.berkeley.edu/static/blog/grads2026/maulik-bhatt.jpg" alt="Maulik Bhatt" class="bd-placeholder-img card-img-top" width="480" height="auto"></a>
          <div class="card-body">
            <p class="card-text">
              </p><h1>Maulik Bhatt</h1><br>
              <strong>Email:</strong><a href="mailto:maulikbhatt@berkeley.edu"> maulikbhatt@berkeley.edu</a><br>
              <strong>Website:</strong> <a href="https://maulikb.com/">https://maulikb.com</a><br>
              
              <strong>Advisor(s):</strong> Negar Mehr<br>
              
              <strong>Research Blurb:</strong> My research develops autonomous robots that can safely coordinate with humans and other robots in shared environments. I build scalable algorithms grounded in game theory and diffusion models that let agents reason about the intent and behavior of others around them. My work spans real-time multi-agent trajectory planning and imitation learning in the presence of multi-modality. I've validated these methods on hardware platforms ranging from quadrotors to manipulators, with the goal of making multi-agent coordination robust, interpretable, and deployable in the real world.<br>
              
              
              <strong>What's next:</strong> Joining Toyota Woven's end-to-end autonomous driving team.
              
              
            
          </div>
        </div>
      </div>
      <hr>
    
      <div class="col-md-4">
        <div class="card mb-4 shadow-sm">
          <a href="https://www.michaelpsenka.io/"><img src="https://bair.berkeley.edu/static/blog/grads2026/michael-psenka.jpg" alt="Michael Psenka" class="bd-placeholder-img card-img-top" width="480" height="auto"></a>
          <div class="card-body">
            <p class="card-text">
              </p><h1>Michael Psenka</h1><br>
              <strong>Email:</strong><a href="mailto:psenka@berkeley.edu"> psenka@berkeley.edu</a><br>
              <strong>Website:</strong> <a href="https://www.michaelpsenka.io/">https://www.michaelpsenka.io/</a><br>
              
              <strong>Advisor(s):</strong> Aditi Krishnapriyan<br>
              
              <strong>Research Blurb:</strong> Work in various domains (reinforcement learning, world models, AI+bio/chem), generally working on longer-horizon and out-of-distribution problems in planning and interpolation (e.g. robot manipulation from start state to goal, molecular dynamics of proteins between ground states). My thesis took a variational approach (think calculus of variations) directly from deep generative models of the environment, framing path-finding as minimizing a functional induced by the learned model itself (its score, its critic, or its dynamics). Through my research I've gained insight on how to properly handle dynamics in deep learning systems, and I plan to continue developing systems that are dynamic and adaptive.<br>
              
              
              <strong>What's next:</strong> Lead Research Scientist at Baseten
              
              
            
          </div>
        </div>
      </div>
      <hr>
    
      <div class="col-md-4">
        <div class="card mb-4 shadow-sm">
          <a href="https://nathanlichtle.com/"><img src="https://bair.berkeley.edu/static/blog/grads2026/nathan-lichtle.jpg" alt="Nathan Lichtlé" class="bd-placeholder-img card-img-top" width="480" height="auto"></a>
          <div class="card-body">
            <p class="card-text">
              </p><h1>Nathan Lichtlé</h1><br>
              <strong>Email:</strong><a href="mailto:nathan.lichtle@gmail.com"> nathan.lichtle@gmail.com</a><br>
              <strong>Website:</strong> <a href="https://nathanlichtle.com/">https://nathanlichtle.com</a><br>
              
              <strong>Advisor(s):</strong> Alexandre M. Bayen<br>
              
              <strong>Research Blurb:</strong> RL for autonomous driving.<br>
              
              
              <strong>What's next:</strong> Chief Scientist &amp; Co-founder at Yumi Health
              
              
            
          </div>
        </div>
      </div>
      <hr>
    
      <div class="col-md-4">
        <div class="card mb-4 shadow-sm">
          <a href="https://neerja.me/"><img src="https://bair.berkeley.edu/static/blog/grads2026/neerja-thakkar.jpg" alt="Neerja Thakkar" class="bd-placeholder-img card-img-top" width="480" height="auto"></a>
          <div class="card-body">
            <p class="card-text">
              </p><h1>Neerja Thakkar</h1><br>
              <strong>Email:</strong><a href="mailto:nthakkar@berkeley.edu"> nthakkar@berkeley.edu</a><br>
              <strong>Website:</strong> <a href="https://neerja.me/">https://neerja.me/</a><br>
              
              <strong>Advisor(s):</strong> Jitendra Malik<br>
              
              <strong>Research Blurb:</strong> My research focuses on scaling predictive world models to handle the complexity of in-the-wild motion. Using autoregressive and diffusion frameworks, I develop better representations for real-world prediction and propose methods to efficiently adapt these models to new domains.<br>
              
              
              <strong>Looking for:</strong> Research scientist
              
              
            
          </div>
        </div>
      </div>
      <hr>
    
      <div class="col-md-4">
        <div class="card mb-4 shadow-sm">
          <a href="https://n-mehandru.github.io/"><img src="https://bair.berkeley.edu/static/blog/grads2026/nikita-mehandru.jpg" alt="Nikita Mehandru" class="bd-placeholder-img card-img-top" width="480" height="auto"></a>
          <div class="card-body">
            <p class="card-text">
              </p><h1>Nikita Mehandru</h1><br>
              <strong>Email:</strong><a href="mailto:nmehandru@berkeley.edu"> nmehandru@berkeley.edu</a><br>
              <strong>Website:</strong> <a href="https://n-mehandru.github.io/">https://n-mehandru.github.io/</a><br>
              
              <strong>Advisor(s):</strong> Ahmed Alaa and David Bamman<br>
              
              <strong>Research Blurb:</strong> My research develops and applies machine learning methods for clinical reasoning and disease progression modeling using unstructured text and time series data from electronic health records. In collaboration with physicians at UCSF, I bridge method development and clinical validation with the intention to build reliable, interpretable AI systems in medicine.<br>
              
              
              <strong>Looking for:</strong> Research Scientist
              
              
            
          </div>
        </div>
      </div>
      <hr>
    
      <div class="col-md-4">
        <div class="card mb-4 shadow-sm">
          <a href="https://niklaslauffer.github.io/"><img src="https://bair.berkeley.edu/static/blog/grads2026/niklas-lauffer.jpg" alt="Niklas Lauffer" class="bd-placeholder-img card-img-top" width="480" height="auto"></a>
          <div class="card-body">
            <p class="card-text">
              </p><h1>Niklas Lauffer</h1><br>
              <strong>Email:</strong><a href="mailto:nlauffer@berkeley.edu"> nlauffer@berkeley.edu</a><br>
              <strong>Website:</strong> <a href="https://niklaslauffer.github.io/">https://niklaslauffer.github.io/</a><br>
              
              <strong>Advisor(s):</strong> Stuart Russell and Sanjit Seshia<br>
              
              <strong>Research Blurb:</strong> Niklas's research is focused on AI safety and reinforcement learning, particularly in the area of multi-agent interaction and LM agents. He's worked on enabling adversarial learning in cooperative and mixed-motive settings, solving issues of covariate shift in training LM agents on long-horizon tasks, as well as evaluating safety risks posed by LM agents in multi-agent settings.<br>
              
              
              <strong>What's next:</strong> Research Scientist at Google Deepmind
              
              
            
          </div>
        </div>
      </div>
      <hr>
    
      <div class="col-md-4">
        <div class="card mb-4 shadow-sm">
          <a href="https://colinqiyangli.github.io/"><img src="https://bair.berkeley.edu/static/blog/grads2026/qiyang-li.jpg" alt="Qiyang Li" class="bd-placeholder-img card-img-top" width="480" height="auto"></a>
          <div class="card-body">
            <p class="card-text">
              </p><h1>Qiyang Li</h1><br>
              <strong>Email:</strong><a href="mailto:qcli@berkeley.edu"> qcli@berkeley.edu</a><br>
              <strong>Website:</strong> <a href="https://colinqiyangli.github.io/">https://colinqiyangli.github.io/</a><br>
              
              <strong>Advisor(s):</strong> Sergey Levine<br>
              
              <strong>Research Blurb:</strong> Recent progress in robotic manipulation policy learning has been largely driven by (1) the increasing availability of large-scale prior datasets and (2) the success of action chunking, where the policy predicts a short sequence of future actions rather than a single one. However, most action chunking policies are trained via supervised imitation learning, because efficient online self-improvement with reinforcement learning (RL) remains challenging—limiting real-world applicability. My PhD research studied how we could leverage prior data to optimize action-chunking policies with RL, combining empirical results with theoretical insights.<br>
              
              
              <strong>Looking for:</strong> Post-doc/research scientist for RL in robotics and LLMs!
              
              
            
          </div>
        </div>
      </div>
      <hr>
    
      <div class="col-md-4">
        <div class="card mb-4 shadow-sm">
          <a href="https://sdeglurkar.github.io/"><img src="https://bair.berkeley.edu/static/blog/grads2026/sampada-deglurkar.jpg" alt="Sampada Deglurkar" class="bd-placeholder-img card-img-top" width="480" height="auto"></a>
          <div class="card-body">
            <p class="card-text">
              </p><h1>Sampada Deglurkar</h1><br>
              <strong>Email:</strong><a href="mailto:sampada_deglurkar@berkeley.edu"> sampada_deglurkar@berkeley.edu</a><br>
              <strong>Website:</strong> <a href="https://sdeglurkar.github.io/">https://sdeglurkar.github.io/</a><br>
              
              <strong>Advisor(s):</strong> Prof Claire Tomlin<br>
              
              <strong>Research Blurb:</strong> My research is in providing safety assurances for AI-enabled autonomous systems, ranging from robots to autonomous vehicles to aviation systems. For this, I have worked with uncertainty quantification for machine learning models, decision-making under uncertainty algorithms, and tools for producing probabilistic guarantees on system operation.<br>
              
              
              <strong>Looking for:</strong> Research scientist, Research engineer
              
              
            
          </div>
        </div>
      </div>
      <hr>
    
      <div class="col-md-4">
        <div class="card mb-4 shadow-sm">
          <a href="https://cs.berkeley.edu/~vbenara"><img src="https://bair.berkeley.edu/static/blog/grads2026/vinamra-benara.jpg" alt="Vinamra Benara" class="bd-placeholder-img card-img-top" width="480" height="auto"></a>
          <div class="card-body">
            <p class="card-text">
              </p><h1>Vinamra Benara</h1><br>
              <strong>Email:</strong><a href="mailto:vbenara@berkeley.edu"> vbenara@berkeley.edu</a><br>
              <strong>Website:</strong> <a href="https://cs.berkeley.edu/~vbenara">https://cs.berkeley.edu/~vbenara</a><br>
              
              <strong>Advisor(s):</strong> Ion Stoica<br>
              
              <strong>Research Blurb:</strong> My research focuses on LLM post-training, including data curation, RLHF, RLVR with VLMs, evaluations, reasoning, agentic workflows, and interpretability. I also have strong expertise in systems infrastructure for distributed computing.<br>
              
              
              <strong>Looking for:</strong> Research scientist / Research Engineer
              
              
            
          </div>
        </div>
      </div>
      <hr>
    
      <div class="col-md-4">
        <div class="card mb-4 shadow-sm">
          <a href="https://people.eecs.berkeley.edu/~vongani_maluleke/"><img src="https://bair.berkeley.edu/static/blog/grads2026/vongani-maluleke.jpg" alt="Vongani Maluleke" class="bd-placeholder-img card-img-top" width="480" height="auto"></a>
          <div class="card-body">
            <p class="card-text">
              </p><h1>Vongani Maluleke</h1><br>
              <strong>Email:</strong><a href="mailto:vongani_maluleke@berkeley.edu"> vongani_maluleke@berkeley.edu</a><br>
              <strong>Website:</strong> <a href="https://people.eecs.berkeley.edu/~vongani_maluleke/">https://people.eecs.berkeley.edu/~vongani_maluleke/</a><br>
              
              <strong>Advisor(s):</strong> Jitendra Malik and Angjoo Kanazawa<br>
              
              <strong>Research Blurb:</strong> Vongani Maluleke is a PhD candidate at UC Berkeley (BAIR, advised by Jitendra Malik and Angjoo Kanazawa), where she led the development of MAGNet, a unified multi-agent motion generation framework that supports a wide range of motion generation tasks without retraining or architectural changes, outperforming task-specialized state-of-the-art baselines. She is currently extending this work by deploying it on a Unitree G1 humanoid to make it embody social intelligence. Before her PhD, she was a Senior AI Consultant at Deloitte, awarded Exceptional Performer two consecutive years, leading AI system development across media, telecommunications, retail, and financial services.<br>
              
              
              <strong>Looking for:</strong> Research scientist
              
              
            
          </div>
        </div>
      </div>
      <hr>
    
      <div class="col-md-4">
        <div class="card mb-4 shadow-sm">
          <a href="https://weijer-chang.github.io/"><img src="https://bair.berkeley.edu/static/blog/grads2026/wei-jer-chang.jpg" alt="Wei-Jer Chang" class="bd-placeholder-img card-img-top" width="480" height="auto"></a>
          <div class="card-body">
            <p class="card-text">
              </p><h1>Wei-Jer Chang</h1><br>
              <strong>Email:</strong><a href="mailto:weijer_chang@berkeley.edu"> weijer_chang@berkeley.edu</a><br>
              <strong>Website:</strong> <a href="https://weijer-chang.github.io/">https://weijer-chang.github.io/</a><br>
              
              <strong>Advisor(s):</strong> Masayoshi Tomizuka<br>
              
              <strong>Research Blurb:</strong> My research focuses on developing safe and intelligent autonomous systems for complex, human-centered environments. I work at the intersection of machine learning, generative models, and reinforcement learning, with applications in autonomy. My work addresses challenges in multi-agent interaction, interactive human behavior, and long-tail safety-critical scenarios at scale.<br>
              
              
              <strong>Looking for:</strong> Research Scientist, Applied Scientist, Roboticist
              
              
            
          </div>
        </div>
      </div>
      <hr>
    
      <div class="col-md-4">
        <div class="card mb-4 shadow-sm">
          <a href="https://xiuyuli.com/"><img src="https://bair.berkeley.edu/static/blog/grads2026/xiuyu-li.jpg" alt="Xiuyu Li" class="bd-placeholder-img card-img-top" width="480" height="auto"></a>
          <div class="card-body">
            <p class="card-text">
              </p><h1>Xiuyu Li</h1><br>
              <strong>Email:</strong><a href="mailto:xiuyu@berkeley.edu"> xiuyu@berkeley.edu</a><br>
              <strong>Website:</strong> <a href="https://xiuyuli.com/">https://xiuyuli.com/</a><br>
              
              <strong>Advisor(s):</strong> Kurt Keutzer<br>
              
              <strong>Research Blurb:</strong> My research focuses on developing scalable and self-improving large language model agents, with emphasis on coding agents for complex, long-horizon tasks. This direction builds on my work in parallel reasoning, and on broader expertise in making generative models more efficient in training and inference across language and vision.<br>
              
              
              <strong>What's next:</strong> Member of Technical Staff at xAI
              
              
            
          </div>
        </div>
      </div>
      <hr>
    
      <div class="col-md-4">
        <div class="card mb-4 shadow-sm">
          <a href="https://yichen928.github.io/"><img src="https://bair.berkeley.edu/static/blog/grads2026/yichen-xie.jpg" alt="Yichen Xie" class="bd-placeholder-img card-img-top" width="480" height="auto"></a>
          <div class="card-body">
            <p class="card-text">
              </p><h1>Yichen Xie</h1><br>
              <strong>Email:</strong><a href="mailto:yichenxie0928@gmail.com"> yichenxie0928@gmail.com</a><br>
              <strong>Website:</strong> <a href="https://yichen928.github.io/">https://yichen928.github.io/</a><br>
              
              <strong>Advisor(s):</strong> Masayoshi Tomizuka<br>
              
              <strong>Research Blurb:</strong> My research focuses on building multimodal foundation models and world models that understand and interact with complex physical environments. I aim to develop unified representations across modalities, enabling AI systems to reason over space, time, and dynamics toward general-purpose embodied intelligence.<br>
              
              
              <strong>What's next:</strong> Research Scientist at Luma AI
              
              
            
          </div>
        </div>
      </div>
      <hr>
    
      <div class="col-md-4">
        <div class="card mb-4 shadow-sm">
          <a href="https://www.linkedin.com/in/erginbas/"><img src="https://bair.berkeley.edu/static/blog/grads2026/yigit-efe-erginbas.jpg" alt="Yigit Efe Erginbas" class="bd-placeholder-img card-img-top" width="480" height="auto"></a>
          <div class="card-body">
            <p class="card-text">
              </p><h1>Yigit Efe Erginbas</h1><br>
              <strong>Email:</strong><a href="mailto:erginbas@berkeley.edu"> erginbas@berkeley.edu</a><br>
              <strong>Website:</strong> <a href="https://www.linkedin.com/in/erginbas/">https://www.linkedin.com/in/erginbas/</a><br>
              
              <strong>Advisor(s):</strong> Kannan Ramchandran, Thomas A. Courtade<br>
              
              <strong>Research Blurb:</strong> My PhD research spans two threads: online learning in large-scale markets, and interpretability of large machine learning models. In the first, I work on sequential decision-making with applications to recommendation, pricing, and assortment selection. My focus is on designing algorithms with provable guarantees for welfare maximization, revenue maximization, and stability. In the second, I develop scalable attribution methods that exploit the sparse, low-degree structure of real-world interactions, using tools from signal processing and information theory. More recently, I have been exploring principled ways to evaluate the faithfulness of model self-explanations.<br>
              
              
              <strong>What's next:</strong> Researcher at Hudson River Trading's AI Labs (HAIL)
              
              
            
          </div>
        </div>
      </div>
      <hr>
    
      <div class="col-md-4">
        <div class="card mb-4 shadow-sm">
          <a href="https://yihengli.com/"><img src="https://bair.berkeley.edu/static/blog/grads2026/yiheng-li.jpg" alt="Yiheng Li" class="bd-placeholder-img card-img-top" width="480" height="auto"></a>
          <div class="card-body">
            <p class="card-text">
              </p><h1>Yiheng Li</h1><br>
              <strong>Email:</strong><a href="mailto:yhli@berkeley.edu"> yhli@berkeley.edu</a><br>
              <strong>Website:</strong> <a href="https://yihengli.com/">https://Yihengli.com</a><br>
              
              <strong>Advisor(s):</strong> Masayoshi Tomizuka<br>
              
              <strong>Research Blurb:</strong> I am working on vision world modeling, with prior experience in diffusion model's efficiency as well as in autonomous driving.<br>
              
              
              <strong>What's next:</strong> Research Scientist at Waymo
              
              
            
          </div>
        </div>
      </div>
      <hr>
    
      <div class="col-md-4">
        <div class="card mb-4 shadow-sm">
          <a href="https://fu-zhe.com/"><img src="https://bair.berkeley.edu/static/blog/grads2026/zhe-fu.jpg" alt="Zhe Fu" class="bd-placeholder-img card-img-top" width="480" height="auto"></a>
          <div class="card-body">
            <p class="card-text">
              </p><h1>Zhe Fu</h1><br>
              <strong>Email:</strong><a href="mailto:zhefu@berkeley.edu"> zhefu@berkeley.edu</a><br>
              <strong>Website:</strong> <a href="https://fu-zhe.com/">https://fu-zhe.com/</a><br>
              
              <strong>Advisor(s):</strong> Alexandre Bayen<br>
              
              <strong>Research Blurb:</strong> My research focuses on physics-informed learning and control for mixed-autonomy systems, with applications in transportation. I design physics-informed neural networks to learn solutions of nonlinear partial differential equations, enabling accurate and data-efficient prediction of traffic dynamics. Building on these models, I develop both model-based and learning-based control strategies that coordinate automated vehicles to improve system-level performance. My work bridges machine learning, control, and real-world deployment, and has been validated in large-scale field experiments. More broadly, I aim to advance trustworthy, interpretable AI for decision-making in complex, real-world systems.<br>
              
              
              <strong>What's next:</strong> I will be an Energy Fellow at Stanford after graduation. Also looking for Faculty, or research scientist positions in AI, control, and autonomy.
              
              
            
          </div>
        </div>
      </div>
      <hr>
    
  </div>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Meta's non-invasive brain-to-text AI is closing the gap with surgical implants]]></title>
<description><![CDATA[Meta's FAIR AI team uses Brain2Qwerty v2 to translate brain activity into typed sentences, with no implants or surgery required. The system reads magnetic signals outside the skull and reconstructs what a person is typing. Clinical use for paralyzed patients is still a long way off, but accuracy ...]]></description>
<link>https://tsecurity.de/de/3639055/ai-nachrichten/metas-non-invasive-brain-to-text-ai-is-closing-the-gap-with-surgical-implants/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3639055/ai-nachrichten/metas-non-invasive-brain-to-text-ai-is-closing-the-gap-with-surgical-implants/</guid>
<pubDate>Wed, 01 Jul 2026 18:05:09 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1376" height="768" src="https://the-decoder.com/wp-content/uploads/2026/07/Brain2Qwertyv2-title.png" class="attachment-full size-full wp-post-image" alt="" decoding="async"></p>
<p>        Meta's FAIR AI team uses Brain2Qwerty v2 to translate brain activity into typed sentences, with no implants or surgery required. The system reads magnetic signals outside the skull and reconstructs what a person is typing. Clinical use for paralyzed patients is still a long way off, but accuracy keeps improving with every additional recording. AI agents that wrote their own code helped with the optimization.</p>
<p>The article <a href="https://the-decoder.com/metas-non-invasive-brain-to-text-ai-is-closing-the-gap-with-surgical-implants/">Meta's non-invasive brain-to-text AI is closing the gap with surgical implants</a> appeared first on <a href="https://the-decoder.com/">The Decoder</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Why 'countdown mode' is the task manager feature I can't live without]]></title>
<description><![CDATA[This setting meshes perfectly with how my brain works, and I don't miss deadlines anymore.]]></description>
<link>https://tsecurity.de/de/3635204/it-security-nachrichten/why-countdown-mode-is-the-task-manager-feature-i-cant-live-without/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3635204/it-security-nachrichten/why-countdown-mode-is-the-task-manager-feature-i-cant-live-without/</guid>
<pubDate>Tue, 30 Jun 2026 12:22:55 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[This setting meshes perfectly with how my brain works, and I don't miss deadlines anymore.]]></content:encoded>
</item>
<item>
<title><![CDATA[Meta AI Releases Brain2Qwerty v2: A Non-Invasive MEG Brain-to-Text Pipeline Decoding Typed Sentences at 61% Word Accuracy]]></title>
<description><![CDATA[Meta AI releases Brain2Qwerty v2, a non-invasive MEG brain-to-text pipeline reaching 61% word accuracy with open training code.
The post Meta AI Releases Brain2Qwerty v2: A Non-Invasive MEG Brain-to-Text Pipeline Decoding Typed Sentences at 61% Word Accuracy appeared first on MarkTechPost.]]></description>
<link>https://tsecurity.de/de/3634953/ai-nachrichten/meta-ai-releases-brain2qwerty-v2-a-non-invasive-meg-brain-to-text-pipeline-decoding-typed-sentences-at-61-word-accuracy/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3634953/ai-nachrichten/meta-ai-releases-brain2qwerty-v2-a-non-invasive-meg-brain-to-text-pipeline-decoding-typed-sentences-at-61-word-accuracy/</guid>
<pubDate>Tue, 30 Jun 2026 10:33:52 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Meta AI releases Brain2Qwerty v2, a non-invasive MEG brain-to-text pipeline reaching 61% word accuracy with open training code.</p>
<p>The post <a href="https://www.marktechpost.com/2026/06/30/meta-ai-releases-brain2qwerty-v2-a-non-invasive-meg-brain-to-text-pipeline-decoding-typed-sentences-at-61-word-accuracy/">Meta AI Releases Brain2Qwerty v2: A Non-Invasive MEG Brain-to-Text Pipeline Decoding Typed Sentences at 61% Word Accuracy</a> appeared first on <a href="https://www.marktechpost.com/">MarkTechPost</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA['I don’t like that he made this donation' — Mullvad CEO reacts to co-founder’s donation to controversial Swedish populist party]]></title>
<description><![CDATA[Mullvad says co-founder's 5 million SEK donation to the Örebro Party 'is not part of Mullvad's values or mission.']]></description>
<link>https://tsecurity.de/de/3633359/it-nachrichten/i-dont-like-that-he-made-this-donation-mullvad-ceo-reacts-to-co-founders-donation-to-controversial-swedish-populist-party/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3633359/it-nachrichten/i-dont-like-that-he-made-this-donation-mullvad-ceo-reacts-to-co-founders-donation-to-controversial-swedish-populist-party/</guid>
<pubDate>Mon, 29 Jun 2026 17:48:27 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Mullvad says co-founder's 5 million SEK donation to the Örebro Party 'is not part of Mullvad's values or mission.']]></content:encoded>
</item>
<item>
<title><![CDATA[Starmind: Elon's Perhaps-Imaginary AI Megaconstellation Gets a Name]]></title>
<description><![CDATA[Is it more Starmind or Galaxy Brain?]]></description>
<link>https://tsecurity.de/de/3632948/it-nachrichten/starmind-elons-perhaps-imaginary-ai-megaconstellation-gets-a-name/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3632948/it-nachrichten/starmind-elons-perhaps-imaginary-ai-megaconstellation-gets-a-name/</guid>
<pubDate>Mon, 29 Jun 2026 15:03:28 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Is it more Starmind or Galaxy Brain?]]></content:encoded>
</item>
<item>
<title><![CDATA[Oh, behave! How Gemini can reshape the web for the way you work]]></title>
<description><![CDATA[Reading about the “revolutionary” nature of generative AI technology these days, it’s hard not to feel a little left out.



Sure, services like Google’s Gemini and its contemporaries can be useful in certain limited, specific areas for productivity purposes. But working with them can also be pre...]]></description>
<link>https://tsecurity.de/de/3632771/it-nachrichten/oh-behave-how-gemini-can-reshape-the-web-for-the-way-you-work/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3632771/it-nachrichten/oh-behave-how-gemini-can-reshape-the-web-for-the-way-you-work/</guid>
<pubDate>Mon, 29 Jun 2026 13:47:43 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Reading about the “revolutionary” nature of generative AI technology these days, it’s hard not to feel a little left out.</p>



<p>Sure, services like Google’s Gemini and its contemporaries <a href="https://www.computerworld.com/article/4007736/gemini-android.html">can be useful</a> in <a href="https://www.computerworld.com/article/3845447/google-workspace-how-to-use-gemini-ai-side-panel.html">certain limited, specific areas</a> for productivity purposes. But working with them can also be pretty disheartening and overwhelming — from <a href="https://www.computerworld.com/article/4047909/burned-out-by-bots-prompt-fatigue-in-workplace.html">prompt fatigue</a> and an onslaught of <a href="https://www.cio.com/article/4077448/ai-workslop-the-new-productivity-killer-only-training-can-stop.html" target="_blank">AI workslop</a> to the fear of <a href="https://www.computerworld.com/article/4175956/the-ai-tech-job-slaughter-gets-real.html">lost jobs</a> and even just the simple <a href="https://www.computerworld.com/article/4059383/openai-admits-ai-hallucinations-are-mathematically-inevitable-not-just-engineering-flaws.html">inconsistencies and inaccuracies</a> these systems are <a href="https://www.computerworld.com/article/4136922/google-gemini-3-years.html">so prone to providing</a>. (And that’s to say nothing of <a href="https://www.computerworld.com/article/4182583/ai-creepy-era.html">the ever-increasing creepy factor</a> that often accompanies this type of technology.)</p>



<p>More and more, it seems the most significant impact of these systems is in <a href="https://www.computerworld.com/article/4022711/when-everything-is-vibing.html">areas like coding</a>, where AI is allowing ambitious tech-heads to <a href="https://www.fastcompany.com/91528164/claude-code-vibe-code-word-processor" target="_blank" rel="noreferrer noopener">create their own custom programs</a> with limited to no programming knowledge (but <a href="https://www.fastcompany.com/91345791/vibecoding-replit-debugging-claude" target="_blank" rel="noreferrer noopener">a <em>lot</em> of time, vision, and patience</a>) — as well as allowing accomplished coders to produce products more quickly by letting AI do the dirty work and then spending <em>their</em> time <a href="https://www.computerworld.com/article/4066260/why-we-need-human-developers.html">guiding, tweaking, and correcting its output</a>.</p>



<p>That’s all well and good, but the reality is that most of us mere mortals are never gonna mess with anything that daunting. That doesn’t, however, mean we can’t enjoy a slice of the custom-coding pie and the productivity advantages it offers — on a much simpler but still supremely useful level.</p>



<p>The average-worker answer lies in an oft-overlooked middle-ground possibility these AI chatbots possess to help us create relatively basic but extremely high-potential custom browser extensions. As their name suggests, these simple little programs run entirely in your browser — the same exact sorts of add-ons you’d typically find and install in a marketplace like <a href="https://chromewebstore.google.com/" target="_blank" rel="noreferrer noopener">Google’s Chrome Web Store</a>.</p>



<p>But with Gemini or any other similar genAI platform, you can dream up your <em>own </em>web-improving extension and turn it into reality in a matter of minutes — simply by describing your goal and then guiding the AI gently along the way. And given how much time most of us spend on the web these days, that opens up a tantalizing series of doors for taking total control of your work environment.</p>



<p>Hate all the extraneous bells and whistles gunking up the Google Docs interface? Gemini can create a Chrome extension that removes them. Annoyed by a glitchy web app? Ask Gemini for an extension that makes some under-the-hood improvements. The possibilities are endless.</p>



<p>Let me show you how exactly it works, how easy it is to approach and master, and how many work-enhancing possibilities are out there just waiting to be created.</p>



<h2 class="wp-block-heading"><a></a>The ins and outs of Gemini’s custom Chrome extensions</h2>



<p>First things first: You don’t need any special tools or subscriptions to make this happen. For the purposes of this article, we’ll focus on Google’s Gemini for the creation and the standard desktop Chrome browser for the installation — but the same basic process would work with most any AI chatbot, if you happen to prefer ChatGPT or Claude, as well as with any extension-supporting, <a href="https://www.computerworld.com/article/1717405/googles-chromium-browser-explained.html">Chromium-compatible browser</a> (a list that includes everything from Microsoft Edge to Brave, <a href="https://www.computerworld.com/article/4148888/8-advanced-ways-vivaldi-boosts-your-productivity.html">Vivaldi</a>, and beyond).</p>



<p>Google offers a dizzying array of <a href="https://blog.google/products-and-platforms/products/google-one/google-ai-subscriptions/" target="_blank" rel="noreferrer noopener">Gemini modes and options</a> and an equally overwhelming series of <a href="https://gemini.google/subscriptions/" target="_blank" rel="noreferrer noopener">AI subscription plans</a> that control how much you can use those capabilities, but you don’t need to worry about any of that to create custom Chrome extensions. You might sometimes see better results if you switch your Gemini model to “Pro” or your Gemini <em>thinking level</em> to “Extended” — designations that even Gemini itself has trouble deciphering (believe me, I asked!) — but just using the default Gemini settings with a free Google account will generally work quite well.</p>



<p>Getting going with a custom Chrome extension is as simple as <a href="https://gemini.google.com/" target="_blank" rel="noreferrer noopener">opening up a new Gemini chat</a> and telling the system what you want it to cook up for you. The hardest part is deciding what you want and what’d be helpful for you — something we’ll explore more in a moment, via specific examples and suggestions. Once you’ve got that, you can just ask Gemini to create a Chrome extension that’ll accomplish what you’re envisioning, with as much specificity as possible about what it’ll do and how it’ll look.</p>



<p>Gemini will spit back a series of plain-text code chunks with instructions to copy each cluster and paste it into a new plain text file with a certain specific name — things like “manifest.json,” “content.js,” and “styles.css.” All you’ll do is use the on-screen button to copy each segment, then open up any simple text editor (like Windows Notepad, macOS TextEdit, or any number of <a href="https://browserpad.org/" target="_blank" rel="noreferrer noopener">simple online text editors</a>) and paste the text in, then save it under the name Gemini gives you.</p>



<p>You’ll need to put all the files into a single isolated folder on your computer, and then you can go into Chrome, type <strong>chrome:extensions </strong>into its address bar, and install your shiny new creation by:</p>



<ul class="wp-block-list">
<li>Flipping the toggle next to “Developer mode” in the upper-right corner of the screen into the on and active position, if it isn’t already</li>



<li>Clicking the “Load unpacked” button</li>



<li>And selecting the folder you just created in the pop-up that appears</li>
</ul>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/06/gemini-custom-chrome-extensions-01-chrome-extension-controls.jpg?quality=50&amp;strip=all&amp;w=1024" alt="chrome extension controls including developer mode toggle and load unpacked button" class="wp-image-4185233" width="1024" height="114" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption"><p>Chrome’s “Developer Mode” toggle and “Load unpacked” button are the keys to importing any extension you create.</p>
</figcaption></figure><p class="imageCredit">JR Raphael / Foundry</p></div>



<p>And that’s pretty much it: No complicated compiling or program publishing — the extension you envisioned will be alive and working right in your browser and ready to use.</p>



<p>Now, odds are, it won’t be <em>exactly</em> what you wanted in its first iteration, and you’ll have to go back to Gemini to request several rounds of updates and corrections. Each time, Gemini will create a new set of code chunks, and you simply overwrite the text in each file with its corresponding new code chunk.</p>



<p>It’s still a bit of a process. But you’ll rarely spend more than an hour on something simple and maybe a few hours on something especially multifaceted and specific, and whatever you create will then work to your advantage indefinitely from that point onward, on any computer where you install it.</p>



<p>Before we dive into specific slivers of inspiration, let’s just note the hopefully obvious asterisk that this’ll work only if you’re <em>either </em>(a) using a personal computer that isn’t associated with an organization or (b) using a work-connected computer where custom Chrome extensions are permitted. In either scenario, you’ll want to use your own best judgment to ensure that whatever you’re adding into your browser won’t expose any corporate data or cause your IT comrades any alarm if they see you using it in your workday.</p>



<p>With most common examples, though — including all the ones we’re about to go over — you shouldn’t have any problem or cause for concern.</p>



<p>Capisce? Capisce. Let’s get into it.</p>



<h2 class="wp-block-heading"><a></a>Custom extension category #1: The interface fixer</h2>



<p>Our first custom Chrome extension category is the one that won me over to this practice initially and has been the most shapeshifting for my own browser-based workflow — and that’s the simple-seeming but transformational ability to have AI remake any web app you rely on to remove unneeded elements and redesign the interface to <em>your</em> exact specifications.</p>



<p>The best example I can show you is what I did with my completely homemade, Gemini-created Docs Zen extension. Google Docs, to put it mildly, has devolved into <a href="https://www.computerworld.com/article/1723650/google-docs-cheat-sheet-how-to-get-started.html#work">a cluttered mess</a>. There are so many on-screen elements I never use and, ironically enough, irrelevant AI elements I’d rather not have in my hair. I just want a calm, simple, minimalist environment for writing — with Google’s second-to-none syncing, universal access, and collaboration systems beneath it.</p>



<p>So rather than try to reinvent the wheel, I described to Gemini all the elements I wanted to remove from Docs and all the ways I wanted to rethink how its interface appeared for me.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-full"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/06/gemini-custom-chrome-extensions-02-initial-prompt.jpg?quality=50&amp;strip=all" alt="prompt asking gemini to make a chrome extension called docs fixer that minimizes and simplifies the google docs interface" class="wp-image-4185238" width="1007" height="621" sizes="auto, (max-width: 1007px) 100vw, 1007px"><figcaption class="wp-element-caption"><p>My original request to Gemini, followed by rounds of expansions and revisions (and eventually also a more poetic name).</p>
</figcaption></figure><p class="imageCredit">JR Raphael / Foundry</p></div>



<p>I went back and forth with numerous iterations and kept coming up with interesting new additions to further flesh out and improve the experience — and I ended up with a delightful setup that gives me a distraction-free view of my writing space with a simple toggle to reveal the main Docs menus and a palette icon that allows me to switch from one eye-pleasing theme to another.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-full is-resized"> width="620" height="161" sizes="auto, (max-width: 620px) 100vw, 620px"&gt;<figcaption class="wp-element-caption"><p>Google Docs with my custom Docs Zen extension — a true delight for daily writing.</p>
</figcaption></figure><p class="imageCredit">JR Raphael / Foundry</p></div>



<p>My setup deliberately doesn’t include comments or other collaborative elements, as I’m mostly writing by myself these days — but when I do need those elements, the eye icon in the upper-right corner of the screen disables my custom adjustments and takes me back to the standard Docs interface. I can then click the eye icon again in <em>that</em> environment to switch back.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-full"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/06/gemini-custom-chrome-extensions-google-docs-toggle-620.gif" alt="animated screenshot of toggling between simplified and full google docs interface" class="wp-image-4185725" width="620" height="117" sizes="auto, (max-width: 620px) 100vw, 620px"><figcaption class="wp-element-caption"><p>My custom extension includes a simple on-off toggle for times when I need the full Docs setup.</p>
</figcaption></figure><p class="imageCredit">JR Raphael / Foundry</p></div>



<p>I used Gemini to create something similar for <a href="https://www.computerworld.com/article/1712947/what-is-trello-a-guide-to-atlassians-collaboration-and-work-management-tool.html">Trello</a>, with which I also have a love-hate relationship — loving the foundational functions and easy access everywhere but hating the interface that’s <a href="https://www.computerworld.com/article/3832819/atlassian-refocuses-trello-on-individual-task-management.html">lost focus</a>, gained bloat, and gotten noticeably clunky and slow over time.</p>



<p>With the same sort of step-by-step, plain-English guidance, I was able to transform Trello from this…</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-full"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/06/gemini-custom-chrome-extensions-05-trello-before.jpg?quality=50&amp;strip=all" alt="screenshot of busy default trello interface" class="wp-image-4185239" width="999" height="639" sizes="auto, (max-width: 999px) 100vw, 999px"><figcaption class="wp-element-caption"><p>Trello, in its typical current-day state.</p>
</figcaption></figure><p class="imageCredit">JR Raphael / Foundry</p></div>



<p>…into <em>this</em>:</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-full"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/06/gemini-custom-chrome-extensions-06-trello-after.jpg?quality=50&amp;strip=all" alt="screenshot of trello interface simplified by custom chrome extension written by gemini" class="wp-image-4185234" width="997" height="641" sizes="auto, (max-width: 997px) 100vw, 997px"><figcaption class="wp-element-caption"><p>Trello, with my custom modifications in place.</p>
</figcaption></figure><p class="imageCredit">JR Raphael / Foundry</p></div>



<p>I couldn’t even begin to recount the number of superfluous features and elements I’ve removed, along with revamping the overall interface to make it both more efficient and more visually pleasing to my eye.</p>



<p>Whether it’s a web app you rely on regularly or even just a website you open often, the possibilities are practically endless for the ways you can reshape it and mold it to make it work better <em>for you</em>.</p>



<p>Speaking of which…</p>



<h2 class="wp-block-heading"><a></a>Custom extension category #2: The feature creator</h2>



<p>In addition to the surface-level adjustments and feature removals in my aforementioned Trello-enhancing extension, I also <em>added in </em>several components — such as one-click buttons for archiving or moving cards — and I managed to speed up the site by making some under-the-hood adjustments Gemini suggested when I asked about its choppy performance. The same sort of concept can apply to any web-based interface you’re using, if there are any options that are annoyingly buried within menus, shortcuts that’d make your life easier, or other improvements you’ve longed to see.</p>



<p>You can also consider some simple standalone extensions for giving yourself on-demand features that aren’t necessarily associated with any one specific website but could be useful in plenty of productivity scenarios. For instance:</p>



<ul class="wp-block-list">
<li>I do a fair amount of basic image editing and frequently find myself needing to reference a hex color code that corresponds with a particular brand color, and I always end up having to open up a new tab and look in a note somewhere to find the code I need. Well, no more: I used Gemini to create a super-simple custom color code pop-up where I can store all the colors I need and then copy any of ’em onto my clipboard with a single click. <em>Major </em>time-saver.</li>
</ul>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-full"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/06/gemini-custom-chrome-extensions-07-color-palette.jpg?quality=50&amp;strip=all" alt="screenshot of color palette selector - a custom chrome extension created by gemini " class="wp-image-4185237" width="478" height="555" sizes="auto, (max-width: 478px) 100vw, 478px"><figcaption class="wp-element-caption"><p>All the color codes I need are now never more than a couple clicks away.</p>
</figcaption></figure><p class="imageCredit">JR Raphael / Foundry</p></div>



<ul class="wp-block-list">
<li>I’m also constantly converting time zones, either for meetings with clients or colleagues or for trying to wrap my head around publishing systems that insist on using random time zones with no meaning to me. It’s infinitely easier for me to manage now, thanks to the custom Chrome extension I made that shows the current time in all the zones I need most often — as well as allowing me to put any <em>other </em>time into any field and have all the other zones instantly adjust to match. It also offers a brilliant plain-text conversion box where I can just type things like “1pm-3pm PT in MT” and have it cough back up an instant answer for any conversion I need.</li>
</ul>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-full"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/06/gemini-custom-chrome-extensions-08-time-zone-converter.jpg?quality=50&amp;strip=all" alt="screenshot of time zone converter  - a custom chrome extension created by gemini " class="wp-image-4185235" width="432" height="542" sizes="auto, (max-width: 432px) 100vw, 432px"><figcaption class="wp-element-caption"><p>My custom time zone conversion extension comes in handy countless times a day.</p>
</figcaption></figure><p class="imageCredit">JR Raphael / Foundry</p></div>



<p>Maybe what you want is the ability to interact with data on different websites more easily — to be able to save any table on a page in front of you as a CSV file, mayhap, or even to save any text you highlight on a page into a new Google Docs document. Whatever the case may be, Gemini can handle it — and that superpower that you’ve always wished for but never found the right tool to make possible can actually now be yours.</p>



<h2 class="wp-block-heading"><a></a>Custom extension category #3: The browser expander</h2>



<p>Our final category of custom Chrome extensions to consider moves beyond the web itself and into your actual browser. The browser is essentially the modern-day desktop, after all — and for the first time now, you can expand and enhance it in all sorts of interesting ways.</p>



<p>Some specific examples, to get your brain-motor whirring:</p>



<ul class="wp-block-list">
<li>You could walk Gemini through creating a smart auto-snooze system for your open browser tabs, both to clear clutter and help with <a href="https://www.computerworld.com/article/1666806/easy-steps-to-make-chrome-faster-and-more-secure.html">Chrome’s performance</a>. It could save any tab that hasn’t been touched in a certain amount of time to your local storage and then give you a simple searchable “Archive Dashboard” where you can find all those auto-closed tabs and re-open ’em as needed.</li>



<li>With the right guidance, Gemini could give you a custom browser research panel — where any info you highlight on a page gets beamed over into a sidebar-style panel that serves as a running scratchpad of notes from the day.</li>



<li>Or, if you find yourself often needing to see two tabs together side by side, you could have Gemini cook up a custom extension that instantly detaches any tab in front of you and puts it into a new tab window in a perfectly sized and spaced pattern. One keyboard shortcut could make that move happen, while another keyboard shortcut could recombine the two tabs into a single centered window.</li>
</ul>



<p>As with all the other ideas we’ve gone over, all you’ve gotta do is ask — and now, with the right inspiration in mind, you’re ready to get your custom extension adventures going and start bending the web to <em>your</em> will.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Grounding, not models, will define your AI advantage]]></title>
<description><![CDATA[Over the past two years, working inside the enterprise AI infrastructure world, tracking where the industry is heading, I have noticed the same question surface repeatedly: should we build our own large language model? I understand the instinct. The model feels like the thing, the engine, the bra...]]></description>
<link>https://tsecurity.de/de/3632693/it-nachrichten/grounding-not-models-will-define-your-ai-advantage/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3632693/it-nachrichten/grounding-not-models-will-define-your-ai-advantage/</guid>
<pubDate>Mon, 29 Jun 2026 13:03:15 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Over the past two years, working inside the enterprise AI infrastructure world, tracking where the industry is heading, I have noticed the same question surface repeatedly: should we build our own large language model? I understand the instinct. The model feels like the thing, the engine, the brain, the asset worth owning. But after significant years as a product manager in the AI world in both customer experience and grounding infrastructure I concluded that it tends to unsettle the room: the model is the least durable part of your AI strategy.</p>



<p>I say this not to be provocative, but because over the last few years we have seen organizations pour their scarcest resources, executive attention, engineering talent, capital, into the one layer of the stack that is commoditizing fastest. Meanwhile, the layer that determines whether their AI is trustworthy, accurate and defensible gets treated as plumbing. That inversion is, in my experience, the single most expensive mistake enterprises are making with AI right now.</p>



<h2 class="wp-block-heading">The model is becoming a commodity</h2>



<p>Let us consider economics. <a href="https://www.gartner.com/en/newsroom/press-releases/2026-03-25-gartner-predicts-that-by-2030-performing-inference-on-an-llm-with-1-trillion-parameters-will-cost-genai-providers-over-90-percent-less-than-in-2025" rel="nofollow">Gartner projects that by 2030, performing inference on a trillion-parameter model will cost providers more than 90% less</a> than it did in 2025, with models becoming up to 100 times more cost-efficient than the earliest versions of comparable size. When the cost of the underlying capability collapses by that magnitude, it stops being a differentiator. Anything that gets that cheap, that fast, is not where competitive advantage lives.</p>



<p>Models that feel innovative are routinely surpassed by something cheaper and better within months. If your advantage is tied to a specific model, it will evaporate the moment the frontier moves, which it always does. But if an enterprise instead invests in how reliably it can feed any model its proprietary context, that investment holds. That part travels from one model generation to the next. When a better model arrives, the organization can simply connect it and immediately capture the upside, because the hard and durable work was already done one layer down.</p>



<p>I wish more leaders could observe this pattern before they commit. The model layer is improving so quickly that any advantage you build into it has a short half-life. The grounding layer behaves in the opposite way: every improvement you make to your data quality, your retrieval logic and your governance compounds, and it carries forward regardless of which model sits on top.</p>



<p>This is why the build-your-own LLM debate so often misses the mark. Training or even meaningfully fine-tuning a foundation model is enormously expensive, and the moment you finish, the open and commercial frontier has usually moved past you. So, technically you spent a fortune to own a depreciating asset. The capability that you should focus on is an AI that knows your business, was never going to come from the weights of the model anyway. It comes from what you put in front of it.</p>



<h2 class="wp-block-heading">Why grounding is the real moat</h2>



<p>Grounding is the discipline of connecting a general-purpose model to your enterprises’ current and authoritative information, most commonly through retrieval-augmented generation, or RAG. Rather than hoping the model memorized something useful during training, you retrieve the relevant facts from your own systems in real time of the query and give the model the context it needs to answer correctly.</p>



<p>Here is the part that matters for anyone thinking about competitive advantage: your competitors can rent the exact same model you use. What they cannot rent is your data, your institutional knowledge, your processes and the quality of the pipeline that surfaces all of it accurately at the right moment. That pipeline is genuinely proprietary, genuinely hard to replicate and it compounds in value over time. That is the textbook definition of a moat, and it has almost nothing to do with which model you chose.</p>



<p>The industry is starting to recognize this. Gartner predicts that <a href="https://www.gartner.com/en/newsroom/press-releases/2025-04-09-gartner-predicts-by-2027-organizations-will-use-small-task-specific-ai-models-three-times-more-than-general-purpose-large-language-models" rel="nofollow">by 2027, organizations will use small, task-specific models at least three times more than general-purpose LLMs</a>, precisely because accuracy in real business workflows depends on domain context rather than raw model scale. But a smaller model holds less in its parameters by design, which means it leans even harder on retrieval to supply current, authoritative context in real time. The model gets smaller and more swappable. The grounding becomes the part that carries the weight. In that same analysis, Gartner makes the same point from the data side: what sets enterprises apart is how well they prepare, check, version and manage their own data. Read that again: the differentiator is the data discipline, not the model.</p>



<p>This matches what I have observed directly. Getting hold of an excellent model was never the hard part, and it was rarely where things broke. The failures I have seen came from not connecting the model efficiently to the right data sources or orchestrating retrieval well. The patterns repeat: missing data produces incomplete summaries, truncated documents leave answers without key details, and noisy context yields irrelevant or confusing responses.</p>



<p>When grounding is absent, answers become inconsistent from one client to the next; when retrieval comes back empty, the model fills the gap with something hallucinated or useless. Stale data produces confidently outdated answers, retrieval gaps surface as generic non-answers, and poor-quality data drags down both speed and output. None of these are model problems. They are grounding problems. And when a system hands an executive an answer that is wrong, no one in the boardroom cares how sophisticated the model was. They care that it was wrong, and the fix always lives in the grounding layer.</p>



<p>One example has stayed with me. In a real enterprise scenario, an AI assistant returned inconsistent answers to the same query across different environments whenever grounding was unavailable, and some of those answers contradicted each other outright. The cause was straightforward in hindsight. With no grounding, the system fell back on its own internal knowledge instead of a shared, grounded source of truth, so its responses drifted with each configuration and context. The damage was not just technical. Users stopped trusting an assistant that could not give them the same answer to the same question twice. That is the actual cost of weak grounding, and it is why consistency and reliability in production depend far more on the data layer than on the model sitting above it. No model upgrade would have fixed that.</p>



<h2 class="wp-block-heading">Where leaders should focus their investment</h2>



<p>If you accept that grounding is where advantage accrues, a few priorities shift in ways that should change how you allocate budget and attention.</p>



<p>First, treat your organization’s data foundation as a first-class AI investment, not a prerequisite you rush through. The unglamorous work, cleaning, structuring, governing and versioning your knowledge, is the work that determines AI quality. I would rather inherit a mediocre model with an excellent retrieval pipeline than the reverse, every single time.</p>



<p>Second, build for model portability from day one. Assume the model you use today will be replaced within a year because it certainly will. If swapping it out is painful, you have coupled your architecture to the wrong layer. Your grounding infrastructure, your evaluation framework and your data contracts should be the stable core; the model should be a component you can swap with minimal disruption.</p>



<p>Third, invest in observability and evaluation for retrieval, not just for the model. The emerging discipline here matters: <a href="https://www.gartner.com/en/newsroom/press-releases/2026-03-30-gartner-predicts-by-2028-explainable-ai-will-drive-llm-observability-investments-to-50-percent-for-secure-genai-deployment" rel="nofollow">Gartner expects LLM observability investments to reach 50% of GenAI deployments by 2028</a>, up from 15% today, as trust requirements outpace the technology itself. Knowing why your system retrieved a particular piece of context, and whether that context was correct, is what makes an AI output defensible and auditable. For any organization operating under real regulatory or reputational scrutiny, that is not optional.</p>



<p>None of this means the model is irrelevant. You still need a capable one and choosing well matters. But choosing a model is now a procurement decision with several excellent options, not a source of lasting differentiation. The lasting differentiation is everything you wrap around it.</p>



<p>I think the organizations that internalize this will look, in a few years, meaningfully ahead of the ones still debating whether to train their own model. Not because they made a bolder bet, but because they made a more durable one. They understood that in a world where everyone has access to the same extraordinary models, the advantage belongs to whoever grounds those models best in the reality of their own business. The model is rented. The grounding is owned. Build accordingly.</p>



<p><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><strong><a href="https://www.cio.com/expert-contributor-network/">Want to join?</a></strong></p>



<p></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[How to keep your IT talent pipeline from collapsing]]></title>
<description><![CDATA[The transformative lure of AI is rapidly pushing IT leaders’ talent pipelines toward more of a crossroads than many may fully want to admit.



The traditional approach of growing IT expertise in-house from entry-level positions is being challenged by a combination of skills-demand shifts toward ...]]></description>
<link>https://tsecurity.de/de/3632581/it-security-nachrichten/how-to-keep-your-it-talent-pipeline-from-collapsing/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3632581/it-security-nachrichten/how-to-keep-your-it-talent-pipeline-from-collapsing/</guid>
<pubDate>Mon, 29 Jun 2026 12:09:08 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>The transformative lure of AI is rapidly pushing IT leaders’ talent pipelines toward more of a crossroads than many may fully want to admit.</p>



<p>The traditional approach of growing IT expertise in-house from entry-level positions is being challenged by a combination of skills-demand shifts toward AI experience and the replacement of entry-level roles in favor of AI automation.</p>



<p>Employment among early-career workers, ages 22 to 25, in the most AI-exposed occupations has fallen 16% since the introduction of ChatGPT in late 2022, according to a widely cited <a href="https://digitaleconomy.stanford.edu/publication/canaries-in-the-coal-mine-six-facts-about-the-recent-employment-effects-of-artificial-intelligence/" rel="nofollow">study from Stanford’s Digital Economy Lab</a>. For entry-level software developers, the drop was nearly 20%. As the pool of talent with early-career IT pros with hands-on experience shrinks, IT leaders are likely to face stiffer challenges filling more vital midlevel roles down the road.</p>



<p>Looking forward, some IT leaders believe replacing junior engineers and other entry-level IT roles with AI to cut costs will eventually backfire, leaving companies short of experienced staff who can tackle difficult problems and design scalable solutions.<br><br></p>



<p>According to a recent <a href="https://www.gartner.com/en/newsroom/press-releases/2026-05-05-gartner-says-autonomous-business-and-artificial-intelligence-layoffs-may-create-budget-room-but-do-not-deliver-returns" rel="nofollow">Gartner survey of global business executives</a>, organizations that automated aspects of their businesses and reduced their workforces aren’t seeing returns from those supposed efficiencies. What has improved the bottom line? Investing in new roles, upskilling, and systems that amplify the capabilities of staff so they can supervise and grow autonomous work.</p>



<p>Moreover, the Gartner report forecasts that autonomous business practices will require more staff, not less, over the next two to three years, leading to a net positive in job growth as people are hired to manage those efforts.</p>



<p>Yet, in the short term, investors are rewarding companies that make AI-related workforce reductions. And many executives are pushing for the same. So how are CIOs and other leaders planning to build the necessary skills for future success by creating a pathway for middle- and senior-level IT talent?</p>



<h2 class="wp-block-heading">‘Early in context’</h2>



<p>In response to this downward trend in early career hiring, Microsoft’s Mark Russinovich and Scott Hanselman penned an <a href="https://dl.acm.org/doi/10.1145/3779312">article</a> that pushes back on this trend. They propose bringing in early-career programming talent and pairing them with experienced mentors on product teams, where they can help new hires identify — and solve — real-world problems that AI might miss.</p>



<p>In the article, the Microsoft execs noted that experienced programmers found dozens of problems in AI-generated code that appeared to work correctly. They also pointed to the risk of “cognitive debt,” citing MIT research that found reduced brain activity among people relying heavily on AI for writing tasks.</p>



<p>“While agents can speed up workflows and reduce manual effort, they lack the intuition to anticipate edge cases and build robust solutions,” the authors wrote. “Relying too much on AI risks missing subtle bugs, architectural flaws, and vulnerabilities that only skilled engineers can catch. Human oversight, critical thinking, and domain knowledge are indispensable for both correcting errors and driving innovation as technology progresses.”</p>



<p>Hanselman, vice president and member of technical staff at Microsoft, argues that software development isn’t simply a matter of writing code. Senior engineers, he notes, have experience in what works, what fails, what can break in production, and what elegant design looks like — and how to scale it. AI can increase output, but it does not help a new developer learn this sort of judgment.</p>



<p>“When you say early in career, it’s actually early in context — junior devs are missing context,” he says. “The way that we develop good taste is through failing in a safe place. And right now, companies hire juniors, throw them at a problem, chew them up and spit them out — and that’s the wrong way to do it.”</p>



<h2 class="wp-block-heading">A new mentorship model</h2>



<p>Hanselman suggests, instead of slashing roles for junior programmers, companies should be creating systems that help them develop the skills necessary to become valued senior contributors in the future.</p>



<p>He proposes adopting a mentorship approach called a “preceptorship,” borrowed from the medical field, where senior engineers are explicitly responsible for helping juniors gain experience and develop good judgment. Hanselman’s wife is a nurse and preceptor, and her experience helped spur the idea.</p>



<p>“The preceptorship acknowledges that a nurse has passed the board,” he explains. “They’ve joined the company. It’s their first day on the job. They are qualified to be there. They are supposed to be there — but they’re missing context.”</p>



<p>Technology companies need a similar model, he argues, where programmers are allowed to learn, not just produce, from experienced mentors: “We need high communicators, with high agency — kind individuals who will invest in the future.”</p>



<p>He contrasts this practical, real-world mentoring approach with a coding boot camp.</p>



<p>“What do people do in boot camps? They wash out,” he says. “You couldn’t hack it. A preceptorship is a relationship between a senior engineer, who has your best interest at heart and is going to help you become a better AI-augmented software engineer — not a vibe coder. We’re not vibing into production. We are using the powerful tools that have been developed to create high-quality software with good taste and with good discernment at scale.”</p>



<h2 class="wp-block-heading"><a></a>A talent gap in the making</h2>



<p>Companies that eliminate junior roles because AI can do some entry-level tasks may see improved short-term output while weakening their future technical capabilities. Tech executives say a lack of investment in early career hiring will show up in the future as a dearth of leadership and institutional knowledge, as well as a reduction in product quality and the ability to effectively manage and oversee code or other work created with AI.</p>



<p>“Senior engineers are built through exposure to real systems, not just writing code,” says Craig Miller, former CIO of fast-food chain Sonic, now a consultant, board advisor, and author. “They need to understand how things scale, how they break, and how decisions impact the business. That experience cannot be automated.”</p>



<p>Reducing junior developer roles should be seen as a long-term capability risk instead of a budget efficiency, says Macaire Montini, vice president of people and culture at cloud-based HR software company HiBob.</p>



<p>“The decline in junior developer roles isn’t just an employment trend,” Montini says. “It’s a long-term pipeline problem that technology leaders should treat with the same urgency as any infrastructure risk. If you stop bringing in early-career talent, you don’t just have a gap today — you have a leadership drought in five years.”</p>



<p>Zsolt Kerecsen, CTO at Graphisoft, argues that replacing early-career staff with AI hurts staff growth and undercuts an organization’s ability to manage autonomous capabilities. CIOs should treat early-career hiring as an investment in future delivery quality, system oversight, and AI governance, he says.</p>



<p>“Experienced developers are needed to train AI and validate its outputs,” he says. “That’s why trying to substitute juniors with AI is a fundamentally flawed approach. Instead, AI should be used — guided by seniors — to support junior developers and help them become seniors more quickly.”</p>



<p>Miller says the reduction in early career hiring is just one sign of a broader issue of “slow decay,” where current tech staff aren’t training their replacements. He points to other indications of a future talent crisis: “Decline in CS enrollments as prospective students respond to deteriorating job market signals, which could produce a senior engineer shortage in 5 to 10 years even as AI reduces demand for entry-level workers today. The real risk is not that AI will eliminate the need for developers. It’s that companies will eliminate the early learning ground that has always produced great ones.”</p>



<h2 class="wp-block-heading">Filling the pipeline</h2>



<p>With early-career roles evolving quickly, experts advise CIOs to take a more intentional approach to hiring and training IT talent, programmers in particular — one that uses AI to help junior staff become better, faster, instead of replacing them.</p>



<p>AI may enable junior developers to take on more advanced tasks earlier, Montini says, but they still need mentoring and structured guidance to become experienced contributors.</p>



<p>“We believe the answer isn’t just hiring,” Montini says. “It’s how you onboard and develop early-career talent once they’re through the door. Structured training, clear skill development pathways, and meaningful mentorship are what actually close the gap between potential and performance. Without that scaffolding, junior hires churn before they become the midlevel talent you need.”</p>



<p>Paul DeMott, CTO at Helium SEO, says organizations should rethink talent development from a new hire’s first day.</p>



<p>“Before a junior developer on our team writes a single line of code on any new feature, they have to propose the full architecture for it, present it in a 15-minute review with the senior team, and explain every tradeoff they considered,” he says. “The junior does not implement anything until they defend those decisions. This process forces systems thinking before syntax thinking, which is exactly what separates a developer who grows into senior roles from one who stays at the execution layer indefinitely.”</p>



<p>In the past year and a half, DeMott says, that process has helped junior hires rise more quickly through the ranks, with two junior developers promoted to midlevel roles.</p>



<p>Kerecsen says his company actively seeks out junior talent at the university level, works with them for several years, then brings them on as junior or potentially midlevel engineers.</p>



<p>“There is a concerning misunderstanding about AI’s potential, especially regarding its ability to replace junior developers,” Kerecsen says. “It is actually disastrous for delivery quality and long-term sustainability. Junior developers are an investment in our future.”</p>



<p>Liz Eversoll, CEO of upskilling and recruitment company Career Highways, says organizations should move from informal apprenticeship to a more intentional model for skills-based growth.</p>



<p>“The next generation of senior programmers will be developed differently,” Eversoll says. “Junior engineers can now contribute to higher-complexity work earlier by using AI as a copilot, but that only works if organizations provide pathways that connect real work, learning, and continuous assessment.”</p>



<h2 class="wp-block-heading"><a></a>Building judgment, not just output</h2>



<p>The goal is to help junior developers gain the kind of experience that allows them to understand systems, weigh tradeoffs, and eventually guide technical decisions.</p>



<p>Former Sonic CIO Miller says that kind of experience cannot be automated.</p>



<p>“The organizations that get this right will balance AI-driven efficiency with structured mentorship and real-world exposure, treating talent development as a long-term priority,” Miller says. “The next generation of senior engineers will not emerge accidentally. They will have to be built through structured apprenticeship, guided use of AI, real exposure to production environments, and deliberate development of judgment, architecture thinking, debugging discipline, and business context.”</p>



<p>Rema Lolas, founder of team-building platform Groziac, says AI may make technical skills more accessible, but it will also put more pressure on how people work together.</p>



<p>“AI may level the technical playing field, but it will amplify the differences in human performance,” Lolas says. “The organizations that recognize this early will stop treating development as a training problem, and start treating it as a system design challenge — where people are intentionally developed not just in skill, but in how they operate and perform together.”</p>



<p>Microsoft’s Hanselman says the skills that matter most today are not just AI prompt fluency or the ability to generate code quickly, but systems thinking and communication.</p>



<p>“So for the young person who’s coming into this, you can’t have blinders on,” he says. “Making large, interesting systems that help people and make their lives better — that is not being commoditized. You need big-picture thinking, taste, discernment, good judgment, good communication skills, and a rock-solid understanding of the basics. Just because I’m riding around in an Uber doesn’t mean that I don’t know how to change a tire.”</p>



<p>Tech leaders say organizations need to make early-career growth a core part of engineering work. That means giving junior staff real programming work, in-the-moment senior guidance and AI support that accelerates learning without replacing it.</p>



<p>“Ultimately, developing senior talent is no longer a byproduct of hiring, it’s the result of deliberate infrastructure,” Eversoll says. “Organizations that invest in skills-based progression systems will not only sustain their pipeline, but accelerate it.”</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Non-Invasive Stimulation of the Brain Ended Opioid Addiction, Cigarette Craving]]></title>
<description><![CDATA[The Jerusalem Post reports that doctors at Haifa's Rambam Health Care Campus "have successfully treated their first Israeli opioid addiction patient using an experimental noninvasive brain technology, easing him through withdrawal in just 20 minutes..."

[T]he team of specialists at the Haifa med...]]></description>
<link>https://tsecurity.de/de/3629956/it-security-nachrichten/non-invasive-stimulation-of-the-brain-ended-opioid-addiction-cigarette-craving/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3629956/it-security-nachrichten/non-invasive-stimulation-of-the-brain-ended-opioid-addiction-cigarette-craving/</guid>
<pubDate>Sat, 27 Jun 2026 19:52:57 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The Jerusalem Post reports that doctors at Haifa's Rambam Health Care Campus "have successfully treated their first Israeli opioid addiction patient using an experimental noninvasive brain technology, easing him through withdrawal in just 20 minutes..."

[T]he team of specialists at the Haifa medical center intervened in the electrical activity of an area of the patient's brain called the nucleus accumbens, the core of the brain system responsible for feelings of satisfaction, pleasure, and reward. The treatment, based on technology from the Israeli company Insightec, is similar to the one used to treat symptoms of essential tremor and Parkinsonian tremor, under MRI control. In this case, the treatment was carried out with the help of a new technology that performs noninvasive neuromodulation, without heating or burning tissue, and allows stimulation in the same area of the brain to increase or suppress activity... 

"Tests carried out a week later produced negative results for opioids and other substances," [said Dr. Lior Lev-Tov, director of the functional neurosurgery unit in Rambam's neurosurgery division and the one leading the new study at the medical center.] "The patient himself reported a craving score of zero out of 10 for using the drug, and even another side effect, a drastic drop in the desire for cigarettes, from three packs a day to just a few cigarettes, and with no urge to use alcohol. In other words, in a treatment that lasted about 20 minutes net, our patient was completely freed from an extreme dependence that had accompanied him every day for years. This is nothing less than a medical and therapeutic revolution."
 
Dr. Lev-Tov added that "This experience opens doors for us to treat a wide range of very serious illnesses such as PTSD, OCD, eating disorders, other addictions, severe depression, severe pain disorders, and I hope we will also be able to reach cognitive areas and treat attention deficit disorders, Alzheimer's, Parkinson's, and more." 

Thanks to Slashdot reader Bruce66423 for sharing the article.
<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=Non-Invasive+Stimulation+of+the+Brain+Ended+Opioid+Addiction%2C+Cigarette+Craving%3A+https%3A%2F%2Fscience.slashdot.org%2Fstory%2F26%2F06%2F26%2F221205%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fscience.slashdot.org%2Fstory%2F26%2F06%2F26%2F221205%2Fnon-invasive-stimulation-of-the-brain-ended-opioid-addiction-cigarette-craving%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://science.slashdot.org/story/26/06/26/221205/non-invasive-stimulation-of-the-brain-ended-opioid-addiction-cigarette-craving?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Apple Plans to Launch a MacBook Ultra and M6 MacBook Pro This Fall]]></title>
<description><![CDATA[If you are waiting for a new computer from Apple, you might have a lot to look forward to later this year. Fresh rumors suggest the brand is getting ready to launch two very different high-end laptops this fall. It looks like buyers will get to choose between a completely redesigned top-tier mode...]]></description>
<link>https://tsecurity.de/de/3629421/ios-mac-os/apple-plans-to-launch-a-macbook-ultra-and-m6-macbook-pro-this-fall/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3629421/ios-mac-os/apple-plans-to-launch-a-macbook-ultra-and-m6-macbook-pro-this-fall/</guid>
<pubDate>Sat, 27 Jun 2026 12:31:49 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[If you are waiting for a new computer from Apple, you might have a lot to look forward to later this year. Fresh rumors suggest the brand is getting ready to launch two very different high-end laptops this fall. It looks like buyers will get to choose between a completely redesigned top-tier model and a familiar design that simply gets the newest brain on the inside.



A brand new touchscreen laptop joins the lineup with older chips



Recent leaks show the tech giant is working on a brand new option called the MacBook Ultra. This top-end gadget will reportedly feature a total redesign that makes it much thinner and lighter than current models. It is also expected to bring some huge firsts to the Mac lineup, including an OLED screen and a real touchscreen.



However, anyone expecting the newest processor might be a bit surprised. As noted in a recent post stating the touchscreen MacBook will feature M5 chips instead of M6, the company plans to stick with the current M5 Pro and M5 Max chips for this new release. It seems the brand wants to focus its energy on getting the new touch design right before pushing the internal speeds even higher.



The standard laptop design gets a bump with the newest processor



For people who do not care about a touchscreen or a super-thin body, there is another great option coming. Alongside the Ultra model, the company also plans to drop an updated version of the regular MacBook Pro. This standard model will keep the same look and feel that buyers already know and like.



The big difference for this standard model will be on the inside. Rumors indicate this machine will actually feature the brand new M6 chip. This means buyers will face a pretty tough choice this fall. They can either grab the familiar machine with the fastest new processor, or they can choose the fancy new Ultra design that runs on slightly older hardware.]]></content:encoded>
</item>
<item>
<title><![CDATA[Opinion: How Higher Ed Can Combat Cognitive Debt From AI Use]]></title>
<description><![CDATA[When AI explains a concept or rewrites an argument for a student, it removes the friction that helps the brain build strong neural connections. To avoid this, institutions need clear guidelines for how best to use AI.]]></description>
<link>https://tsecurity.de/de/3628701/ai-nachrichten/opinion-how-higher-ed-can-combat-cognitive-debt-from-ai-use/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3628701/ai-nachrichten/opinion-how-higher-ed-can-combat-cognitive-debt-from-ai-use/</guid>
<pubDate>Sat, 27 Jun 2026 00:48:39 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[When AI explains a concept or rewrites an argument for a student, it removes the friction that helps the brain build strong neural connections. To avoid this, institutions need clear guidelines for how best to use AI.]]></content:encoded>
</item>
<item>
<title><![CDATA[AI Brain Harvest, Fortibleed, Win 10, Blacksite, Windchill, Cisco, BB-8, Josh Marpet - SWN #593]]></title>
<description><![CDATA[AI Brain Harvest, Fortibleed, Win 10, Blacksite, Windchill, Cisco, BB-8 Sidewalk Bots, Josh Marpet, and More on this episode of the Security Weekly News. Visit https://www.securityweekly.com/swn for all the latest episodes! Show Notes: https://securityweekly.com/swn-593]]></description>
<link>https://tsecurity.de/de/3628595/it-security-nachrichten/ai-brain-harvest-fortibleed-win-10-blacksite-windchill-cisco-bb-8-josh-marpet-swn-593/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3628595/it-security-nachrichten/ai-brain-harvest-fortibleed-win-10-blacksite-windchill-cisco-bb-8-josh-marpet-swn-593/</guid>
<pubDate>Fri, 26 Jun 2026 23:21:08 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>AI Brain Harvest, Fortibleed, Win 10, Blacksite, Windchill, Cisco, BB-8 Sidewalk Bots, Josh Marpet, and More on this episode of the Security Weekly News.</p> <p>Visit <a rel="noopener" target="_blank" href="https://www.securityweekly.com/swn">https://www.securityweekly.com/swn</a> for all the latest episodes!</p> <p>Show Notes: <a rel="noopener" target="_blank" href="https://securityweekly.com/swn-593">https://securityweekly.com/swn-593</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[AI Brain Harvest, Fortibleed, Win 10, Blacksite, Windchill, Cisco, BB-8, Josh Marpet - SWN #593]]></title>
<description><![CDATA[Author: Security Weekly - A CRA Resource - Bewertung: 0x - Views:5 AI Brain Harvest, Fortibleed, Win 10, Blacksite, Windchill, Cisco, BB-8 Sidewalk Bots, Josh Marpet, and More on this episode of the Security Weekly News.

Visit https://www.securityweekly.com/swn for all the latest episodes!

Show...]]></description>
<link>https://tsecurity.de/de/3628593/it-security-video/ai-brain-harvest-fortibleed-win-10-blacksite-windchill-cisco-bb-8-josh-marpet-swn-593/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3628593/it-security-video/ai-brain-harvest-fortibleed-win-10-blacksite-windchill-cisco-bb-8-josh-marpet-swn-593/</guid>
<pubDate>Fri, 26 Jun 2026 23:17:32 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: Security Weekly - A CRA Resource - Bewertung: 0x - Views:5 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/0TVGOi-Xd6o?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>AI Brain Harvest, Fortibleed, Win 10, Blacksite, Windchill, Cisco, BB-8 Sidewalk Bots, Josh Marpet, and More on this episode of the Security Weekly News.<br />
<br />
Visit https://www.securityweekly.com/swn for all the latest episodes!<br />
<br />
Show Notes: https://securityweekly.com/swn-593<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Run Gemma on Reachy Mini, an open source robot]]></title>
<description><![CDATA[Author: Google for Developers - Bewertung: 23x - Views:168 Ian Ballantyne, Developer Relations Engineer at Google DeepMind, shows how Gemma runs on hardware like Raspberry Pi, Jetson, and Nano, letting a model see, hear, and act the way a robot would. The demo is Reachy Mini, the open source robo...]]></description>
<link>https://tsecurity.de/de/3628424/videos/run-gemma-on-reachy-mini-an-open-source-robot/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3628424/videos/run-gemma-on-reachy-mini-an-open-source-robot/</guid>
<pubDate>Fri, 26 Jun 2026 21:18:29 +0200</pubDate>
<category>🎥 Videos</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: Google for Developers - Bewertung: 23x - Views:168 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/KPx3nRwbldE?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>Ian Ballantyne, Developer Relations Engineer at Google DeepMind, shows how Gemma runs on hardware like Raspberry Pi, Jetson, and Nano, letting a model see, hear, and act the way a robot would. The demo is Reachy Mini, the open source robot from Hugging Face and Pollen Robotics, a small robot that sees with cameras, reacts with emotion and head movement, and holds a conversation through its microphone and speaker.<br />
<br />
What's covered: A live conversation with Reachy Mini about why local on-device models matter for privacy and speed, the robot's ability to move its head, show emotion, and take pictures to understand its surroundings, controlling smart devices and APIs like lights, thermostats, calendars, and live data, and an early look at the robot reasoning about a chessboard and explaining how a knight moves.<br />
Explore the Reachy Mini project from Hugging Face and Pollen Robotics, and try running Gemma on your own hardware.<br />
<br />
What would you build with Gemma on a robot or IoT device? Drop it in the comments.<br />
<br />
Resources: <br />
Reachy Mini → https://goo.gle/4xJNpVJ <br />
Local Reachy Mini → https://goo.gle/4f1dOXC <br />
Gemma Docs → https://goo.gle/4xMnVXS <br />
Gemma Cookbook → https://goo.gle/4epYEuZ <br />
<br />
<br />
Subscribe to Google for Developers → https://goo.gle/developers  <br />
<br />
Speaker: Ian Ballantyne<br />
Products Mentioned:  Google AI, Gemini<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[The Download: brain-melting heatwaves and unprecedented OpenAI restrictions]]></title>
<description><![CDATA[This is today’s edition of The Download, our weekday newsletter that provides a daily dose of what’s going on in the world of technology. Heat waves mess with your brain. Scientists are trying to figure out why. —Jessica Hamzelou It’s been hot in London this week. Really hot. A dangerous heat wav...]]></description>
<link>https://tsecurity.de/de/3627340/ai-nachrichten/the-download-brain-melting-heatwaves-and-unprecedented-openai-restrictions/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3627340/ai-nachrichten/the-download-brain-melting-heatwaves-and-unprecedented-openai-restrictions/</guid>
<pubDate>Fri, 26 Jun 2026 14:17:59 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[This is today’s edition of The Download, our weekday newsletter that provides a daily dose of what’s going on in the world of technology. Heat waves mess with your brain. Scientists are trying to figure out why. —Jessica Hamzelou It’s been hot in London this week. Really hot. A dangerous heat wave has hit Western…]]></content:encoded>
</item>
<item>
<title><![CDATA[Heat waves mess with your brain. Scientists are trying to figure out why.]]></title>
<description><![CDATA[It’s been hot in London this week. Really hot. A dangerous heat wave has hit Western Europe. Yesterday, the UK recorded its highest ever June temperature at 36.1 °C (about 97 °F). But as the weather app on my phone confirmed, it felt like 39 °C. It’s frightening that we are seeing such temperatur...]]></description>
<link>https://tsecurity.de/de/3626876/ai-nachrichten/heat-waves-mess-with-your-brain-scientists-are-trying-to-figure-out-why/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3626876/ai-nachrichten/heat-waves-mess-with-your-brain-scientists-are-trying-to-figure-out-why/</guid>
<pubDate>Fri, 26 Jun 2026 11:18:40 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[It’s been hot in London this week. Really hot. A dangerous heat wave has hit Western Europe. Yesterday, the UK recorded its highest ever June temperature at 36.1 °C (about 97 °F). But as the weather app on my phone confirmed, it felt like 39 °C. It’s frightening that we are seeing such temperatures in…]]></content:encoded>
</item>
<item>
<title><![CDATA[Understanding the brain with AI-driven explanations and experiments]]></title>
<description><![CDATA[Researchers introduce generative causal testing, which translates black box models into clear hypotheses and verifies them in the scanner, revealing what specific brain regions respond to in language.
The post Understanding the brain with AI-driven explanations and experiments appeared first on M...]]></description>
<link>https://tsecurity.de/de/3625197/ai-nachrichten/understanding-the-brain-with-ai-driven-explanations-and-experiments/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3625197/ai-nachrichten/understanding-the-brain-with-ai-driven-explanations-and-experiments/</guid>
<pubDate>Thu, 25 Jun 2026 18:05:30 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Researchers introduce generative causal testing, which translates black box models into clear hypotheses and verifies them in the scanner, revealing what specific brain regions respond to in language.</p>
<p>The post <a href="https://www.microsoft.com/en-us/research/blog/understanding-the-brain-with-ai-driven-explanations-and-experiments/">Understanding the brain with AI-driven explanations and experiments</a> appeared first on <a href="https://www.microsoft.com/en-us/research">Microsoft Research</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Apple stock getting hit after price hikes, analysts mostly nonplussed]]></title>
<description><![CDATA[Apple's rare mid-cycle hardware price increases pushed the stock lower on June 25, but Wall Street's early response stayed largely upbeat as analysts kept their ratings and targets unchanged.Wall Street reacts to Apple's price hikesApple shares fell about 4.8% in morning trading Thursday after th...]]></description>
<link>https://tsecurity.de/de/3625073/ios-mac-os/apple-stock-getting-hit-after-price-hikes-analysts-mostly-nonplussed/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3625073/ios-mac-os/apple-stock-getting-hit-after-price-hikes-analysts-mostly-nonplussed/</guid>
<pubDate>Thu, 25 Jun 2026 17:25:34 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Apple's rare mid-cycle hardware price increases pushed the stock lower on June 25, but Wall Street's early response stayed largely upbeat as analysts kept their ratings and targets unchanged.<br><br><div><img src="https://photos5.appleinsider.com/gallery/68069-143500-IMG_7744-xl.jpg" alt="Green fluctuating stock price line graph on dark background with prominent green Apple logo centered behind the chart, suggesting Apple's market performance over time" height="738"><span>Wall Street reacts to Apple's price hikes</span></div><br>Apple shares fell about 4.8% in morning trading Thursday after the company announced the price increases. The announcement followed Micron's blockbuster earnings report, which reinforced Wall Street's view that AI-driven demand will keep DRAM and NAND prices elevated.<br><br>The selloff made Apple one of the biggest losers among megacap technology stocks even as analysts largely maintained their bullish outlooks.<br><br>The first analyst reactions published after Apple's June 25 announcement show a consistent view. Rather than cutting ratings or price targets, analysts argued the <a href="https://appleinsider.com/articles/26/06/25/apple-confirms-price-nikes-across-macs-ipads-and-more">higher prices</a> should help offset soaring memory costs that have become increasingly difficult for Apple to absorb.<br><br><br> <a href="https://appleinsider.com/articles/26/06/25/apple-stock-getting-hit-after-price-hikes-analysts-mostly-nonplussed?utm_source=rss">Continue Reading on AppleInsider</a> | <a href="https://forums.appleinsider.com/discussion/244779?urm_source=rss">Discuss on our Forums</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Anthropic accuses Alibaba of using 25,000 fake accounts to scrape Claude AI]]></title>
<description><![CDATA[Anthropic has accused Alibaba of using nearly 25,000 fraudulent accounts to extract capabilities from its Claude AI models, in what the US AI company described as the largest known attack of its kind against it.



The campaign, carried out between April 22 and June 5, generated more than 28.8 mi...]]></description>
<link>https://tsecurity.de/de/3624147/ai-nachrichten/anthropic-accuses-alibaba-of-using-25000-fake-accounts-to-scrape-claude-ai/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3624147/ai-nachrichten/anthropic-accuses-alibaba-of-using-25000-fake-accounts-to-scrape-claude-ai/</guid>
<pubDate>Thu, 25 Jun 2026 12:48:04 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Anthropic has accused Alibaba of using nearly 25,000 fraudulent accounts to extract capabilities from its Claude AI models, in what the US AI company described as the largest known attack of its kind against it.</p>



<p>The campaign, carried out between April 22 and June 5, generated more than 28.8 million exchanges with Claude, according to a June 10 letter Anthropic sent to senior members of the US Senate Banking Committee, <a href="https://www.reuters.com/world/china/anthropic-says-alibaba-illicitly-extracted-claude-ai-model-capabilities-2026-06-24/" target="_blank" rel="noreferrer noopener">Reuters reported</a>.</p>



<p>Anthropic said the effort involved “distillation,” a technique in which a less capable AI model is trained on the outputs of a more advanced system, potentially allowing rivals to replicate some of its capabilities at lower cost.</p>



<p>The company said the campaign was conducted by operators affiliated with Alibaba and Alibaba Qwen, Alibaba’s AI lab, according to the report.</p>



<p>The allegation comes as businesses adopt generative AI tools across business functions, putting pressure on vendors to show they can detect misuse while keeping services available for corporate customers.</p>



<p>The dispute also comes as AI development becomes more closely tied to <a href="https://www.computerworld.com/article/4149313/chinas-use-of-open%E2%80%91source-ai-threatens-the-us-lead-in-ai-development-us-commission-warns.html">US-China technology tensions</a>. Anthropic said the alleged campaign could help accelerate China’s ability to reach the capabilities of its advanced <a href="https://www.computerworld.com/article/4162278/claude-mythos-signals-a-new-era-in-ai-driven-security-finding-271-flaws-in-firefox-3.html">Mythos Preview</a> model, while US officials have stepped up scrutiny of advanced AI systems over fears they could be used by military or intelligence users in countries of concern.</p>



<p>In February, Anthropic said it had identified similar campaigns by DeepSeek, Moonshot AI, and MiniMax to extract capabilities from Claude, with the alleged activity ranging from more than 150,000 exchanges by DeepSeek to more than 13 million by MiniMax.</p>



<p>Alibaba did not immediately respond to a request for comment.</p>



<h2 class="wp-block-heading">A new supply chain risk</h2>



<p>If Anthropic’s claims are true, the alleged campaign could allow Alibaba to build a comparable model in a short period of time and offer it at a much lower cost, said <a href="https://www.techinsights.com/experts/Anand-Joshi" target="_blank" rel="noreferrer noopener">Anand Joshi</a>, an AI analyst at TechInsights.</p>



<p>Analysts said the alleged campaign also points to a broader pattern beyond the two companies. Viewed alongside previous incidents cited by Anthropic, they said, model extraction appears to be escalating rather than remaining an isolated risk.</p>



<p>“The enterprise supply chain no longer ends at software, APIs, and cloud regions,” said <a href="https://greyhoundresearch.com/svg/" target="_blank" rel="noreferrer noopener">Sanchit Vir Gogia</a>, chief analyst at Greyhound Research. “It now includes rented intelligence, and rented intelligence can be copied and redeployed well outside the safety controls it was born with.”</p>



<p>Gogia said distillation should be a board-level concern because a weaker model trained on a stronger one can inherit its capabilities without the governance and controls around the original system.</p>



<p>For enterprises, the allegations point to a potentially more serious risk than conventional intellectual property theft: reverse engineering at scale. If proven, they would suggest that AI models can be copied systematically, turning model extraction into a new AI supply-chain risk.</p>



<p>“If a rival can clone the exact brain of the AI your company relies on, they can easily find its blind spots, hack your automated systems, or cause the AI vendor to panic and shut down services that your business needs to run every day,” said <a href="https://pareekh.com/" target="_blank" rel="noreferrer noopener">Pareekh Jain</a>, CEO of Pareekh Consulting.</p>



<h2 class="wp-block-heading">Mitigating the risks</h2>



<p><br>The allegation raises questions about the controls AI vendors have in place and how customers can protect themselves.</p>



<p>“Vendors should provide verified accounts, smart rate limits, abuse detection, usage monitoring, contractual bans on distillation, incident disclosure, and audit rights,” Jain said. “Enterprises should ask how the vendor detects and blocks large-scale model extraction and can demand contracts that guarantee backup plans and financial refunds if the AI service gets attacked or suddenly shut down.”</p>



<p>Joshi said enterprise customers should also press vendors for greater transparency around model development and safeguards.</p>



<p>“Enterprise buyers should ask what training data was used, how it was trained, what guardrails exist, how they can audit it, and so on,” Joshi said. “Model publishers will have to come up with watermarking technology in models as well as model responses. So if the model ‘skills’ are stolen, they should be able to find the thief.”</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Anthropic accuses Alibaba of using 25,000 fake accounts to scrape Claude AI]]></title>
<description><![CDATA[Anthropic has accused Alibaba of using nearly 25,000 fraudulent accounts to extract capabilities from its Claude AI models, in what the US AI company described as the largest known attack of its kind against it.



The campaign, carried out between April 22 and June 5, generated more than 28.8 mi...]]></description>
<link>https://tsecurity.de/de/3624110/it-nachrichten/anthropic-accuses-alibaba-of-using-25000-fake-accounts-to-scrape-claude-ai/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3624110/it-nachrichten/anthropic-accuses-alibaba-of-using-25000-fake-accounts-to-scrape-claude-ai/</guid>
<pubDate>Thu, 25 Jun 2026 12:32:54 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Anthropic has accused Alibaba of using nearly 25,000 fraudulent accounts to extract capabilities from its Claude AI models, in what the US AI company described as the largest known attack of its kind against it.</p>



<p>The campaign, carried out between April 22 and June 5, generated more than 28.8 million exchanges with Claude, according to a June 10 letter Anthropic sent to senior members of the US Senate Banking Committee, <a href="https://www.reuters.com/world/china/anthropic-says-alibaba-illicitly-extracted-claude-ai-model-capabilities-2026-06-24/" target="_blank" rel="noreferrer noopener">Reuters reported</a>.</p>



<p>Anthropic said the effort involved “distillation,” a technique in which a less capable AI model is trained on the outputs of a more advanced system, potentially allowing rivals to replicate some of its capabilities at lower cost.</p>



<p>The company said the campaign was conducted by operators affiliated with Alibaba and Alibaba Qwen, Alibaba’s AI lab, according to the report.</p>



<p>The allegation comes as businesses adopt generative AI tools across business functions, putting pressure on vendors to show they can detect misuse while keeping services available for corporate customers.</p>



<p>The dispute also comes as AI development becomes more closely tied to <a href="https://www.computerworld.com/article/4149313/chinas-use-of-open%E2%80%91source-ai-threatens-the-us-lead-in-ai-development-us-commission-warns.html">US-China technology tensions</a>. Anthropic said the alleged campaign could help accelerate China’s ability to reach the capabilities of its advanced <a href="https://www.computerworld.com/article/4162278/claude-mythos-signals-a-new-era-in-ai-driven-security-finding-271-flaws-in-firefox-3.html">Mythos Preview</a> model, while US officials have stepped up scrutiny of advanced AI systems over fears they could be used by military or intelligence users in countries of concern.</p>



<p>In February, Anthropic said it had identified similar campaigns by DeepSeek, Moonshot AI, and MiniMax to extract capabilities from Claude, with the alleged activity ranging from more than 150,000 exchanges by DeepSeek to more than 13 million by MiniMax.</p>



<p>Alibaba did not immediately respond to a request for comment.</p>



<h2 class="wp-block-heading">A new supply chain risk</h2>



<p>If Anthropic’s claims are true, the alleged campaign could allow Alibaba to build a comparable model in a short period of time and offer it at a much lower cost, said <a href="https://www.techinsights.com/experts/Anand-Joshi" target="_blank" rel="noreferrer noopener">Anand Joshi</a>, an AI analyst at TechInsights.</p>



<p>Analysts said the alleged campaign also points to a broader pattern beyond the two companies. Viewed alongside previous incidents cited by Anthropic, they said, model extraction appears to be escalating rather than remaining an isolated risk.</p>



<p>“The enterprise supply chain no longer ends at software, APIs, and cloud regions,” said <a href="https://greyhoundresearch.com/svg/" target="_blank" rel="noreferrer noopener">Sanchit Vir Gogia</a>, chief analyst at Greyhound Research. “It now includes rented intelligence, and rented intelligence can be copied and redeployed well outside the safety controls it was born with.”</p>



<p>Gogia said distillation should be a board-level concern because a weaker model trained on a stronger one can inherit its capabilities without the governance and controls around the original system.</p>



<p>For enterprises, the allegations point to a potentially more serious risk than conventional intellectual property theft: reverse engineering at scale. If proven, they would suggest that AI models can be copied systematically, turning model extraction into a new AI supply-chain risk.</p>



<p>“If a rival can clone the exact brain of the AI your company relies on, they can easily find its blind spots, hack your automated systems, or cause the AI vendor to panic and shut down services that your business needs to run every day,” said <a href="https://pareekh.com/" target="_blank" rel="noreferrer noopener">Pareekh Jain</a>, CEO of Pareekh Consulting.</p>



<h2 class="wp-block-heading">Mitigating the risks</h2>



<p><br>The allegation raises questions about the controls AI vendors have in place and how customers can protect themselves.</p>



<p>“Vendors should provide verified accounts, smart rate limits, abuse detection, usage monitoring, contractual bans on distillation, incident disclosure, and audit rights,” Jain said. “Enterprises should ask how the vendor detects and blocks large-scale model extraction and can demand contracts that guarantee backup plans and financial refunds if the AI service gets attacked or suddenly shut down.”</p>



<p>Joshi said enterprise customers should also press vendors for greater transparency around model development and safeguards.</p>



<p>“Enterprise buyers should ask what training data was used, how it was trained, what guardrails exist, how they can audit it, and so on,” Joshi said. “Model publishers will have to come up with watermarking technology in models as well as model responses. So if the model ‘skills’ are stolen, they should be able to find the thief.”</p>



<p><em>The article originally appeared on <a href="https://www.infoworld.com/article/4189342/anthropic-accuses-alibaba-of-using-25000-fake-accounts-to-scrape-claude-ai.html">InfoWorld</a>.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Building a state-of-the-art development platform with Backstage]]></title>
<description><![CDATA[Key takeaways




Backstage solved the portal problem, not the platform problem. A portal organizes catalogs, documentation, and templates. A platform owns deployments, environments, policies, and runtime operations. Backstage assumes that the execution layer exists beneath it.



Point-to-point ...]]></description>
<link>https://tsecurity.de/de/3623951/ai-nachrichten/building-a-state-of-the-art-development-platform-with-backstage/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3623951/ai-nachrichten/building-a-state-of-the-art-development-platform-with-backstage/</guid>
<pubDate>Thu, 25 Jun 2026 11:34:09 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<h2 class="wp-block-heading">Key takeaways</h2>



<ul class="wp-block-list">
<li>Backstage solved the portal problem, not the platform problem. A portal organizes catalogs, documentation, and templates. A platform owns deployments, environments, policies, and runtime operations. Backstage assumes that the execution layer exists beneath it.</li>



<li>Point-to-point integrations become a maintenance burden. Many organizations end up with a “messy middle” where Backstage is connected directly to <a href="https://www.infoworld.com/article/2269266/what-is-cicd-continuous-integration-and-continuous-delivery-explained.html" data-type="link" data-id="https://www.infoworld.com/article/2269266/what-is-cicd-continuous-integration-and-continuous-delivery-explained.html">CI/CD</a>, <a href="https://www.infoworld.com/article/2259088/what-is-gitops-extending-devops-to-kubernetes-and-beyond.html" data-type="link" data-id="https://www.infoworld.com/article/2259088/what-is-gitops-extending-devops-to-kubernetes-and-beyond.html">GitOps</a>, <a href="https://www.infoworld.com/article/2266945/what-is-kubernetes-scalable-cloud-native-applications.html" data-type="link" data-id="https://www.infoworld.com/article/2266945/what-is-kubernetes-scalable-cloud-native-applications.html">Kubernetes</a>, and <a href="https://www.infoworld.com/article/2262666/what-is-observability-software-monitoring-on-steroids.html" data-type="link" data-id="https://www.infoworld.com/article/2262666/what-is-observability-software-monitoring-on-steroids.html">observability</a> tools through custom wiring that’s fragile and hard to evolve.</li>



<li>Abstractions are the interface between developers and infrastructure. Developers work with components, endpoints, and dependencies. Platform engineers work with environments, pipelines, and component types. The platform compiles both into Kubernetes resources.</li>



<li>A control plane bridges the gap. It sits between the portal and runtime, compiling abstractions into infrastructure, enforcing policies consistently, reconciling drift, and aggregating runtime state back to the portal.</li>



<li>Good abstractions enable advanced capabilities. Unified observability, automated guardrails, and AI agents that can reason about and act on your platform. All becomes possible when you have well-defined concepts and a control plane that understands both sides.</li>
</ul>



<p>…</p>



<h2 class="wp-block-heading">Start with Backstage</h2>



<p>If you’re building an <a href="https://www.infoworld.com/article/2263059/what-is-an-internal-developer-platform-paas-done-your-way.html" data-type="link" data-id="https://www.infoworld.com/article/2263059/what-is-an-internal-developer-platform-paas-done-your-way.html">internal developer platform</a>, Backstage is certainly part of your architecture. It solved the discovery problem and became the default choice for developer portals.</p>



<p>Before Backstage, developers navigated wikis, spreadsheets, and tribal knowledge just to find who owned a service or how to spin up a new one. Backstage brought structure: a unified catalog, a plugin ecosystem, and golden-path templates that actually got adopted.</p>



<p><a href="https://github.com/backstage/backstage" data-type="link" data-id="https://github.com/backstage/backstage">Backstage</a> is a Cloud Native Computing Foundation (CNCF) project with one of the most active contributor communities in the ecosystem. When organizations evaluate developer portals, Backstage is the starting point.</p>



<p>However, many teams discover something after deployment: Backstage provides a portal, not a platform. A portal organizes information. A platform owns execution: deployments, environments, policies, observability, and runtime operations.</p>



<p>Backstage assumes that the execution layer exists beneath it. That layer is where most of the complexity lives, and it’s what this article is about.</p>



<h2 class="wp-block-heading"><a></a>What a developer platform actually is</h2>



<p>A developer platform or an internal developer platform is a self-service framework you build to help developers build, deploy, and manage applications independently.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-full"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/06/Image_01_developer_platform.png" alt="Image_01_developer_platform" class="wp-image-4189088" width="1024" height="307" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">WSO2</p></div>



<p>Most organizations already have an organically grown version of this:</p>



<ul class="wp-block-list">
<li>Developer commits code</li>



<li>CI pipeline builds and pushes images to a registry</li>



<li>Pipeline updates a GitOps repo containing Helm charts or Kubernetes manifests</li>



<li>Argo CD or Flux syncs those manifests to clusters</li>
</ul>



<p>You may have this workflow running today. The question is whether it’s a pipeline stitched together with scripts and tribal knowledge, or a platform with consistent abstractions and self-service capabilities.</p>



<h2 class="wp-block-heading"><a></a>What usually happens after adopting Backstage</h2>



<p>How do you add Backstage to this setup? The common approach is for developers to maintain Backstage entity files (primarily component and API entities) alongside the source code. Then you configure the built-in entity provider in Backstage to scan source code repositories to populate the catalog. Eventually, you’ll end up with a portal with all your systems, components, APIs, and other resources. So far, so good.</p>



<p>Once developers start using the portal, you’ll be hit with a consistent flow of feature requests:</p>



<ul class="wp-block-list">
<li>“I see my component in the catalog, but is it actually running?” You configure the Kubernetes plugin and link components to their corresponding manifests. Now developers can see pod status, deployment state, and replica counts.</li>



<li>“I need logs, metrics, and traces related to my component.” You integrate your observability stack or developers context-switch to Grafana, Datadog, or whatever you’re running. Either way, more wiring.</li>



<li>“Can I create new components from here?” You build Backstage templates that scaffold repos with the right structure, Backstage entities, Helm charts, and CI pipelines, all of which encode your organization’s best practices. Now you’re maintaining golden paths in templates, separately from the runtime configuration that actually enforces them.</li>
</ul>



<p>Each request is reasonable and achievable, but they add up.</p>



<h2 class="wp-block-heading"><a></a>The messy middle</h2>



<p>Eventually, you end up with a platform held together by point-to-point connections. Every new capability requires new wiring. Every upgrade risks breaking something. You spend more time maintaining integrations than building features.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-full"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/06/Image_02_messy_middle.png" alt="Image_02_messy_middle" class="wp-image-4189092" width="1024" height="893" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">WSO2</p></div>



<p>You would never design a production system with this many point-to-point dependencies. Why accept it for your platform?</p>



<h2 class="wp-block-heading"><a></a>Treat the platform as a product, but also as a system</h2>



<p>Organically grown systems get you started, but once you commit to Backstage as your portal, you need a product mindset. Start from developer experience, understand their pain points, then design a system that addresses them coherently.</p>



<p>A platform is also a system. Approach it the way you would approach any production system you’re building. You wouldn’t design a back-end service without thinking about separation of concerns, clear interfaces, and extensibility.</p>



<p>The same principles apply here:</p>



<ul class="wp-block-list">
<li>Separation of concerns: Don’t mix developer-facing abstractions with infrastructure implementation. Keep them separate so you can evolve each independently.</li>



<li>Clear interfaces: Define explicit abstractions. Developers and platform engineers should interact with well-defined concepts rather than implementation details scattered across Helm charts and CI scripts.</li>



<li>Extensibility: Requirements keep changing. If every new capability requires custom wiring, you’ll spend more time maintaining than improving. Design for extension from the start.</li>
</ul>



<p>The difference between a pile of integrations and a platform is architecture. Get the system design right, and new capabilities slot in cleanly. Get it wrong, and every feature request becomes a maintenance burden.</p>



<h2 class="wp-block-heading">The missing layer beneath Backstage</h2>



<p>Moving from an organically grown pipeline to an actionable developer platform is a big leap. You probably have CI/CD pipelines that work, a Kubernetes cluster running workloads, and a Backstage catalog describing what exists.</p>



<p>The questions are:</p>



<ul class="wp-block-list">
<li>How do you transform an informational portal into one with a platform under the hood?</li>



<li>How do you bridge the gap between what the catalog describes and what’s actually running?</li>



<li>How do you enforce golden paths beyond initial scaffolding?</li>



<li>How do you design a platform that evolves with your organization’s needs?</li>
</ul>



<p>What’s missing is a connective layer between Backstage and your runtime, something that makes the portal operational rather than just informational. Let’s look at the key architectural elements to consider when designing that layer and the whole platform.</p>



<h2 class="wp-block-heading"><a></a>Start with abstractions</h2>



<p>One of the main goals of a developer platform is to reduce cognitive load. The platform should meet developers where they are and speak their language, not Kubernetes’.</p>



<p>Every organization has its own vocabulary, but the Backstage system model is a good starting point. It may not cover everything, but you can extend it with custom entities. The key is that developers work with high-level concepts while the platform compiles them into Kubernetes resources. Developers are abstracted away from the underlying details, but they can still see what’s happening underneath.</p>



<figure class="wp-block-table"><div class="overflow-table-wrapper"><table class="has-fixed-layout"><tbody><tr><td><strong>Concept</strong></td><td><strong>Description</strong></td><td><strong>Backstage mapping</strong></td></tr><tr><td>Project</td><td>A cloud-native application composed of multiple components. It is also a unit of isolation.</td><td>System</td></tr><tr><td>Component</td><td>A deployable unit, such as web services, APIs, workers, or scheduled tasks.</td><td>Component</td></tr><tr><td>Endpoint</td><td>A network-accessible interface exposed by a component. </td><td>API</td></tr><tr><td>Resource</td><td>External infrastructure such as databases, queues, and caches.</td><td>Resource</td></tr><tr><td>Dependency</td><td>A component’s reliance on endpoints or resources.</td><td>consumesAPI, dependsOn</td></tr></tbody></table> </div></figure>



<p>These are not just static abstractions; they also have associated runtime semantics. The following diagram illustrates runtime representations of these concepts.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-full"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/06/Image_03_cell_diagram.png" alt="Image_03_cell_diagram" class="wp-image-4189100" width="1024" height="905" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">WSO2</p></div>



<p>In the workload cluster, a project becomes an isolation boundary for all of its components. The platform translates this into Kubernetes namespaces and network policies that enforce the boundary, not just document it.</p>



<p>Endpoint visibility determines which endpoints can talk to which. A project-scoped endpoint gets network policies that block traffic from outside the project. An organization-scoped endpoint is exposed to internal traffic but remains behind the internal gateway. An external endpoint gets routed through the public gateway with appropriate authentication. Developers declare visibility; the platform generates the policies.</p>



<p>Dependencies work the same way. When a component declares a dependency on an endpoint, the platform injects the URL and other environment variables required to connect to the dependency. It configures the network policies for both directions, egress from the calling endpoint and ingress to the target endpoint. Without the declared dependency, egress is blocked by default. The dependency graph you see above reflects actual permitted traffic flow, not just intended relationships.</p>



<h2 class="wp-block-heading"><a></a>You need platform abstractions, too</h2>



<p>Developer abstractions help your developers. Platform abstractions help you.</p>



<p>While developers work with components, endpoints, and dependencies, you need a different vocabulary to design and operate the platform itself. These abstractions let you and your team define standards, enforce policies, and create structure without writing low-level configurations for every scenario.</p>



<figure class="wp-block-table"><div class="overflow-table-wrapper"><table class="has-fixed-layout"><tbody><tr><td><strong>Concept</strong></td><td><strong>Description</strong></td></tr><tr><td>Namespace</td><td>A logical grouping of users and resources, typically aligned to a company, business unit, or team. Defines ownership and access boundaries.</td></tr><tr><td>Data plane</td><td>A Kubernetes cluster that hosts one or more deployment environments. You can have multiple data planes for isolation, regional distribution, or scaling.</td></tr><tr><td>Environment</td><td>A runtime context, such as dev, test, staging, or prod, where workloads are deployed and executed. Environments carry their own policies and resource configurations.</td></tr><tr><td>Pipeline</td><td>A defined process that governs how work, such as builds, deployments, promotions, or any automated workflows, flows through the platform. Encodes your operational processes as a platform primitive.</td></tr><tr><td>Component type</td><td>Defines a category of workload—Service, Worker, Cron, Job.</td></tr><tr><td>Trait</td><td>A reusable capability that attaches to any component, such as autoscaling, resilience, observability, and security policies. Compose behaviors without duplicating configuration.</td></tr></tbody></table> </div></figure>



<p>These abstractions separate platform concerns from application concerns. Developers don’t need to know which cluster their code runs on or how environments are wired together. They deploy to “staging” or “prod,” and you define what those terms mean.</p>



<h2 class="wp-block-heading"><a></a>The missing layer is a control plane</h2>



<p>The control plane is where abstractions become real. It sits between the portal and your workload clusters, translating developer intent into infrastructure configuration.</p>



<p>You can think of it as a compiler that targets Kubernetes clusters, converting higher-level abstractions into what Kubernetes and its underlying frameworks understand. It can also apply platform-wide rules during this compilation. Resource limits, security requirements, etc., can be enforced consistently, not merely documented and hoped for.</p>



<p>But compilation is only half the job. The control plane also reconciles continuously. It monitors drift between the declared and actual states. When they diverge, it corrects. Your abstractions remain the source of truth; the control plane enforces them over time.</p>



<h2 class="wp-block-heading"><a></a>Programmability is not optional</h2>



<p>One of the key aspects of this control plane is programmability. If you want your platform to evolve, the control plane needs to be extensible. Different teams have different requirements. New capabilities emerge. You can’t anticipate everything up front.</p>



<p>This means allowing customization of how abstractions compile to Kubernetes manifests. But extensibility without guardrails is dangerous. You need programmability that preserves your invariants. The goal is constrained flexibility, open enough to evolve, structured enough to stay coherent.</p>



<h2 class="wp-block-heading"><a></a>Observable abstractions make the portal useful</h2>



<p>The control plane also aggregates runtime state and associates it with your abstractions. This is what makes the portal useful. Without this, developers piece together information from different tools: Kubernetes dashboard for pod status, Argo CD for the deployment state, Grafana for metrics, Jaeger for traces. Each tool knows part of the story; none shows the full picture.</p>



<p>With the control plane aggregating state, the portal tells a connected story. When a developer opens a component page in Backstage, they see:</p>



<ul class="wp-block-list">
<li>Deployed environments and their status</li>



<li>Current replicas and resource usage</li>



<li>Recent deployments and who triggered them</li>



<li>Logs, metrics, and traces that are scoped to that component, in each environment</li>



<li>Dependencies and their health</li>
</ul>



<p>No context-switching. No reconstructing which pod belongs to which service in which cluster. The abstraction is the anchor; everything else attaches to it.</p>



<p>This only works because the control plane understands both sides. It compiled the abstractions to Kubernetes, so it knows how to map runtime data back. Information flows in both directions. Downward: developer intent flows through the control plane and becomes running workloads. Upward: runtime state flows back through the control plane and appears in the portal.</p>



<p>This is what makes the portal actionable. It’s not just displaying information; it’s connected to a system that can act.</p>



<h2 class="wp-block-heading"><a></a>Data plane: keep it simple</h2>



<p>The data plane is where your workloads actually run. In most cases, this means one or more Kubernetes clusters. The data plane doesn’t know about your abstractions. It understands Kubernetes primitives such as pods, deployments, services, and ingresses. The control plane’s job is to compile your higher-level concepts into these primitives and apply them.</p>



<p>The data plane does one thing: it runs what the control plane tells it to run. The intelligence lives in the control plane; the execution happens in the data plane.</p>



<h2 class="wp-block-heading">Where AI fits into the platform</h2>



<p>AI is now part of every platform conversation, but the architectural question is where it actually belongs.</p>



<p>The abstractions and control plane you’ve built create the foundation. You have well-defined concepts such as components, endpoints, and dependencies. You have a runtime state aggregated and tied to those concepts. You have a connected view of your system. AI agents can definitely leverage this.</p>



<h3 class="wp-block-heading"><a></a>Agents as platform users</h3>



<p>AI agents should be able to interact with your platform as first-class participants. This requires exposing platform capabilities through interfaces that agents can use, such as <a href="https://www.infoworld.com/article/4029634/what-is-model-context-protocol-how-mcp-bridges-ai-and-external-services.html" data-type="link" data-id="https://www.infoworld.com/article/4029634/what-is-model-context-protocol-how-mcp-bridges-ai-and-external-services.html">Model Context Protocol</a> (MCP) servers, APIs with clear semantics, user-friendly CLIs, and skills that map to platform operations.</p>



<p>These capabilities of the platform enable agents to create components, trigger builds and deployments, query environment status, and reason about dependencies. They help you and your developers become more productive.</p>



<h3 class="wp-block-heading"><a></a>Agents as platform capabilities</h3>



<p>You can also embed agents inside your platform to help your teams’ day-to-day operations. Here are some examples of agents you can develop:</p>



<ul class="wp-block-list">
<li>SRE agents: Analyze logs, metrics, and traces to surface likely root causes. Instead of developers digging through dashboards, the agent correlates signals and suggests where to look.</li>



<li>FinOps agents: Help teams understand and optimize resource costs across environments and components.</li>



<li>Architect agents: Assist with system design decisions, such as dependency analysis, capacity planning, and migration impact assessment.</li>
</ul>



<p>These agents work because they have access to the control plane’s unified view. They see abstractions, runtime state, and observability data in one place, the same connected story developers see in the portal.</p>



<p>The pattern holds. Good abstractions make everything easier, including AI.</p>



<h2 class="wp-block-heading"><a></a>OpenChoreo as a reference implementation</h2>



<p><a href="https://github.com/openchoreo/openchoreo" data-type="link" data-id="https://github.com/openchoreo/openchoreo">OpenChoreo</a> is an open-source developer platform for Kubernetes. It was recently accepted into the CNCF as a sandbox project. OpenChoreo implements the architecture described in this article: developer abstractions backed by a control plane, a Backstage-powered portal, integrated CI/CD and GitOps, and observability wired to your abstractions.</p>



<p>If you’re building this architecture yourself, OpenChoreo is worth studying as a reference, even if you don’t adopt it directly. The project demonstrates how these pieces fit together: how abstractions compile into Kubernetes resources, how runtime state flows back to the portal, and how guardrails are enforced during compilation.</p>



<p>You can use OpenChoreo as a complete platform, or install its Backstage plugins into your existing portal and use just the control plane layer. Either way, the underlying patterns are what matter. The architecture is the idea. OpenChoreo is one way to implement it.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/06/image_04_multi_plane_architecture.png?w=1024" alt="image_04_multi_plane_architecture" class="wp-image-4189109" width="1024" height="552" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">WSO2</p></div>



<h2 class="wp-block-heading">A useful mental model: multi-plane architecture</h2>



<p>OpenChoreo separates concerns across five planes:</p>



<ol class="wp-block-list">
<li>Experience plane: Where developers, platform engineers, and SREs interact with the platform via the Backstage-powered portal, CLI, GitOps, or AI agents.</li>



<li>Control plane: The brain that translates high-level abstractions (components, APIs, environments, pipelines) into Kubernetes manifests. Programmable through component types and traits, so you can extend it without forking or writing low-level controllers. Continuously reconciles the runtime state back into those abstractions.</li>



<li>Data plane: Where workloads run. Enforces the semantics of your abstractions, such as project isolation, traffic policies, and security boundaries. These aren’t just configurations; the platform guarantees them.</li>



<li>Observability plane: Feeds metrics, logs, and traces back through the same abstractions developers already understand, requiring no translation.</li>



<li>Workflow plane (optional): Handles builds using Cloud Native Buildpacks and Argo Workflows by default.</li>
</ol>



<p>These planes work together but remain separate concerns. You can reason about each independently, evolve them at different rates, and deploy them flexibly: a single cluster with namespace isolation for dev/test, fully separated multi-cluster setups for production, or hybrid topologies that colocate planes like Control and CI for cost efficiency.</p>



<h2 class="wp-block-heading"><a></a>AI and OpenChoreo</h2>



<p>OpenChoreo is being built to treat AI agents as first-class participants. In OpenChoreo 1.0, external agents can interact with the platform via MCP servers, agent skills, or the CLI to generate and edit component configurations, reason about releases and environments, and more. The built-in SRE Agent is a first example of this. It analyzes logs, metrics, and traces from your deployments and uses LLMs to surface likely root causes and actionable insights.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/06/Image_05_external_internal_agents_openchoreo.png?w=1024" alt="Image_05_external_internal_agents_openchoreo" class="wp-image-4189115" width="1024" height="584" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">WSO2</p></div>



<h2 class="wp-block-heading">From portal to platform</h2>



<p>Backstage solved the portal problem. It gave you a unified interface for catalogs, documentation, and golden paths. But a portal isn’t a platform. There’s a gap between what developers see and what’s actually running, and that’s where you get stuck. You fill it with point-to-point integrations, custom plugins, and scripts that become their own maintenance burden.</p>



<p>The pattern that works is portal, control plane, data plane: </p>



<ul class="wp-block-list">
<li>A portal that gives developers ready access to catalogs, documentation, and templates.</li>



<li>A control plane that compiles platform abstractions, reconciles drift, and aggregates runtime state.</li>



<li>A data plane that runs workloads and enforces guarantees.</li>
</ul>



<p>Whether you build this yourself or you adopt something like OpenChoreo, the architecture matters more than the tools. Get the layers right, and new capabilities slot in cleanly. Get them wrong, and every feature request becomes a project.</p>



<p>Backstage gives you the front door. The real platform begins behind it.</p>



<p><em>—</em></p>



<p><a href="https://www.infoworld.com/blogs/new-tech-forum"><strong><em>New Tech Forum</em></strong></a><em><strong> provides a venue for technology leaders—including vendors and other outside contributors—to explore and discuss emerging enterprise technology in unprecedented depth and breadth. The selection is subjective, based on our pick of the technologies we believe to be important and of greatest interest to InfoWorld readers. InfoWorld does not accept marketing collateral for publication and reserves the right to edit all contributed content. Send all </strong></em><em><strong>inquiries to </strong></em><a href="mailto:doug_dineley@foundryco.com"><strong><em>doug_dineley@foundryco.com</em></strong></a><em><strong>.</strong></em></p>
</div></div></div>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Digital ID brain trust will meet behind closed doors as minister ducks cost questions]]></title>
<description><![CDATA[Minutes will not be published, and MPs still have no answer on the group's budget or how its members were chosen]]></description>
<link>https://tsecurity.de/de/3623945/it-nachrichten/digital-id-brain-trust-will-meet-behind-closed-doors-as-minister-ducks-cost-questions/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3623945/it-nachrichten/digital-id-brain-trust-will-meet-behind-closed-doors-as-minister-ducks-cost-questions/</guid>
<pubDate>Thu, 25 Jun 2026 11:33:14 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Minutes will not be published, and MPs still have no answer on the group's budget or how its members were chosen]]></content:encoded>
</item>
<item>
<title><![CDATA[Stanford researchers will discuss their agentic 'scientists' that are on course to reshape drug discovery at VB Transform 2026]]></title>
<description><![CDATA[Drug discovery is notoriously inefficient. Pharmaceutical projects span years, moving from one specialized human team to the next through disconnected workflows that result in knowledge loss during each handoff. A shocking 90% to 95% of drug discovery projects reportedly fail — one of the highest...]]></description>
<link>https://tsecurity.de/de/3622617/it-nachrichten/stanford-researchers-will-discuss-their-agentic-scientists-that-are-on-course-to-reshape-drug-discovery-at-vb-transform-2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3622617/it-nachrichten/stanford-researchers-will-discuss-their-agentic-scientists-that-are-on-course-to-reshape-drug-discovery-at-vb-transform-2026/</guid>
<pubDate>Wed, 24 Jun 2026 21:18:04 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Drug discovery is notoriously inefficient. Pharmaceutical projects span years, moving from one specialized human team to the next through disconnected workflows that result in knowledge loss during each handoff. </p><p>A shocking <a href="https://www.sciencedirect.com/science/article/pii/S2211383522000521?via%3Dihub">90% to 95% of drug discovery projects reportedly fail</a> — one of the highest failure rates of any industry. A single successful drug can take over a dozen years and up to $1 billion from initial discovery to patient distribution, according to published reports. </p><p><a href="https://venturebeat.com/business/rethinking-drug-design-the-growing-role-of-generative-models-in-early-stage">Generative AI is being used</a> to solve some of the challenges, but Stanford researchers have moved the ball forward with agentic AI. </p><p>A team led by James Zou, associate professor of Biomedical Data Science at Stanford University, has deployed thousands autonomous AI "scientist" agents in a virtual biotech that simulates the full lifecycle of drug development. The agents handle everything from initial discovery through safety testing and clinical trial design, while maintaining the continuity that’s lacking in today’s drug discovery processes, according to Zou.</p><p>The project uses a hierarchical orchestration framework. At the top sits a chief scientist officer agent that acts as a planner, delegating tasks to teams of specialized agents, Zou told VentureBeat during a call ahead of his upcoming session at <a href="https://venturebeat.com/vbtransform2026">VB Transform 2026</a>.</p><p>While one team of agents focuses on discovery, another manages safety, and others handle specialized analytical tasks. Because these agents operate within a unified, hierarchical ecosystem, they retain the full context of a project, maintaining continuity from the first molecule identified to the final clinical outcome.</p><p>The "brain" of the system relies on a vast amount of primary data. The agents are granted access to data sources ranging from genomics and FDA chemistry data to clinical trial databases <a href="https://venturebeat.com/ai/model-context-protocol-a-promising-ai-integration-layer-but-not-a-standard-yet">using a model context protocol</a>.</p><p>The team has invested heavily in agent-native and agent-friendly data, allowing the AI to synthesize complex information more effectively. The system relies on a combination of models, with Zou noting that while Claude often serves as the backbone for coding and data analysis, the architecture employs a mixture of models, including those fine-tuned specialized use cases.</p><p>Zou is raising money at a roughly $1 billion valuation for his startup, Human Intelligence, based on the research.</p><p>During Zou’s session at VB Transform on July 15, titled <b>How 10,000 agentic scientists in Stanford’s lab are set to revolutionize medical research and discovery</b>, he will share valuable insights including strategies for managing context and long-running, multi-step workflows in a multi-agent system, the process of transforming and indexing raw enterprise data to make it agent native, and how to use human auditing and experimental reward signals to verify agent actions.</p><p>Another session at VB Transform focused on the value of agentic context includes <b>Building a trustworthy agentic AI foundation: How Zillow accelerated engineering by 40%</b>, with Zillow's SVP of engineering and technology, Toby Roberts and Glean’s CEO Arvind Jain. </p><p><i>Interested in attending VB Transform 2026? Register </i><a href="https://web.cvent.com/event/27401f5a-f49e-46fc-90a3-eee31c2a4818/register"><i>here</i></a><i>. A select number of complimentary passes are also available to senior technology leaders. </i><a href="mailto:events@venturebeat.com"><i>Contact us </i></a><i>to get yours.</i></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Intuit will show off how it rebuilt its AI infrastructure to support fast and complex tasks at VB Transform 2026]]></title>
<description><![CDATA[Customer expectations have shifted from simple, fast conversational interactions to complex agentic AI-powered tasks that legacy IT architectures simply can’t handle. To address this, Intuit made the bold decision to overhaul its technical infrastructure for its business platform. The company mov...]]></description>
<link>https://tsecurity.de/de/3622060/it-nachrichten/intuit-will-show-off-how-it-rebuilt-its-ai-infrastructure-to-support-fast-and-complex-tasks-at-vb-transform-2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3622060/it-nachrichten/intuit-will-show-off-how-it-rebuilt-its-ai-infrastructure-to-support-fast-and-complex-tasks-at-vb-transform-2026/</guid>
<pubDate>Wed, 24 Jun 2026 18:04:03 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Customer expectations have shifted from simple, fast conversational interactions to complex agentic AI-powered tasks that legacy IT architectures simply can’t handle. </p><p>To address this, Intuit made the bold decision to overhaul its technical infrastructure for its business platform. The company moved away from its multi-agent setup, which prioritized broad capabilities, to a granular, skill-and-tool-based architecture while <a href="https://venturebeat.com/orchestration/intuits-ai-agents-hit-85-repeat-usage-the-secret-was-keeping-humans-involved">embedding human experts directly into the workflow</a> alongside AI. This shift involved decomposing its massive agents into specialized components, separating the brain from the hands, essentially.</p><p>"We went from a multi-agent system where we had large agents that did a lot to fully incorporating workflows, skills and tools<b> </b>down to the base level,” said Nhung Ho, VP of AI at Intuit. “We changed the orchestrator, we changed the planner, we changed the brain, and we also changed what everybody had to build across the whole company."</p><p>At <a href="https://venturebeat.com/vbtransform2026">VB Transform 2026</a> on July 14 and 15, Ho will share details about the technology decisions behind building an abstraction layer behind Intuit’s system of intelligence. She’ll also share how the new architecture has allowed the company to decouple its orchestration from specific model providers, allowing Intuit to remain agile and use the best tools for the job, whether from large model providers or their own home-grown tools.</p><p>Other VB Transform sessions focused on agentic orchestration include: </p><ul><li><p><b>From signals to shelves: How Target is engineering Agentic AI for the right product, right place, right time </b>with speaker Siobhan McFeeney, SVP Technology, Target;</p></li><li><p><b>The engineer's multiplier: How Instacart uses agentic AI to eliminate toil, elevate teams and slash costs </b>with speaker Anirban Kundu, CTO, Instacart;</p></li><li><p><b>MCP connection isn't orchestration: Building the agent execution layer </b>with Arnab Bose, chief product officer, Asana;</p></li><li><p><b>Building the agentic workforce: A blueprint for scaling AI operations without the sprawl </b>with Romit Jadhwani, Sr. Director, Enterprise AI, Data &amp; Productivity, Rivian and Craig Wiley, VP of AI, Databricks; and </p></li><li><p><b>Inside Atlassian’s Living Lab: Deploying context-aware agents at scale </b>with Dr. Molly Sands, head of the Teamwork Lab at Atlassian</p></li></ul><p><i>Interested in attending VB Transform 2026? Register </i><a href="https://web.cvent.com/event/27401f5a-f49e-46fc-90a3-eee31c2a4818/register"><i>here</i></a><i>. A select number of complimentary passes are also available to senior technology leaders. </i><a href="mailto:events@venturebeat.com"><i>Contact us </i></a><i>to get yours.</i></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Mushroom Behind 'Tiny Human' Visions Lacks Genes For Known Psychedelics]]></title>
<description><![CDATA[alternative_right shares a report from ScienceAlert: If you consumed a wild mushroom and suddenly started seeing tiny people around you, you might reasonably assume it contained a familiar psychedelic. But that does not appear to be the case with Lanmaoa asiatica, known locally as jian shou qing,...]]></description>
<link>https://tsecurity.de/de/3621095/it-security-nachrichten/mushroom-behind-tiny-human-visions-lacks-genes-for-known-psychedelics/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3621095/it-security-nachrichten/mushroom-behind-tiny-human-visions-lacks-genes-for-known-psychedelics/</guid>
<pubDate>Wed, 24 Jun 2026 13:09:21 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[alternative_right shares a report from ScienceAlert: If you consumed a wild mushroom and suddenly started seeing tiny people around you, you might reasonably assume it contained a familiar psychedelic. But that does not appear to be the case with Lanmaoa asiatica, known locally as jian shou qing, a mushroom species sold in markets in Yunnan, southwestern China. When eaten undercooked, the mushroom can produce vivid visions of miniature people -- not unlike Gulliver on his travels to Lilliput. To try and find out the root cause, University of Utah mycologists Colin Domnauer and Bryn Dentinger sequenced the genomes of 53 mushroom samples from across the wider Lanmaoa genus. And despite the reported hallucinations, they found no close matches to genes associated with psilocybin or ibotenic acid, two well-known mushroom hallucinogens whose biosynthetic pathways were specifically examined in the study.
 
"Biosynthetic gene mining of the L. asiatica genome found no close hits with any genes known in the production of mushroom psychoactive compounds," write the researchers in their published paper. "This supports our hypothesis of the presence of a novel unidentified metabolite responsible for the unique hallucinogenic properties of L. asiatica." [...] Whatever chemical pathways are causing these effects in the brain, the responsible compound appears to be something scientists have not yet identified. [...] By identifying 1,515 corresponding genes across the selected specimens, the researchers obtained a clearer answer to the question of what defines a mushroom species as part of the genus Lanmaoa. There are now 17 recognized species in the genus, including four that haven't been identified before, two of which the researchers specifically named here: Lanmaoa fallax and Lanmaoa carbonilivor. The researchers say the Lanmaoa family and evolutionary tree can now be more fully mapped out, and some existing specimens may need to be reclassified.<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=Mushroom+Behind+'Tiny+Human'+Visions+Lacks+Genes+For+Known+Psychedelics%3A+https%3A%2F%2Fscience.slashdot.org%2Fstory%2F26%2F06%2F24%2F0624256%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fscience.slashdot.org%2Fstory%2F26%2F06%2F24%2F0624256%2Fmushroom-behind-tiny-human-visions-lacks-genes-for-known-psychedelics%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://science.slashdot.org/story/26/06/24/0624256/mushroom-behind-tiny-human-visions-lacks-genes-for-known-psychedelics?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[The brain was never just a language model]]></title>
<description><![CDATA[The future of AI: the brain is much more than a large language model. It is a fusion engine, able to weigh multiple streams of data at the same time.]]></description>
<link>https://tsecurity.de/de/3618220/it-nachrichten/the-brain-was-never-just-a-language-model/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3618220/it-nachrichten/the-brain-was-never-just-a-language-model/</guid>
<pubDate>Tue, 23 Jun 2026 14:18:20 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The future of AI: the brain is much more than a large language model. It is a fusion engine, able to weigh multiple streams of data at the same time.]]></content:encoded>
</item>
<item>
<title><![CDATA[3 People Have Gotten Cancer-Detecting Implants in Their Brains]]></title>
<description><![CDATA[Coherence Neuro has started testing a brain-computer interface that could one day use electrical stimulation to prevent tumors from growing.]]></description>
<link>https://tsecurity.de/de/3617667/it-nachrichten/3-people-have-gotten-cancer-detecting-implants-in-their-brains/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3617667/it-nachrichten/3-people-have-gotten-cancer-detecting-implants-in-their-brains/</guid>
<pubDate>Tue, 23 Jun 2026 11:02:46 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Coherence Neuro has started testing a brain-computer interface that could one day use electrical stimulation to prevent tumors from growing.]]></content:encoded>
</item>
<item>
<title><![CDATA[Voidling Bound Review (PC)]]></title>
<description><![CDATA[Right upon starting Voidling Bound, I’ve been very excited about the idea of a creature collector, third person game with elements from Pokemon, Skylanders and so on. However, even if it does borrow some elements from those games, Voidling Bound also manages to stand on its own, while delivering ...]]></description>
<link>https://tsecurity.de/de/3616338/it-security-nachrichten/voidling-bound-review-pc/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3616338/it-security-nachrichten/voidling-bound-review-pc/</guid>
<pubDate>Mon, 22 Jun 2026 20:09:10 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Right upon starting Voidling Bound, I’ve been very excited about the idea of a creature collector, third person game with elements from Pokemon, Skylanders and so on. However, even if it does borrow some elements from those games, Voidling Bound also manages to stand on its own, while delivering an intense and rather impressive gameplay mechanic.

In the game, the idea is that our planet and the entire universe are in peril, so we need to find new resources and thus we have to identify new worlds. That’s why humans are venturing out into space and the focus is on finding hew locations. But as we do that, we are finding all kinds of species. And in the meantime, humans have created tech to link the human brain to evolving creatures. That’s where Voidling Bound comes in, and it delivers a rather impressive and intense experience, but also something you rarely get to see in this type of game.

 When you take control of a creature, you can easily jump, run, dash and do a...]]></content:encoded>
</item>
<item>
<title><![CDATA[No Claude Fable 5? No problem: Sakana achieves frontier performance with new Fugu multi-model, auto synthesis system]]></title>
<description><![CDATA[Last night, the increasingly enterprise-focused AI startup Sakana launched Fugu, a multi-agent orchestration system that delivers frontier-level AI performance through a single, OpenAI-compatible API. Designed for developers, enterprises, and nations seeking resilience against vendor lock-in and ...]]></description>
<link>https://tsecurity.de/de/3616186/it-nachrichten/no-claude-fable-5-no-problem-sakana-achieves-frontier-performance-with-new-fugu-multi-model-auto-synthesis-system/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3616186/it-nachrichten/no-claude-fable-5-no-problem-sakana-achieves-frontier-performance-with-new-fugu-multi-model-auto-synthesis-system/</guid>
<pubDate>Mon, 22 Jun 2026 19:03:25 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Last night, the increasingly enterprise-focused AI startup <a href="https://sakana.ai/fugu/">Sakana launched Fugu</a>, a multi-agent orchestration system that delivers frontier-level AI performance through a single, OpenAI-compatible API. </p><p>Designed for developers, enterprises, and nations seeking resilience against vendor lock-in and geopolitical export controls, Fugu (Japanese for "pufferfish"), bypasses the traditional monolithic model structure by dynamically routing queries to a swappable pool of specialized AI agents. </p><p>Sakana CEO and co-founder David Ha, formerly of Google Brain, positioned Fugu as a more reliable option for enterprise workflows than any single AI model provider in the wake of<a href="https://venturebeat.com/technology/anthropic-blocks-all-public-access-to-claude-fable-5-mythos-5-following-us-government-order-what-enterprises-should-do"> Anthropic's move on June 12 to revoke public access</a> to its most powerful models, Claude Mythos 5 and Claude Fable 5, in the wake of a U.S. government export control order. As <a href="https://x.com/hardmaru/status/2068884466056225025">Ha wrote in a post today on X:</a></p><blockquote><p>"Fugu dynamically orchestrates the world’s best models to tackle complex tasks. We are proving that a well-orchestrated pool of swappable agents can match restricted frontier models like Fable and Mythos.

But Fugu is about more than just performance. I believe that Orchestration Models are the next frontier, beyond bigger models.

Relying on a single company’s model for national infrastructure is a massive risk. As recent export controls have shown, access to top models can disappear overnight.

Collective intelligence is the practical hedge against this concentration of power. Fugu simply routes around vendor restrictions by relying on an entirely swappable agent pool."</p></blockquote><p>Sakana AI explicitly states that the specific models Fugu selects and how it coordinates them are proprietary, meaning this routing information is hidden from the user by design. The documentation only refers generally to a "diverse pool of powerful models," "multiple LLMs," or "specialized models" without providing a specific count.</p><p>By acting as a sophisticated coordinator rather than a standalone foundation model, Fugu matches the output quality of top-tier models like Fable and Mythos on third-party benchmarks of agentic tasks, while fundamentally altering how developers deploy critical AI infrastructure.</p><h2><b>How Sakana Fugu works and where it beats Anthropic's Claude Fable 5</b></h2><p>At its core, Sakana Fugu operates like a master general contractor. When presented with a complex request, Fugu does not attempt to execute every step itself. </p><p>Instead, it breaks the problem down, delegates sub-tasks to a pool of expert foundation models, verifies their work, and synthesizes the final output.</p><p>"Fugu is itself an LLM, trained to call various LLMs in an agent pool, including instances of itself recursively," the Sakana AI team noted in their technical release. </p><p>Grounded in two of Sakana's 2026 research papers, <a href="https://sakana.ai/trinity/">TRINITY</a> and the <a href="https://sakana.ai/learning-to-orchestrate/">Conductor</a>, the system autonomously manages the entire lifecycle of model selection and verification using learned coordination strategies rather than hand-designed workflows. To the end user, this multi-agent swarm is entirely abstracted behind a standard API endpoint.</p><p>Sakana AI is offering two variants of the system to cater to different operational workloads:</p><ul><li><p><b>Fugu:</b> A high-speed, low-latency model optimized for everyday tasks. It is designed to act as the default engine for interactive chatbots and integrates directly into coding environments like Codex.</p></li><li><p><b>Fugu Ultra:</b> The flagship tier engineered for complex, high-stakes tasks such as AI research, cybersecurity analysis, and multi-step patent investigations. According to Sakana, Fugu Ultra coordinates a deeper pool of experts and matches industry-leading monolithic models across rigorous scientific and reasoning benchmarks.</p></li></ul><p>Additionally, on the pay-as-you-go plan, standard Fugu charges a dynamic rate based on the specific underlying models activated, whereas Fugu Ultra utilizes a fixed pricing structure starting at $5 per million input tokens and $30 per million output tokens.</p><p>As indicated by benchmark charts shared by Sakana, Fugu actually exceeds the performance of Anthropic's Claude Fable 5 on <a href="https://huggingface.co/blog/leaderboard-livecodebench">LiveCodeBench</a>, an open source benchmark testing coding performance on regularly refreshed, software problem-solving tasks (Fugu Ultra: 93.2, Fugu: 92.9, Fable: 89.8), and beats the prior Claude Mythos Preview model on <a href="https://epoch.ai/benchmarks/gpqa-diamond">GPQA-D (Diamond)</a> , a test of 198 graduate-level multiple-choice questions in biology, physics, and chemistry (Fugu Ultra: 95.5, Fugu: 95.5, Mythos Preview: 94.6).</p><p>By orchestrating multiple models from different providers, Fugu essentially builds native redundancy into the AI stack. If one provider suffers an outage or faces sudden regulatory restrictions, Fugu routes around the disruption to maintain uptime.</p><h2><b>Licensing and availability</b></h2><p>Fugu is offered as a commercial, proprietary API service, not an open-source framework. </p><p>Because Sakana’s core intellectual property lies in its non-obvious collaboration patterns, the specific routing information—meaning exactly which underlying models Fugu selects for a given query—remains proprietary and is intentionally hidden from the user.</p><p>However, Sakana offers critical controls for enterprise data compliance. Developers can explicitly opt specific models or providers out of their Fugu routing pool to maintain strict corporate privacy standards. </p><p>Additionally, users can opt out of having their prompts used for future training data. Geographically, Fugu is restricted from operating within the European Union (EU) and European Economic Area (EEA) while Sakana works to align its black-box data routing architecture with GDPR regulations.</p><h2><b>Pricing is fairly steep</b></h2><p>Fugu is available immediately in most regions—with the temporary exception of the EU and EEA—at subscription tiers and pay-as-you-go pricing.</p><p>Teams can opt for monthly <a href="https://sakana.ai/fugu/">subscription allowances </a>designed for individual or hands-on use: a Standard tier at $20/month for lightweight workflows, a Pro tier at $100/month providing 10x standard usage, and a Max tier at $200/month offering 20x usage for continuous, long-running tasks. I wasn't able to find the actual amount of tokens covered under these plans, but I've reached out to Ha on X for more information.</p><p>As part of the initial rollout, Sakana is offering a free second month for users who subscribe to any tier by July 31, 2026.</p><p>For enterprise scaling and production deployments, Sakana offers an elastic pay-as-you-go plan. Crucially for high-stakes environments, requests made under this consumption-based model are served at a higher priority than those from monthly subscription plans. </p><p>Under this framework, the standard Fugu engine charges the single rate of the highest-tier underlying model involved in a query, without ever stacking multi-agent fees. The flagship Fugu Ultra tier (fugu-ultra-20260615) utilizes a fixed pricing structure per one million tokens: $5 for input, $30 for output, and $0.50 for cached input. These rates increase to $10, $45, and $1.00 respectively for extreme workloads utilizing context windows above 272K tokens. That puts it among the more expensive options compared to single AI models via provider APIs:</p><h1><b>VentureBeat Frontier AI Model API Pricing Snapshot</b></h1><table><tbody><tr><td><p><b>Model</b></p></td><td><p><b>Input</b></p></td><td><p><b>Output</b></p></td><td><p><b>Total Cost</b></p></td><td><p><b>Source</b></p></td></tr><tr><td><p>MiMo-V2.5 Flash</p></td><td><p>$0.10</p></td><td><p>$0.30</p></td><td><p>$0.40</p></td><td><p>Xiaomi MiMo</p></td></tr><tr><td><p>deepseek-v4-flash</p></td><td><p>$0.14</p></td><td><p>$0.28</p></td><td><p>$0.42</p></td><td><p>DeepSeek</p></td></tr><tr><td><p>deepseek-v4-pro</p></td><td><p>$0.435</p></td><td><p>$0.87</p></td><td><p>$1.305</p></td><td><p>DeepSeek</p></td></tr><tr><td><p>MiniMax-M3</p></td><td><p>$0.30</p></td><td><p>$1.20</p></td><td><p>$1.50</p></td><td><p>MiniMax</p></td></tr><tr><td><p>Gemini 3.1 Flash-Lite</p></td><td><p>$0.25</p></td><td><p>$1.50</p></td><td><p>$1.75</p></td><td><p>Google</p></td></tr><tr><td><p>Qwen3.7-Plus</p></td><td><p>$0.40</p></td><td><p>$1.60</p></td><td><p>$2.00</p></td><td><p>Alibaba Cloud</p></td></tr><tr><td><p>MiMo-V2.5</p></td><td><p>$0.40</p></td><td><p>$2.00</p></td><td><p>$2.40</p></td><td><p>Xiaomi MiMo</p></td></tr><tr><td><p>Grok 4.3 (low context)</p></td><td><p>$1.25</p></td><td><p>$2.50</p></td><td><p>$3.75</p></td><td><p>xAI</p></td></tr><tr><td><p>MiMo-V2.5 Pro (≤256K)</p></td><td><p>$1.00</p></td><td><p>$3.00</p></td><td><p>$4.00</p></td><td><p>Xiaomi MiMo</p></td></tr><tr><td><p>Kimi-K2.6</p></td><td><p>$0.95</p></td><td><p>$4.00</p></td><td><p>$4.95</p></td><td><p>Moonshot</p></td></tr><tr><td><p>GLM-5.2</p></td><td><p>$1.40</p></td><td><p>$4.40</p></td><td><p>$5.80</p></td><td><p>Z.ai</p></td></tr><tr><td><p>Grok 4.3 (high context)</p></td><td><p>$2.50</p></td><td><p>$5.00</p></td><td><p>$7.50</p></td><td><p>xAI</p></td></tr><tr><td><p>MiMo-V2.5 Pro (&gt;256K)</p></td><td><p>$2.00</p></td><td><p>$6.00</p></td><td><p>$8.00</p></td><td><p>Xiaomi MiMo</p></td></tr><tr><td><p>Qwen3.7-Max</p></td><td><p>$2.50</p></td><td><p>$7.50</p></td><td><p>$10.00</p></td><td><p>Alibaba Cloud</p></td></tr><tr><td><p>Gemini 3.5 Flash</p></td><td><p>$1.50</p></td><td><p>$9.00</p></td><td><p>$10.50</p></td><td><p>Google</p></td></tr><tr><td><p>Gemini 3.1 Pro Preview (≤200K)</p></td><td><p>$2.00</p></td><td><p>$12.00</p></td><td><p>$14.00</p></td><td><p>Google</p></td></tr><tr><td><p>GPT-5.4</p></td><td><p>$2.50</p></td><td><p>$15.00</p></td><td><p>$17.50</p></td><td><p>OpenAI</p></td></tr><tr><td><p>Gemini 3.1 Pro Preview (&gt;200K)</p></td><td><p>$4.00</p></td><td><p>$18.00</p></td><td><p>$22.00</p></td><td><p>Google</p></td></tr><tr><td><p>Claude Opus 4.8</p></td><td><p>$5.00</p></td><td><p>$25.00</p></td><td><p>$30.00</p></td><td><p>Anthropic</p></td></tr><tr><td><p>GPT-5.5</p></td><td><p>$5.00</p></td><td><p>$30.00</p></td><td><p>$35.00</p></td><td><p>OpenAI</p></td></tr><tr><td><p><b>Sakana Fugu Ultra</b></p></td><td><p><b>$5.00</b></p></td><td><p><b>$30.00</b></p></td><td><p><b>$35.00</b></p></td><td><p><b>Sakana AI</b></p></td></tr><tr><td><p>Claude Fable 5 / Claude Mythos 5</p></td><td><p>$10.00</p></td><td><p>$50.00</p></td><td><p>$60.00</p></td><td><p>Anthropic</p></td></tr></tbody></table><p>Developers modeling operational costs should also note a significant architectural caveat in how Fugu bills for its multi-agent capabilities. According to the developer documentation, Fugu Ultra’s API responses include detailed usage fields that separate user-visible token generation from internal orchestration work. The background tokens consumed and generated when Fugu delegates sub-tasks, verifies code, or routes between underlying agents are not absorbed by the provider; they represent real token usage and are counted toward the final price of the request at standard rates.</p><h2><b>The Orchestration landscape: Fugu vs. The Field and notable benchmark performance</b></h2><p>To understand Fugu’s position in the mid-2026 AI ecosystem, it is critical to distinguish between <i>model routing</i> and <i>multi-agent orchestration</i>. </p><p>Over the past year, enterprise adoption of standard routing platforms—such as Not Diamond, Martian, and the open-source RouteLLM framework—has skyrocketed. These systems act as intelligent air traffic controllers; using semantic classifiers or meta-models, they analyze an incoming prompt and predict which single foundation model will yield the highest quality or most cost-effective response, dispatching the query accordingly.</p><p>Fugu operates on a fundamentally different paradigm. Rather than making a one-shot routing decision, Fugu aligns more closely with complex multi-round systems like Router-R1 (a framework introduced at NeurIPS 2025). It breaks a query down, interleaves reasoning with delegation, and dynamically assigns sub-tasks to multiple models in parallel or sequence before synthesizing a final output.</p><p>While frameworks like LangGraph, CrewAI, and Microsoft AutoGen offer developers the tools to build similar multi-agent systems, they require immense manual configuration—defining roles, setting up conditional edges, and managing state across long-running loops. </p><p>Fugu abstracts this operational overhead entirely. It is essentially a LangGraph-style workflow packaged as a single, black-box API endpoint.</p><p>An orchestration system is ultimately bounded by the raw capabilities of the underlying models in its pool, a reality reflected in Sakana’s own benchmark testing against standalone frontier models.</p><p>On rigorous coding and agentic tasks, collective intelligence shows a distinct advantage over standard models. Fugu Ultra posted a <b>73.7 on SWE-Bench Pro</b>, significantly outperforming Anthropic's Claude Opus 4.8 (69.2) and OpenAI's GPT-5.5 (58.6). </p><p>However, Fugu is not a silver bullet, and its performance is not a clean sweep across the board. When compared to highly specialized or restricted-access monolithic models, Fugu occasionally trails:</p><ul><li><p><b>SWE-Bench Pro:</b> While Fugu Ultra (73.7) beat most accessible models, it was comfortably eclipsed by Anthropic’s limited-access Fable 5 (80.0), which is currently absent from Fugu's swappable pool due to the U.S. government's export control order and Anthropic's subsequent response to remove the model entirely from global usage. </p></li><li><p><b>Humanity's Last Exam:</b> Fugu Ultra (50.0) narrowly edged out Opus 4.8 (49.8), but again fell short of Fable 5 (53.3).</p></li><li><p><b>Long-Context and Security:</b> On the MRCRv2 long-context-recall test, OpenAI's GPT-5.5 maintained the lead (94.8 vs Fugu Ultra's 93.6), and Opus 4.8 remained the top performer on the CTI-REALM cybersecurity benchmark (69.6 vs Fugu Ultra's 69.4).</p></li></ul><p>The quantitative data points to a clear conclusion: Fugu is highly effective at boosting performance on messy, multi-step tasks (like writing a complex HTML5 game from scratch) by leaning on the combined strengths of multiple mid-tier and high-tier models. </p><p>However, for sheer brute-force reasoning within a single, highly constrained domain, the industry's largest standalone models still hold the edge—provided an enterprise can maintain uninterrupted access to them.</p><h2><b>Background on Sakana's formation and noteworthy achievements to date</b></h2><p><a href="https://venturebeat.com/ai/what-you-need-to-know-about-sakana-ai-the-new-startup-from-a-transformer-paper-co-author">Sakana AI was formed in Tokyo in 2023 </a>by Llion Jones, a co-author of Google’s foundational 2017 "Attention Is All You Need" paper, and David Ha, the former head of research at Stability AI. </p><p>Disillusioned by large tech company bureaucracy and the industry's hyper-fixation on scaling single, massive foundational models, the founders built Sakana around principles of biomimicry and evolutionary computing.</p><p>The company's name, derived from the Japanese word for fish, reflects its core technical thesis: utilizing collective "swarm" intelligence rather than brute-force compute. Following a $2.6 billion Series B valuation in late 2025 and <a href="https://venturebeat.com/technology/when-deep-research-isnt-enough-for-your-business-sakana-ai-launches-ultra-deep-research-agent-for-100-page-reports-in-8-hours">the recent June 2026 launch of Marlin</a>—an autonomous, eight-hour research agent for the B2B sector—Fugu represents the commercialization of Sakana's multi-agent routing technology for everyday developers.</p><h2><b>A mixed reception among the broader AI community online</b></h2><p>The developer community has responded to Fugu by rigorously testing its practical tradeoffs, weighing its routing efficiencies against the sheer power of monolithic foundation models.</p><p>AI observer, developer and influencer <a href="https://x.com/ChrissGPT/status/2068904825685787083?s=20">Chris (@ChrissGPT on X)</a> highlighted the specific utility of Fugu over raw foundational AI. </p><p>"For a single clean prompt, you probably would [use Fable 5, Mythos, or GPT-5.5 directly]," he noted, but argued that Fugu's true value emerges in messy, multi-step environments. "...whether it involves delegation, verification, synthesis, code review, research loops, security analysis... the more it would make sense to use this," he wrote.</p><p>Chris also pointed out the strategic geopolitical advantage of Fugu's architecture, noting that if frontier AI access is abruptly revoked due to regulation or export controls, an orchestrator can dynamically swap models to prevent a total system failure.</p><p>Creative agency owner <a href="https://x.com/markksantos/status/2068962823007285628?s=20">Mark Santos (@markksantos) </a>of Mark Studios provided a direct, real-world comparison by tasking both Fugu Ultra and Claude Opus 4.8 with building a "Crossy Road" game clone using Three.js. The results underscored the operational differences between an orchestrator and a monolithic giant:</p><ul><li><p><b>Sakana Fugu Ultra:</b> Completed the task in 22 minutes using ~89,000 tokens for roughly $7.32. However, the final game suffered from minor logic errors, such as inverted directional turns and wonky camera angles.</p></li><li><p><b>Claude Opus 4.8:</b> Took 79 minutes, burned ~940,000 tokens for nearly $37.85, and got stuck in a retry loop requiring human intervention. Despite the inefficiency, it ultimately produced superior application design and functionality.</p></li></ul><p>Santos concluded the experiment by stating, "In terms of application functionality, quality, and design, Opus won. In terms of model speed and performance, Fugu... won".</p><p>Elie Bakouch, a research engineer at cloud-based, open AI infrastructure and systems provider <a href="https://www.primeintellect.ai/">Prime Intellect</a>, <a href="https://x.com/eliebakouch/status/2068939729811468503">pointed out on X</a> that "to be clear, this is a closed source orchestrator on top of closed source models. if before you didn't control the models, now you don't even control which ones are used or how much. this is not 'AI sovereignty'..."</p><div></div><p>These early tests and reactions mirror the sentiment summarized by <a href="https://www.reddit.com/r/LLMDevs/comments/1uca8e3/comment/ot2k0kx/?utm_source=share&amp;utm_medium=web3x&amp;utm_name=web3xcss&amp;utm_term=1&amp;utm_content=share_button">Reddit user GreedyWorking1499</a> in initial platform discussions: "<i>Until proven otherwise, this is just a highly advanced router/wrapper, not a fundamental not a fundamental leap in intelligence like Mythos/Fable was.</i>"</p><p>Yet, as enterprises increasingly demand fail-safes against single-vendor reliance, Sakana is proving that packaging collective intelligence into a single API endpoint is a highly viable commercial path.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[The AI second brain: The future of knowledge work]]></title>
<description><![CDATA[The knowledge work is where AI matters most]]></description>
<link>https://tsecurity.de/de/3615227/it-nachrichten/the-ai-second-brain-the-future-of-knowledge-work/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3615227/it-nachrichten/the-ai-second-brain-the-future-of-knowledge-work/</guid>
<pubDate>Mon, 22 Jun 2026 13:01:57 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The knowledge work is where AI matters most]]></content:encoded>
</item>
<item>
<title><![CDATA[Your Brain Is a Better AI Detector Than Any Tool Out There. Here's How to Use It]]></title>
<description><![CDATA[AI writing has consistent, recognizable patterns that no detector captures better than a well-trained eye.]]></description>
<link>https://tsecurity.de/de/3613758/it-nachrichten/your-brain-is-a-better-ai-detector-than-any-tool-out-there-heres-how-to-use-it/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3613758/it-nachrichten/your-brain-is-a-better-ai-detector-than-any-tool-out-there-heres-how-to-use-it/</guid>
<pubDate>Sun, 21 Jun 2026 17:03:23 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[AI writing has consistent, recognizable patterns that no detector captures better than a well-trained eye.]]></content:encoded>
</item>
<item>
<title><![CDATA[AI, Mind Reading and Microchip Brain Implants]]></title>
<description><![CDATA[How neurotech advancements and new state laws are shaping the future of human-machine interfaces.]]></description>
<link>https://tsecurity.de/de/3613425/ai-nachrichten/ai-mind-reading-and-microchip-brain-implants/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3613425/ai-nachrichten/ai-mind-reading-and-microchip-brain-implants/</guid>
<pubDate>Sun, 21 Jun 2026 12:02:25 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[How neurotech advancements and new state laws are shaping the future of human-machine interfaces.]]></content:encoded>
</item>
<item>
<title><![CDATA['This might actually force some actual brain cells to fire': Norway is banning younger school kids from using generative AI]]></title>
<description><![CDATA[Norway is taking steps to limit how generative AI can be used in schools from the start of the next school year.]]></description>
<link>https://tsecurity.de/de/3612289/it-nachrichten/this-might-actually-force-some-actual-brain-cells-to-fire-norway-is-banning-younger-school-kids-from-using-generative-ai/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3612289/it-nachrichten/this-might-actually-force-some-actual-brain-cells-to-fire-norway-is-banning-younger-school-kids-from-using-generative-ai/</guid>
<pubDate>Sat, 20 Jun 2026 15:47:42 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Norway is taking steps to limit how generative AI can be used in schools from the start of the next school year.]]></content:encoded>
</item>
<item>
<title><![CDATA[CoreFreq v2.1.2]]></title>
<description><![CDATA[[AMD]  Route SMN I/O through per-UMC PCI device on multi-die platforms Remove AMD_UMC_Normalize_Channels() function Skip Rank calculation when secondary regions are active Aggregate DIMM size from RAM regions [UMC] Attempt to detect shared DRAM CS mask  [x86_64]  Decode and display Extended Super...]]></description>
<link>https://tsecurity.de/de/3611472/linux-tipps/corefreq-v212/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3611472/linux-tipps/corefreq-v212/</guid>
<pubDate>Sat, 20 Jun 2026 02:08:51 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><h2>[AMD]</h2> <ul> <li>Route SMN I/O through per-UMC PCI device on multi-die platforms</li> <li>Remove <code>AMD_UMC_Normalize_Channels()</code> function</li> <li>Skip <code>Rank</code> calculation when secondary regions are active</li> <li>Aggregate DIMM size from RAM regions</li> <li>[UMC] Attempt to detect shared DRAM CS mask</li> </ul> <h2>[x86_64]</h2> <ul> <li>Decode and display Extended Supervisor State Mask (XSS)</li> <li><code>STMXCSR</code>: remove XCR0.SSE condition with legacy architectures</li> <li>Reorder processing logic of XCR0 and MXCSR registers</li> <li>[AVX|SSE] Media and Extended Control and Status Register</li> <li>[Intel][AMD] Complete CPUID dump leaf list from updated specs</li> </ul> <h2>[Intel]</h2> <ul> <li>Rephrase to " Advanced Matrix Extensions Brain Float16 "</li> <li>Rename <code>CPUID.(EAX=0x29, ECX=0).EBX[0]</code> feature to APX_NDD_NF</li> <li>Display AVX10-128/256/512 and APX-NCI_NDD_NF CPUID bits</li> <li>Display APX_F, AMX_COMPLEX and new leaf 7.1 features</li> <li>Dump additional CPUID leaves through 0x29</li> </ul> <h2>[CLI]</h2> <ul> <li>Show blanks instead of zero values in DIMM geometry</li> </ul> <h2>[Doc]</h2> <ul> <li>[AMD] DDR4 Limit encoding specification</li> <li>[AMD] DDR5 Limit encoding specification</li> <li>[AMD] Register HWCR[34] Downgrade FP512 to FP256</li> <li>[Intel] Architecture Instruction Set Extensions and Future Features</li> <li>[x86_64] Dump undocumented CPUID leaves introduced in AMD Family 1Ah</li> <li>[AMD][Zen] Fix the bit fields of <code>AMD_CPPC_REQUEST</code> MSR register</li> </ul> <h2>[Build]</h2> <ul> <li>[CR] Fix <code>__builtin_strnlen()</code> fallback for GCC &lt; 7</li> <li>[CR] Propagate <code>StrCopy()</code> hardening to other architectures</li> <li>[CR] Ensure bounded and null-terminated string copies</li> <li>[Build] Add a dependency to create Symlink first</li> <li>[Build] Fix module rebuild dependency tracking</li> <li>[Build][openSUSE] Fix WRMSRNS collision with Leap 16.0 kernel headers (#594)</li> </ul> <h2>[Kernel]</h2> <ul> <li>[aarch64][ppc64][riscv64] Make use of <code>cpufreq_cpu_put()</code></li> <li>[CPUFreq] Fallback to policy-based governor label when unavailable</li> <li>[CPPC] Read per CPU the updated ACPI-CPPC registers</li> <li>[CPPC] Read the updated ACPI-CPPC registers</li> <li>[CR][Kernel] Remove <code>__free(put_cpufreq_policy)</code> dependency</li> <li>[CR][Kernel] Call <code>cpufreq_cpu_put()</code> to release <code>cpu_policy</code></li> <li>[CPPC] Compute Bounds after altering the Energy Policy</li> </ul> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/CyrIng"> /u/CyrIng </a> <br> <span><a href="https://github.com/cyring/CoreFreq/releases/tag/2.1.2">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/1ua12t3/corefreq_v212/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[Best 50 Psychological Thrillers to Watch on Netflix]]></title>
<description><![CDATA[Sometimes you feel like laughing, other times, you feel like hiding under your blanket with your brain trying to make a million connections so you can figure out what’s going on in the movie. Well, if you want to check some of the best 50 Netflix psychological thriller picks available right now, ...]]></description>
<link>https://tsecurity.de/de/3611031/betriebssysteme/best-50-psychological-thrillers-to-watch-on-netflix/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3611031/betriebssysteme/best-50-psychological-thrillers-to-watch-on-netflix/</guid>
<pubDate>Fri, 19 Jun 2026 19:21:31 +0200</pubDate>
<category>🖥️  Betriebssysteme</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Sometimes you feel like laughing, other times, you feel like hiding under your blanket with your brain trying to make a million connections so you can figure out what’s going on in the movie. Well, if you want to check some of the best 50 Netflix psychological thriller picks available right now, let’s dive into […]</p>
<p>The post <a rel="nofollow" href="https://www.addictivetips.com/media-streaming/psychological-thrillers-netflix/">Best 50 Psychological Thrillers to Watch on Netflix</a> appeared first on <a rel="nofollow" href="https://www.addictivetips.com/">AddictiveTips</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[OpenAI gets the attention it needs from AI researcher Noam Shazeer]]></title>
<description><![CDATA[An IT executive changing jobs usually attracts little attention outside a narrow group of people, but Noam Shazeer’s move from Google to OpenAI is as momentous as any high-value soccer transfer.



He announced the news in a post on X: “I’m excited to share that I’ll be joining OpenAI and look fo...]]></description>
<link>https://tsecurity.de/de/3610960/ai-nachrichten/openai-gets-the-attention-it-needs-from-ai-researcher-noam-shazeer/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3610960/ai-nachrichten/openai-gets-the-attention-it-needs-from-ai-researcher-noam-shazeer/</guid>
<pubDate>Fri, 19 Jun 2026 18:49:11 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>An IT executive changing jobs usually attracts little attention outside a narrow group of people, but Noam Shazeer’s move from Google to OpenAI is as momentous as any high-value soccer transfer.</p>



<p>He announced the news <a href="https://x.com/NoamShazeer/status/2067400851438932297" target="_blank" rel="noreferrer noopener">in a post on X</a>: “I’m excited to share that I’ll be joining OpenAI and look forward to working with the exceptional team there.”</p>



<p>Shazeer initially achieved fame as one of the eight co-authors of the influential AI paper <a href="https://arxiv.org/abs/1706.03762" target="_blank" rel="noreferrer noopener">Attention Is All You Need</a>, published when he was working at Google Brain. He is also one of the creators of the <a href="https://www.infoworld.com/article/2335213/large-language-models-the-foundations-of-generative-ai.html">transformer technology</a> that lies at the heart of modern AI models.</p>



<p>He left Google when the company failed to back his chatbot Meena and was tempted back when Google subsequently bought the company he founded, Character.AI, for $2.7 billion. That company achieved notoriety when it was sued by a grieving mother, who <a href="https://www.computerworld.com/article/4050700/ai-chatbots-are-not-your-friends.html#:~:text=In%20addition%2C%20there%E2%80%99s%20an%20ongoing%20lawsuit%20against%20Character.AI%20for%20encouraging%20a%2014-year-old%20to%20commit%20suicide%3B">alleged that a Character.AI chatbot had contributed to her son’s death</a> by suicide. The company subsequently settling out of court.</p>



<p>Shazeer has since been working as the co-lead on Google’s Gemini project. It’s not clear what role he will play at OpenAI, but hiring someone with his background shortly before the company’s IPO could be an attractive move for investors.</p>



<p><em>This article first appeared on <a href="https://www.computerworld.com/article/4187293/openai-gets-the-attention-it-needs-from-ai-researcher-noam-shazeer.html">Computerworld</a>.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[OpenAI gets the attention it needs from AI researcher Noam Shazeer]]></title>
<description><![CDATA[An IT executive changing jobs usually attracts little attention outside a narrow group of people, but Noam Shazeer’s move from Google to OpenAI is as momentous as any high-value soccer transfer.



He announced the news in a post on X: “I’m excited to share that I’ll be joining OpenAI and look fo...]]></description>
<link>https://tsecurity.de/de/3610955/it-nachrichten/openai-gets-the-attention-it-needs-from-ai-researcher-noam-shazeer/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3610955/it-nachrichten/openai-gets-the-attention-it-needs-from-ai-researcher-noam-shazeer/</guid>
<pubDate>Fri, 19 Jun 2026 18:48:16 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>An IT executive changing jobs usually attracts little attention outside a narrow group of people, but Noam Shazeer’s move from Google to OpenAI is as momentous as any high-value soccer transfer.</p>



<p>He announced the news <a href="https://x.com/NoamShazeer/status/2067400851438932297" target="_blank" rel="noreferrer noopener">in a post on X</a>: “I’m excited to share that I’ll be joining OpenAI and look forward to working with the exceptional team there.”</p>



<p>Shazeer initially achieved fame as one of the eight co-authors of the influential AI paper <a href="https://arxiv.org/abs/1706.03762" target="_blank" rel="noreferrer noopener">Attention Is All You Need</a>, published when he was working at Google Brain. He is also one of the creators of the <a href="https://www.infoworld.com/article/2335213/large-language-models-the-foundations-of-generative-ai.html">transformer technology</a> that lies at the heart of modern AI models.</p>



<p>He left Google when the company failed to back his chatbot Meena and was tempted back when Google subsequently bought the company he founded, Character.AI, for $2.7 billion. That company achieved notoriety when it was sued by a grieving mother, who <a href="https://www.computerworld.com/article/4050700/ai-chatbots-are-not-your-friends.html#:~:text=In%20addition%2C%20there%E2%80%99s%20an%20ongoing%20lawsuit%20against%20Character.AI%20for%20encouraging%20a%2014-year-old%20to%20commit%20suicide%3B">alleged that a Character.AI chatbot had contributed to her son’s death</a> by suicide. The company subsequently settling out of court.</p>



<p>Shazeer has since been working as the co-lead on Google’s Gemini project. It’s not clear what role he will play at OpenAI, but hiring someone with his background shortly before the company’s IPO could be an attractive move for investors.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[New Tesla Robot Killer? ENO Autonomous Assistant In 2026 (AI NEWS)]]></title>
<description><![CDATA[Author: AI News - Bewertung: 5x - Views:36 Is this the most autonomous, dexterous robot yet? In this episode of AI News, we cover the massive unveiling of Genesis ENO, a game-changing general-purpose robot challenging the traditional humanoid robot design. Powered by the GENE AI brain, ENO featur...]]></description>
<link>https://tsecurity.de/de/3609961/it-security-video/new-tesla-robot-killer-eno-autonomous-assistant-in-2026-ai-news/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3609961/it-security-video/new-tesla-robot-killer-eno-autonomous-assistant-in-2026-ai-news/</guid>
<pubDate>Fri, 19 Jun 2026 12:03:23 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: AI News - Bewertung: 5x - Views:36 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/zDSiHzE1kUs?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>Is this the most autonomous, dexterous robot yet? In this episode of AI News, we cover the massive unveiling of Genesis ENO, a game-changing general-purpose robot challenging the traditional humanoid robot design. Powered by the GENE AI brain, ENO features 20 DoF proprietary hands for human-level dexterous manipulation across manufacturing, logistics, and laboratories.<br />
<br />
We also break down Sony AI Ace, the revolutionary autonomous physical agent that just defeated elite human athletes in table tennis under official ITTF rules using deep reinforcement learning and advanced 3D perception. Plus, a look at NVIDIA’s groundbreaking Motion Bricks framework generating robotics physical motion at a staggering 15,000 FPS, and Anthropic’s new Claude Code Artifacts update for developers.<br />
<br />
Discovery the AI agent economy: https://8004agents.ai<br />
<br />
0:00 Eno<br />
4:08 Sony AI<br />
5:15 MotionBricks<br />
6:16 Claude Code<br />
7:30 Aeon<br />
<br />
#ai #news #robot<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Brain-computer interface trials are taking off]]></title>
<description><![CDATA[This week, I covered the story of Casey Harrell—a man with ALS who is “the first power user” of a brain implant, according to the researchers who worked with him. Harrell is paralyzed and unable to speak coherently without the device. He has now spent almost three years using a brain-computer int...]]></description>
<link>https://tsecurity.de/de/3609875/ai-nachrichten/brain-computer-interface-trials-are-taking-off/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3609875/ai-nachrichten/brain-computer-interface-trials-are-taking-off/</guid>
<pubDate>Fri, 19 Jun 2026 11:33:14 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[This week, I covered the story of Casey Harrell—a man with ALS who is “the first power user” of a brain implant, according to the researchers who worked with him. Harrell is paralyzed and unable to speak coherently without the device. He has now spent almost three years using a brain-computer interface (BCI) that enables…]]></content:encoded>
</item>
<item>
<title><![CDATA[AI coding agents may be getting bad instructions from ‘smelly’ config files]]></title>
<description><![CDATA[AI coding agents are becoming critical to software development, but the configuration files that guide them, such as Agents.md or Claude.md, can be “smelly.”



That means they can contain structural flaws, redundancies, or counterproductive workflows that bloat context, waste tokens, and make co...]]></description>
<link>https://tsecurity.de/de/3609268/ai-nachrichten/ai-coding-agents-may-be-getting-bad-instructions-from-smelly-config-files/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3609268/ai-nachrichten/ai-coding-agents-may-be-getting-bad-instructions-from-smelly-config-files/</guid>
<pubDate>Fri, 19 Jun 2026 04:18:56 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>AI coding agents are becoming critical to software development, but the configuration files that guide them, such as Agents.md or Claude.md, can be “smelly.”</p>



<p>That means they can contain structural flaws, redundancies, or counterproductive workflows that bloat context, waste tokens, and make coding agents less reliable.</p>



<p>Researchers from the Department of Computer Science at Brazil’s Federal University of Minas Gerais hope to shed light on this problem, presenting what they call the “first catalog of smells” for coding agent configuration files. The most odorous? Lint and skill leakage, context bloat, and conflicting instructions.</p>



<p>“Our results show that these smells are widespread in practice,” the <a href="https://arxiv.org/pdf/2606.15828" target="_blank" rel="noreferrer noopener">researchers wrote</a>. Consequently, they “may directly influence how coding agents interpret project conventions, prioritize instructions, and perform development tasks.”</p>



<h2 class="wp-block-heading">Smelly configs in the harness make models misbehave</h2>



<p>Agents like Claude Code, Codex, Cursor, and Gemini are increasingly taking over software engineering tasks like <a href="https://www.infoworld.com/article/4141358/the-ai-coding-hangover.html" target="_blank">code generation</a> and review, test creation, bug fixing, software migration, and documentation writing.</p>



<p>Essentially, they are a combination of a large language model (LLM) and a harness; the model is the brain, the harness provides a loop that executes actions and allows agents to call the tools they need to fulfill a task. These might include web search engines, issue-tracking platforms, and test runners.</p>



<p>Agents’ behavior is guided by config files such as Agents.md and Claude.md, which provide instructions around project workflows, testing requirements, and domain-specific knowledge. This helps maintain consistency across separate tasks and sessions. Typically, these config files are loaded at the start of a session as part of a prompt and are maintained throughout the task.</p>



<p>But the researchers found that these configurations are riddled with smells; 91 of 100 popular open-source repositories containing Agent.md or Claude.md files had at least one smell.</p>



<p>The six strongest odors:</p>



<ul class="wp-block-list">
<li>Lint leakage (appearing in 62% of files)</li>



<li>Context bloat (42%)</li>



<li>Skill leakage (35%)</li>



<li>Conflicting instructions (28%)</li>



<li>Init fossilization (24%)</li>



<li>Blind reference (16%)</li>
</ul>



<h2 class="wp-block-heading">The scent of waste</h2>



<p><strong>Lint leakage</strong> occurs when instructions in config files needlessly include rules that are already enforced by analysis tools like code formatters or linters (which filter out bugs, security vulnerabilities, inconsistencies, and programmatic errors, by, for example, restating generic style guide recommendations, formatting rules, line length, naming conventions, or import ordering).</p>



<p>This repetition increases a model’s context size and wastes tokens, the researchers pointed out. It “can divert the model from focusing on more important project-specific concerns, such as architectural constraints, domain rules, or safety policies.”</p>



<p><strong>Context bloat</strong> means that configurations are excessively large and overloaded with rules, examples, or details that are unnecessary or low priority. This drives up token usage, ultimately raising costs and distracting the model from higher priority instructions.</p>



<p>With <strong>skill leakage</strong>, rarely-used or task-specific instructions are unnecessarily included in the configuration, rather than in separate dedicated skill or task files. This specialized knowledge is dragged into every session, even when the model doesn’t need it to perform its task. Thus, the context window becomes larger, more expensive, and difficult to maintain, the researchers noted.</p>



<p>“Furthermore, such rules may compete for attention with the rules that are actually critical for the project,” they wrote.</p>



<p>Just as it sounds, <strong>conflicting instructions</strong> means that file rules contradict one another, leading to ambiguity; the model essentially gets “confused” and has to choose arbitrarily. This can lead to inconsistency and unstable results.</p>



<p><strong>Init fossilization</strong> occurs when files are generated once but never reviewed or edited again, so they include stale or irrelevant rules because they don’t reflect changes in the <a href="https://www.infoworld.com/article/4182518/shipping-enterprise-quality-code-with-ai-agents.html" target="_blank">codebase</a>. “As a result, the configuration tends to accumulate noise, increase context consumption, and reduce the overall effectiveness of the agent over time,” the researchers explained.</p>



<p>Finally, <strong>blind references</strong> point to files or docs without explaining what they’re for. Consequently, the <a href="https://www.infoworld.com/article/4154570/best-practices-for-building-agentic-systems.html" target="_blank">agent</a> might simply ignore them, leading to problems if they’re critical to a task, load unnecessary materials to gather context, taking up tokens and space, or fail to prioritize important information.</p>



<p>Additionally, the researchers discovered that smells often co-occur in the same file and trigger the appearance of others; for instance, skill leaking and conflicting instructions can increase the likelihood of context bloat by 83% because they add extemporaneous or irrelevant information.</p>



<h2 class="wp-block-heading">How to air out smells</h2>



<p>While these smells are “widespread in practice,” there are ways to air them out.</p>



<p>For example, to reduce lint leakage, stylistic constraints such as formatting, and import ordering should be removed from prompts. Let programmatic tools handle them; spending budget on style rules is a waste, the researchers noted.</p>



<p>To cut down on context bloat, Claude.md and Agents.md files should remain concise and provide project-specific guidance. For instance, Anthropic recommends a target of fewer than 200 lines per Claude.md file.</p>



<p>To limit skill leakage, developers should provide specific instructions in config files about the project build, test running, code conventions, and other important context. Task-specific instructions should be kept in separate markdown files with descriptive names, the researchers advise.</p>



<p>Additionally, to avoid conflicting instructions, builders should periodically review config files to remove instructions that are contradictory or outdated. Similarly, reducing init fossilization requires continuous updating of files, the researchers explained. This is particularly important in cases where an agent makes the same mistake twice in a row, a code review reveals a detail the agent should have already known, or when developers find themselves prompting corrections and clarifications already addressed in a previous session.</p>



<p>Finally, to minimize blind references, developers should tell <a href="https://www.infoworld.com/article/4112542/how-to-make-ai-agents-reliable.html" target="_blank">agents</a> when and why to read files, and include references with concise explanations of the document’s role, the information it contains, and scenarios where it should be used. For instance, text may reference an external dependency, include a link to its GitHub repository, and provide a brief explanation of its purpose. “Then the agent is able to understand the role of the dependency without needing to load or inspect the external repository directly,” the researchers explained.</p>



<p>Ultimately, they concluded, configuration files are “key artifacts” in agentic software development, and when they get smelly, there’s a problem. Therefore, “their quality deserves effort and attention.”</p>
</div></div></div>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[AI coding agents may be getting bad instructions from ‘smelly’ config files]]></title>
<description><![CDATA[AI coding agents are becoming critical to software development, but the configuration files that guide them, such as Agents.md or Claude.md, can be “smelly.”



That means they can contain structural flaws, redundancies, or counterproductive workflows that bloat context, waste tokens, and make co...]]></description>
<link>https://tsecurity.de/de/3609265/it-nachrichten/ai-coding-agents-may-be-getting-bad-instructions-from-smelly-config-files/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3609265/it-nachrichten/ai-coding-agents-may-be-getting-bad-instructions-from-smelly-config-files/</guid>
<pubDate>Fri, 19 Jun 2026 04:18:05 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>AI coding agents are becoming critical to software development, but the configuration files that guide them, such as Agents.md or Claude.md, can be “smelly.”</p>



<p>That means they can contain structural flaws, redundancies, or counterproductive workflows that bloat context, waste tokens, and make coding agents less reliable.</p>



<p>Researchers from the Department of Computer Science at Brazil’s Federal University of Minas Gerais hope to shed light on this problem, presenting what they call the “first catalog of smells” for coding agent configuration files. The most odorous? Lint and skill leakage, context bloat, and conflicting instructions.</p>



<p>“Our results show that these smells are widespread in practice,” the <a href="https://arxiv.org/pdf/2606.15828" target="_blank" rel="nofollow">researchers wrote</a>. Consequently, they “may directly influence how coding agents interpret project conventions, prioritize instructions, and perform development tasks.”</p>



<h2 class="wp-block-heading">Smelly configs in the harness make models misbehave</h2>



<p>Agents like Claude Code, Codex, Cursor, and Gemini are increasingly taking over software engineering tasks like <a href="https://www.infoworld.com/article/4141358/the-ai-coding-hangover.html" target="_blank">code generation</a> and review, test creation, bug fixing, software migration, and documentation writing.</p>



<p>Essentially, they are a combination of a large language model (LLM) and a harness; the model is the brain, the harness provides a loop that executes actions and allows agents to call the tools they need to fulfill a task. These might include web search engines, issue-tracking platforms, and test runners.</p>



<p>Agents’ behavior is guided by config files such as Agents.md and Claude.md, which provide instructions around project workflows, testing requirements, and domain-specific knowledge. This helps maintain consistency across separate tasks and sessions. Typically, these config files are loaded at the start of a session as part of a prompt and are maintained throughout the task.</p>



<p>But the researchers found that these configurations are riddled with smells; 91 of 100 popular open-source repositories containing Agent.md or Claude.md files had at least one smell.</p>



<p>The six strongest odors:</p>



<ul class="wp-block-list">
<li>Lint leakage (appearing in 62% of files)</li>



<li>Context bloat (42%)</li>



<li>Skill leakage (35%)</li>



<li>Conflicting instructions (28%)</li>



<li>Init fossilization (24%)</li>



<li>Blind reference (16%)</li>
</ul>



<h2 class="wp-block-heading">The scent of waste</h2>



<p><strong>Lint leakage</strong> occurs when instructions in config files needlessly include rules that are already enforced by analysis tools like code formatters or linters (which filter out bugs, security vulnerabilities, inconsistencies, and programmatic errors, by, for example, restating generic style guide recommendations, formatting rules, line length, naming conventions, or import ordering).</p>



<p>This repetition increases a model’s context size and wastes tokens, the researchers pointed out. It “can divert the model from focusing on more important project-specific concerns, such as architectural constraints, domain rules, or safety policies.”</p>



<p><strong>Context bloat</strong> means that configurations are excessively large and overloaded with rules, examples, or details that are unnecessary or low priority. This drives up token usage, ultimately raising costs and distracting the model from higher priority instructions.</p>



<p>With <strong>skill leakage</strong>, rarely-used or task-specific instructions are unnecessarily included in the configuration, rather than in separate dedicated skill or task files. This specialized knowledge is dragged into every session, even when the model doesn’t need it to perform its task. Thus, the context window becomes larger, more expensive, and difficult to maintain, the researchers noted.</p>



<p>“Furthermore, such rules may compete for attention with the rules that are actually critical for the project,” they wrote.</p>



<p>Just as it sounds, <strong>conflicting instructions</strong> means that file rules contradict one another, leading to ambiguity; the model essentially gets “confused” and has to choose arbitrarily. This can lead to inconsistency and unstable results.</p>



<p><strong>Init fossilization</strong> occurs when files are generated once but never reviewed or edited again, so they include stale or irrelevant rules because they don’t reflect changes in the <a href="https://www.infoworld.com/article/4182518/shipping-enterprise-quality-code-with-ai-agents.html" target="_blank">codebase</a>. “As a result, the configuration tends to accumulate noise, increase context consumption, and reduce the overall effectiveness of the agent over time,” the researchers explained.</p>



<p>Finally, <strong>blind references</strong> point to files or docs without explaining what they’re for. Consequently, the <a href="https://www.infoworld.com/article/4154570/best-practices-for-building-agentic-systems.html" target="_blank">agent</a> might simply ignore them, leading to problems if they’re critical to a task, load unnecessary materials to gather context, taking up tokens and space, or fail to prioritize important information.</p>



<p>Additionally, the researchers discovered that smells often co-occur in the same file and trigger the appearance of others; for instance, skill leaking and conflicting instructions can increase the likelihood of context bloat by 83% because they add extemporaneous or irrelevant information.</p>



<h2 class="wp-block-heading">How to air out smells</h2>



<p>While these smells are “widespread in practice,” there are ways to air them out.</p>



<p>For example, to reduce lint leakage, stylistic constraints such as formatting, and import ordering should be removed from prompts. Let programmatic tools handle them; spending budget on style rules is a waste, the researchers noted.</p>



<p>To cut down on context bloat, Claude.md and Agents.md files should remain concise and provide project-specific guidance. For instance, Anthropic recommends a target of fewer than 200 lines per Claude.md file.</p>



<p>To limit skill leakage, developers should provide specific instructions in config files about the project build, test running, code conventions, and other important context. Task-specific instructions should be kept in separate markdown files with descriptive names, the researchers advise.</p>



<p>Additionally, to avoid conflicting instructions, builders should periodically review config files to remove instructions that are contradictory or outdated. Similarly, reducing init fossilization requires continuous updating of files, the researchers explained. This is particularly important in cases where an agent makes the same mistake twice in a row, a code review reveals a detail the agent should have already known, or when developers find themselves prompting corrections and clarifications already addressed in a previous session.</p>



<p>Finally, to minimize blind references, developers should tell <a href="https://www.infoworld.com/article/4112542/how-to-make-ai-agents-reliable.html" target="_blank">agents</a> when and why to read files, and include references with concise explanations of the document’s role, the information it contains, and scenarios where it should be used. For instance, text may reference an external dependency, include a link to its GitHub repository, and provide a brief explanation of its purpose. “Then the agent is able to understand the role of the dependency without needing to load or inspect the external repository directly,” the researchers explained.</p>



<p>Ultimately, they concluded, configuration files are “key artifacts” in agentic software development, and when they get smelly, there’s a problem. Therefore, “their quality deserves effort and attention.”</p>



<p><em>This article originally appeared on <a href="https://www.infoworld.com/article/4187057/ai-coding-agents-may-be-getting-bad-instructions-from-smelly-config-files.html" target="_blank">InfoWorld</a>.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Perplexity Launches Brain, a Self-Improving Memory System That Builds a Context Graph of an Agent’s Work and Learns Overnight]]></title>
<description><![CDATA[Perplexity has launched Brain, a self-improving memory system for its Computer agent. Instead of remembering the user, Brain remembers the agent's work — what worked, what failed, and what corrections got made. It builds a traceable context graph, reviews it overnight, and reports early gains in ...]]></description>
<link>https://tsecurity.de/de/3608898/ai-nachrichten/perplexity-launches-brain-a-self-improving-memory-system-that-builds-a-context-graph-of-an-agents-work-and-learns-overnight/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3608898/ai-nachrichten/perplexity-launches-brain-a-self-improving-memory-system-that-builds-a-context-graph-of-an-agents-work-and-learns-overnight/</guid>
<pubDate>Thu, 18 Jun 2026 22:33:30 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Perplexity has launched Brain, a self-improving memory system for its Computer agent. Instead of remembering the user, Brain remembers the agent's work — what worked, what failed, and what corrections got made. It builds a traceable context graph, reviews it overnight, and reports early gains in correctness, recall, and cost.</p>
<p>The post <a href="https://www.marktechpost.com/2026/06/18/perplexity-launches-brain/">Perplexity Launches Brain, a Self-Improving Memory System That Builds a Context Graph of an Agent’s Work and Learns Overnight</a> appeared first on <a href="https://www.marktechpost.com/">MarkTechPost</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Why agentic architecture is still so puzzling]]></title>
<description><![CDATA[Many IT leaders looking to capitalize on the promise of agentic AI still struggle with a basic step — building out their agentic architecture — even as they roll out dozens or hundreds of agents.



AI agent deployment is expected to skyrocket over the next year, with IDC predicting a tenfold inc...]]></description>
<link>https://tsecurity.de/de/3607339/it-nachrichten/why-agentic-architecture-is-still-so-puzzling/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3607339/it-nachrichten/why-agentic-architecture-is-still-so-puzzling/</guid>
<pubDate>Thu, 18 Jun 2026 12:18:55 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Many IT leaders looking to capitalize on the promise of agentic AI still struggle with a basic step — building out their agentic architecture — even as they roll out dozens or hundreds of agents.</p>



<p>AI agent deployment is expected to skyrocket over the next year, with IDC predicting a <a href="https://www.idc.com/resource-center/blog/agent-adoption-the-it-industrys-next-great-inflection-point/">tenfold increase</a> in agent use by large enterprises by the end of this year. But in some cases, CIOs haven’t focused on the building blocks needed to run a huge team of agents, experts say.</p>



<p>Many CIOs have underestimated the <a href="https://www.cio.com/article/4159773/your-ai-agent-is-ready-to-go-is-your-infrastructure.html?utm=hybrid_search">infrastructure work</a> required to get agents to scale responsibly, says <a href="https://www.linkedin.com/in/hilarypacker/" rel="nofollow">Hilary Packer</a>, EVP and head of enterprise data and AI at American Express.</p>



<p>“There’s a tendency to focus on what an agent can do and then move quickly to deployment before the underlying infrastructure is in place,” she says. “It is essential to first build the enterprise capabilities that allow agents to operate consistently across systems, data sources, and workflows.”</p>



<p>IT leaders must also set up well-governed data foundations, but many companies still operate with fragmented systems, inconsistent data definitions, and siloed ownership structures, Packer adds.</p>



<p>“Before deploying increasingly sophisticated models and agents, organizations need confidence that the underlying data is accurate, accessible, and fit for purpose,” she says. “That requires investments in governance, lineage, and modern data infrastructure that allows information to move efficiently across the enterprise.”</p>



<h2 class="wp-block-heading">More than an IT challenge</h2>



<p>Packer sees agentic AI as much a governance and operating model challenge as a technology challenge. In some cases, IT teams are reinventing the wheel with each agent pilot, she suggests.</p>



<p>“As organizations experiment, teams often end up rebuilding the same capabilities repeatedly — for example, identity management, access controls, monitoring, and observability,” she says. “That may be sufficient for isolated pilots, but it becomes difficult to manage and scale across the enterprise.”</p>



<h2 class="wp-block-heading">What agentic architecture really requires</h2>



<p>CIOs need to take a wholistic approach to <a href="https://www.cio.com/article/4129620/agentic-ai-fails-without-an-architecture-of-flow-to-eliminate-the-friction-tax.html?utm=hybrid_search">agentic architecture</a>. While some IT leaders think of architecture as the AI model powering agents, it goes much deeper.</p>



<p>Agentic architecture includes several elements, and in some cases, CIOs have underinvested in some functionality, says <a href="https://www.linkedin.com/in/saurabhpitkar/" rel="nofollow">Saurabh Pitkar</a>, director of product management for agentic commerce at Dell Technologies.</p>



<p>Agentic architecture, Pitkar says, includes an <a href="https://www.cio.com/article/4138739/21-agent-orchestration-tools-for-managing-your-ai-fleet.html">orchestrator</a>, the brain that controls subagents; subagents themselves, which have specialized functions; APIs and other tools; memory to maintain context of an agent session and overall behavior over a longer period; and guardrails to set boundaries for agents</p>



<p>Many organizations are now building <a href="https://www.cio.com/article/4119297/how-to-get-your-enterprise-architecture-ready-for-agentic-ai.html?utm=hybrid_search">agentic architecture</a>, but those still struggling have failed to make the right investments in areas such as building memory and creating <a href="https://www.cio.com/article/4035003/mcp-explained-the-ai-gamechanger.html?utm=hybrid_search">MCP tool</a> standardizations, Pitkar says.</p>



<p>A lack of data access and integration can be a huge barrier to agent deployments despite heavy investments in data modernization, he adds.</p>



<p>In addition, IT leaders struggling to deploy agents have often failed to manage organizational changes to account for a faster, agent-driven delivery cycle, he says. Adoption can slow down considerably if teams aren’t ready to engage with agent-speed outputs.</p>



<p>“AI does not care about org structure when it comes to accessing data,” he says.</p>



<h2 class="wp-block-heading">Use cases determine the details</h2>



<p>While the elements of agentic architecture are fairly standard, CIOs may need to focus more on different functionality depending on the use case, according to Pitkar. The devil is in the details.</p>



<p>“Customer support may need higher investments in dynamic intent mappings, memory, effective UX as these are emotionally charged conversations with human users who need a problem solved to continue their job,” Pitkar adds. “Agentic commerce may focus on deterministic APIs with machine readable data, guardrails, and compliance to securely process transactions with real money.”</p>



<p>Another way to look at agentic architecture is to think about four layers:</p>



<ul class="wp-block-list">
<li><strong>System of context</strong>, including unified, semantically enriched data</li>



<li><strong>System of work</strong>, or composable application services agents can act on</li>



<li><strong>System of agency</strong>, where planning, coordination, and governance live</li>



<li><strong>System of engagement</strong>, the interfaces that enable agents to interact with employees and customers</li>
</ul>



<p>Most organizations have these four functions happening in other enterprise software packages, but they are built for human-paced orchestration instead of machine-speed agents, says <a href="https://www.linkedin.com/in/shibaniahujasalesforce/" rel="nofollow">Shibani Ahuja</a>, SVP for enterprise IT strategy at Salesforce.</p>



<p>“Agentic architecture is the enterprise foundation that allows AI agents to autonomously reason and act — not just respond — in a way that’s governed and secure,” she says. “It’s the difference between an AI that drafts an email and an AI that closes tickets, triggers payments, and updates records, without waiting for a human to pass the baton.”</p>



<p>Ahuja sees organizations struggling to even define agentic architecture, much less deploy it. Throughout 2025, she heard CIOs describing how they implemented AI on a scale.</p>



<p>“If you listened carefully, one was describing predictive AI, one generative AI, and one an agentic workflow that was really just a sophisticated chatbot,” she says. “We were using the same word for fundamentally different things. When the ROI didn’t materialize, organizations didn’t know what had actually failed.”</p>



<p>Agent deployment struggles, meanwhile, have been less about capability and more about where organizations focus their energy, Ahuja says. Many IT leaders focus on the agent, including the use case, the prompt, and the model, but it’s just as important to ask whether the organization’s architecture actually supports its agentic goals, she adds.</p>



<p>“Can agents access real-time, governed data across your entire business?” she says. “Can they act across systems with minimal human input to reconcile inconsistencies? In most enterprises, the honest answer is not yet, and no amount of prompt tuning fixes that.”</p>



<h2 class="wp-block-heading">Setup is only the first step</h2>



<p>It’s now trivial to set up an agent, with most organizations able to do it in days, if not hours. But the work doesn’t stop there, says <a href="https://www.linkedin.com/in/adamfield/" rel="nofollow">Adam Field</a>, chief AI officer at workflow automation provider Tungsten Automation.</p>



<p>Good agentic architecture allows agents to operate reliably inside real business processes, not just in isolation, he says. For the past 30 years, enterprise systems were built for humans to navigate UIs, but agents work silently on the inside by calling APIs and requiring action-level permissions rather than login access.</p>



<p>The underestimated piece of agentic architecture is the governance controls that define what agents can do autonomously and when they must stop and hand off control to a human, Field says.</p>



<p>“Deploying an agent on a discrete task is straightforward,” he adds. “The hard part is that businesses don’t run on discrete tasks.”</p>



<p>Instead, enterprises operate on end-to-end, regulated processes with exceptions, dependencies, compliance requirements, and humans in the loop at specific moments, he notes.</p>



<p>“Designing agentic architecture that works across an entire process, not just a single step, is a fundamentally different challenge,” Field adds. “Traditional software fails obviously. Agents fail silently, confidently, at scale.”</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[AI and Brain-Computer Interface Allow Speechless ALS Patient To Work a Full-Time Job]]></title>
<description><![CDATA[UC Davis researchers say an implanted brain-computer interface has allowed Casey Harrell, an ALS patient who cannot speak, to synthesize sentences from brain activity with 99% accuracy in controlled tests and about 92% accuracy in everyday use. The Register reports that the system has remained us...]]></description>
<link>https://tsecurity.de/de/3603887/it-security-nachrichten/ai-and-brain-computer-interface-allow-speechless-als-patient-to-work-a-full-time-job/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3603887/it-security-nachrichten/ai-and-brain-computer-interface-allow-speechless-als-patient-to-work-a-full-time-job/</guid>
<pubDate>Wed, 17 Jun 2026 09:24:05 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[UC Davis researchers say an implanted brain-computer interface has allowed Casey Harrell, an ALS patient who cannot speak, to synthesize sentences from brain activity with 99% accuracy in controlled tests and about 92% accuracy in everyday use. The Register reports that the system has remained usable at home since 2023, helping Harrell communicate naturally, control a computer, and return to full-time work without researchers needing to supervise each session. The Register reports: A team of scientists from the University of California, Davis, published a paper Monday detailing a years-long study of a brain computer interface (BCI) system implanted in a patient with amyotrophic lateral sclerosis (ALS, also known as Lou Gehrig's disease), which destroys motor neurons and causes loss of motor control and eventual paralysis. According to the team, their patient, Casey Harrell, has been living with BCI implants since 2023 that are still working today, giving him the ability not only to control a computer cursor with his thoughts, but also to speak. [...] Davis neurosurgeon David Brandman, co-principal investigator and co-senior author of the paper published Monday, as well as the surgeon who placed Harrell's implant, described the results his team published as the crossing of a threshold in BCI technology: Not only has Harrell's implant been working well with daily use since 2023, but it's also incredibly accurate.
 
In controlled tests, the system managed to synthesize sentences from Harrell's brain activity with 99 percent accuracy; outside of the lab in daily use, Harrell still assessed it as being accurate 92 percent of the time. "The key thing to me is that it's enabling everyday communication for a guy who wants to talk but can't," Brandman told The Register in an interview. "Despite being paralyzed [Harrell] has gone back to work full time and has meaningful conversations with his daughter who's never heard the sound of his voice."
 
Prior work in the BCI space, Brandman told us, has either required researchers to be in a patient's home whenever they're using the tech, or for the patient to come to the researchers. That's not the case here, with the system allowing Harrell's home care team to hook him up to the system themselves, enabling him to use the device for more than 3,800 hours in the past few years. Based on the time the study was filed (It published Monday but went into peer review in July 2025) that would mean Harrell was using the device for more than five hours a day, on average. "It is a life that is more full of dynamic action and with friends and family, with colleagues, and it is something that allows me to communicate more in my natural way of communicating than any other technology that I have experienced," Harrell told UC Davis via his BCI system.<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=AI+and+Brain-Computer+Interface+Allow+Speechless+ALS+Patient+To+Work+a+Full-Time+Job%3A+https%3A%2F%2Fscience.slashdot.org%2Fstory%2F26%2F06%2F16%2F2342243%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fscience.slashdot.org%2Fstory%2F26%2F06%2F16%2F2342243%2Fai-and-brain-computer-interface-allow-speechless-als-patient-to-work-a-full-time-job%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://science.slashdot.org/story/26/06/16/2342243/ai-and-brain-computer-interface-allow-speechless-als-patient-to-work-a-full-time-job?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Lawmakers leary about Trump administration’s Anthropic order]]></title>
<description><![CDATA[Some panned it, some said they needed more information, but caution figured into all of the responses.
The post Lawmakers leary about Trump administration’s Anthropic order appeared first on CyberScoop.]]></description>
<link>https://tsecurity.de/de/3603154/it-security-nachrichten/lawmakers-leary-about-trump-administrations-anthropic-order/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3603154/it-security-nachrichten/lawmakers-leary-about-trump-administrations-anthropic-order/</guid>
<pubDate>Tue, 16 Jun 2026 23:08:31 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Some panned it, some said they needed more information, but caution figured into all of the responses.</p>
<p>The post <a href="https://cyberscoop.com/congress-reacts-anthropic-ai-export-controls/">Lawmakers leary about Trump administration’s Anthropic order</a> appeared first on <a href="https://cyberscoop.com/">CyberScoop</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[AI and brain-computer interface allow speechless ALS patient to work a full-time job]]></title>
<description><![CDATA[The hardware isn't new, but a UC Davis research team's machine learning-powered method of translating brain activity in an ALS patient into sentences with 92% accuracy is]]></description>
<link>https://tsecurity.de/de/3602925/it-nachrichten/ai-and-brain-computer-interface-allow-speechless-als-patient-to-work-a-full-time-job/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3602925/it-nachrichten/ai-and-brain-computer-interface-allow-speechless-als-patient-to-work-a-full-time-job/</guid>
<pubDate>Tue, 16 Jun 2026 20:47:39 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The hardware isn't new, but a UC Davis research team's machine learning-powered method of translating brain activity in an ALS patient into sentences with 92% accuracy is]]></content:encoded>
</item>
<item>
<title><![CDATA[Inside China’s Push to Build a Shared ‘Super Brain’ for Humanoid Robots]]></title>
<description><![CDATA[China’s robot schools are training humanoids through repetition, VR-guided demonstrations, and shared data to prepare them for real-world work.]]></description>
<link>https://tsecurity.de/de/3602782/it-nachrichten/inside-chinas-push-to-build-a-shared-super-brain-for-humanoid-robots/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3602782/it-nachrichten/inside-chinas-push-to-build-a-shared-super-brain-for-humanoid-robots/</guid>
<pubDate>Tue, 16 Jun 2026 19:47:04 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[China’s robot schools are training humanoids through repetition, VR-guided demonstrations, and shared data to prepare them for real-world work.]]></content:encoded>
</item>
<item>
<title><![CDATA['A cybersecurity disaster waiting to happen' — The VPN industry reacts to the UK's teen social media ban]]></title>
<description><![CDATA[VPN companies and privacy advocates are concerned about the increasing role of age verification online]]></description>
<link>https://tsecurity.de/de/3602546/it-nachrichten/a-cybersecurity-disaster-waiting-to-happen-the-vpn-industry-reacts-to-the-uks-teen-social-media-ban/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3602546/it-nachrichten/a-cybersecurity-disaster-waiting-to-happen-the-vpn-industry-reacts-to-the-uks-teen-social-media-ban/</guid>
<pubDate>Tue, 16 Jun 2026 18:32:55 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[VPN companies and privacy advocates are concerned about the increasing role of age verification online]]></content:encoded>
</item>
<item>
<title><![CDATA[The Download: the first brain implant power user and South Korea’s AI obsession]]></title>
<description><![CDATA[This is today’s edition of The Download, our weekday newsletter that provides a daily dose of what’s going on in the world of technology. This man with ALS is the first “power user” of a brain implant that lets him speak Casey Harrell has had a set of electrodes embedded in his brain for almost…]]></description>
<link>https://tsecurity.de/de/3601763/ai-nachrichten/the-download-the-first-brain-implant-power-user-and-south-koreas-ai-obsession/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3601763/ai-nachrichten/the-download-the-first-brain-implant-power-user-and-south-koreas-ai-obsession/</guid>
<pubDate>Tue, 16 Jun 2026 14:19:08 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[This is today’s edition of The Download, our weekday newsletter that provides a daily dose of what’s going on in the world of technology. This man with ALS is the first “power user” of a brain implant that lets him speak Casey Harrell has had a set of electrodes embedded in his brain for almost…]]></content:encoded>
</item>
<item>
<title><![CDATA[The Intelligent Shield. OpenCTI]]></title>
<description><![CDATA[Beyond Ingestion Subtitle: Deploying AI-Driven Enrichment in OpenCTITransforming Threat Data into High-Confidence IntelligenceIn an era of relentless and complex cyber attacks, traditional, manual threat intelligence cannot keep pace. Security teams are overwhelmed by data fragmentation and the c...]]></description>
<link>https://tsecurity.de/de/3600900/hacking/the-intelligent-shield-opencti/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3600900/hacking/the-intelligent-shield-opencti/</guid>
<pubDate>Tue, 16 Jun 2026 09:09:15 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h4>Beyond Ingestion <strong>Subtitle:</strong> Deploying AI-Driven Enrichment in OpenCTI</h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*yZJrYF0KW4x5gzDg6xNN6A.png"></figure><h3>Transforming Threat Data into High-Confidence Intelligence</h3><p>In an era of relentless and complex cyber attacks, traditional, manual threat intelligence cannot keep pace. Security teams are overwhelmed by data fragmentation and the critical lack of context. “The Intelligent Shield” introduces a new paradigm: beyond simply ingesting data, it’s about deploying advanced, automated machine learning pipelines for <strong>AI-driven enrichment.</strong></p><p>This guide demonstrates how to integrate state-of-the-art Large Language Models (LLMs), such as <strong>Claude AI</strong>, into an <strong>OpenCTI</strong> ecosystem. By leveraging the <strong>OpenCTI STIX 2.1 Knowledge Graph</strong> and natural language processing, this architecture converts disparate, unstructured data feeds into high-fidelity, actionable intelligence. It automatically builds context, executes deep mapping to frameworks like the <strong>MITRE ATT&amp;CK Matrix</strong>, and generates calculated, real-time <strong>Confidence Scores</strong>, enabling organizations to proactively strengthen their defenses with an intuitive, automated <strong>Intelligent Shield.</strong></p><h3>Table of Contents</h3><ol><li><a href="https://infosecwriteups.com/the-intelligent-shield-057c9b4b9394#6e45"><strong>What is OpenCTI?</strong></a></li><li><a href="https://infosecwriteups.com/the-intelligent-shield-057c9b4b9394#8ff6"><strong>Core Capabilities</strong></a></li><li><a href="https://infosecwriteups.com/the-intelligent-shield-057c9b4b9394#7dc1"><strong>Architecture Overview</strong></a></li><li><a href="https://infosecwriteups.com/the-intelligent-shield-057c9b4b9394#7865"><strong>Threat Intelligence Feeds</strong></a></li><li><a href="https://infosecwriteups.com/the-intelligent-shield-057c9b4b9394#fe8e"><strong>AI Integration Layer</strong></a></li><li><a href="https://infosecwriteups.com/the-intelligent-shield-057c9b4b9394#c6df"><strong>Prerequisites</strong></a></li><li><a href="https://infosecwriteups.com/the-intelligent-shield-057c9b4b9394#7c94"><strong>Docker Compose Deployment</strong></a></li><li><a href="https://infosecwriteups.com/the-intelligent-shield-057c9b4b9394#b276"><strong>Connector Configuration</strong></a></li><li><a href="https://infosecwriteups.com/the-intelligent-shield-057c9b4b9394#a2bd"><strong>AI-Driven Enrichment Pipeline</strong></a></li><li><a href="https://infosecwriteups.com/the-intelligent-shield-057c9b4b9394#99be"><strong>Post-Deployment Hardening</strong></a></li><li><a href="https://infosecwriteups.com/the-intelligent-shield-057c9b4b9394#fd26"><strong>Operational Runbook</strong></a></li><li><a href="https://infosecwriteups.com/the-intelligent-shield-057c9b4b9394#aabb"><strong>Troubleshooting</strong></a></li><li><a href="https://infosecwriteups.com/the-intelligent-shield-057c9b4b9394#7e3e"><strong>Usage Examples</strong></a></li></ol><h3>1. What is OpenCTI?</h3><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*fSYjMAN2q5yyUccU6F6daQ.png"></figure><p><strong>OpenCTI</strong> (Open Cyber Threat Intelligence) is an open-source platform developed by Filigran (formerly a project of ANSSI, the French national cybersecurity agency) for structuring, storing, organizing, visualizing, and sharing cyber threat intelligence (CTI).</p><p>It implements the <strong>STIX 2.1</strong> (Structured Threat Information eXpression) standard as its native data model and exposes a <strong>GraphQL API</strong> for all read/write operations. Every object — threat actors, campaigns, malware, vulnerabilities, indicators, attack patterns — is stored as a STIX Domain Object (SDO) or STIX Relationship Object (SRO) backed by two databases:</p><ul><li><strong>ElasticSearch / OpenSearch</strong> — full-text search and analytics</li><li><strong>Apache Cassandra (via JanusGraph)</strong> — graph relationship storage</li></ul><h3>Why OpenCTI?</h3><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*1a3jOT66dfRuy3XvkQJ5NQ.png"></figure><h3>2. Core Capabilities</h3><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*uj2dA3oWyo03XyrbjkNrGg.png"></figure><h4>2.1 Knowledge Graph</h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*YvoudJ_c2ItEwEgTZ8TGaQ.png"></figure><ul><li>Entities: Threat Actors, Intrusion Sets, Campaigns, Malware, Tools, Vulnerabilities (CVE), Attack Patterns (MITRE ATT&amp;CK), Courses of Action, Sectors, Countries, Organizations</li><li>Relationships modelled as first-class STIX SROs with confidence scores, date ranges, and TLP markings</li><li>Diamond Model and Kill Chain views built in</li></ul><h4>2.2 Indicator Management</h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*pGfNRDKffBczwNJeMydW8w.png"></figure><ul><li>IOC lifecycle: valid_from / valid_until with automatic expiry</li><li>Detection rule generation (Sigma, YARA, Snort)</li><li>Bulk import via STIX, CSV, OpenIOC, MISP formats</li><li>Scoring and confidence weighting per source</li></ul><h4>2.3 MITRE ATT&amp;CK Navigator Integration</h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*_jOEvP3job4uFFPBnXLIkA.png"></figure><ul><li>Full ATT&amp;CK Enterprise / Mobile / ICS matrices</li><li>Heatmaps of technique usage per threat actor or campaign</li><li>Gap analysis against your current detection coverage</li></ul><h4>2.4 Threat Actor Profiling</h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*N98FeMPaxF2ZYnhLF8kEGQ.png"></figure><ul><li>Attributed aliases, motivations (financial, espionage, hacktivism)</li><li>Geo and sector targeting mapped on world map</li><li>Timeline of campaigns and malware usage</li></ul><h4>2.5 Automation &amp; Playbooks</h4><ul><li>Built-in playbook engine (since v5.9): trigger enrichment, notifications, or SOAR actions on entity creation/modification(<strong>Enterprise Edition only)</strong></li><li>Python SDK for custom automation</li><li>Webhook support for external integrations</li></ul><h4>2.6 Collaboration &amp; Sharing</h4><ul><li>Role-based access control (RBAC) with groups and organizations</li><li>TLP (Traffic Light Protocol) enforcement at object level</li><li>TAXII 2.1 server — push feeds to SIEMs, firewalls, EDR platforms</li><li>Sharing with partner organizations via federated instances</li></ul><h4>2.7 Dashboard &amp; Reporting</h4><ul><li>Customizable dashboards with widget library</li><li>PDF report generation</li><li>Timeline, matrix, and entity views</li><li>Attack path visualization</li></ul><h3>3. Architecture Overview</h3><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*xAFxmmcNnaHdD8ZDbXIbDw.png"></figure><h3>4. Threat Intelligence Feeds</h3><h4>4.1 Free / Open-Source Feeds</h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*zamxLo7VEhjGX0cOnZvRJQ.png"></figure><ul><li><a href="https://attack.mitre.org/?utm_source=chatgpt.com"><strong>MITRE ATT&amp;CK</strong></a> — Connector: opencti/connector-mitre — Data: Techniques, mitigations, groups, software — Setup: API key not needed.</li><li><a href="https://nvd.nist.gov/?utm_source=chatgpt.com"><strong>CVE / NVD</strong></a> — Connector: opencti/connector-cve — Data: Vulnerabilities — Setup: <a href="https://nvd.nist.gov/developers/request-an-api-key">NVD API key</a> recommended/required depending on configuration.</li><li><a href="https://otx.alienvault.com/?utm_source=chatgpt.com"><strong>AlienVault OTX</strong></a> — Connector: opencti/connector-alienvault — Data: IOCs, pulses, malware families — Setup: Free OTX account/API key.</li><li><a href="https://bazaar.abuse.ch/?utm_source=chatgpt.com"><strong>Abuse.ch MalwareBazaar</strong></a> — Connector: opencti/connector-malwarebazaar — Data: Malware hashes, malware metadata, file observables — Setup: Free MalwareBazaar API key.</li><li><a href="https://urlhaus.abuse.ch/?utm_source=chatgpt.com"><strong>Abuse.ch URLhaus</strong></a> — Connector: opencti/connector-urlhaus — Data: Malicious URLs — Setup: Public feed; no API key for CSV feed.</li><li><a href="https://feodotracker.abuse.ch/?utm_source=chatgpt.com"><strong>Abuse.ch Feodo Tracker</strong></a> — Connector: use <a href="https://github.com/OpenCTI-Platform/connectors/tree/master/external-import/misp-feed?utm_source=chatgpt.com">opencti/connector-misp-feed</a> or ingest the Feodo CSV/blocklist feed manually — Data: Botnet C2 IPs — Setup: Free.</li><li><a href="https://internetdb.shodan.io/"><strong>Shodan InternetDB</strong></a> — Connector: opencti/connector-shodan-internetdb — Data: IP enrichment, domains, CPEs, CVEs, tags — Setup: No API key required.</li><li><a href="https://www.misp-project.org/feeds/?utm_source=chatgpt.com"><strong>MISP Default / CIRCL OSINT Feeds</strong></a> — Connector: <a href="https://github.com/OpenCTI-Platform/connectors/tree/master/external-import/misp-feed?utm_source=chatgpt.com">opencti/connector-misp-feed</a> — Data: STIX/MISP bundles, indicators, observables — Setup: Free.</li><li><a href="https://www.misp-project.org/feeds/?utm_source=chatgpt.com"><strong>CyberCrime-Tracker feed via MISP default feeds</strong></a> — Connector: use <a href="https://github.com/OpenCTI-Platform/connectors/tree/master/external-import/misp-feed?utm_source=chatgpt.com">opencti/connector-misp-feed</a> rather than a dedicated current connector — Data: C2 panels / freetext indicators — Setup: Free.</li><li><a href="https://openphish.com/?utm_source=chatgpt.com"><strong>OpenPhish</strong></a> — Connector: no verified current dedicated OpenCTI connector in the main repo; use generic feed ingestion where suitable — Data: Phishing URLs — Setup: Free/community feed options.</li><li><strong>DigitalSide IT-ISAC MISP Feed</strong> — Connector: <a href="https://github.com/OpenCTI-Platform/connectors/tree/master/external-import/misp-feed?utm_source=chatgpt.com">opencti/connector-misp-feed</a> with custom MISP_FEED_URL — Data: IOCs / MISP-format feed — Setup: Free.</li></ul><h4>4.2 Commercial Feeds (require license/API key)</h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*dMgCc4cuy0X9LxEAcR0PiQ.png"></figure><ul><li><a href="https://www.misp-project.org/"><strong>MISP — self-hosted</strong></a> — Connector: opencti/connector-misp — Strengths: community sharing, custom events, internal/private CTI exchange. The OpenCTI repo lists both misp and misp-feed; use misp for a live MISP instance with API access, and misp-feed for static MISP feed URLs.</li><li><a href="https://www.virustotal.com/"><strong>VirusTotal / Google Threat Intelligence</strong></a> — Connector: opencti/connector-virustotal — Strengths: file, URL, domain, and IP enrichment. The connector is under internal-enrichment, not external-import.</li><li><strong>Mandiant Threat Intelligence / Google Threat Intelligence</strong> — Connector: opencti/connector-mandiant — Strengths: APT intelligence, actor reporting, malware/campaign context.</li><li><a href="https://www.recordedfuture.com/"><strong>Recorded Future</strong></a> — Connectors: opencti/connector-recordedfuture and opencti/connector-recordedfuture-enrichment — Strengths: risk lists, enrichment, vulnerability/contextual intelligence, dark web and external threat data. Recorded Future documentation describes the OpenCTI integration as two components: an enrichment connector and a Recorded Future connector.</li><li><a href="https://www.crowdstrike.com/products/threat-intelligence/"><strong>CrowdStrike Falcon Intelligence</strong></a> — Connector: opencti/connector-crowdstrike — Strengths: actor tracking, indicators, adversary intelligence, Falcon ecosystem context.</li><li><a href="https://www.sekoia.io/"><strong>Sekoia.io Intelligence</strong></a> — Connector: opencti/connector-sekoia — Strengths: European threat landscape, CTI feed ingestion, actor/campaign context. Sekoia’s own documentation points to the OpenCTI GitHub connector path.</li><li><a href="https://threatconnect.com/"><strong>ThreatConnect</strong></a> — Connector: <strong>no verified current dedicated connector in the main OpenCTI connector tree</strong> — Strengths: enterprise TI management, source aggregation, workflow and case management. I found an OpenCTI GitHub label/feature reference for “threat connect,” but not a confirmed current connector folder equivalent to external-import/threatconnect.</li><li><a href="https://intel471.com/"><strong>Intel 471</strong></a> — Connectors: opencti/connector-intel471, opencti/connector-intel471-darknet, and opencti/connector-intel471_v2 — Strengths: underground forums, cybercrime actors, malware, infrastructure, dark web intelligence.</li></ul><h4>4.3 ISAC / Government Feeds</h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*dtrgjORW-h5AoEi0rOMBHw.png"></figure><ul><li><a href="https://www.cisa.gov/resources-tools/services/automated-indicator-sharing-ais-service?utm_source=chatgpt.com"><strong>CISA Automated Indicator Sharing / AIS</strong></a> — Method: TAXII/STIX client, AIS 2.0 uses TAXII 2.1 — Access: free service for eligible participants; contact CISA to onboard.</li><li><a href="https://www.fsisac.com/?utm_source=chatgpt.com"><strong>FS-ISAC</strong></a> — Method: STIX/TAXII and MISP automated feeds — Access: financial-sector membership; automated-feed credentials/licensing must be explicitly requested.</li><li><a href="https://health-isac.org/"><strong>Health-ISAC / H-ISAC</strong></a> — Method: HITS indicator-sharing feed; STIX/TAXII-compatible threat intelligence sharing — Access: healthcare-sector membership / Health-ISAC member access.</li><li><a href="https://www.misp-project.org/communities/?utm_source=chatgpt.com"><strong>NATO MISP Community</strong></a> — Method: MISP community / MISP sync — Access: official government cyber-defense entities from NATO nations, sponsored by their national representative in the NATO Multinational MISP Steering Board.</li><li><a href="https://www.enisa.europa.eu/topics/cyber-threats/threat-landscape?utm_source=chatgpt.com"><strong>ENISA Threat Landscape</strong></a> — Method: public reports and CTI publications; not a confirmed public TAXII/STIX feed. ENISA’s CTL methodology references STIX 2.1 as a common CTI representation format, but this is different from offering a public feed endpoint.</li></ul><h4>4.4 Feed Priority and TLP Assignment</h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*XhNw0PBdOVuwb9zHT37S5Q.png"></figure><pre># Recommended TLP assignment by source<br>feeds:<br>  - source: mitre_attack<br>    tlp: WHITE          # public, shareable<br>    confidence: 90<br>  - source: alienvault_otx<br>    tlp: GREEN          # community sharing<br>    confidence: 60<br>  - source: mandiant<br>    tlp: AMBER          # restricted to org<br>    confidence: 85<br>  - source: internal_soc<br>    tlp: RED            # internal only<br>    confidence: 95</pre><h3>5. AI Integration Layer</h3><p>This is the “AI-driven” layer on top of standard OpenCTI — a custom connector and MCP server that adds:</p><h4>5.1 AI Enrichment Connector (Claude API)</h4><ul><li>On every new Report, Malware, or Threat-Actor ingested → call Claude API</li><li>Extract structured STIX entities from unstructured text (PDFs, blog posts)</li><li>Summarize long reports into 3-sentence executive briefs</li><li>Score indicator relevance against your organization’s sector profile</li><li>Suggest ATT&amp;CK technique mappings from narrative descriptions</li></ul><h4>5.2 AI Pipeline Architecture</h4><pre>New Report ingested<br>        │<br>        ▼<br>[AI Enrichment Connector]<br>        │<br>        ├─► Claude API: Extract entities → creates STIX SDOs<br>        ├─► Claude API: Map to ATT&amp;CK techniques<br>        ├─► Claude API: Generate executive summary<br>        └─► Claude API: Score severity for your sector<br>                │<br>                ▼<br>        Update Report in OpenCTI<br>        (summary, related entities, confidence scores)</pre><h3>6. Prerequisites</h3><h4>6.1 Hardware (minimum production)</h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*Ics48TK_7nXqH-diy8Uzng.png"></figure><h4>6.2 Software</h4><pre># Install Docker Engine (Ubuntu 22.04)<br>sudo apt-get update<br>sudo apt-get install -y ca-certificates curl gnupg lsb-release<br>sudo install -m 0755 -d /etc/apt/keyrings<br>curl -fsSL https://download.docker.com/linux/ubuntu/gpg | \<br>  sudo gpg --dearmor -o /etc/apt/keyrings/docker.gpg<br>sudo chmod a+r /etc/apt/keyrings/docker.gpg<br>echo "deb [arch=$(dpkg --print-architecture) signed-by=/etc/apt/keyrings/docker.gpg] \<br>  https://download.docker.com/linux/ubuntu $(lsb_release -cs) stable" | \<br>  sudo tee /etc/apt/sources.list.d/docker.list &gt; /dev/null<br>sudo apt-get update<br>sudo apt-get install -y docker-ce docker-ce-cli containerd.io docker-compose-plugin<br># Add user to docker group<br>sudo usermod -aG docker $USER<br>newgrp docker<br># Verify<br>docker compose version</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/698/1*eM3O8rdQsyvwxf-0WEZX8w.png"></figure><h4>6.3 System Tuning (required for ElasticSearch)</h4><pre># ElasticSearch requires high vm.max_map_count<br>sudo sysctl -w vm.max_map_count=1048575<br>echo "vm.max_map_count=1048575" | sudo tee -a /etc/sysctl.conf<br><br># Increase file descriptor limits<br>echo "* soft nofile 65536" | sudo tee -a /etc/security/limits.conf<br>echo "* hard nofile 65536" | sudo tee -a /etc/security/limits.conf</pre><h3>7. Docker Compose Deployment</h3><h4><strong>7.0 Deploy from GitHub (recommended)</strong></h4><p>The fastest deployment path is to clone the maintained project repository and create a local `.env` from the sanitized template:</p><pre>cd /home/andrey<br>git clone https://github.com/anpa1200/opencti-intelligent-shield.git openCTI<br>cd /home/andrey/openCTI<br># Create local secrets/config. This file is ignored by Git.<br>cp .env.example .env<br>nano .env<br># Start the full stack after filling in .env<br>./scripts/start-all.sh</pre><p>This gives you the Docker Compose files, OpenCTI patches, AI enrichment connector, helper scripts, and Docusaurus documentation in one checkout. Use the manual sections below if you want to recreate the files by hand or compare the generated content.</p><h4>7.1 Directory Structure</h4><pre>/home/andrey/openCTI/<br>├── .env                          # secrets and config<br>├── docker-compose.yml            # core stack<br>├── docker-compose.connectors.yml # feed connectors<br>├── docker-compose.ai.yml         # AI enrichment connector<br>├── patches/<br>│   └── back.js                   # ILM race condition fix (ES 8.13 + OpenCTI 6.2.0)<br>└── connectors/<br>    └── ai-enrichment/            # custom AI connector source</pre><h4>7.2 Environment File</h4><pre>cat &gt; /home/andrey/openCTI/.env &lt;&lt; 'EOF'<br># === Core ===<br>OPENCTI_ADMIN_EMAIL=admin@opencti.local<br>OPENCTI_ADMIN_PASSWORD=CHANGE_ME_STRONG_PASSWORD<br>OPENCTI_ADMIN_TOKEN=CHANGE_ME_UUID4_TOKEN<br>OPENCTI_BASE_URL=http://localhost:8080<br><br># === Secrets ===<br>APP__ADMIN__TOKEN=CHANGE_ME_UUID4_TOKEN<br>APP__SECRET_KEY=CHANGE_ME_SECRET<br><br># === ElasticSearch ===<br># NOTE: key is ELASTIC_PASSWORD, not ELASTIC_AUTH<br>ELASTIC_PASSWORD=CHANGE_ME_ELASTIC_PASS<br><br># === Redis ===<br>REDIS_PASSWORD=opencti<br><br># === MinIO ===<br>MINIO_ROOT_USER=opencti<br>MINIO_ROOT_PASSWORD=CHANGE_ME_MINIO_PASS<br><br># === RabbitMQ ===<br>RABBITMQ_DEFAULT_USER=opencti<br>RABBITMQ_DEFAULT_PASS=CHANGE_ME_RABBITMQ_PASS<br><br># === Connector IDs (unique UUID4 per connector — NOT used for auth) ===<br>CONNECTOR_MITRE_TOKEN=CHANGE_ME_UUID4<br>CONNECTOR_CVE_TOKEN=CHANGE_ME_UUID4<br>CONNECTOR_ALIENVAULT_TOKEN=CHANGE_ME_UUID4<br>CONNECTOR_ABUSE_SSL_TOKEN=CHANGE_ME_UUID4<br>CONNECTOR_URLHAUS_TOKEN=CHANGE_ME_UUID4<br>CONNECTOR_AI_ENRICHMENT_TOKEN=CHANGE_ME_UUID4<br><br># === External API keys ===<br>ALIENVAULT_API_KEY=your_otx_key_here<br>NVD_API_KEY=your_nvd_api_key_here     # UUID format from nvd.nist.gov/developers/request-an-api-key<br>ANTHROPIC_API_KEY=your_claude_api_key_here<br>EOF<br><br># Generate unique UUIDs for connector IDs<br>python3 -c "import uuid; [print(uuid.uuid4()) for _ in range(8)]"# Generate proper tokens<br>python3 -c "import uuid; [print(f'Token: {uuid.uuid4()}') for _ in range(10)]"</pre><h4>7.3 Core Stack — docker-compose.yml</h4><pre>nano docker-compose.yml</pre><pre>version: "3"<br>services:<br>  redis:<br>    image: redis:7.2<br>    restart: always<br>    volumes:<br>      - redisdata:/data<br>    command: redis-server --requirepass ${REDIS_PASSWORD:-opencti}<br>  elasticsearch:<br>    image: docker.elastic.co/elasticsearch/elasticsearch:8.13.0<br>    volumes:<br>      - esdata:/usr/share/elasticsearch/data<br>    environment:<br>      - discovery.type=single-node<br>      - xpack.ml.enabled=false<br>      - xpack.security.enabled=true<br>      - ELASTIC_PASSWORD=${ELASTIC_PASSWORD:-CHANGE_ME}<br>      - "ES_JAVA_OPTS=-Xms2g -Xmx2g"<br>      - cluster.routing.allocation.disk.threshold_enabled=false<br>    ulimits:<br>      memlock:<br>        soft: -1<br>        hard: -1<br>    restart: always<br>  minio:<br>    image: minio/minio:RELEASE.2024-01-16T16-07-38Z<br>    volumes:<br>      - miniodata:/data<br>    ports:<br>      - "9001:9001"   # console<br>    environment:<br>      MINIO_ROOT_USER: ${MINIO_ROOT_USER:-opencti}<br>      MINIO_ROOT_PASSWORD: ${MINIO_ROOT_PASSWORD:-CHANGE_ME}<br>    command: server /data --console-address ":9001"<br>    restart: always<br>  rabbitmq:<br>    image: rabbitmq:3.13-management<br>    environment:<br>      RABBITMQ_DEFAULT_USER: ${RABBITMQ_DEFAULT_USER:-opencti}<br>      RABBITMQ_DEFAULT_PASS: ${RABBITMQ_DEFAULT_PASS:-CHANGE_ME}<br>      RABBITMQ_NODENAME: rabbit01@localhost<br>    volumes:<br>      - rabbitmqdata:/var/lib/rabbitmq<br>    restart: always<br>  opencti:<br>    image: opencti/platform:6.2.0<br>    environment:<br>      NODE_OPTIONS: --max-old-space-size=8096<br>      APP__PORT: 8080<br>      APP__BASE_URL: ${OPENCTI_BASE_URL:-http://localhost:8080}<br>      APP__ADMIN__EMAIL: ${OPENCTI_ADMIN_EMAIL}<br>      APP__ADMIN__PASSWORD: ${OPENCTI_ADMIN_PASSWORD}<br>      APP__ADMIN__TOKEN: ${OPENCTI_ADMIN_TOKEN}<br>      APP__APP_LOGS__LOGS_LEVEL: error<br>      REDIS__HOSTNAME: redis<br>      REDIS__PORT: 6379<br>      REDIS__USE_SSL: "false"<br>      REDIS__PASSWORD: ${REDIS_PASSWORD:-opencti}<br>      ELASTICSEARCH__URL: http://elasticsearch:9200<br>      ELASTICSEARCH__USERNAME: elastic<br>      ELASTICSEARCH__PASSWORD: ${ELASTIC_PASSWORD:-CHANGE_ME}<br>      MINIO__ENDPOINT: minio<br>      MINIO__PORT: 9000<br>      MINIO__USE_SSL: "false"<br>      MINIO__ACCESS_KEY: ${MINIO_ROOT_USER:-opencti}<br>      MINIO__SECRET_KEY: ${MINIO_ROOT_PASSWORD:-CHANGE_ME}<br>      RABBITMQ__HOSTNAME: rabbitmq<br>      RABBITMQ__PORT: 5672<br>      RABBITMQ__USERNAME: ${RABBITMQ_DEFAULT_USER:-opencti}<br>      RABBITMQ__PASSWORD: ${RABBITMQ_DEFAULT_PASS:-CHANGE_ME}<br>      SMTP__HOSTNAME: localhost<br>      PROVIDERS__LOCAL__STRATEGY: LocalStrategy<br>    volumes:<br>      - ./patches/back.js:/opt/opencti/build/back.js:ro<br>    ports:<br>      - "8080:8080"<br>    depends_on:<br>      - redis<br>      - elasticsearch<br>      - minio<br>      - rabbitmq<br>    restart: always<br>  worker:<br>    image: opencti/worker:6.2.0<br>    environment:<br>      OPENCTI_URL: http://opencti:8080<br>      OPENCTI_TOKEN: ${OPENCTI_ADMIN_TOKEN}<br>      WORKER_LOG_LEVEL: error<br>    depends_on:<br>      - opencti<br>    deploy:<br>      mode: replicated<br>      replicas: 3<br>    restart: always<br>volumes:<br>  esdata:<br>  redisdata:<br>  miniodata:<br>  rabbitmqdata:<br>networks:<br>  default:<br>    name: opencti_network<br>    external: true</pre><h4>7.4 Connectors — docker-compose.connectors.yml</h4><pre>nano docker-compose.connectors.yml</pre><pre>version: "3"<br>services:<br>  # MITRE ATT&amp;CK (no API key needed)<br>  connector-mitre:<br>    image: opencti/connector-mitre:6.2.0<br>    environment:<br>      OPENCTI_URL: http://opencti:8080<br>      OPENCTI_TOKEN: ${OPENCTI_ADMIN_TOKEN}<br>      CONNECTOR_ID: ${CONNECTOR_MITRE_TOKEN}<br>      CONNECTOR_NAME: "MITRE ATT&amp;CK"<br>      CONNECTOR_SCOPE: "marking-definition,identity,attack-pattern,course-of-action,intrusion-set,campaign,malware,tool,vulnerability,x-mitre-matrix,x-mitre-tactic,x-mitre-collection"<br>      CONNECTOR_CONFIDENCE_LEVEL: 75<br>      CONNECTOR_UPDATE_EXISTING_DATA: "true"<br>      CONNECTOR_LOG_LEVEL: error<br>      MITRE_REMOVE_STATEMENT_MARKING: "true"<br>      MITRE_INTERVAL: 7  # days between full refresh<br>    restart: always<br>  # CVE / NVD Vulnerabilities<br>  connector-cve:<br>    image: opencti/connector-cve:6.2.0<br>    volumes:<br>      - ./patches/cve/api.py:/opt/opencti-connector-cve/services/client/api.py:ro<br>      - ./patches/cve/vulnerability.py:/opt/opencti-connector-cve/services/client/vulnerability.py:ro<br>    environment:<br>      OPENCTI_URL: http://opencti:8080<br>      OPENCTI_TOKEN: ${OPENCTI_ADMIN_TOKEN}<br>      CONNECTOR_ID: ${CONNECTOR_CVE_TOKEN}<br>      CONNECTOR_NAME: "Common Vulnerabilities and Exposures"<br>      CONNECTOR_SCOPE: "identity,vulnerability"<br>      CONNECTOR_CONFIDENCE_LEVEL: 75<br>      CONNECTOR_LOG_LEVEL: info<br>      CONNECTOR_UPDATE_EXISTING_DATA: "true"<br>      CVE_BASE_URL: "https://services.nvd.nist.gov/rest/json/cves"<br>      CVE_API_KEY: ${NVD_API_KEY}<br>      CVE_MAX_DATE_RANGE: 120<br>      CVE_MAINTAIN_DATA: "true"<br>      CVE_INTERVAL: 2<br>    restart: always<br>  # AlienVault OTX<br>  connector-alienvault:<br>    image: opencti/connector-alienvault:6.2.0<br>    environment:<br>      OPENCTI_URL: http://opencti:8080<br>      OPENCTI_TOKEN: ${OPENCTI_ADMIN_TOKEN}<br>      CONNECTOR_ID: ${CONNECTOR_ALIENVAULT_TOKEN}<br>      CONNECTOR_NAME: "AlienVault OTX"<br>      CONNECTOR_SCOPE: "stix-core-object"<br>      CONNECTOR_CONFIDENCE_LEVEL: 40<br>      CONNECTOR_LOG_LEVEL: error<br>      ALIENVAULT_BASE_URL: "https://otx.alienvault.com"<br>      ALIENVAULT_API_KEY: ${ALIENVAULT_API_KEY}<br>      ALIENVAULT_TLP: "White"<br>      ALIENVAULT_CREATE_OBSERVABLES: "true"<br>      ALIENVAULT_CREATE_INDICATORS: "true"<br>      ALIENVAULT_PULSE_START_TIMESTAMP: "2020-01-01T00:00:00"<br>      ALIENVAULT_REPORT_STATUS: "New"<br>      ALIENVAULT_REPORT_TYPE: "threat-report"<br>      ALIENVAULT_GUESS_MALWARE: "false"<br>      ALIENVAULT_GUESS_CVE: "false"<br>      ALIENVAULT_INTERVAL: 30   # minutes<br>    restart: always<br>  # Abuse.ch SSL Blacklist<br>  connector-abuse-ssl:<br>    image: opencti/connector-abuse-ssl:6.2.0<br>    environment:<br>      OPENCTI_URL: http://opencti:8080<br>      OPENCTI_TOKEN: ${OPENCTI_ADMIN_TOKEN}<br>      CONNECTOR_ID: ${CONNECTOR_MALWAREBAZAAR_TOKEN}<br>      CONNECTOR_NAME: "Abuse.ch SSL Blacklist"<br>      CONNECTOR_SCOPE: "stix-core-object"<br>      CONNECTOR_CONFIDENCE_LEVEL: 50<br>      CONNECTOR_LOG_LEVEL: error<br>      ABUSE_SSL_URL: "https://sslbl.abuse.ch/blacklist/sslblacklist.csv"<br>      ABUSE_SSL_INTERVAL: 30  # minutes<br>    restart: always<br>  # Abuse.ch URLhaus<br>  connector-urlhaus:<br>    image: opencti/connector-urlhaus:6.2.0<br>    environment:<br>      OPENCTI_URL: http://opencti:8080<br>      OPENCTI_TOKEN: ${OPENCTI_ADMIN_TOKEN}<br>      CONNECTOR_ID: ${CONNECTOR_URLHAUS_TOKEN}<br>      CONNECTOR_NAME: "Abuse.ch URLhaus"<br>      CONNECTOR_SCOPE: "stix-core-object"<br>      CONNECTOR_CONFIDENCE_LEVEL: 40<br>      CONNECTOR_LOG_LEVEL: error<br>      URLHAUS_CSV_URL: "https://urlhaus.abuse.ch/downloads/csv_recent/"<br>      URLHAUS_IMPORT_OFFLINE: "true"<br>      URLHAUS_INTERVAL: 2  # hours<br>    restart: always<br>  connector-threatfox:<br>    image: opencti/connector-threatfox:6.2.0<br>    environment:<br>      OPENCTI_URL: http://opencti:8080<br>      OPENCTI_TOKEN: ${OPENCTI_ADMIN_TOKEN}<br>      CONNECTOR_ID: ${CONNECTOR_THREATFOX_TOKEN}<br>      CONNECTOR_NAME: "ThreatFox"<br>      CONNECTOR_SCOPE: "stix-core-object"<br>      CONNECTOR_CONFIDENCE_LEVEL: 40<br>      CONNECTOR_LOG_LEVEL: error<br>      THREATFOX_API_URL: "https://threatfox-api.abuse.ch/api/v1/"<br>      THREATFOX_CREATE_INDICATORS: "true"<br>      THREATFOX_CREATE_OBSERVABLES: "true"<br>      THREATFOX_INTERVAL: 3<br>    restart: always<br>  connector-import-document:<br>    image: opencti/connector-import-document:6.2.0<br>    environment:<br>      OPENCTI_URL: http://opencti:8080<br>      OPENCTI_TOKEN: ${OPENCTI_ADMIN_TOKEN}<br>      CONNECTOR_ID: ${CONNECTOR_IMPORT_DOCUMENT_TOKEN}<br>      CONNECTOR_NAME: "ImportDocument"<br>      CONNECTOR_SCOPE: "application/pdf,text/plain,text/html"<br>      CONNECTOR_AUTO: "true"<br>      CONNECTOR_CONFIDENCE_LEVEL: 75<br>      CONNECTOR_LOG_LEVEL: error<br>    restart: always<br>networks:<br>  default:<br>    name: opencti_network<br>    external: true</pre><h4>7.5 AI Enrichment Connector — docker-compose.ai.yml</h4><pre>nano docker-compose.ai.yml</pre><pre>version: "3"<br><br>services:<br>  connector-ai-enrichment:<br>    build:<br>      context: ./connectors/ai-enrichment<br>      dockerfile: Dockerfile<br>    environment:<br>      OPENCTI_URL: http://opencti:8080<br>      OPENCTI_TOKEN: ${OPENCTI_ADMIN_TOKEN}<br>      CONNECTOR_ID: ${CONNECTOR_AI_ENRICHMENT_TOKEN}<br>      CONNECTOR_NAME: "AI Enrichment (Claude)"<br>      CONNECTOR_LOG_LEVEL: info<br>      ANTHROPIC_API_KEY: ${ANTHROPIC_API_KEY}<br>      AI_MODEL: claude-opus-4-7<br>      AI_ENRICHMENT_REPORTS: "true"<br>      AI_ENRICHMENT_MALWARE: "true"<br>      AI_ENRICHMENT_THREAT_ACTORS: "true"<br>    restart: always<br><br>networks:<br>  default:<br>    name: opencti_network<br>    external: true</pre><h3>8. Connector Configuration</h3><h4>Fast Start / Stop Scripts</h4><p>The repository includes two helper scripts for daily operations:</p><pre># Start core OpenCTI, wait for the UI/API, then start connectors and AI enrichment<br>./scripts/start-all.sh<br># Stop AI enrichment, connectors, and core OpenCTI while preserving Docker volumes<br>./scripts/stop-all.sh</pre><p>Use these scripts for normal start/stop operations after .env is configured. Use the manual commands below when debugging a specific service startup problem.</p><pre>nano start-all.sh</pre><pre>#!/usr/bin/env bash<br>set -euo pipefail<br><br>ROOT_DIR="$(cd "$(dirname "${BASH_SOURCE[0]}")/.." &amp;&amp; pwd)"<br>cd "$ROOT_DIR"<br><br>WAIT_TIMEOUT="${WAIT_TIMEOUT:-300}"<br><br>wait_for_opencti() {<br>  local deadline=$((SECONDS + WAIT_TIMEOUT))<br><br>  echo "[start] Waiting for OpenCTI API on http://localhost:8080..."<br>  until curl -fsS http://localhost:8080 &gt;/dev/null 2&gt;&amp;1; do<br>    if (( SECONDS &gt;= deadline )); then<br>      echo "[start] OpenCTI did not become reachable within ${WAIT_TIMEOUT}s." &gt;&amp;2<br>      echo "[start] Check logs with: docker compose logs -f opencti" &gt;&amp;2<br>      return 1<br>    fi<br>    sleep 5<br>  done<br>}<br><br>echo "[start] Starting OpenCTI core stack..."<br>docker compose -f docker-compose.yml up -d<br><br>wait_for_opencti<br><br>echo "[start] Starting external connectors..."<br>docker compose -f docker-compose.connectors.yml up -d<br><br>echo "[start] Building and starting AI enrichment connector..."<br>docker compose -f docker-compose.ai.yml up -d --build<br><br>echo "[start] Done."<br>docker compose -f docker-compose.yml ps</pre><pre>nano stop-all.sh</pre><pre>#!/usr/bin/env bash<br>set -euo pipefail<br><br>ROOT_DIR="$(cd "$(dirname "${BASH_SOURCE[0]}")/.." &amp;&amp; pwd)"<br>cd "$ROOT_DIR"<br><br>echo "[stop] Stopping OpenCTI core, connectors, and AI enrichment..."<br>docker compose \<br>  -f docker-compose.yml \<br>  -f docker-compose.connectors.yml \<br>  -f docker-compose.ai.yml \<br>  down --remove-orphans<br><br>echo "[stop] Done. Volumes are preserved."</pre><h4>8.1 Start the Core Stack</h4><pre>cd /home/andrey/openCTI<br><br># Pre-flight: ElasticSearch refuses allocation above 90% disk usage<br>df -h /var/lib/docker<br># If &gt; 90% full, run: docker system prune -a   (frees ~47 GB of unused images)<br><br># Create the shared Docker network (idempotent — safe to re-run)<br>docker network create opencti_network 2&gt;/dev/null || true<br><br># Start core services<br>docker compose -f docker-compose.yml up -d<br><br># Wait for ElasticSearch to be healthy before OpenCTI finishes initializing<br>until curl -s -u "elastic:${ELASTIC_PASSWORD}" \<br>  http://localhost:9200/_cluster/health | grep -q '"status":"green"\|"status":"yellow"'; do<br>  echo "Waiting for ES..."; sleep 5<br>done<br><br># Watch logs — first-run index creation takes 5-10 minutes<br># Look for "Listening on port 8080"<br>docker compose -f docker-compose.yml logs -f opencti | grep -E "Listening|ERROR|indices"</pre><h4>8.2 Start Connectors</h4><pre># Start feed connectors (after OpenCTI is healthy)<br>docker compose -f docker-compose.connectors.yml up -d<br># Verify connectors registered (wait ~60s for startup)<br>docker compose -f docker-compose.connectors.yml ps</pre><h4>8.3 Verify in UI</h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*bgDghte5c5Hd2tKbutvP8A.png"></figure><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*fIQLlAGqYjzNesmSnRw2QQ.png"></figure><pre>http://localhost:8080<br>Login: admin@opencti.local / &lt;your password&gt;Navigation:<br>  Data → Connectors → check all show status "connected"<br>  Knowledge → Malwares → should start populating within minutes<br>  Activities → Logs → watch ingest events</pre><h3>9. AI-Driven Enrichment Pipeline</h3><h4>Overview</h4><p>The AI enrichment pipeline adds a Claude-powered layer on top of the standard OpenCTI ingestion flow. Every time a connector (AlienVault, MITRE, URLhaus, etc.) writes a new object into OpenCTI, an event is published to RabbitMQ. The AI connector subscribes to that event stream, calls the Claude API with the object’s content, and writes the extracted structured intelligence back into the graph as STIX relationships, notes, and entity updates — all automatically.</p><p><strong>Without AI enrichment:</strong></p><pre>AlienVault pulse → Report object in OpenCTI<br>                   (raw text, no relationships, no ATT&amp;CK mapping)</pre><p><strong>With AI enrichment:</strong></p><pre>AlienVault pulse → Report object in OpenCTI<br>                       ↓ AI connector picks it up from event stream<br>                   Claude API: extract entities, map techniques, score severity<br>                       ↓<br>                   Report now has:<br>                   ├── Note: executive summary (2-3 sentences)<br>                   ├── Relationship → ThreatActor (if found in graph)<br>                   ├── Relationship → Malware (if found in graph)<br>                   ├── Relationship → AttackPattern T1059.001 (created if missing)<br>                   └── x_opencti_score updated based on AI confidence</pre><h4>9.1 How the Event Stream Works</h4><p>OpenCTI uses RabbitMQ as its internal message bus. Every write operation (create, update, delete) on any STIX object publishes a message to a topic exchange. Connectors subscribe to this exchange via pycti's OpenCTIConnectorHelper.listen() method.</p><pre>OpenCTI platform<br>      │<br>      │ write event (STIX bundle)<br>      ▼<br>  RabbitMQ<br>  exchange: amq.topic<br>      │<br>      ├──► worker-1 (standard workers — write to ES/graph)<br>      ├──► worker-2<br>      ├──► worker-3<br>      └──► connector-ai-enrichment  ← our connector subscribes here<br>                  │<br>                  │ reads event payload:<br>                  │ {<br>                  │   "type": "create",<br>                  │   "data": { "id": "report--uuid", "type": "report", ... }<br>                  │ }<br>                  ▼<br>            calls Claude API<br>                  ▼<br>            writes enrichment back via GraphQL API</pre><p>Each message contains the full STIX object that was just created. The connector processes it and acknowledges the message — if it crashes mid-processing, RabbitMQ redelivers it.</p><p><strong>Connector type </strong><strong>INTERNAL_ENRICHMENT</strong> means:</p><ul><li>It does not import data on a schedule</li><li>It reacts to existing objects as they are created or updated</li><li>It appears in Settings → Connectors → Enrichment in the UI</li></ul><h4>9.2 Rules Engine (CE Automation)</h4><p><strong>Note:</strong> Playbooks are an Enterprise Edition feature. The Community Edition uses the built-in Rules Engine, which automatically infers and propagates relationships as data arrives.</p><p>All 20 rules are enabled. To verify or toggle: <strong>Settings → Customization → Rules</strong></p><p>To enable all rules via API (already done — included for re-initialization):</p><pre>RULES="attribution_attribution attribution_targets indicate_sighted attribution_use \<br>localization_of_targets location_location location_targets participate-to_parts \<br>observable_related observe_sighting part_part part-of_targets sighting_incident \<br>sighting_observable sighting_indicator report_ref_identity_part_of \<br>report_ref_indicator_based_on report_ref_observable_based_on \<br>report_ref_location_located_at parent_technique_use"<br>TOKEN=$(grep OPENCTI_ADMIN_TOKEN /home/andrey/openCTI/.env | cut -d= -f2)<br>for rule in $RULES; do<br>  curl -s -X POST http://localhost:8080/graphql \<br>    -H "Authorization: Bearer $TOKEN" \<br>    -H "Content-Type: application/json" \<br>    -d "{\"query\":\"mutation { ruleSetActivation(id: \\\"$rule\\\", enable: true) { id activated } }\"}" \<br>    | python3 -c "import sys,json; d=json.load(sys.stdin); print('$rule:', d['data']['ruleSetActivation']['activated'])"<br>done</pre><p><strong>What these rules do automatically once data arrives:</strong></p><p>RuleEffectattribution_attributionIf APT-X is attributed to Country-A, and APT-Y is a sub-group of APT-X → APT-Y also attributed to Country-Asighting_incidentIf an indicator is sighted, automatically raise an Incidentindicate_sightedIf indicator is sighted → infer the targeted entity from the indicator's relationshipreport_ref_indicator_based_onIf a Report references Observable X, and X has an Indicator → auto-link the Indicator to the Reportobservable_relatedIf two objects share a common Observable → infer a related-to relationshipparent_technique_useIf a sub-technique (T1059.001) is used → auto-link parent technique (T1059) as used</p><p><strong>For custom event-driven automation in CE</strong>, use a pycti script or the AI connector (section 9.1). The pycti library supports streaming the live event feed via helper.listen() — the AI connector in 9.1 uses exactly this pattern.10. Post-Deployment Hardening</p><h4>9.2 What Claude Extracts and How It Maps to STIX</h4><p>The connector sends the report’s description text to Claude with a structured prompt. Claude returns JSON. The connector then maps each field to STIX operations:</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*f1BfkVeUO3Qlt9Kj6-MkFg.png"></figure><p>Claude output fieldSTIX actionsummaryCreates a Note object attached to the report (object_refs)threat_actors[]Looks up ThreatActor by name in graph → creates related-to relationship to reportmalware_families[]Looks up Malware by name → creates related-to relationship to reportattack_techniques[]Looks up AttackPattern by external_id (T1059.001) → creates uses relationship to reporttargeted_sectors[]Looks up Identity (sector) → creates targets relationshiptargeted_countries[]Looks up Location by ISO code → creates targets relationshipconfidenceSets x_opencti_score on the report (0–100)</p><p><strong>Why look up instead of creating?</strong> MITRE ATT&amp;CK and identity data is already loaded by the MITRE connector. Looking up prevents duplicates. Only AttackPattern objects are created if missing (since Claude may identify techniques not yet in the graph).</p><h4>9.3 Connector Code</h4><pre>mkdir -p /home/andrey/openCTI/connectors/ai-enrichment</pre><p><a href="https://infosecwriteups.com/connectors/ai-enrichment/connector.py"><strong>connectors/ai-enrichment/connector.py</strong></a></p><pre>import os<br>import json<br>import time<br>import anthropic<br>from pycti import OpenCTIConnectorHelper<br><br>SYSTEM_PROMPT = """You are a senior cyber threat intelligence analyst.<br>Analyze threat intelligence content and return structured JSON only.<br>No prose, no markdown fences, no explanation — raw JSON."""<br><br>REPORT_PROMPT = """Analyze this threat intelligence report. Return JSON with exactly these keys:<br>- summary: string (2-3 sentence executive brief, plain text)<br>- threat_actors: list of strings (actor names, aliases, groups mentioned)<br>- malware_families: list of strings (malware/tool names)<br>- attack_techniques: list of strings (MITRE ATT&amp;CK IDs only, e.g. ["T1059.001", "T1003"])<br>- targeted_sectors: list of strings (e.g. ["Finance", "Healthcare", "Government"])<br>- targeted_countries: list of strings (ISO 3166-1 alpha-2, e.g. ["US", "UA", "DE"])<br>- confidence: integer 0-100<br><br>Report:<br>{content}"""<br><br>INTRUSION_SET_PROMPT = """Analyze this threat actor / intrusion set profile. Return JSON with exactly these keys:<br>- summary: string (2-3 sentence executive brief)<br>- aliases: list of strings (other known names)<br>- malware_families: list of strings (malware/tools this actor uses)<br>- attack_techniques: list of strings (MITRE ATT&amp;CK IDs, e.g. ["T1059.001", "T1003"])<br>- targeted_sectors: list of strings (sectors this actor targets)<br>- targeted_countries: list of strings (ISO 3166-1 alpha-2 codes)<br>- motivation: string (one of: "espionage", "financial", "hacktivism", "destruction", "unknown")<br>- sophistication: string (one of: "minimal", "intermediate", "advanced", "expert", "unknown")<br>- confidence: integer 0-100<br><br>Profile:<br>{content}"""<br><br><br>class AIEnrichmentConnector:<br>    def __init__(self):<br>        config = {<br>            "opencti": {<br>                "url": os.environ.get("OPENCTI_URL", "http://opencti:8080"),<br>                "token": os.environ["OPENCTI_TOKEN"],<br>            },<br>            "connector": {<br>                "id": os.environ["CONNECTOR_ID"],<br>                "type": "INTERNAL_ENRICHMENT",<br>                "name": os.environ.get("CONNECTOR_NAME", "AI Enrichment (Claude)"),<br>                "scope": "Report,Intrusion-Set,Threat-Actor-Group,Malware",<br>                "log_level": os.environ.get("CONNECTOR_LOG_LEVEL", "info"),<br>                "auto": False,<br>            },<br>        }<br>        self.helper = OpenCTIConnectorHelper(config)<br>        self.client = anthropic.Anthropic(api_key=os.environ["ANTHROPIC_API_KEY"])<br>        self.model = os.environ.get("AI_MODEL", "claude-opus-4-7")<br><br>    # -------------------------------------------------------------------------<br>    # Claude call with retry on rate limit<br>    # -------------------------------------------------------------------------<br><br>    def _call_claude(self, prompt_template: str, content: str) -&gt; dict | None:<br>        for attempt in range(3):<br>            try:<br>                msg = self.client.messages.create(<br>                    model=self.model,<br>                    max_tokens=2048,<br>                    system=SYSTEM_PROMPT,<br>                    messages=[{"role": "user", "content": prompt_template.format(content=content[:8000])}],<br>                )<br>                return json.loads(msg.content[0].text)<br>            except anthropic.RateLimitError:<br>                wait = 60 * (attempt + 1)<br>                self.helper.log_warning(f"Rate limited — waiting {wait}s")<br>                time.sleep(wait)<br>            except (json.JSONDecodeError, anthropic.APIError) as e:<br>                self.helper.log_error(f"Claude call failed: {e}")<br>                return None<br>        return None<br><br>    # -------------------------------------------------------------------------<br>    # STIX write-back helpers<br>    # -------------------------------------------------------------------------<br><br>    def _add_note(self, entity_id: str, summary: str, confidence: int) -&gt; None:<br>        self.helper.api.note.create(<br>            abstract="AI Summary",<br>            content=summary,<br>            confidence=confidence,<br>            object_ids=[entity_id],<br>        )<br><br>    def _link_threat_actors(self, entity_id: str, names: list, confidence: int) -&gt; None:<br>        for name in names:<br>            actor = self.helper.api.threat_actor_group.read(<br>                filters={"mode": "and", "filters": [{"key": "name", "values": [name]}], "filterGroups": []}<br>            )<br>            if actor:<br>                self.helper.api.stix_core_relationship.create(<br>                    fromId=entity_id,<br>                    toId=actor["id"],<br>                    relationship_type="related-to",<br>                    confidence=confidence,<br>                )<br><br>    def _link_malware(self, entity_id: str, names: list, confidence: int) -&gt; None:<br>        for name in names:<br>            malware = self.helper.api.malware.read(<br>                filters={"mode": "and", "filters": [{"key": "name", "values": [name]}], "filterGroups": []}<br>            )<br>            if malware:<br>                self.helper.api.stix_core_relationship.create(<br>                    fromId=entity_id,<br>                    toId=malware["id"],<br>                    relationship_type="uses",<br>                    confidence=confidence,<br>                )<br><br>    def _link_attack_patterns(self, entity_id: str, technique_ids: list, confidence: int) -&gt; None:<br>        for tid in technique_ids:<br>            pattern = self.helper.api.attack_pattern.read(<br>                filters={"mode": "and", "filters": [{"key": "x_mitre_id", "values": [tid]}], "filterGroups": []}<br>            )<br>            if not pattern:<br>                pattern = self.helper.api.attack_pattern.create(<br>                    name=tid,<br>                    x_mitre_id=tid,<br>                    confidence=50,<br>                )<br>            if pattern:<br>                self.helper.api.stix_core_relationship.create(<br>                    fromId=entity_id,<br>                    toId=pattern["id"],<br>                    relationship_type="uses",<br>                    confidence=confidence,<br>                )<br><br>    def _update_score(self, entity_id: str, confidence: int) -&gt; None:<br>        self.helper.api.stix_domain_object.update_field(<br>            id=entity_id,<br>            input={"key": "x_opencti_score", "value": str(confidence)},<br>        )<br><br>    # -------------------------------------------------------------------------<br>    # Enrichment handlers per entity type<br>    # -------------------------------------------------------------------------<br><br>    def _enrich_report(self, report: dict) -&gt; str:<br>        content = report.get("description") or ""<br>        if len(content) &lt; 50:<br>            content = report.get("name", "")<br>        if not content or len(content) &lt; 10:<br>            return "Skipped: content too short"<br><br>        self.helper.log_info(f"Enriching report: {report['name']}")<br>        result = self._call_claude(REPORT_PROMPT, content)<br>        if not result:<br>            return "Skipped: Claude error"<br><br>        confidence = result.get("confidence", 50)<br>        entity_id = report["id"]<br><br>        if result.get("summary"):<br>            self._add_note(entity_id, result["summary"], confidence)<br>        if result.get("threat_actors"):<br>            self._link_threat_actors(entity_id, result["threat_actors"], confidence)<br>        if result.get("malware_families"):<br>            self._link_malware(entity_id, result["malware_families"], confidence)<br>        if result.get("attack_techniques"):<br>            self._link_attack_patterns(entity_id, result["attack_techniques"], confidence)<br><br>        self._update_score(entity_id, confidence)<br>        self.helper.log_info(f"Enriched report '{report['name']}'")<br>        return "Enriched"<br><br>    def _enrich_intrusion_set(self, entity: dict) -&gt; str:<br>        content = entity.get("description") or entity.get("name", "")<br>        if not content or len(content) &lt; 10:<br>            return "Skipped: content too short"<br><br>        self.helper.log_info(f"Enriching intrusion set: {entity['name']}")<br>        result = self._call_claude(INTRUSION_SET_PROMPT, content)<br>        if not result:<br>            return "Skipped: Claude error"<br><br>        confidence = result.get("confidence", 50)<br>        entity_id = entity["id"]<br><br>        if result.get("summary"):<br>            self._add_note(entity_id, result["summary"], confidence)<br>        if result.get("malware_families"):<br>            self._link_malware(entity_id, result["malware_families"], confidence)<br>        if result.get("attack_techniques"):<br>            self._link_attack_patterns(entity_id, result["attack_techniques"], confidence)<br><br>        self.helper.log_info(f"Enriched intrusion set '{entity['name']}'")<br>        return "Enriched"<br><br>    # -------------------------------------------------------------------------<br>    # Event handler<br>    # -------------------------------------------------------------------------<br><br>    def process_message(self, data: dict) -&gt; str:<br>        entity_type = data.get("entity_type", "").lower()<br>        entity_id = data.get("entity_id")<br>        enrichment_entity = data.get("enrichment_entity", {})<br><br>        self.helper.log_info(f"Received entity_type='{entity_type}' id='{entity_id}'")<br><br>        if not entity_id:<br>            return "Skipped"<br><br>        entity = enrichment_entity or {}<br><br>        if entity_type == "report":<br>            if not entity:<br>                entity = self.helper.api.report.read(id=entity_id) or {}<br>            if entity.get("confidence", 0) &lt; 40:<br>                return "Skipped: low confidence"<br>            return self._enrich_report(entity)<br><br>        if entity_type in ("intrusion-set", "threat-actor-group"):<br>            if not entity:<br>                entity = self.helper.api.intrusion_set.read(id=entity_id) or {}<br>            if not entity:<br>                return "Not found"<br>            return self._enrich_intrusion_set(entity)<br><br>        if entity_type == "malware":<br>            if not entity:<br>                entity = self.helper.api.malware.read(id=entity_id) or {}<br>            if not entity:<br>                return "Not found"<br>            content = entity.get("description") or entity.get("name", "")<br>            if not content or len(content) &lt; 10:<br>                return "Skipped: content too short"<br>            self.helper.log_info(f"Enriching malware: {entity['name']}")<br>            result = self._call_claude(REPORT_PROMPT, content)<br>            if not result:<br>                return "Skipped: Claude error"<br>            confidence = result.get("confidence", 50)<br>            if result.get("summary"):<br>                self._add_note(entity["id"], result["summary"], confidence)<br>            if result.get("attack_techniques"):<br>                self._link_attack_patterns(entity["id"], result["attack_techniques"], confidence)<br>            self._update_score(entity["id"], confidence)<br>            return "Enriched"<br><br>        return "Skipped"<br><br>    def start(self):<br>        self.helper.log_info("AI Enrichment connector starting...")<br>        self.helper.listen(self.process_message)<br><br><br>if __name__ == "__main__":<br>    AIEnrichmentConnector().start()</pre><p><a href="https://infosecwriteups.com/connectors/ai-enrichment/Dockerfile"><strong>connectors/ai-enrichment/Dockerfile</strong></a></p><pre>FROM python:3.11-slim<br>WORKDIR /app<br>COPY requirements.txt .<br>RUN pip install --no-cache-dir -r requirements.txt<br>COPY connector.py .<br>CMD ["python", "connector.py"]</pre><p><a href="https://infosecwriteups.com/connectors/ai-enrichment/requirements.txt"><strong>connectors/ai-enrichment/requirements.txt</strong></a></p><pre>pycti&gt;=6.2.0<br>anthropic&gt;=0.40.0</pre><h4>9.4 Deploy the AI Connector</h4><p><strong>Prerequisites:</strong> Set ANTHROPIC_API_KEY in .env first.</p><pre>cd /home/andrey/openCTI<br># Build the image<br>docker compose -f docker-compose.ai.yml build<br># Start it<br>docker compose -f docker-compose.ai.yml up -d<br># Verify it registered with OpenCTI (look for "AI Enrichment" in connector list)<br>docker logs opencti-connector-ai-enrichment-1 --tail=20</pre><p>In the OpenCTI UI: <strong>Settings → Connectors → Enrichment</strong> — the connector should appear with status connected after ~10 seconds.</p><h4>9.5 Testing the Pipeline</h4><p>Trigger a manual enrichment by importing a real threat report:</p><pre># Import a STIX report via the API to trigger the connector<br>curl -s -X POST http://localhost:8080/graphql \<br>  -H "Authorization: Bearer $(grep OPENCTI_ADMIN_TOKEN .env | cut -d= -f2)" \<br>  -H "Content-Type: application/json" \<br>  -d '{<br>    "query": "mutation { reportAdd(input: { name: \"Test: APT29 spearphishing campaign\", description: \"APT29, also known as Cozy Bear, conducted a spearphishing campaign targeting NATO members using a malicious PDF dropper that installed Cobalt Strike beacon via PowerShell (T1059.001). The campaign targeted defense contractors in Poland and Germany. The malware communicated with C2 over HTTPS using domain fronting (T1090.004).\", published: \"2024-01-15T00:00:00Z\", report_types: [\"threat-report\"] }) { id name } }"<br>  }'</pre><p>Then check what the AI connector wrote back:</p><pre># Watch connector logs for the enrichment<br>docker logs -f opencti-connector-ai-enrichment-1 2&gt;&amp;1 | grep -E "Enriching|Enriched|Error"<br># Expected output:<br># Enriching report: Test: APT29 spearphishing campaign<br># Enriched: 1 actors, 1 malware, 2 techniques</pre><p>In the UI, open the report — it should now have a Note with the summary, relationships to APT29 and Cobalt Strike, and links to T1059.001 and T1090.004.</p><h4>9.6 Cost and Rate Limiting</h4><p><strong>Estimated Claude API cost per report:</strong></p><ul><li>~500–2000 tokens input (report text, truncated at 8000 chars)</li><li>~300 tokens output (JSON response)</li><li>At claude-opus-4-7 pricing: ~$0.01–0.05 per report</li></ul><p><strong>Rate limiting:</strong> The Anthropic API has per-minute token limits. If AlienVault imports hundreds of reports in a burst, the connector will hit rate limits. Add a simple backoff:</p><pre>import time<br>def _call_claude(self, content: str) -&gt; dict | None:<br>    for attempt in range(3):<br>        try:<br>            msg = self.client.messages.create(...)<br>            return json.loads(msg.content[0].text)<br>        except anthropic.RateLimitError:<br>            time.sleep(60 * (attempt + 1))<br>        except (json.JSONDecodeError, anthropic.APIError) as e:<br>            self.helper.log_error(f"Claude call failed: {e}")<br>            return None<br>    return None</pre><p><strong>To limit scope</strong> (only enrich reports above a confidence threshold, skip low-quality feeds):</p><pre>def process_message(self, data: dict) -&gt; str:<br>    report = self.helper.api.report.read(id=entity_id)<br>    # Skip reports with low confidence (e.g. AlienVault auto-generated)<br>    if report.get("confidence", 0) &lt; 40:<br>        return "Skipped: low confidence"<br>    return self._enrich_report(report)</pre><h4>9.7 Rules Engine (CE Automation)</h4><p><strong>Note:</strong> Playbooks are an Enterprise Edition feature. The Community Edition uses the built-in Rules Engine, which automatically infers and propagates relationships as data arrives.</p><p>All 20 rules are enabled. To verify or toggle: <strong>Settings → Customization → Rules</strong></p><p>To enable all rules via API (already done — included for re-initialization):</p><pre>RULES="attribution_attribution attribution_targets indicate_sighted attribution_use \<br>localization_of_targets location_location location_targets participate-to_parts \<br>observable_related observe_sighting part_part part-of_targets sighting_incident \<br>sighting_observable sighting_indicator report_ref_identity_part_of \<br>report_ref_indicator_based_on report_ref_observable_based_on \<br>report_ref_location_located_at parent_technique_use"<br>TOKEN=$(grep OPENCTI_ADMIN_TOKEN /home/andrey/openCTI/.env | cut -d= -f2)<br>for rule in $RULES; do<br>  curl -s -X POST http://localhost:8080/graphql \<br>    -H "Authorization: Bearer $TOKEN" \<br>    -H "Content-Type: application/json" \<br>    -d "{\"query\":\"mutation { ruleSetActivation(id: \\\"$rule\\\", enable: true) { id activated } }\"}" \<br>    | python3 -c "import sys,json; d=json.load(sys.stdin); print('$rule:', d['data']['ruleSetActivation']['activated'])"<br>done</pre><p><strong>What these rules do automatically once data arrives:</strong></p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*epLGa3gwJILd0FyMKdsQQg.png"></figure><p>RuleEffectattribution_attributionIf APT-X is attributed to Country-A, and APT-Y is a sub-group of APT-X → APT-Y also attributed to Country-Asighting_incidentIf an indicator is sighted, automatically raise an Incidentindicate_sightedIf indicator is sighted → infer the targeted entity from the indicator's relationshipreport_ref_indicator_based_onIf a Report references Observable X, and X has an Indicator → auto-link the Indicator to the Reportobservable_relatedIf two objects share a common Observable → infer a related-to relationshipparent_technique_useIf a sub-technique (T1059.001) is used → auto-link parent technique (T1059) as used</p><p><strong>For custom event-driven automation in CE</strong>, use a pycti script or the AI connector (section 9.1). The pycti library supports streaming the live event feed via helper.listen() — the AI connector in 9.1 uses exactly this pattern.</p><h3>10. Post-Deployment Hardening</h3><h4>10.1 Reverse Proxy with TLS (nginx)</h4><pre># /etc/nginx/sites-available/opencti<br>server {<br>    listen 443 ssl http2;<br>    server_name opencti.yourdomain.com;<br>ssl_certificate     /etc/letsencrypt/live/opencti.yourdomain.com/fullchain.pem;<br>    ssl_certificate_key /etc/letsencrypt/live/opencti.yourdomain.com/privkey.pem;<br>    ssl_protocols       TLSv1.2 TLSv1.3;<br>    ssl_ciphers         ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384;<br>    location / {<br>        proxy_pass         http://127.0.0.1:8080;<br>        proxy_set_header   Host $host;<br>        proxy_set_header   X-Real-IP $remote_addr;<br>        proxy_set_header   X-Forwarded-For $proxy_add_x_forwarded_for;<br>        proxy_set_header   X-Forwarded-Proto $scheme;<br>        proxy_read_timeout 300s;<br>        client_max_body_size 100m;<br>    }<br>}<br>server {<br>    listen 80;<br>    server_name opencti.yourdomain.com;<br>    return 301 https://$host$request_uri;<br>}</pre><h4>10.2 Backup Strategy</h4><pre>#!/bin/bash<br># /home/andrey/openCTI/scripts/backup.sh<br>set -euo pipefail<br>BACKUP_DIR="/mnt/backup/opencti/$(date +%Y%m%d_%H%M%S)"<br>mkdir -p "$BACKUP_DIR"<br># Snapshot ElasticSearch<br>curl -s -u elastic:${ELASTIC_PASSWORD} \<br>  -X PUT "http://localhost:9200/_snapshot/backup/snapshot_$(date +%Y%m%d)" \<br>  -H 'Content-Type: application/json' \<br>  -d '{"indices": "*", "ignore_unavailable": true}'<br># Dump MinIO (reports, files)<br>docker run --rm \<br>  --network opencti_network \<br>  -v "$BACKUP_DIR:/backup" \<br>  minio/mc:latest \<br>  mirror myminio/opencti /backup/minio/<br>echo "Backup completed: $BACKUP_DIR"</pre><h4>10.3 Security Checklist</h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*hjQWso4p7MIiBfcRr15oZw.png"></figure><ul><li>Change all default passwords in .env</li><li>Generate unique UUID4 tokens for every connector</li><li>Enable TLS via nginx reverse proxy</li><li>Restrict port 8080 to localhost only (127.0.0.1:8080:8080)</li><li>Enable ElasticSearch authentication (already configured above)</li><li>Set up fail2ban on the nginx access log</li><li>Rotate OPENCTI_ADMIN_TOKEN every 90 days</li><li>Review TLP markings — ensure nothing RED leaks via TAXII</li><li>Enable audit logging: APP__APP_LOGS__LOGS_LEVEL: info</li></ul><h3>11. Operational Runbook</h3><h4>Day 1 — Initial Data Load</h4><pre># MITRE ATT&amp;CK loads first (foundational framework)<br># Wait ~10 minutes for it to complete, then verify:<br>TOKEN=$(grep OPENCTI_ADMIN_TOKEN /home/andrey/openCTI/.env | cut -d= -f2)<br><br>curl -s -X POST http://localhost:8080/graphql \<br>  -H "Authorization: Bearer $TOKEN" \<br>  -H "Content-Type: application/json" \<br>  -d '{"query": "{ attackPatterns { edges { node { name } } } }"}' | \<br>  python3 -c "import sys,json; d=json.load(sys.stdin); print('Techniques loaded:', len(d['data']['attackPatterns']['edges']))"<br># Should return 500+ techniques</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*V2XGUwLrUpe1XNLUono5Ng.png"></figure><h4>Common Operations</h4><pre># Check all connector health<br>docker compose -f docker-compose.connectors.yml ps<br># View connector logs<br>docker compose -f docker-compose.connectors.yml logs --tail=50 connector-alienvault<br># Restart a stuck connector<br>docker compose -f docker-compose.connectors.yml restart connector-malwarebazaar<br># Scale workers for high ingest load<br>docker compose -f docker-compose.yml up -d --scale worker=5<br># Check ElasticSearch cluster health<br>curl -s -u elastic:${ELASTIC_PASSWORD} http://localhost:9200/_cluster/health?pretty<br># Check RabbitMQ queue depth (should stay near 0 at rest)<br>docker exec $(docker ps -qf name=rabbitmq) rabbitmqctl list_queues name messages</pre><h4>Monitoring Metrics to Watch</h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*dn9gJsZa98wedqD6PdcrQA.png"></figure><h4>Quick Reference</h4><pre># Start everything<br>cd /home/andrey/openCTI<br>docker network create opencti_network 2&gt;/dev/null || true<br>docker compose -f docker-compose.yml up -d<br>docker compose -f docker-compose.connectors.yml up -d<br>docker compose -f docker-compose.ai.yml up -d<br># Stop everything<br>docker compose -f docker-compose.ai.yml down<br>docker compose -f docker-compose.connectors.yml down<br>docker compose -f docker-compose.yml down<br># Access<br># UI:      http://localhost:8080<br># API:     http://localhost:8080/graphql<br># MinIO:   http://localhost:9001<br># RabbitMQ: http://localhost:15672</pre><h3>12. Troubleshooting</h3><h3>Known Issues — OpenCTI 6.2.0 + ElasticSearch 8.13</h3><h4>ILM Race Condition (resource_already_exists_exception)</h4><p>ES 8.13’s ILM daemon auto-bootstraps rollover indices the moment an index template with lifecycle.rollover_alias is created. OpenCTI's elCreateIndex does a check-then-create which loses the race. This kills initialization and loops with restart: always.</p><p><strong>Fix already applied:</strong> patches/back.js is mounted over the compiled bundle and makes elCreateIndex idempotent — it catches resource_already_exists_exception and returns null.</p><p><strong>Re-initialization procedure</strong> (if ES volume is dropped):</p><pre># 1. Delete any leftover index templates from a failed run<br>curl -s -u elastic:${ELASTIC_PASSWORD} -X DELETE \<br>  "http://localhost:9200/_index_template/opencti*"</pre><pre># 2. Flush Redis state<br>docker exec opencti-redis-1 redis-cli -a opencti FLUSHALL</pre><pre># 3. Start ES first, wait for green/yellow<br>docker compose up -d elasticsearch<br>until curl -s -u elastic:${ELASTIC_PASSWORD} \<br>  <a href="http://localhost:9200/_cluster/health">http://localhost:9200/_cluster/health</a> | grep -q '"status":"green"\|"status":"yellow"'; do<br>  sleep 5; done</pre><pre># 4. Start the rest — OpenCTI will create 13 indices and load base STIX data (~5-10 min)<br>docker compose up -d</pre><h4>ElasticSearch Disk Watermark (cluster RED, no shard allocation)</h4><p>ES 8.x refuses all shard allocation when disk exceeds 90% high watermark. cluster.routing.allocation.disk.threshold_enabled=false is set in docker-compose.yml.</p><p>To reclaim disk space:</p><pre>docker system prune -a   # frees ~47 GB of unused images/containers</pre><h4>Connectors Can’t Reach opencti Hostname</h4><p>Both compose files must share the same Docker network. docker-compose.yml defines:</p><pre>networks:<br>  default:<br>    name: opencti_network<br>    external: true</pre><p>If the main stack was started without this, run:</p><pre>docker network connect --alias opencti opencti_network opencti-opencti-1</pre><p>Then add the networks: block to docker-compose.yml and run docker compose up -d to make it permanent.</p><h4>OPENCTI_TOKEN vs CONNECTOR_ID</h4><p>Connectors authenticate to OpenCTI using OPENCTI_TOKEN: ${OPENCTI_ADMIN_TOKEN}. The per-connector UUID variables (CONNECTOR_MITRE_TOKEN, etc.) are only used as CONNECTOR_ID — they identify the connector instance in the UI, not for authentication.</p><h4>CVE Connector — Zero Vulnerabilities Imported (NVD API Key Bug)</h4><p>connector-cve:6.2.0 has a bug: it sends the NVD API key as Bearer: &lt;key&gt; in the HTTP header, but NVD 2.0 API requires apiKey: &lt;key&gt;. The connector silently gets a non-200 response and imports nothing. Additionally, CVE_MAX_DATE_RANGE is required but missing from the image's default config — omitting it causes a TypeError: '&gt;' not supported between instances of 'NoneType' and 'int' crash every 60 seconds.</p><p><strong>Fix:</strong> Mount a patched api.py that uses the correct header, and add the missing vars:</p><pre>connector-cve:<br>  image: opencti/connector-cve:6.2.0<br>  volumes:<br>    - ./patches/cve/api.py:/opt/opencti-connector-cve/services/client/api.py:ro<br>  environment:<br>    CVE_MAX_DATE_RANGE: 120<br>    CVE_MAINTAIN_DATA: "true"<br>    # ... other vars</pre><p>patches/cve/api.py — change header from "Bearer": api_key to "apiKey": api_key:</p><pre>headers = {"User-Agent": header}<br>if api_key:<br>    headers["apiKey"] = api_key</pre><h3>13. Usage Examples</h3><h4>13.1 Standard OpenCTI Workflows</h4><h4>Example 1 — Investigate an IP address</h4><p>You received an alert from your SIEM about suspicious outbound traffic to 103.113.70.102.</p><p><strong>In OpenCTI UI:</strong></p><pre>Search → type 103.113.70.102</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*2k7QE2Urnr8tw_xJ2MyAPA.png"></figure><p>If AlienVault or URLhaus has seen it, you’ll find:</p><ul><li>Which threat actor uses this IP as C2</li><li>What malware family communicates with it</li><li>When it was first/last observed</li><li>TLP marking and confidence score</li><li>All reports that mention it</li></ul><p><strong>Via API:</strong></p><pre>TOKEN=$(grep OPENCTI_ADMIN_TOKEN /home/andrey/openCTI/.env | cut -d= -f2)<br>curl -s -X POST http://localhost:8080/graphql \<br>  -H "Authorization: Bearer $TOKEN" \<br>  -H "Content-Type: application/json" \<br>  -d '{"query": "{ stixCyberObservables(filters: {mode: and, filters: [{key: \"value\", values: [\"https://103.113.70.102/bin/support.client.exe\"]}], filterGroups: []}) { edges { node { id entity_type ... on Url { value } } } } }"}' | python3 -m json.tool</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*fe53xHSxwntH5knkGjSO6g.png"></figure><h4>Example 2 — Build an APT profile</h4><p>You want to understand everything known about Lazarus Group before a threat briefing.</p><pre><br>Threats → Intrusion Sets → search "Lazarus"</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*S-QNk2tNF4lgs9q6-YaTUQ.png"></figure><p>The profile shows:</p><ul><li><strong>Attributed to:</strong> North Korea</li><li><strong>Motivations:</strong> Financial gain, Espionage</li><li><strong>Targets:</strong> Finance, Cryptocurrency, Defense</li><li><strong>Malware used:</strong> WannaCry, Hermes, BLINDINGCAN (all auto-linked by MITRE connector)</li><li><strong>Techniques:</strong> 80+ ATT&amp;CK techniques with usage relationships</li><li><strong>Campaigns:</strong> Operation AppleJeus, Dream Job, etc.</li><li><strong>Timeline:</strong> chronological view of all activity</li></ul><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*Gmvuu4OUs0uIgRZDt9p3fA.png"></figure><p>Click <strong>“ATT&amp;CK Patterns”</strong> tab → heatmap showing which techniques Lazarus uses most.</p><h4>Example 3 — Import a threat report (PDF / blog post)</h4><p>You found a Mandiant or CrowdStrike blog post about a new campaign.</p><pre>Data → Import → drag and drop the PDF or paste the URL<br>Select format: "Auto detect" or "Report"</pre><p>OpenCTI parses it and creates a Report object. The AI enrichment connector then picks it up automatically and extracts:</p><ul><li>Threat actors mentioned</li><li>Malware families</li><li>ATT&amp;CK technique IDs</li><li>Targeted sectors and countries</li></ul><p>All as STIX relationships, visible immediately in the UI.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*zPViHJ6GKjMeHMtM8240gg.png"></figure><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*YQBdTFlcQ_q9NcblRik5pw.png"></figure><h4>Example 4 — Track a CVE across your environment</h4><p>CVE-2024–21762 (Fortinet FortiOS RCE) was just published. Check what you know about it.</p><pre>Arsenal → Vulnerabilities → search "CVE-2024-21762"</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*G9LM5wxYywcTYVdLC331jw.png"></figure><p>After the CVE connector syncs, you’ll see:</p><ul><li>CVSS score and vector</li><li>Affected software versions</li><li>Which threat actors exploit it (once AlienVault/MITRE data arrives)</li><li>Which campaigns used it</li><li>Related indicators (IPs, domains used in exploitation)</li></ul><h4>Example 5 — Create an incident from a sighting</h4><p>Your EDR detected Cobalt Strike beacon on a workstation.</p><pre>Activities → Incidents → Create<br>  Name: "CS beacon on WS-042"<br>  Type: "Intrusion"<br>  Confidence: 90<br>  Add object: link to Cobalt Strike (malware)<br>  Add object: link to T1071.001 (C2 over HTTP)<br>  Add observable: add the C2 IP</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*Zm8Mi5l-QnFsTb0jAia32A.png"></figure><p>With sighting_incident rule enabled, future detections of the same C2 IP automatically raise new incidents without manual work.</p><h4>Example 6 — Export IOCs to your firewall / SIEM</h4><p>You want a live blocklist of all HIGH confidence IPv4 indicators.</p><pre>Data → Indicators<br>Filter: Score &gt; 70, Type = IPv4-Addr, Valid until &gt; today<br>Export → CSV or STIX</pre><p>Or use the built-in <strong>TAXII 2.1 server</strong> to push directly to your SIEM:</p><pre>Settings → Taxii Server → Create collection "High confidence IOCs"<br>Configure your SIEM to poll: http://localhost:8080/taxii2/</pre><h4>Example 7 — Map your detection coverage against ATT&amp;CK</h4><p>You want to know which techniques you detect vs which you’re blind to.</p><pre>Technics → Attack Patterns<br>Filter by: used by (Lazarus Group)</pre><p>Cross-reference the list with your SIEM detection rules. Techniques with no detection rule = gap in coverage.</p><p>Export the filtered list as CSV and import into ATT&amp;CK Navigator for a visual heatmap of covered vs uncovered techniques.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*mPwgsMfkEtXK1y1rnlj0Hw.png"></figure><h4>Example 8 — Pivot from malware to infrastructure</h4><p>You found a Ryuk ransomware sample (SHA256 hash).</p><pre>Search → paste the SHA256</pre><p>From the malware object, pivot to:</p><ul><li><strong>Related indicators</strong> → domains and IPs used for C2</li><li><strong>Used by</strong> → Wizard Spider (threat actor)</li><li><strong>Campaigns</strong> → which ransomware campaigns used this variant</li><li><strong>Techniques</strong> → T1486 (Data Encrypted for Impact), T1490 (Inhibit System Recovery)</li></ul><p>Each pivot is one click in the graph view.</p><h4>Example 9 — Share intelligence with a partner org</h4><p>You want to share a report with a partner but strip out RED-marked internal data.</p><pre>Open the report → Actions → Share<br>Select TLP level: TLP:AMBER (only partner can see it)</pre><p>Or use <strong>Workspaces → Sharing groups</strong> to create a federated share with another OpenCTI instance. All objects above RED are automatically excluded from the export.</p><h4>Example 10 — Build a custom dashboard for your sector</h4><p>Your org is in Finance. You want a live dashboard showing threats to your sector.</p><pre>Home → Dashboards → Create dashboard "Finance Threat Landscape"<br>Add widgets:<br>  - "Threat actors targeting Finance" (bar chart)<br>  - "Most used techniques against Finance" (ATT&amp;CK heatmap)<br>  - "New IOCs last 7 days" (timeline)<br>  - "Active campaigns" (list)<br>  - "CVEs affecting banking software" (table)</pre><p>Each widget auto-updates as new data arrives from connectors.</p><h4>If you like this research, <a href="https://www.paypal.com/donate/?business=W3XDKS7J9XTCG&amp;no_recurring=0&amp;item_name=Buy+me+a+coffee+%28PayPal%29+%E2%80%94+Keep+the+lab+running&amp;currency_code=USD">buy me a coffee (PayPal) — Keep the lab running</a></h4><h3>Follow for practical cybersecurity research</h3><p>If you’re interested in <strong>Offensive security,</strong> <strong>AI security, real-world attack simulations, CTI, and detection engineering</strong> — this is exactly what I focus on.</p><h4>Stay connected:</h4><p>→ <strong>Subscribe on Medium:</strong> <a href="https://medium.com/@1200km">medium.com/@1200km</a><br>→ <strong>Connect on LinkedIn:</strong> <a href="https://www.linkedin.com/in/andrey-pautov/">andrey-pautov</a><br>→ <strong>GitHub — tools &amp; labs:</strong> <a href="https://github.com/anpa1200">github.com/anpa1200</a><br>→ <strong>Contact:</strong> <a href="mailto:1200km@gmail.com">1200km@gmail.com</a></p><h4>Andrey Pautov</h4><p>Follow My Work</p><p>I publish practical cybersecurity research, CTI workflows, detection engineering notes, malware analysis projects, OpenCTI work, cloud and Kubernetes security research, AI-assisted security tooling, labs, and technical guides.</p><p>Portfolio / Knowledge Base: <a href="https://1200km.com/">https://1200km.com/</a><br>Medium: <a href="https://medium.com/@1200km">https://medium.com/@1200km</a><br>GitHub: <a href="https://github.com/anpa1200">https://github.com/anpa1200</a><br>LinkedIn: <a href="https://www.linkedin.com/in/andrey-pautov/">https://www.linkedin.com/in/andrey-pautov/</a></p><p>Andrey Pautov</p><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=057c9b4b9394" width="1" height="1" alt=""><hr><p><a href="https://infosecwriteups.com/the-intelligent-shield-057c9b4b9394">The Intelligent Shield. OpenCTI</a> was originally published in <a href="https://infosecwriteups.com/">InfoSec Write-ups</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[The human brain is not a machine]]></title>
<description><![CDATA[This common comparison invites us to see ourselves as sub-optimal alternatives to AI agents]]></description>
<link>https://tsecurity.de/de/3600680/ai-nachrichten/the-human-brain-is-not-a-machine/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3600680/ai-nachrichten/the-human-brain-is-not-a-machine/</guid>
<pubDate>Tue, 16 Jun 2026 07:08:33 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[This common comparison invites us to see ourselves as sub-optimal alternatives to AI agents]]></content:encoded>
</item>
<item>
<title><![CDATA[When deep research isn't enough for your business: Sakana AI launches 'ultra deep research' agent for 100+ page reports in 8 hours]]></title>
<description><![CDATA[Tokyo-based AI startup Sakana AI has officially launched its first commercial product, Sakana Marlin. Billed as a "Virtual CSO" (Chief Strategy Officer), Marlin is an autonomous, B2B research agent that deliberately abandons the instantaneous text generation of modern chatbots in favor of deep, l...]]></description>
<link>https://tsecurity.de/de/3600172/it-nachrichten/when-deep-research-isnt-enough-for-your-business-sakana-ai-launches-ultra-deep-research-agent-for-100-page-reports-in-8-hours/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3600172/it-nachrichten/when-deep-research-isnt-enough-for-your-business-sakana-ai-launches-ultra-deep-research-agent-for-100-page-reports-in-8-hours/</guid>
<pubDate>Mon, 15 Jun 2026 22:34:07 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Tokyo-based AI startup Sakana AI has officially launched its first commercial product, <a href="https://sakana.ai/marlin/">Sakana Marlin</a>. </p><p>Billed as a "<a href="https://sakana.ai/marlin-release/#English">Virtual CSO</a>" (Chief Strategy Officer), Marlin is an autonomous, B2B research agent that deliberately abandons the instantaneous text generation of modern chatbots in favor of deep, long-horizon reasoning. </p><p>What sets Marlin apart from the current ecosystem of AI tools is its temporal scale: instead of returning an answer in seconds, it runs continuous, self-governing reasoning loops for up to eight hours at a time to deliver deeply researched, well cited, 100-page strategy reports and executive slides. The company posted sample reports generated my Marlin on its product website <a href="https://sakana.ai/marlin/">here</a>.</p><p>Available immediately via the company’s website with pricing starting at a pay-as-you-go tier, the platform is designed strictly for enterprise use—specifically targeting corporations, financial institutions, and think tanks. </p><p>The generative AI hype cycle has largely been defined by speed. For the past two years, the industry standard has been the ability to generate a poem, a line of code, or a surface-level summary in mere milliseconds. But the enterprise frontier is rapidly shifting from shallow, rapid generation to deep, methodical reasoning. </p><p>With Marlin, major businesses are no longer asking how fast an AI can answer, but how deeply it can think.</p><h2><b>The Product: A Virtual CSO</b></h2><p>What exactly is a business getting when they deploy Sakana Marlin? The workflow is fundamentally different from typical large language model (LLM) interactions. Rather than engaging in a tedious back-and-forth prompt engineering session, the user simply provides a core research topic. Following a brief initial exchange to sharpen the scope and direction of the investigation, the human steps away entirely.</p><p>For the next several hours, Marlin operates as a self-contained digital strategy team. It formulates its own initial hypotheses, navigates the web to gather data, cross-references sources to verify findings, and maps the causal dynamics within complex business environments. It is effectively searching for the "winning formula" within a sea of noise.</p><p>Think of it less like a search engine and more like a junior strategy consultant locked in a room with a whiteboard and an internet connection. You provide the strategic prompt in the morning, and by the end of the workday, the system delivers a comprehensive, professional-grade portfolio. </p><p>In Marlin's case, the final output is not a generic text blob; it is a structured set of strategic options, complete with executive summary slides, appendices, references, and a deeply researched report. </p><p>The company highlighted several real-world use cases to demonstrate Marlin's capacity for complex synthesis, including generating detailed resolution scenarios for a theoretical blockade of the Strait of Hormuz, mapping out the fragmented global AI regulation patchwork, and analyzing macroeconomic trends like the return of "bond vigilantes".</p><p>Sakana says Marlin relies on multiple AI models, but did not provide specific model names or providers. I've reached out on X to find out more and will update when I receive a repsonse.</p><h2><b>The Engine of Long-Horizon Reasoning</b></h2><p>Under the hood, Marlin is the commercial culmination of Sakana AI’s extensive laboratory breakthroughs over the past two years. </p><p>The product is powered by an exploration engine relying on Sakana's own prior research breakthrough, <a href="https://sakana.ai/ab-mcts/">Adaptive Branching Monte Carlo Tree Search (AB-MCTS)</a>, and leverages frameworks derived from "The AI Scientist," an earlier Sakana AI research project featured in the journal <i>Nature</i> that successfully automated the scientific discovery process from ideation to peer review.</p><p>To understand how this works in practice, consider a real-world analogy: modern chess engines. When a computer plays chess, it doesn't just look at the board and guess; it plays out thousands of potential future moves, evaluating the strength of each resulting position before committing to an action. </p><p>Marlin’s AB-MCTS engine does something similar for research. </p><h2><b>Inside the Engine: The Mechanics of AB-MCTS</b></h2><p>The chronology of this technology traces back to June 2025, when Sakana AI first introduced the framework to the public alongside the research paper <i>“</i><a href="https://arxiv.org/pdf/2503.04412"><i>Wider or Deeper? Scaling LLM Inference-Time Compute with Adaptive Branching Tree Search</i></a><i>”</i>. </p><p>At that time, to encourage developer experimentation with collective AI intelligence, the company released the underlying algorithm as an open-source software library called <b>TreeQuest</b>, distributed under the permissive <b>Apache 2.0 license</b>. This open-source milestone laid the technical foundation for what would eventually evolve into the proprietary, enterprise-grade Marlin product a year later.</p><p>Traditionally, when developers attempt to extract higher-quality reasoning from large language models, they rely on a brute-force method called "repeated sampling"—essentially running the model dozens of times in parallel and hoping one of the answers is correct. However, repeated sampling operates blindly; it cannot evaluate its own intermediate steps or pivot based on external feedback.</p><p>AB-MCTS replaces this paradigm with a principled, multi-turn approach driven by a Bayesian decision framework. As the AI constructs a strategy report, the system treats the research process as a branching tree of possibilities. At each node of the tree, the algorithm dynamically balances two distinct behaviors based on external feedback signals:</p><ul><li><p><b>Going Wider (Exploration):</b> Spawning entirely new, alternative hypotheses or candidate responses when the current path yields diminishing returns or unresolved contradictions.</p></li><li><p><b>Going Deeper (Exploitation):</b> Methodically refining, auditing, and building upon an existing candidate solution that shows high strategic promise.</p></li></ul><p>What transforms this from a laboratory experiment into a commercial engine is its extension into <b>Multi-LLM AB-MCTS</b>. </p><p>Sakana AI’s architecture introduces a critical third dimension to the search tree: the ability to dynamically choose <i>which</i> model to invoke for a specific sub-task, treating the industry’s leading frontier models as a plug-and-play collective intelligence network.</p><p>According to technical documentation published by the company, the engine can coordinate highly heterogeneous models—allowing an orchestration model to delegate initial ideation to one LLM, while utilizing a reasoning-heavy model to audit, verify, and correct intermediate errors generated earlier in the search tree.</p><p>By scaling up compute at inference time—leveraging the distinct "personalities" and strengths of multiple foundation models over thousands of automated cycles—AB-MCTS provides the mathematical guardrails Marlin requires. It ensures that the resulting 100-page strategy reports are not merely long-winded AI generations, but the highly vetted product of systemic, automated trial-and-error.</p><h2><b>Licensing, Data, and Enterprise Implications</b></h2><p>It is crucial to note that Sakana Marlin is distinctly not a general consumer tool; it is a commercial software-as-a-service (SaaS) offering restricted to corporate entities, organizations, and sole proprietors.</p><p>For enterprises, licensing and data handling terms are often the determining factors in software adoption. Unlike many consumer-grade AI tools that silently harvest user inputs and proprietary data to train future foundational models, Sakana Marlin operates under a strict, enterprise-grade data policy. </p><p>Neither Sakana AI nor its external AI service providers will use customer data or inputs for model training or fine-tuning unless the client provides explicit opt-in consent. </p><p>Even with consent, data is heavily processed to remove personally identifiable information. This closed-loop security is absolutely vital for companies handling sensitive M&amp;A research, unreleased product strategies, or proprietary market analyses.</p><p>The commercial licensing is structured into tiered pricing models that reflect its enterprise nature:</p><ul><li><p><b>Pay-as-you-go:</b> Users can purchase credits on demand, with a single run costing 100 credits, and add-on credits priced at ¥98 ($0.61 USD) each.</p></li><li><p><b>Pro Plan:</b> At ¥150,000 ($935.68 USD) per month, businesses receive 2,000 credits, bringing down the cost of add-on credits to ¥90 ($0.56 USD).</p></li><li><p><b>Team Plan:</b> Geared toward larger departments, this ¥400,000 ($2,495.14 USD) per month tier includes 6,000 credits, lowering add-on costs to ¥85 ($0.53 USD) per credit.</p></li><li><p><b>Enterprise:</b> Fully custom quotes with dedicated support and customized credit allocations.</p></li></ul><h2><b>Why Sakana Is Worth Watching</b></h2><p>Sakana AI’s transition into a commercial enterprise powerhouse is rooted in the pedigree of its founders, who famously helped spark the current generative AI boom. </p><p><a href="https://venturebeat.com/ai/what-you-need-to-know-about-sakana-ai-the-new-startup-from-a-transformer-paper-co-author">Formed in Tokyo in 2023</a>, the startup was co-founded by Llion Jones—a co-author of Google’s seminal 2017 “Attention Is All You Need” paper who coined the term “transformer”—and David Ha, a former Google Brain researcher and head of research at Stability AI. </p><p>The decision to build a new laboratory outside the Silicon Valley bubble was a deliberate rejection of the current AI ecosystem. At a TED AI conference in late 2025, <a href="https://venturebeat.com/technology/sakana-ais-cto-says-hes-absolutely-sick-of-transformers-the-tech-that-powers">Jones candidly expressed that he was "absolutely sick" of transformers</a>, warning that the intense pressure from investors and the hyper-fixation on scaling single, monolithic models had calcified the industry's creativity and blinded researchers to the next major breakthrough.</p><p>To break free from this "big company-itis," Jones and Ha structured Sakana AI around principles of biomimicry and evolutionary computing. </p><p>The company's name, derived from the Japanese word for fish, reflects its core technical philosophy: leveraging collective intelligence similar to schools of fish, ant colonies, or insect swarms. Rather than attempting to build one massive, do-it-all foundation model, Sakana’s research has consistently focused on deploying networks of smaller, specialized models that collaborate dynamically to adapt to complex environments. </p><p>This philosophy posits that by treating individual AI models as members of a "dream team" with complementary strengths, systems can achieve more robust and cost-effective reasoning than relying on sheer scale alone.</p><p>This nature-inspired approach quickly yielded dividends in rigorous, competitive testing. Sakana AI has made significant strides in "inference-time scaling"—allocating computational resources during the problem-solving phase to allow models to think, iterate, and refine their own answers over extended periods. </p><p>In early 2026, the company’s<a href="https://sakana.ai/ahc058/"> ALE-Agent took first place in the highly complex AtCoder Heuristic Contest (AHC058),</a> a combinatorial optimization challenge, outperforming over 800 top-tier human programmers by autonomously rebuilding and testing hundreds of solutions over a four-hour window. </p><p>Similarly,<a href="https://venturebeat.com/orchestration/how-sakana-trained-a-7b-model-to-orchestrate-gpt-5-claude-sonnet-4-and-gemini-2-5-pro"> Sakana introduced "RL Conductor,"</a> a small 7-billion-parameter model trained via reinforcement learning specifically to orchestrate and delegate tasks among a diverse pool of worker models—ranging from GPT-5 to Claude Sonnet 4—achieving state-of-the-art results on reasoning benchmarks at a fraction of traditional computing costs.</p><p>Sakana's rapid evolution from a disruptive research lab to a commercial software provider has attracted intense attention from global financial heavyweights. </p><p>By late 2025, the Tokyo-based startup secured a massive <a href="https://techcrunch.com/2025/11/17/sakana-ai-raises-135m-series-b-at-a-2-65b-valuation-to-continue-building-ai-models-for-japan/">Series B funding round that pushed its post-money valuation past $2.6 billion</a>, cementing its status as one of Japan’s most highly valued private tech companies. The firm boasts a sprawling roster of strategic investors, including early venture backers Khosla Ventures, Lux Capital, and New Enterprise Associates (NEA), alongside industry titans like Nvidia and Google. </p><p>As Sakana has expanded its focus toward mission-critical sectors like defense and finance, it has also drawn investments from major global banking institutions like Mitsubishi UFJ Financial Group (MUFG) and Citi, as well as enterprise tech giant Salesforce, positioning the startup to actively reshape corporate AI infrastructure from the ground up.</p><h2><b>Community Reactions and Field Testing</b></h2><p>Sakana AI’s shift toward commercial, long-horizon agents did not happen in a vacuum. The company ran a rigorous closed beta test beginning in April 2026, putting the tool in the hands of approximately 300 professionals across financial institutions, consulting firms, and think tanks. The feedback underscores a stark qualitative difference between standard generative chatbots and Marlin’s autonomous, fact-driven approach.</p><p>A senior consultant at a major Tokyo consulting firm noted that the tool "exceeded expectations by discovering angles we hadn't even imagined," praising its ability to match human comprehensiveness while stripping away human bias. Meanwhile, a cybersecurity division at a major Japanese IT system integrator lauded the system for providing "a highly convincing report driven by high-quality, primary research," rather than relying on recycled secondary sources.</p><p>On social media, the company’s announcement resonated with the broader tech community's growing appetite for autonomous agents. </p><p>As the AI industry matures, the value proposition is clearly shifting. Tools that act as fast, conversational encyclopedias are becoming commoditized. With Sakana Marlin, the focus moves entirely to separating the heavy lifting of thinking from the final act of deciding. By delegating the exhaustive mapping of causal dynamics to an agent capable of sustained reasoning, human executives are free to do what they do best: take action.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Satya Nadella warns that AI could hollow out entire industries, echoing the damage done by globalization]]></title>
<description><![CDATA[Microsoft CEO Satya Nadella published a sweeping essay on Sunday laying out what he describes as the defining economic challenge of the AI era: the risk that a handful of frontier models will absorb the expertise of entire industries and commoditize it, leaving businesses stripped of their compet...]]></description>
<link>https://tsecurity.de/de/3600170/it-nachrichten/satya-nadella-warns-that-ai-could-hollow-out-entire-industries-echoing-the-damage-done-by-globalization/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3600170/it-nachrichten/satya-nadella-warns-that-ai-could-hollow-out-entire-industries-echoing-the-damage-done-by-globalization/</guid>
<pubDate>Mon, 15 Jun 2026 22:34:04 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Microsoft CEO Satya Nadella <a href="https://x.com/satyanadella/status/2066182223213293753">published a sweeping essay</a> on Sunday laying out what he describes as the defining economic challenge of the AI era: the risk that a handful of frontier models will absorb the expertise of entire industries and commoditize it, leaving businesses stripped of their competitive moats.</p><p>"The last thing any of us want is a world where every company across every sector is ceding value to a few models that eat everything they see," Nadella wrote in the piece, titled "A frontier without an ecosystem is not stable," which he posted on X. "If all the value is accrued by only a few models, the political economy will simply not tolerate it. There is no societal permission for an AI future that hollows out entire industries."</p><p>The essay is unusually philosophical for a sitting CEO of a $3 trillion technology company. But it arrives at a moment when the theoretical risks Nadella describes are becoming tangible — and, critically, when Microsoft itself is grappling with the very dynamics he warns about.</p><h2>Nadella introduces "token capital" as the new currency of enterprise AI strategy</h2><p>At the center of Nadella's essay sits a conceptual framework built on two pillars he calls "<a href="https://x.com/satyanadella/status/2066182223213293753">human capital</a>" and "<a href="https://x.com/satyanadella/status/2066182223213293753">token capital</a>." Human capital, he writes, "comprises the knowledge, judgment, relationships, ingenuity, and pattern recognition of its people," while token capital refers to "the firm's AI capability it builds and owns."</p><p>The two are not in tension, he insists. "Importantly, human capital does not become less valuable as token capital grows. It only becomes more valuable!" he writes. "I believe human agency will be the driver of token capital growth. Humans will set ambitious goals, connect dots across domains, build relationships, and recognize patterns that matter most. Without human direction, you have compute running in circles."</p><p>This framing is a deliberate counterweight to the narrative that <a href="https://hub.jhu.edu/2026/02/23/will-ai-make-human-workers-obsolete/">AI will simply replace human workers</a> or, at the enterprise level, dissolve the intellectual property that differentiates one company from another. Nadella is arguing that the real danger is not AI's capability but its tendency to centralize — and that the solution requires a fundamentally new architecture for how businesses interact with the technology.</p><p>He describes the real opportunity as "not in picking the best model but instead in building a learning loop on top of models where human capital and token capital compound." The key test of a company's sovereignty in this new era, he writes, is whether it can "switch out a 'generalist' model without losing the 'company veteran' expertise built into their learning system."</p><p>This is the essay's most actionable claim — and its most provocative. Nadella is telling enterprises they need to decouple their institutional intelligence from whatever frontier model they happen to be running, creating portable knowledge systems that survive vendor changes.</p><h2>Why Nadella is comparing AI concentration to the outsourcing crisis that gutted industrial economies</h2><p>Nadella draws a pointed historical parallel to make his warning concrete. "Think about what happened in the first phase of globalization where entire industrial economies were hollowed out by outsourcing," he writes. "The GDP numbers looked fine on the surface, but the displacement was real and the consequences are still being felt. Let us not bring that dynamic into the AI era, with a small number of AI systems capturing all the economic returns, while entire industries find their knowledge commoditized right out from underneath them."</p><p>The globalization analogy is not accidental. It reframes the AI concentration debate from a narrow technology question into a political-economy argument — one that regulators, policymakers, and voters can grasp. By invoking the social costs of offshoring, Nadella is signaling that the stakes extend well beyond the enterprise technology stack. He is warning that if the AI industry fails to distribute value broadly, the political system will intervene to force the issue.</p><p>"In my view, our priority has to be building a frontier ecosystem, not just a frontier model, so value flows broadly across every company, every industry, and every country," he writes. He grounds this in an older platform philosophy: "This is the ethos I've grown up with where platforms enable more value on top than is captured inside, and where every company can continuously innovate and build value of its own." It is a direct echo of the Windows-era argument, updated for the age of inference — and it carries a similarly self-interested subtext, given that Microsoft's cloud business sits squarely in that platform layer.</p><h2>Microsoft's own runaway AI costs reveal the gap between Nadella's vision and operational reality</h2><p>What makes Nadella's essay so striking is its timing. He published it on a day when Reuters reported that <a href="https://www.reuters.com/business/microsoft-sued-by-shareholders-over-expenses-cloud-business-ai-2026-06-15/">Microsoft shareholders filed a proposed class-action lawsuit</a> in Seattle federal court, accusing the company of inflating its stock price by failing to disclose slowing growth in its Azure cloud business and the need to spend billions of dollars on AI infrastructure. The suit names Nadella and Chief Financial Officer Amy Hood among the defendants.</p><p>As the <a href="https://finance.yahoo.com/markets/stocks/articles/msft-stock-rises-despite-shareholder-180947071.html">Yahoo Finance report</a> on the lawsuit noted, Microsoft allegedly "aggressively promoted its AI developments, specifically its 'Copilot' assistant and close financial alliance with ChatGPT creator OpenAI, to artificially boost investor optimism," while understating infrastructure strain and capital risks. Microsoft also reported <a href="https://www.reuters.com/business/retail-consumer/microsoft-edges-past-cloud-growth-expectations-2026-01-28/">$37.5 billion of capital spending</a> in its second quarter, up nearly 66% from a year earlier and above the $34.3 billion that analysts projected.</p><p>Microsoft's internal cost pressures around AI have surfaced in other concrete ways this year. The company is <a href="https://www.theverge.com/tech/930447/microsoft-claude-code-discontinued-notepad">canceling the majority of its internal Claude Code licenses</a> in its Experiences and Devices division, effective June 30, 2026. Monthly usage rates reached 84 to 95% by April 2026, and per-engineer API costs ranged between $500 and $2,000 monthly, according to <a href="https://windowsforum.com/threads/microsoft-cancels-internal-claude-code-licenses-pushes-copilot-cli-by-2026.418482/">Windows Forum</a>. The cancellation came after Microsoft exhausted portions of its annual AI budget due to token-based billing, as <a href="https://fortune.com/2026/05/22/microsoft-ai-cost-problem-tokens-agents/">Fortune</a> had reported in May.</p><p>The Claude Code episode illustrates, at the micro level, the exact dynamic Nadella describes at the macro level. When a company's AI usage is metered by the token — the fundamental unit of compute that powers model inference — the more productive the tool becomes, the more expensive it gets. The term "token capital" in Nadella's essay carries a double meaning: it refers both to a firm's proprietary AI capability and, implicitly, to the actual tokens consumed in running it. Building a learning loop that compounds is aspirational. Paying the bills for that loop is operational reality.</p><h2>Uber, Meta, and Amazon are all hitting the same AI spending wall — and it validates Nadella's warning</h2><p>Microsoft is not alone in this bind. <a href="https://finance.yahoo.com/sectors/technology/articles/uber-burned-entire-2026-ai-180347400.html">Uber burned through its entire 2026 AI coding tools budget</a> in just four months after incentivizing employees to adopt the technology through an internal leaderboard ranking teams by total AI tool usage. Uber has since instituted a monthly $1,500 cap per employee per agentic coding tool, according to <a href="https://techcrunch.com/2026/06/02/uber-caps-employee-ai-spending-after-blowing-through-budget-in-four-months/">TechCrunch</a>. At Meta, an employee created a leaderboard called "<a href="https://finance.yahoo.com/sectors/technology/articles/meta-just-killed-dashboard-let-084400197.html">Claudeonomics</a>" to track which workers consumed the most AI tokens. Amazon, meanwhile, has pushed employees to "<a href="https://fortune.com/2026/05/12/amazon-tokenmaxxing-claude-ai-capex-meta-gil-luria/">tokenmaxx</a>" — use as many AI tokens as possible.</p><p>The emerging pattern is clear: enterprises adopted AI coding tools aggressively, saw genuine productivity gains, and then discovered that the consumption-based economics of frontier models created budget crises that traditional software licensing never would have. Bryan Catanzaro, vice president of applied deep learning at Nvidia, captured the tension bluntly in an <a href="https://fortune.com/article/why-is-the-cost-of-ai-higher-than-human-workers-nvidia-executive/">interview with Axios</a>: "For my team, the cost of compute is far beyond the costs of the employees," he said.</p><p>These cost dynamics land differently in the context of Nadella's essay. He prescribes a three-layer architecture — evaluation, reinforcement learning, and retrieval — designed to sit between a company's workforce and whatever frontier model it subscribes to. Companies, he argues, need to build "private evals" that "capture whether a model is actually improving against outcomes that matter to the business (not just external benchmarks!)," alongside "private reinforcement learning environments" that "let models grow stronger on real traces from inside the organization" and a knowledge base that "makes institutional memory queryable and use of tokens more efficient." He calls the resulting system "a hill climbing machine" that, "unlike most assets, it compounds."</p><h2>Other Big Tech CEOs are echoing Nadella's fears about AI models devouring enterprise knowledge</h2><p>Nadella's concerns do not exist in isolation. Other technology leaders have been raising similar warnings throughout 2026, though none have offered as prescriptive a response.</p><p>Snowflake CEO Sridhar Ramaswamy warned in a <a href="https://podcasts.apple.com/us/podcast/whos-winning-the-ai-race-softwares-future-with/id1522960417?i=1000749256704">February podcast</a> that the biggest software companies risk being reduced to mere data sources. "The big model makers want to create a world in which all of the data for all of the enterprises is easily available to them," Ramaswamy said, describing everything else as "a dumb data pipe that feeds into that big brain." He added that Snowflake needs to operate with a "fear" that enterprises would abandon software-specific AI agents in favor of all-inclusive agents that hoover up data from everywhere.</p><p>Box CEO Aaron Levie struck a similar note in a <a href="https://www.linkedin.com/feed/update/urn:li:activity:7414386514186498048/">January LinkedIn post</a>. AI models can now perform high-level knowledge work across nearly every profession, from law to strategy to scientific research, he argued. "The question that we will have to wrestle with is, in a world where everyone has access to the same expert intelligence, how does a company differentiate?" he wrote.</p><p>The combined effect of these statements is a shared diagnosis from three very different corners of the enterprise technology market: the current trajectory of AI development threatens to collapse competitive differentiation across entire industries. Nadella's essay stands apart from the others because it moves beyond diagnosis and proposes a specific architectural remedy. But the prescription is impossible to separate from the prescriber's interests.</p><p>Microsoft sits in precisely the platform layer that Nadella's framework would make indispensable — the company builds its own frontier models, operates the cloud infrastructure those models run on, and maintains deep partnerships with the leading independent AI labs. A world in which every enterprise builds a proprietary learning loop on top of commodity foundation models is, conveniently, a world in which Microsoft sells the picks and shovels to all of them.</p><h2>Nadella's Scout controversy and shareholder lawsuit reveal the tension inside Microsoft's own AI strategy</h2><p>The essay also arrives just ten days after Nadella publicly rebuked one of his own executives for outlining a plan to "<a href="https://nypost.com/2026/06/05/business/microsofts-satya-nadella-slams-company-exec-for-outlining-plan-to-make-people-addicted-to-scout-ai-tool/">make people addicted</a>" to a new AI tool called Scout.. Microsoft corporate vice president Omar Shahine had written an internal memo describing a three-phase plan to transform Scout "from addictive app to agentic platform," with the first phase focused on features that "make people depend on it daily." Nadella responded on an internal message board: "This is absolutely a non-goal! If anything we are doing the exact opposite. We want to make sure AI empowers and adds real value to human endeavor and broad economic growth!"</p><p>The Scout incident and Sunday's essay together suggest Nadella is actively constructing a public philosophy of AI that emphasizes broad value creation over extractive engagement — whether or not every corner of Microsoft has internalized that message. One anonymous Microsoft employee told 404 Media, as the Post reported, that the leaked Scout document was "very troubling," adding: "It feels like one of those 'saying the quiet part out loud' moments."</p><p>For technical decision-makers evaluating Nadella's essay, the practical implications are significant. He is arguing that choosing an AI model matters less than building the learning infrastructure around it. He is arguing that the ability to swap models without losing institutional intelligence is the critical test of AI sovereignty. And he is warning that companies that fail to build these systems will find their expertise absorbed and commoditized by the models themselves. "You can offload a task, or even a job, but you can never offload your learning," Nadella writes. "The future of the firm is the ability to compound that learning across people and AI."</p><h2>The question Nadella's essay cannot answer is whether Microsoft will practice what its CEO preaches</h2><p>Whether Nadella's vision materializes depends on a question his essay carefully sidesteps: whether the platform providers who build and host the frontier ecosystem will resist the temptation to capture the value flowing through it. Nadella insists that "platforms enable more value on top than is captured inside." But Microsoft's own trajectory this year — the ballooning capital expenditures, the Claude Code budget crisis, the shareholder lawsuit alleging concealed costs, the internal memo about making users addicted — suggests the economics of restraint are harder than the philosophy of restraint.</p><p>Nadella ends his essay with the claim that broad value distribution "is the stable equilibrium we should build together." He may be right. Ecosystems have historically outperformed walled gardens over long time horizons. But stable equilibria require every major player to forgo short-term extraction in favor of long-term compounding — and right now, the AI industry is burning through budgets in four months and spending 66% more on infrastructure than analysts expected. The CEO of the world's most valuable technology company has written an eloquent argument for why the AI economy needs to work differently. The open question is whether his own company's balance sheet will let him prove it.</p><p>
</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Brain-Computer-Interface: ALS-Patient nutzt Hirnimplantat 19 Monate lang]]></title>
<description><![CDATA[Ein ALS-Patient hat ein Brain-Computer-Interface fast zwei Jahre lang täglich zu Hause genutzt. Die Studie liefert wichtige Belege für die Alltagstauglichkeit.]]></description>
<link>https://tsecurity.de/de/3599791/it-nachrichten/brain-computer-interface-als-patient-nutzt-hirnimplantat-19-monate-lang/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3599791/it-nachrichten/brain-computer-interface-als-patient-nutzt-hirnimplantat-19-monate-lang/</guid>
<pubDate>Mon, 15 Jun 2026 19:04:19 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Ein ALS-Patient hat ein Brain-Computer-Interface fast zwei Jahre lang täglich zu Hause genutzt. Die Studie liefert wichtige Belege für die Alltagstauglichkeit.]]></content:encoded>
</item>
<item>
<title><![CDATA[Brain experts tell the UK government there's 'very little' scientific evidence that phones are harming kids — but a social media ban is going ahead anyway]]></title>
<description><![CDATA[A few words from the academics speaking at the Science, Innovation and Technology Committee in the House of Parliament.]]></description>
<link>https://tsecurity.de/de/3599618/it-nachrichten/brain-experts-tell-the-uk-government-theres-very-little-scientific-evidence-that-phones-are-harming-kids-but-a-social-media-ban-is-going-ahead-anyway/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3599618/it-nachrichten/brain-experts-tell-the-uk-government-theres-very-little-scientific-evidence-that-phones-are-harming-kids-but-a-social-media-ban-is-going-ahead-anyway/</guid>
<pubDate>Mon, 15 Jun 2026 17:54:35 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A few words from the academics speaking at the Science, Innovation and Technology Committee in the House of Parliament.]]></content:encoded>
</item>
<item>
<title><![CDATA[This man with ALS is “the first power user” of a brain implant that lets him speak]]></title>
<description><![CDATA[Casey Harrell has had a set of electrodes embedded in his brain for almost three years. Harrell, who has amyotrophic lateral sclerosis (ALS) and is paralyzed, first used his brain-computer interface (BCI) to “speak” sentences with the help of a research team in 2023. Since then, Harrell has clock...]]></description>
<link>https://tsecurity.de/de/3599589/ai-nachrichten/this-man-with-als-is-the-first-power-user-of-a-brain-implant-that-lets-him-speak/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3599589/ai-nachrichten/this-man-with-als-is-the-first-power-user-of-a-brain-implant-that-lets-him-speak/</guid>
<pubDate>Mon, 15 Jun 2026 17:34:20 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Casey Harrell has had a set of electrodes embedded in his brain for almost three years. Harrell, who has amyotrophic lateral sclerosis (ALS) and is paralyzed, first used his brain-computer interface (BCI) to “speak” sentences with the help of a research team in 2023. Since then, Harrell has clocked thousands of hours of use. He…]]></content:encoded>
</item>
<item>
<title><![CDATA[Are Many College Students Losing the Ability to Read?]]></title>
<description><![CDATA[Futurism reports:

in a new essay for The Chronicle Higher Education, university-level literature and writing instructor Tyler Jagt recalls how not a single one of his students could get through an assigned 20-page article, something that he had read "without complaint" as an undergraduate a deca...]]></description>
<link>https://tsecurity.de/de/3598981/it-security-nachrichten/are-many-college-students-losing-the-ability-to-read/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3598981/it-security-nachrichten/are-many-college-students-losing-the-ability-to-read/</guid>
<pubDate>Mon, 15 Jun 2026 13:53:04 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Futurism reports:

in a new essay for The Chronicle Higher Education, university-level literature and writing instructor Tyler Jagt recalls how not a single one of his students could get through an assigned 20-page article, something that he had read "without complaint" as an undergraduate a decade ago. 

One student confessed that the reason they didn't finish was that they kept losing track of what the paper was about. And there's no doubt that they're not alone. Jagt cites the 2024 National Assessment of Educational Progress reading assessment results released last year. It showed that 12th grade reading scores were at the lowest level since the assessment began in 1992. Nearly a third of those 12th graders scored below the assessment's "basic" level in reading, meaning they likely "cannot draw general conclusions based on concepts presented explicitly in a text." Younger children aren't better off: a recent report from the Annie E. Casey Foundation found that 70 percent of fourth graders, or around two million kids, can't read at a proficient level. 

"What I am seeing in my classroom is no longer a hunch," Jagt writes. "There is a measurable, generational collapse in sustained reading and writing, and the academy is responding to it with improvisation and exhaustion rather than the structural overhaul it requires...." Jagt cites an MIT study that found users who used ChatGPT during cognitive tasks like writing essays showed lower brain activity in areas associated with creativity compared to students who only used a traditional Google Search or didn't lookup information at all. An astonishing 83 percent of the AI users couldn't quote a single line from the essays they had just written, and capstoning the alarm, the brain activity in the AI users didn't return to normal when they were later asked to write without AI... 

On our pernicious pocket devices, Jagt touted a 2017 study that found that simply having a smartphone physically nearby — even if it's face down or turned off — reduced available cognitive capacity and impaired cognitive functioning. "So when a student tells me they 'kept losing track' of a 20-page article, I have to acknowledge that they may be describing a measurable neurological condition," Jagt wrote. "The neural pathways that support sustained attention are built by use, and they atrophy without it. Your body is a use-it-or-lose-it system, and the brain is no exception."
 

Sunday an "Ask Reddit" question went viral — drawing over 11,000 upvotes — for its question to any teachers reading Reddit. "Is the 'Gen Alpha can't read (write, or do math ext)' crisis real? If so how bad is it?" Some responses...

 
"The run of the mill non-honors kids have gotten really bad," posted one high school teacher. "Very low tolerance for working hard, very short attention span, very short stamina for active listening... It's the group that is the most worrying because a decade ago, I'd estimate that maybe 10-20% of kids at a school are like this, and now it's probably 40-50% of each graduating class... Then there's of course the bottom 10-20% kids (excluding the special ed/severe/moderate learning disability kids). This is what the viral videos are about and it's not an exaggeration. They can't read, write, or do very basic math like multiplication or division as a 17 year old."

"This is the first year the MAJORITY of my class cheated on their first essays...." posted one high school English teacher. "It was also the first year a kid yelled 'We don't care about your fucking books, Miss!' while I was in front of the class presenting books they might be interested in for their book reviews... Almost all of them cheated on the book review they had to write."


Thanks to long-time Slashdot reader schwit1 for sharing the article.
<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=Are+Many+College+Students+Losing+the+Ability+to+Read%3F%3A+https%3A%2F%2Fnews.slashdot.org%2Fstory%2F26%2F06%2F14%2F2227254%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fnews.slashdot.org%2Fstory%2F26%2F06%2F14%2F2227254%2Fare-many-college-students-losing-the-ability-to-read%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://news.slashdot.org/story/26/06/14/2227254/are-many-college-students-losing-the-ability-to-read?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[UK Scientists See Little Evidence for Claims Smartphones Are Rewiring Kids' Brains]]></title>
<description><![CDATA[UK's Members of Parliament (MP) were "looking for proof that smartphones and social media are rotting children's brains," writes The Register — but they got "a less satisfying answer from neuroscientists on Wednesday: nobody can really prove it."

 Appearing before the Science, Innovation and Tec...]]></description>
<link>https://tsecurity.de/de/3597659/it-security-nachrichten/uk-scientists-see-little-evidence-for-claims-smartphones-are-rewiring-kids-brains/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3597659/it-security-nachrichten/uk-scientists-see-little-evidence-for-claims-smartphones-are-rewiring-kids-brains/</guid>
<pubDate>Sun, 14 Jun 2026 23:49:54 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[UK's Members of Parliament (MP) were "looking for proof that smartphones and social media are rotting children's brains," writes The Register — but they got "a less satisfying answer from neuroscientists on Wednesday: nobody can really prove it."

 Appearing before the Science, Innovation and Technology Committee this week, three researchers spent much of the session explaining that concern and evidence are not quite the same thing. Asked what evidence exists on the impact of digital devices on infants and young children, Professor Denis Mareschal, director of the Centre for Brain and Cognitive Development at Birkbeck, replied: "There is very little, if any, causal research in the early years. Almost everything is correlational." 

MPs kept coming back to the question — and the experts kept coming back to the same answer. When questioned about social media's impact on adolescents, Professor Sarah-Jayne Blakemore of the University of Cambridge was equally cautious. "What evidence do we have of the impact of digital devices or social media on the adolescent brain?" she asked. "Almost nothing. There are a few small studies, but they haven't been replicated, and they're purely correlational...." 

MPs also wanted to know whether neuroscience could settle one of the liveliest arguments in the debate: how old a child should be before they're allowed onto social media. "What neuroscience can't do is pinpoint a precise age," Blakemore said. "The individual differences in brain development are vast...." If there was a takeaway from the hearing, it was that concern about digital childhood is running well ahead of the evidence needed to settle the argument.<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=UK+Scientists+See+Little+Evidence+for+Claims+Smartphones+Are+Rewiring+Kids'+Brains%3A+https%3A%2F%2Fmobile.slashdot.org%2Fstory%2F26%2F06%2F14%2F2132212%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fmobile.slashdot.org%2Fstory%2F26%2F06%2F14%2F2132212%2Fuk-scientists-see-little-evidence-for-claims-smartphones-are-rewiring-kids-brains%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://mobile.slashdot.org/story/26/06/14/2132212/uk-scientists-see-little-evidence-for-claims-smartphones-are-rewiring-kids-brains?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Pioneering UK Nerve Lab harnesses AI to map effect of children’s screen time]]></title>
<description><![CDATA[Other projects include developing tools to help visually impaired people navigate video games  Parents are constantly being told to limit their children’s screen time. But when it comes to deciphering which films or TV shows are best suited to developing minds, the guidance remains largely one-si...]]></description>
<link>https://tsecurity.de/de/3595447/ai-nachrichten/pioneering-uk-nerve-lab-harnesses-ai-to-map-effect-of-childrens-screen-time/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3595447/ai-nachrichten/pioneering-uk-nerve-lab-harnesses-ai-to-map-effect-of-childrens-screen-time/</guid>
<pubDate>Sat, 13 Jun 2026 13:03:27 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Other projects include developing tools to help visually impaired people navigate video games </p><p> </p><p>Parents are constantly being told to limit their children’s screen time. But when it comes to deciphering which films or TV shows are best suited to developing minds,<strong> </strong>the guidance remains largely one-size-fits-all. A relatively slow-paced programme such as Bluey offers a very different viewing experience to a fast-moving action series such as PAW Patrol, yet both are broadly considered suitable for young children.</p><p>This challenge is growing as the type of content children are exposed to evolves. “Today’s young viewers are increasingly engaging with short-form, fast-paced, highly captivating content, often created by splicing and rearranging existing episodic content into quickly digestible snippets or compilations,” said Prof Tim Smith, director of University of the Arts London’s Nerve Lab. “This evolution is not only changing how content is produced and distributed, but may also affect children’s attention, comprehension and emotional response.”</p> <a href="https://www.theguardian.com/society/2026/jun/13/nerve-lab-uk-ai-brain-scanning-tech-childrens-screen-time">Continue reading...</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Neue KI-Behörde: Bundesnetzagentur wird oberste deutsche KI-Aufsicht]]></title>
<description><![CDATA[Der Bundestag hat entschieden: Die Bundesnetzagentur wird die zentrale Überwachungsbehörde für Künstliche Intelligenz in Deutschland. Damit setzt die Regierung Vorgaben der EU um. Doch an der neuen Aufsichtsstruktur gibt es auch deutliche Kritik.			(Weiter lesen)]]></description>
<link>https://tsecurity.de/de/3594368/it-security-nachrichten/neue-ki-behoerde-bundesnetzagentur-wird-oberste-deutsche-ki-aufsicht/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3594368/it-security-nachrichten/neue-ki-behoerde-bundesnetzagentur-wird-oberste-deutsche-ki-aufsicht/</guid>
<pubDate>Fri, 12 Jun 2026 21:04:37 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<a href="https://winfuture.de/news,159316.html"><img hspace="5" border="0" align="left" alt="Google, Ki, Künstliche Intelligenz, AI, Artificial Intelligence, Chatbot, Bard, Google Bard, Google KI, Mensch, Google Brain, Brain, Human, Google AI" width="1920" height="1080" src="https://i.wfcdn.de/teaser/1920/66127.png"></a>
			Der Bundestag hat entschieden: Die Bundesnetzagentur wird die zentrale Überwachungsbehörde für <a href="https://winfuture.de/special/kuenstliche-intelligenz/" title="Künstliche Intelligenz Special">Künstliche Intelligenz</a> in Deutschland. Damit setzt die Regierung Vorgaben der EU um. Doch an der neuen Aufsichtsstruktur gibt es auch deutliche Kritik.			(<a href="https://winfuture.de/news,159316.html">Weiter lesen</a>)]]></content:encoded>
</item>
<item>
<title><![CDATA[Inside Elon Musk’s AI Ecosystem: How xAI, Tesla, X, Neuralink, and SpaceX Are Converging]]></title>
<description><![CDATA[Elon Musk’s AI ecosystem spans xAI, Tesla, X, Neuralink, and SpaceX, connecting chatbots, robots, brain implants, and spacecraft.
The post Inside Elon Musk’s AI Ecosystem: How xAI, Tesla, X, Neuralink, and SpaceX Are Converging appeared first on TechRepublic.]]></description>
<link>https://tsecurity.de/de/3594249/it-nachrichten/inside-elon-musks-ai-ecosystem-how-xai-tesla-x-neuralink-and-spacex-are-converging/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3594249/it-nachrichten/inside-elon-musks-ai-ecosystem-how-xai-tesla-x-neuralink-and-spacex-are-converging/</guid>
<pubDate>Fri, 12 Jun 2026 20:02:53 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Elon Musk’s AI ecosystem spans xAI, Tesla, X, Neuralink, and SpaceX, connecting chatbots, robots, brain implants, and spacecraft.</p>
<p>The post <a href="https://www.techrepublic.com/article/news-elon-musk-ai-ecosystem-xai-tesla-neuralink-spacex/">Inside Elon Musk’s AI Ecosystem: How xAI, Tesla, X, Neuralink, and SpaceX Are Converging</a> appeared first on <a href="https://www.techrepublic.com/">TechRepublic</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[NanoClaw and JFrog launch 'immune system' to block AI agents from downloading malicious code]]></title>
<description><![CDATA[The creators of the hit, enterprise-friendly, open source OpenClaw variant NanoClaw are partnering with software supply chain management leader JFrog have to launch a new, joint security integration they say will protect NanoClaw autonomous agents from malicious code injection. "These agents are ...]]></description>
<link>https://tsecurity.de/de/3594132/it-nachrichten/nanoclaw-and-jfrog-launch-immune-system-to-block-ai-agents-from-downloading-malicious-code/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3594132/it-nachrichten/nanoclaw-and-jfrog-launch-immune-system-to-block-ai-agents-from-downloading-malicious-code/</guid>
<pubDate>Fri, 12 Jun 2026 19:05:29 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>The creators of the hit, enterprise-friendly, open source OpenClaw variant <a href="https://venturebeat.com/orchestration/nanoclaws-creators-are-turning-the-secure-open-source-ai-agent-harness-into-an-enterprise-second-brain">NanoClaw</a> are partnering with software supply chain management leader <a href="https://jfrog.com/">JFrog</a> have to launch a new, joint security integration they say will protect NanoClaw autonomous agents from malicious code injection. </p><p>"These agents are doing things that you cannot necessarily control, and you cannot necessarily train," said Gal Marder, Chief Strategy Officer at JFrog, in an exclusive interview with VentureBeat.</p><p>Available immediately, the partnership hardwires NanoClaw agents directly to JFrog’s vetted software registries, ensuring that AI assistants can only pull scanned, safe dependencies. </p><p>The release addresses a rapidly growing blind spot in tech: autonomous agents frequently install packages in the background to extend their capabilities, often without their human operators' knowledge or oversight. </p><p>"The people who are operating the agents are not necessarily developers, and they are not even aware of the implications," explained Gavriel Cohen, creator of NanoClaw and CEO and co-founder of its new commercial services startup, NanoCo AI. </p><p>To secure the broader ecosystem, the integration is available completely free of charge for the open-source community, while enterprise organizations can seamlessly route their agents through their existing, commercially licensed JFrog environments.</p><p>The new technical capability enabled by this partnership follows NanoCo's moves to add permissions dialogs across the apps in which it's available via <a href="https://venturebeat.com/orchestration/should-my-enterprise-ai-agent-do-that-nanoclaw-and-vercel-launch-easier-agentic-policy-setting-and-approval-dialogs-across-15-messaging-apps">a partnership with Vercel</a>, and a <a href="https://venturebeat.com/infrastructure/nanoclaw-and-docker-partner-to-make-sandboxes-the-safest-way-for-enterprises">new partnership with Docker to allow NanoClaw</a> agents to run more securely, isolated from other software environments directly inside Docker virtual containers. </p><h2><b>The risk of current, personal autonomous AI agents </b></h2><p>When an operator interacts with an autonomous system like NanoCo's NanoClaw, they communicate at a high level of abstraction. </p><p>A user might simply send an audio file or a voice note, prompting the agent to independently figure out how to process it. </p><p>As Cohen explained, the agent thinks, "oh, I can't understand voice notes, so let me go and grab a package and download something and install it and set it up and run it".</p><p>This dynamic self-improvement makes AI agents incredibly powerful, but it also renders them highly susceptible to software supply chain attacks. </p><p>Bad actors are increasingly poisoning open-source registries with malicious packages. Because agents act autonomously to fetch what they need, they bypass human scrutiny. </p><p>The operators, who may not even be developers, are largely unaware of the security implications unfolding behind the scenes.</p><h2><b>How NanoCo and JFrog are working to stop agents from running malicious code</b></h2><p>The integration between NanoCo and JFrog acts as an automated immune system for these AI environments.</p><p>Under the hood, NanoClaw agents are now configured to route their requests for software packages, CLI tools, and Model Context Protocol (MCP) servers exclusively through JFrog’s registries.</p><p>If an agent attempts to download a compromised library—such as a vulnerable version of the popular Axios package—the JFrog registry intercepts the request.</p><p>It blocks the installation, returning a security policy error to the agent, noting that the request was "rejected by JFrog's registry with a 403 security policy". </p><p>Crucially, the system does not just stop at blocking the threat; it creates a dynamic correction loop. The agent is notified of the vulnerability and guided to automatically seek out and install an approved, non-malicious version of the requested package instead.</p><p>For large organizations, this integration solves a massive compliance headache. Marder notes that as enterprises adopt autonomous agents, they require absolute visibility. </p><p>Organizations need "a system of record, we need somewhere to track what agents that's running by whom and consuming what packages and using what skills and using what MCPs," he told VentureBeat.</p><p>Beyond visibility, the JFrog integration provides a foundational "trust layer" and strict governance over what these automated systems are permitted to access.</p><h2><b>Licensing and accessibility</b></h2><p>In the realm of software distribution, licensing and access parameters dictate adoption. The NanoCo and JFrog partnership utilizes a dual-track approach to serve both individual open-source developers and highly regulated enterprises.</p><p>For the open-source community, the integration is completely free. JFrog is providing open-source NanoClaw users with complimentary access to safe, vetted sources of artifacts, tools, and skills. </p><p>This allows individual developers to run autonomous agents locally without drowning in manual approval requests for every single dependency. Furthermore, as community members build and share new "skills" for the agents, these contributions are uploaded to the registry, scanned for malicious code, and cleared before anyone else can use them. </p><p>This infrastructure directly neutralizes the threat of poisoned community repositories.</p><p>For enterprise deployments, the architecture plugs seamlessly into an organization's existing commercial environment. Rather than using the public open-source registry, corporate users point their NanoClaw agents to their own internal JFrog registries. </p><p>This ensures that all agent activity adheres to the company’s specific commercial licenses, internal security policies, visibility needs, and governance standards.</p><p>As AI continues to blur the line between human intent and machine execution, the infrastructure securing that execution must evolve. This partnership acknowledges a core reality: you cannot train an AI to perfectly recognize every zero-day vulnerability; instead, you must build an environment where the agent simply cannot reach the vulnerability in the first place.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[How Jeetu Patel made Cisco unrecognizable]]></title>
<description><![CDATA[Cisco Live 2026 is in the books, and it was “prove it” time for a promise made 24 months ago. At Cisco Live 2024, Chief Product Officer Jeetu Patel promised that Cisco would be unrecognizable as a company—in a positive way—in two years. The innovation payload at the event suggests he has largely ...]]></description>
<link>https://tsecurity.de/de/3593888/it-security-nachrichten/how-jeetu-patel-made-cisco-unrecognizable/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3593888/it-security-nachrichten/how-jeetu-patel-made-cisco-unrecognizable/</guid>
<pubDate>Fri, 12 Jun 2026 17:29:18 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p><a href="https://www.ciscolive.com/">Cisco Live 2026</a> is in the books, and it was “prove it” time for a promise made 24 months ago. At Cisco Live 2024, Chief Product Officer Jeetu Patel promised that <a href="https://www.cisco.com/">Cisco</a> would be unrecognizable as a company—in a positive way—in two years. The innovation payload at the event suggests he has largely delivered on that pledge. Cisco is repositioning itself from a holding company of products and dashboards to a unified, AI-native infrastructure platform, with Cloud Control as the control plane, Cisco IQ as the CX brain, and Secure Networking as the glue binding it all together.</p>



<p>The shift is not just about new features; it is about a new operating model. Instead of humans clicking through a sprawl of consoles, Cisco is building an environment where human operators and AI agents share the same data, context, and system of action, with humans staying in control. For longtime Cisco customers, the result is a company that, in fact, looks and feels very different from the one Patel inherited.</p>



<h2 class="wp-block-heading">From dashboard sprawl to Cloud Control</h2>



<p>The most visible proof point of the new Cisco is <a href="https://www.networkworld.com/article/4180810/what-is-cisco-cloud-control-and-why-should-customers-care.html">Cloud Control</a>, the unified management plane that now spans networking, security, compute, observability, collaboration, and an expanding ecosystem of third-party tools. Cisco is careful to note that this is not just another single pane of glass but an active execution environment with policy and identity embedded in the control path, designed from the ground up for humans and AI agents to operate infrastructure together.</p>



<p>Patel’s demo underscores how far Cisco has come from its historical dashboard sprawl. When operators land in Cloud Control, they see a familiar, ChatGPT‑style interface with three modes: Assistant, Canvas, and Actions. Assistant lets operators converse with the platform in natural language. Canvas provides a multiplayer workspace where humans and agents can investigate and resolve issues together. Actions become the mission control for supervising what agents propose and execute.</p>



<p>Crucially, Cloud Control surfaces shared platform services such as inventory and topology across the entire Cisco estate and exposes product tiles for Meraki, Intersight, security services, Splunk, Webex Control Hub, and Cisco IQ, all accessible with a single login. Instead of bouncing between multiple dashboards and authentication domains, operators can move seamlessly between platform services and product experiences within the same environment. For customers who have lived with overlapping portals and inconsistent workflows, this alone makes Cisco feel fundamentally different.</p>



<h2 class="wp-block-heading">Cloud Control as an AI harness, not a console</h2>



<p>Under the hood, Cloud Control is built on a shared data fabric that correlates telemetry across users, devices, applications, networks, and threats. That fabric fuels both human decision-making and agentic automation. Cisco describes this evolution as moving from “infrastructure as code” to “infrastructure as a harness.” Rather than relying solely on scripts and playbooks written by humans, Cloud Control becomes the governed substrate where AI agents can safely observe, reason, and act on real systems.</p>



<p>That harness appears in three visible dimensions. First, AI Canvas provides the workspace where humans and agents co-investigate incidents, with context persisting across shifts and escalations so nothing is lost. Second, Cloud Control Studio offers Agent Builder and App Builder, which let customers and partners build their own agents and applications on top of Cisco’s data, policy, and control plane using natural language and embedded coding assistants. Third, everything built in Studio—plus partner solutions—flows into the Cloud Control Marketplace, where integrations from dozens of ecosystem partners are already available.</p>



<p>For enterprises, the net effect is that Cloud Control shifts from a place to click through settings to the “secure harness” for agentic operations: a governed environment where AI agents can be deployed, monitored, constrained, and audited end-to-end. That is a very different proposition from the traditional network management console.</p>



<h2 class="wp-block-heading">CX and products finally share a brain</h2>



<p>Historically, <a href="https://www.cisco.com/site/us/en/services/support">Cisco’s Customer Experience (CX)</a> organization (services) and product groups have often felt like parallel universes. Services were layered on top of products rather than tightly integrated into how those products operated. Cisco IQ changes that dynamic by placing CX capabilities directly within the same Cloud Control environment where the products themselves live and by wiring CX workflows into the same telemetry and policy plane. This is notable as Cisco IQ isn’t yet another dashboard but an integrated part of Cloud Control.</p>



<p>Cisco IQ is positioned as the AI‑powered delivery vehicle for support and professional services. The goal is to give customers “complete landscape clarity,” proactive resilience, rapid resolution, and contextualized services. It runs as a SaaS platform, with an on‑premises deployment option for customers with strict data sovereignty requirements. By tapping the shared data fabric, Cisco IQ can inventory assets whether they are deployed or still in the warehouse, flag risks before customers experience issues, and benchmark an organization’s posture against anonymized peers by vertical, market segment or geography.</p>



<p>New capabilities, including Resilient Infrastructure Services and Quantum Ready Assessments, further underscore the integration of CX and product engineering. Resilient Infrastructure Services uses a three-step framework: Exposure Assessment, Infrastructure Modernization, and Defense Resiliency to help customers prepare for frontier-model threats. Quantum Ready Assessments, delivered through Cisco IQ, identify assets most exposed to “harvest now, decrypt later” attacks and map a path to quantum-safe infrastructure. Putting CX’s “brain” into Cloud Control and connecting it to the same data and AI models that drive operations is both a cultural and an architectural shift.</p>



<h2 class="wp-block-heading">Secure Networking as the integration proof point</h2>



<p>If you want a single domain that illustrates how integrated the new Cisco has become, look at Secure Networking. Cisco’s stated vision is to embed security directly into the fabric of the infrastructure, from silicon through the network to operations, rather than treating it as a separate stack. That strategy manifests in several concrete ways.</p>



<p>Live Protect, described internally as a “digital immune system,” applies precise compensating controls to Cisco products in production to protect them from newly discovered vulnerabilities at runtime. It does so without reboots, upgrades, or maintenance windows. The controls are narrowly targeted to avoid performance impact and minimize false positives. Live Protect is already shipping on Nexus 9000 switches and expanding across the portfolio, including campus switches, tightening the feedback loop between vulnerability discovery and mitigation from weeks to minutes.</p>



<p>Hybrid Mesh Firewall extends a unified security policy across networks, applications, and both Cisco and third-party firewalls, limiting the blast radius when something goes wrong. At the same time, Cisco is embedding post-quantum crypto libraries, secure boot, and trust anchors across its core portfolio, and has committed to enabling quantum-safe communications capabilities across most core products by December 2026. New enterprise and data center routers, switches, and firewall series are launching as “quantum-safe by default.”</p>



<p>All of this is orchestrated through Cloud Control, the security command center for a post-Mythos era, with Splunk providing the telemetry backbone and agentic SOC and SRE capabilities to detect, triage, and respond at machine speed. Secure Networking is no longer just about point firewalls and SD-WAN; it has become the spine that ties Cisco’s networking, security, observability, and AI assets into a coherent platform.</p>



<h2 class="wp-block-heading">Multicloud Fabric: networking as a service for AI</h2>



<p>Another hallmark of the new Cisco is a willingness to deliver networking as a managed fabric rather than a toolkit that customers must stitch together themselves. Multicloud Fabric, introduced as a network‑as‑a‑service offering delivered through Cloud Control, illustrates this shift.</p>



<p>Multicloud Fabric gives enterprises a single fabric for secure site-to-cloud and cloud-to-cloud networking, with Cisco operating virtual points of presence across major cloud providers and regions. Customers can onboard sites and cloud environments, define intent-based connectivity, attach security policies, and monitor performance “with one button” from Cloud Control, instead of building and maintaining their own hub-and-spoke architectures. Security and observability are built in—Zero Trust routing, cloud firewall service chaining, and ThousandEyes agents embedded in each point of presence—so the network is no longer a passive pipe but part of the AI intelligence stack.</p>



<p>This matters because AI-first applications increasingly chain inference across multiple clouds and data sources. Cisco’s own research shows that these agentic workflows can generate many times more network traffic than manual equivalents, with much of it being latency-sensitive inference. Multicloud Fabric, operated as a service and integrated into the same Cloud Control environment, is Cisco’s answer to this new reality.</p>



<h2 class="wp-block-heading">What this means for customers</h2>



<p>Cisco has spent four decades building category-leading products, from Meraki and Nexus to Webex and ThousandEyes. But the company’s biggest opportunity has always been in how those pieces work together. As Patel has said, tightly integrated and loosely coupled. Cloud Control, Cisco IQ, Multicloud Fabric, and Secure Networking suggest the product organization is finally closing that gap, turning dashboards into agentic workflows and discrete boxes into a secure harness for the AI era.</p>



<p>For customers, Cisco’s transformation matters because it changes the operating model, not just the product lineup. Cloud Control gives IT teams a single management plane across networking, security, observability, collaboration, and services, replacing the fragmented dashboard experience that has long complicated Cisco environments. That should make operations faster and simpler, but it also raises the bar for customers.</p>



<p>As Cisco pushes AgenticOps, AI Canvas, Live Protect, and Cisco IQ into the mainstream, IT teams will need to shift from manually managing tools to supervising agents, setting policy guardrails, and validating machine-speed actions. That shift will demand new skills in prompt design, policy modeling, risk scoring, and governance, especially as agents propose and test more changes before humans ever click “approve.”</p>



<p>It also means customers should view Cisco less as a best-of-breed product and more as an integrated platform. The more of the Cisco estate that is tied to Cloud Control, the more value customers should derive from shared telemetry, unified workflows, embedded security, and cross-domain automation—especially in areas like Secure Networking and multicloud operations. Conversely, customers that remain heavily heterogeneous will need clear integration strategies and governance models to ensure third-party tools plug safely into the harness.</p>



<p>Finally, this new Cisco has the potential to reduce one of the biggest pain points enterprise buyers have faced for years: complexity. If the company can deliver on its vision of one login, one view, tighter product integration, and CX services finally aligned with the product groups, customers may find that Cisco is not only unrecognizable in a positive way but also easier to buy, deploy, and operate than at any point in its history.</p>



<h3 class="wp-block-heading">Read more stories from Cisco Live 2026</h3>



<ul class="wp-block-list">
<li><a href="https://www.networkworld.com/article/4180842/cisco-sees-quantum-networking-as-the-future-of-networking.html">Cisco sees quantum networking as the future of networking</a></li>



<li><a href="https://www.networkworld.com/article/4180810/what-is-cisco-cloud-control-and-why-should-customers-care.html">What is Cisco Cloud Control and why should customers care?</a></li>



<li><a href="https://www.networkworld.com/article/4179942/cisco-live-the-network-is-back-and-ai-rewrote-the-rules.html">Cisco Live: The network is back, and AI rewrote the rules</a> </li>



<li><a href="https://www.networkworld.com/article/4179673/cisco-brings-agentic-ops-platform-and-security-overhaul-to-cisco-live.html">Cisco brings agentic ops platform and security overhaul to Cisco Live</a></li>



<li><a href="https://www.networkworld.com/article/4181727/how-cisco-it-cut-observability-costs-by-86-and-eliminated-major-network-outages.html">How Cisco IT cut observability costs by 86% and eliminated major network outages</a></li>
</ul>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Brain-inspired chip runs near absolute zero and could transform quantum computing]]></title>
<description><![CDATA[Scientists at the University of Hong Kong have created a remarkable new type of brain-inspired chip that can function just above absolute zero, one of the coldest environments imaginable. By using a standard silicon carbide transistor in a completely new…
Read more →
The post Brain-inspired chip ...]]></description>
<link>https://tsecurity.de/de/3593785/it-security-nachrichten/brain-inspired-chip-runs-near-absolute-zero-and-could-transform-quantum-computing/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3593785/it-security-nachrichten/brain-inspired-chip-runs-near-absolute-zero-and-could-transform-quantum-computing/</guid>
<pubDate>Fri, 12 Jun 2026 16:44:46 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Scientists at the University of Hong Kong have created a remarkable new type of brain-inspired chip that can function just above absolute zero, one of the coldest environments imaginable. By using a standard silicon carbide transistor in a completely new…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/brain-inspired-chip-runs-near-absolute-zero-and-could-transform-quantum-computing/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/brain-inspired-chip-runs-near-absolute-zero-and-could-transform-quantum-computing/">Brain-inspired chip runs near absolute zero and could transform quantum computing</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Brain-inspired chip runs near absolute zero and could transform quantum computing]]></title>
<description><![CDATA[Scientists at the University of Hong Kong have created a remarkable new type of brain-inspired chip that can function just above absolute zero, one of the coldest environments imaginable. By using a standard silicon carbide transistor in a completely new way, the team made a single device behave ...]]></description>
<link>https://tsecurity.de/de/3593666/ai-nachrichten/brain-inspired-chip-runs-near-absolute-zero-and-could-transform-quantum-computing/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3593666/ai-nachrichten/brain-inspired-chip-runs-near-absolute-zero-and-could-transform-quantum-computing/</guid>
<pubDate>Fri, 12 Jun 2026 16:05:20 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Scientists at the University of Hong Kong have created a remarkable new type of brain-inspired chip that can function just above absolute zero, one of the coldest environments imaginable. By using a standard silicon carbide transistor in a completely new way, the team made a single device behave like an energy-efficient neuron, firing electrical “spikes” similar to those in the human brain.]]></content:encoded>
</item>
<item>
<title><![CDATA[Scientists are working on headphones that block annoying noises and allow the ones you love? I can’t wait! | Emma Beddington]]></title>
<description><![CDATA[Imagine a world with more birdsong and less Nigel Farage. If this is the future, bring it onUnpopular opinion incoming: there’s cool stuff brewing in the world. Microbots might one day mend spinal cords, a petri dish of brain cells can already play video games, and now the prospect of a new wonde...]]></description>
<link>https://tsecurity.de/de/3593423/ai-nachrichten/scientists-are-working-on-headphones-that-block-annoying-noises-and-allow-the-ones-you-love-i-cant-wait-emma-beddington/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3593423/ai-nachrichten/scientists-are-working-on-headphones-that-block-annoying-noises-and-allow-the-ones-you-love-i-cant-wait-emma-beddington/</guid>
<pubDate>Fri, 12 Jun 2026 14:19:55 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Imagine a world with more birdsong and less Nigel Farage. If this is the future, bring it on</p><p>Unpopular opinion incoming: there’s cool stuff brewing in the world. <a href="https://www.nature.com/articles/s41563-026-02625-3">Microbots might one day mend spinal cords</a>, a <a href="https://www.theguardian.com/games/2026/mar/16/petri-dish-brain-cells-playing-doom-cortical-labs">petri dish of brain cells can already play video games</a>, and now the prospect of a new wonder: according to a <a href="https://www.newyorker.com/magazine/2026/06/15/for-people-with-misophonia-everyday-noises-can-be-agony">New Yorker article on misophonia</a> (<a href="https://www.theguardian.com/commentisfree/2025/may/30/misophonia-condition-disorder-noise-sound-triggers">the condition</a> where unwanted noise triggers disproportionate, unpleasant cognitive and physiological reactions), a team of miracle workers are “using machine learning to develop headphones that … can quickly target and eliminate irksome audio”.</p><p>Now we’re talking! This project, led by Shyam Gollakota of the University of Washington’s Mobile Intelligence Lab, aims to develop headphones that selectively filter out triggering noises, leaving or enhancing the good sounds. Gollakota offers the example of sitting on a park bench, oblivious to loud talkers next to you but able to hear birdsong.</p> <a href="https://www.theguardian.com/commentisfree/2026/jun/12/scientists-headphones-block-annoying-noises">Continue reading...</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[UK digital ID gets brain trust to ‘challenge’ ministers on policy]]></title>
<description><![CDATA[CEO of Mumsnet among the six-member team This article has been indexed from www.theregister.com – Articles Read the original article: UK digital ID gets brain trust to ‘challenge’ ministers on policy
Read more →
The post UK digital ID gets brain trust to ‘challenge’ ministers on policy appeared f...]]></description>
<link>https://tsecurity.de/de/3593163/it-security-nachrichten/uk-digital-id-gets-brain-trust-to-challenge-ministers-on-policy/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3593163/it-security-nachrichten/uk-digital-id-gets-brain-trust-to-challenge-ministers-on-policy/</guid>
<pubDate>Fri, 12 Jun 2026 12:36:10 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>CEO of Mumsnet among the six-member team This article has been indexed from www.theregister.com – Articles Read the original article: UK digital ID gets brain trust to ‘challenge’ ministers on policy</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/uk-digital-id-gets-brain-trust-to-challenge-ministers-on-policy/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/uk-digital-id-gets-brain-trust-to-challenge-ministers-on-policy/">UK digital ID gets brain trust to ‘challenge’ ministers on policy</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[UK digital ID gets brain trust to 'challenge' ministers on policy]]></title>
<description><![CDATA[CEO of Mumsnet among the six-member team]]></description>
<link>https://tsecurity.de/de/3593139/it-security-nachrichten/uk-digital-id-gets-brain-trust-to-challenge-ministers-on-policy/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3593139/it-security-nachrichten/uk-digital-id-gets-brain-trust-to-challenge-ministers-on-policy/</guid>
<pubDate>Fri, 12 Jun 2026 12:23:26 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[CEO of Mumsnet among the six-member team]]></content:encoded>
</item>
<item>
<title><![CDATA[Inside Interoception: The hidden sense of how you feel inside]]></title>
<description><![CDATA[MIT Technology Review Explains: Let our writers untangle the complex, messy world of science and technology to help you understand what’s coming next. You can read more from the series here. Your brain lives in the dark space of your skull. Yet it knows when the wind lifts the hairs on your skin,...]]></description>
<link>https://tsecurity.de/de/3592970/ai-nachrichten/inside-interoception-the-hidden-sense-of-how-you-feel-inside/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3592970/ai-nachrichten/inside-interoception-the-hidden-sense-of-how-you-feel-inside/</guid>
<pubDate>Fri, 12 Jun 2026 11:20:02 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[MIT Technology Review Explains: Let our writers untangle the complex, messy world of science and technology to help you understand what’s coming next. You can read more from the series here. Your brain lives in the dark space of your skull. Yet it knows when the wind lifts the hairs on your skin, when your heart is…]]></content:encoded>
</item>
<item>
<title><![CDATA[Inside Elon Musk’s AI Ecosystem: How xAI, Tesla, X, Neuralink, and SpaceX Are Converging]]></title>
<description><![CDATA[Elon Musk’s AI ecosystem spans xAI, Tesla, X, Neuralink, and SpaceX, connecting chatbots, robots, brain implants, and spacecraft.]]></description>
<link>https://tsecurity.de/de/3592041/it-nachrichten/inside-elon-musks-ai-ecosystem-how-xai-tesla-x-neuralink-and-spacex-are-converging/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3592041/it-nachrichten/inside-elon-musks-ai-ecosystem-how-xai-tesla-x-neuralink-and-spacex-are-converging/</guid>
<pubDate>Fri, 12 Jun 2026 01:17:33 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Elon Musk’s AI ecosystem spans xAI, Tesla, X, Neuralink, and SpaceX, connecting chatbots, robots, brain implants, and spacecraft.]]></content:encoded>
</item>
<item>
<title><![CDATA[Humans Prefer To Walk Anticlockwise, Scientists Find]]></title>
<description><![CDATA[fjo3 shares a report from The Guardian: Tests reveal that when people are ambling about, they have a natural tendency to turn to the left and walk in an anticlockwise direction. "If you simply ask someone to start walking, whether they are wandering around a museum, a supermarket, or even an empt...]]></description>
<link>https://tsecurity.de/de/3589713/it-security-nachrichten/humans-prefer-to-walk-anticlockwise-scientists-find/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3589713/it-security-nachrichten/humans-prefer-to-walk-anticlockwise-scientists-find/</guid>
<pubDate>Thu, 11 Jun 2026 09:09:32 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[fjo3 shares a report from The Guardian: Tests reveal that when people are ambling about, they have a natural tendency to turn to the left and walk in an anticlockwise direction. "If you simply ask someone to start walking, whether they are wandering around a museum, a supermarket, or even an empty room, it is surprisingly likely that they will drift counterclockwise," said Dr Inaki Echeverria Huarte at University of Navarra in Spain.
 
As with many critical discoveries in science, the revelation owes a debt to serendipity. During the pandemic, the researchers ran experiments to see how many people could share a space while keeping a safe distance. On reviewing the video, they noticed that crowds overwhelmingly walked in an anticlockwise direction. The surprise set in motion an entire research project. The scientists conducted a series of experiments in which individual pedestrians or small crowds roamed around enclosed spaces. Time and again, the researchers observed the tendency to walk in an anticlockwise direction.
 
Suspecting that cultural norms might play a role, the team joined forces with Dr Claudio Feliciani at the University of Tokyo. He found the same results in Japan. The finding held when the researchers accounted for people being right-handed, right-footed and right-eye dominant, and was seen in both male and female walkers. The only difference they spotted was a more pronounced bias in children. "Each of us carries a small personal bias to turn slightly to one side, and when many people share a space, those tiny biases add up into a net counterclockwise rotation," said Echeverria Huarte. Researchers think the tendency may be tied to biomechanics: people are not perfectly symmetrical, and the way the brain processes sensory information and coordinates muscles may gently tip walkers toward one side. Right-side dominance may also play a role, especially in running, where anticlockwise movement puts more internal force on the right side of the body and may feel more natural to right-leg-dominant athletes.
 
"We have tested several ideas and the bias stubbornly keeps showing up, so the exact mechanism is still an open question," said Echeverria Huarte.
 
The findings have been published in Nature Communications.<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=Humans+Prefer+To+Walk+Anticlockwise%2C+Scientists+Find%3A+https%3A%2F%2Fscience.slashdot.org%2Fstory%2F26%2F06%2F10%2F2040212%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fscience.slashdot.org%2Fstory%2F26%2F06%2F10%2F2040212%2Fhumans-prefer-to-walk-anticlockwise-scientists-find%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://science.slashdot.org/story/26/06/10/2040212/humans-prefer-to-walk-anticlockwise-scientists-find?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Smashing Security podcast #471: This AI worm just rewrote its own rules]]></title>
<description><![CDATA[Researchers at the University of Toronto have built a worm that thinks for itself. Using free off-the-shelf AI models it works out how to break into each new computer it encounters, and hijacks the powerful ones to host its own AI brain. And then the researchers discovered their creation had quie...]]></description>
<link>https://tsecurity.de/de/3589176/it-security-nachrichten/smashing-security-podcast-471-this-ai-worm-just-rewrote-its-own-rules/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3589176/it-security-nachrichten/smashing-security-podcast-471-this-ai-worm-just-rewrote-its-own-rules/</guid>
<pubDate>Thu, 11 Jun 2026 01:38:29 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Researchers at the University of Toronto have built a worm that thinks for itself. Using free off-the-shelf AI models it works out how to break into each new computer it encounters, and hijacks the powerful ones to host its own AI brain. And then the researchers discovered their creation had quietly removed the list of machines it wasn't supposed to attack.

Meanwhile, Meta's shiny new AI customer support agent has been cheerfully helping hackers help themselves to other people's Instagram accounts. Just keep asking, politely but firmly, to have a password reset sent to a different email address - and the AI will eventually agree.

All this and more in episode 471 of the "Smashing Security" podcast with cybersecurity expert and keynote speaker Graham Cluley, and special guest James Ball.]]></content:encoded>
</item>
<item>
<title><![CDATA[Surprise upset: GPT-5.5 beats Claude Fable 5 on brutal new Agents’ Last Exam benchmark]]></title>
<description><![CDATA[Researchers from the University of California, Berkeley's Center for Responsible, Decentralized Intelligence (RDI), alongside an advisory committee of over 300 domain experts, have launched Agents’ Last Exam (ALE)—a grueling new benchmark built to measure whether artificial intelligence can actua...]]></description>
<link>https://tsecurity.de/de/3589172/it-nachrichten/surprise-upset-gpt-55-beats-claude-fable-5-on-brutal-new-agents-last-exam-benchmark/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3589172/it-nachrichten/surprise-upset-gpt-55-beats-claude-fable-5-on-brutal-new-agents-last-exam-benchmark/</guid>
<pubDate>Thu, 11 Jun 2026 01:32:51 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Researchers from the University of California, Berkeley's Center for Responsible, Decentralized Intelligence (RDI), alongside an advisory committee of over 300 domain experts, have <a href="https://agents-last-exam.org/">launched Agents’ Last Exam (ALE)</a>—a grueling new benchmark built to measure whether artificial intelligence can actually execute economically valuable, long-horizon professional workflows.</p><p>In a shocking upset,<a href="https://venturebeat.com/ai/openais-gpt-5-5-is-here-and-its-no-potato-narrowly-beats-anthropics-claude-mythos-preview-on-terminal-bench-2-0"> OpenAI’s GPT-5.5 from April,</a> operating through the Codex harness, secured the absolute top spot on the new <a href="https://agents-last-exam.org/leaderboard">ALE Leaderboard</a> with a 24.0% pass rate, beating Anthropic's highly anticipated, brand new <a href="https://venturebeat.com/technology/anthropic-brings-mythos-to-the-masses-with-claude-fable-5-its-most-powerful-generally-available-model-ever">Mythos-class Claude Fable 5 model</a> released just yesterday, which came in third with a score of 22.0%.</p><p>Rather than testing models on isolated coding puzzles, ALE is explicitly designed as an instrument to close the gap between academic benchmark hype and real, GDP-relevant labor impact. And right now, the data proves the most advanced models in the world are fundamentally failing the exam.</p><h2><b>Ending the Era of 'Cheating' and Brittle Graders</b></h2><p>The fundamental shift in ALE lies in its evaluation architecture and the demands it places on the agent. </p><p>Historically, AI benchmarks have relied on static question-answering or narrow, text-based terminal environments. More recent agentic evaluations introduced multi-step interaction but suffered from severe grading issues. </p><p>As noted in recent independent audits of older leaderboards like SWE-Bench Pro, automated verifiers frequently reject correct solutions, and certain models—specifically the Claude Opus family—have been caught "cheating" by reading hidden answer keys in a container's Git history rather than solving the underlying problem.</p><p>ALE neutralizes these loopholes by forcing models into a strict Generalist Computer-Use Agent (GCUA) framework. To pass, an agent cannot merely execute terminal commands. </p><p>The benchmark maps capability across five functional layers: Brain (reasoning), Eyes (visual perception), Body (orchestration), Hands (tool invocation), and Feet (runtime substrate).</p><p>An agent must use its "Eyes" and "Hands" to navigate Linux or Windows virtual machines, interleaving shell scripting with point-and-click operations inside heavy desktop software.</p><p>Crucially, ALE almost entirely rejects the unpredictable "LLM-as-a-judge" grading paradigm, relying on it for a mere 6.8% of its workflows. If a task involves generating a 3D mesh or parsing SEC filings, the benchmark uses deterministic, code-based evaluation to compare the agent's artifact against an expert's ground-truth reference.</p><h2><b>Measuring Task Performance Across 55 Industries</b></h2><p>ALE launches with 1,490 task instances and is scaling toward a massive 5,000-task target. What makes the product remarkable is its authenticity. The tasks are strictly anchored in the <a href="https://www.onetcenter.org/taxonomy.html">U.S. federal occupational taxonomy (O*NET / SOC 2018)</a>, covering 55 non-physical industry sub-domains.</p><p>The workflows are sourced directly from the professional histories of industry practitioners. Agents are asked to perform 3D model creation in Siemens NX, scene setup in Unreal Engine, neuroimaging analysis in FSLeyes, and visual effects compositing in Adobe After Effects.</p><p>When faced with these authentic, long-horizon workflows, the limitations of current AI are glaring. ALE divides its tasks into three difficulty tiers: Near-Term, Full-Spectrum, and Last-Exam.</p><h2><b>Top 5 Agentic Harnesses on the ALE Leaderboard</b></h2><table><tbody><tr><td><p><b>Rank</b></p></td><td><p><b>Agent Harness</b></p></td><td><p><b>Underlying Model</b></p></td><td><p><b>Pass Rate</b></p></td><td><p><b>Mean Score</b></p></td></tr><tr><td><p><b>1</b></p></td><td><p>Codex</p></td><td><p>gpt-5-5</p></td><td><p><b>24.0%</b></p></td><td><p>42.8%</p></td></tr><tr><td><p><b>2</b></p></td><td><p>Ale Claw</p></td><td><p>gpt-5-5</p></td><td><p><b>23.0%</b></p></td><td><p>45.8%</p></td></tr><tr><td><p><b>3</b></p></td><td><p>Claude Code</p></td><td><p>claude-fable-5</p></td><td><p><b>22.0%</b></p></td><td><p>40.5%</p></td></tr><tr><td><p><b>4</b></p></td><td><p>OpenClaw</p></td><td><p>gpt-5-5</p></td><td><p><b>21.1%</b></p></td><td><p>41.0%</p></td></tr><tr><td><p><b>5</b></p></td><td><p>Cursor CLI</p></td><td><p>composer-2-5</p></td><td><p><b>20.4%</b></p></td><td><p>38.5%</p></td></tr></tbody></table><p>The victory of GPT-5.5 aligns with recent third-party analysis suggesting that OpenAI's models are currently superior at strictly adhering to multi-part, complex prompts. Conversely, users report Anthropic's Claude architecture can sometimes be "forgetful" with multi-part instructions, abandoning required steps mid-workflow — a fatal flaw in ALE's rigorous pipeline.</p><p>And while hitting a 24.0% pass rate is enough to claim the crown, the absolute performance ceiling remains remarkably low. </p><p>On the hardest "Last-Exam" tier — representing the frontier of professional difficulty — most configurations, including Anthropic's older Claude Opus 4.8 and Google's Gemini CLI, record a devastating 0.0% pass rate.</p><h2><b>Solving Benchmark Contamination</b></h2><p>A core vulnerability in modern AI evaluation is "benchmark contamination"—the phenomenon where test questions inevitably leak into the massive data lakes used to train next-generation models. Once a model memorizes the benchmark, the evaluation becomes entirely useless.</p><p>ALE solves this through a dual-use deployment strategy. The project operates as an open-source research initiative, but it closely guards its evaluation data.<b> Only about 10% of the dataset (roughly 150 tasks) is released publicly</b> on platforms like GitHub and Hugging Face. The remaining 1,300+ tasks are kept strictly private.</p><p>For developers and enterprise evaluators, this means ALE functions as a "living benchmark". Private tasks are systematically rotated into the public pool over time, while retired public tasks are swapped out. </p><p>This rolling release ensures that the evaluation surface remains uncontaminated across successive model generations, giving enterprise buyers confidence that an agent's high score is <i>earned</i>, not memorized.</p><p>Additionally, ALE provides transparency by tracking both "Full" and "Unlicensed" scores. Because real professional work often requires paid, proprietary software, the "Full" leaderboard incorporates tasks that rely on commercial CAD tools, paid APIs, or licensed datasets. </p><p>The "Unlicensed" tier drops these license-gated tasks to provide a clean, like-for-like comparison using only freely available tools, ensuring models aren't simply rewarded for having access to paid enterprise software.</p><h2><b>Bottom Line: ALE Shows Even the Highest-Performing Models and Harnesses Have Room for Improvement</b></h2><p>For developers frustrated by the gap between marketing claims and actual production performance, ALE's brutal grading curve is highly validating.

<a href="https://x.com/qinzytech/status/2064407279898952092?s=20">Zengyi Qin</a>, an MIT PhD researcher and data contributor to the project, took to X to announce the launch, sharing images of the paper and the staggering 100+ institution contributor list.</p><blockquote><p>"Introducing Agents’ Last Exam (ALE)," Qin wrote. "Built by 300+ domain experts from 100+ institutions. Covering 55 industry domains. Claude Opus 4.8 has 0.0% pass rate on the hardest subset. Glad to have contributed to this benchmark".</p></blockquote><p>In a follow-up post highlighting the Hugging Face ArXiv paper link, Qin added:</p><blockquote><p>"Very solid work from project leads @YiyouSun @Xinyang_Han_ @dawnsongtweets and @BerkeleyRDI".</p></blockquote><p>As businesses deploy billions in capital betting on AI agents, they desperately need a compass that points true north. If an agent can eventually conquer the gauntlet of Agents' Last Exam, it won't just be passing a test—it will be proving it is ready to join the workforce. Until then, the sobering pass rates on the leaderboard serve as a necessary reality check for the entire AI ecosystem.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[The Art of the Badge: A Hard Truth About Physical Security]]></title>
<description><![CDATA[He walked into the lobby with a fake badge clipped to his shirt. He had bought it online the week before. It was not perfect, and it did not need to be. From a few feet away, it looked close enough: a logo, a name, a photo, and a lanyard. The kind of thing most people glance at for half a second ...]]></description>
<link>https://tsecurity.de/de/3587917/it-security-nachrichten/the-art-of-the-badge-a-hard-truth-about-physical-security/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3587917/it-security-nachrichten/the-art-of-the-badge-a-hard-truth-about-physical-security/</guid>
<pubDate>Wed, 10 Jun 2026 16:29:50 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1280" height="720" src="https://www.blackhillsinfosec.com/wp-content/uploads/2026/06/badge_header.png" class="attachment-full size-full wp-post-image" alt="" decoding="async" fetchpriority="high" srcset="https://www.blackhillsinfosec.com/wp-content/uploads/2026/06/badge_header.png 1280w, https://www.blackhillsinfosec.com/wp-content/uploads/2026/06/badge_header-500x281.png 500w, https://www.blackhillsinfosec.com/wp-content/uploads/2026/06/badge_header-1024x576.png 1024w, https://www.blackhillsinfosec.com/wp-content/uploads/2026/06/badge_header-768x432.png 768w" sizes="(max-width: 1280px) 100vw, 1280px"></p>
<p>He walked into the lobby with a fake badge clipped to his shirt. He had bought it online the week before. It was not perfect, and it did not need to be. From a few feet away, it looked close enough: a logo, a name, a photo, and a lanyard. The kind of thing most people glance at for half a second before their brain decides, “Looks fine.”</p>
<p>The post <a href="https://www.blackhillsinfosec.com/the-art-of-the-badge/">The Art of the Badge: A Hard Truth About Physical Security</a> appeared first on <a href="https://www.blackhillsinfosec.com/">Black Hills Information Security, Inc.</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[A classic brain test exposed AI's biggest weakness]]></title>
<description><![CDATA[Researchers gave top AI models a classic attention test used in psychology and found a major flaw. While the models could correctly name colors in short lists, their performance deteriorated sharply as the task became longer and more complex. Some leading systems fell from over 90% accuracy to ne...]]></description>
<link>https://tsecurity.de/de/3587547/ai-nachrichten/a-classic-brain-test-exposed-ais-biggest-weakness/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3587547/ai-nachrichten/a-classic-brain-test-exposed-ais-biggest-weakness/</guid>
<pubDate>Wed, 10 Jun 2026 14:05:54 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Researchers gave top AI models a classic attention test used in psychology and found a major flaw. While the models could correctly name colors in short lists, their performance deteriorated sharply as the task became longer and more complex. Some leading systems fell from over 90% accuracy to nearly complete failure.]]></content:encoded>
</item>
<item>
<title><![CDATA[New AI Brain KILLS Robot Programming? (80% FASTER TECH)]]></title>
<description><![CDATA[Author: AI News - Bewertung: 0x - Views:1 Bring brains to your bots: https://www.xaba.ai/

What if a new AI brain could completely eliminate traditional robot programming? In this episode of AI News, we break down Zaba’s revolutionary physics-based AI that is changing industrial automation foreve...]]></description>
<link>https://tsecurity.de/de/3584034/it-security-video/new-ai-brain-kills-robot-programming-80-faster-tech/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3584034/it-security-video/new-ai-brain-kills-robot-programming-80-faster-tech/</guid>
<pubDate>Tue, 09 Jun 2026 11:48:17 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: AI News - Bewertung: 0x - Views:1 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/M4yCjBssXq0?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>Bring brains to your bots: https://www.xaba.ai/<br />
<br />
What if a new AI brain could completely eliminate traditional robot programming? In this episode of AI News, we break down Zaba’s revolutionary physics-based AI that is changing industrial automation forever. Traditional robotics hardware isn't the real expense—75% of manufacturing costs actually come from constant programming and manual retuning.<br />
<br />
Zaba’s Xcognition physics engine fixes this by embedding a synthetic brain directly into machines, delivering 80% faster tech deployment. We dive into 5 engineering breakthroughs disrupting the robotics industry, including scalable high-mix automation, autonomous parameter control, and legacy robot repurposing without new hardware.<br />
<br />
See how real-time physics modeling allows robots to adapt to new specifications in a single day, eliminating static code. With production-validated results alongside global manufacturers like Hitachi, this autonomous AI is redefining the future of artificial intelligence in industry.<br />
<br />
#AI #Robotics #XabaAI<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Neue Berufskrankheit? Wie intensive KI-Nutzung die mentale Gesundheit belastet]]></title>
<description><![CDATA[Mentaler Nebel, ein summendes Gefühl im Kopf, Entscheidungsschwierigkeiten: Davon berichten Mitarbeitende, die durch intensive KI-Nutzung unter „AI Brain Fryweiterlesen auf t3n.de]]></description>
<link>https://tsecurity.de/de/3583809/it-nachrichten/neue-berufskrankheit-wie-intensive-ki-nutzung-die-mentale-gesundheit-belastet/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3583809/it-nachrichten/neue-berufskrankheit-wie-intensive-ki-nutzung-die-mentale-gesundheit-belastet/</guid>
<pubDate>Tue, 09 Jun 2026 10:17:17 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Mentaler Nebel, ein summendes Gefühl im Kopf, Entscheidungsschwierigkeiten: Davon berichten Mitarbeitende, die durch intensive KI-Nutzung unter „AI Brain Fry<a href="https://t3n.de/news/neue-berufskrankheit-wie-intensive-ki-nutzung-die-mentale-gesundheit-belastet-1744069/?utm_source=rss&amp;utm_medium=newsFeed&amp;utm_campaign=newsFeed">weiterlesen auf t3n.de</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[The New Siri: Everything Apple Announced About Its Gemini-Powered Assistant]]></title>
<description><![CDATA[Apple recently unveiled a massive upgrade to its famous voice assistant during the Worldwide Developers Conference. The tech giant is changing the name of its software to Siri AI, marking the biggest shift for the product since it originally launched. By teaming up with Google to use its powerful...]]></description>
<link>https://tsecurity.de/de/3583284/ios-mac-os/the-new-siri-everything-apple-announced-about-its-gemini-powered-assistant/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3583284/ios-mac-os/the-new-siri-everything-apple-announced-about-its-gemini-powered-assistant/</guid>
<pubDate>Tue, 09 Jun 2026 03:23:06 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Apple recently unveiled a massive upgrade to its famous voice assistant during the Worldwide Developers Conference. The tech giant is changing the name of its software to Siri AI, marking the biggest shift for the product since it originally launched. By teaming up with Google to use its powerful Gemini models, the company has created an assistant that understands real conversations and deep personal context. 



Here's how Apple is bringing a smarter, much more capable helper to your favorite devices across the USA and beyond this fall.



The voice helper finally gets a dedicated home screen application



Until now, the voice helper lived mostly as a pop-up window on your screen. That changes with this major update, as the manufacturer created a brand new application just for Siri. Users can open this app to scroll through previous requests and revisit their chat history easily.



This conversation history is saved privately to iCloud. This means you can start a chat on a Mac and finish it later on an iPhone or Apple Watch. You do not have to speak out loud either. The new interface allows you to type your questions directly, making it much easier to use the software in quiet places.



The software finally understands what is showing on your screen



One of the most impressive additions is onscreen awareness. The assistant now tracks what you are actively looking at and can answer questions related to that specific content.



If a friend messages you about a potluck dinner, you can ask the helper to find recipe ideas based on that specific text. It can then take those ideas and save them straight to your Notes app without making you jump between different windows. This level of deep integration shows how artificial intelligence works quietly in the background to handle tasks across multiple apps naturally.



The system uses personal context to find your hidden information



The upgraded software acts like a highly organized personal secretary. It looks securely through your messages, emails, and photos to pull up specific details when you need them.



For example, you can ask it to locate an old hotel booking confirmation buried deep in an inbox. You can also ask it to find certain photos from a recent family trip and instantly share them with a contact. Because it remembers the context of the conversation, you can ask follow-up questions without having to repeat the original topic.



Google brings complex reasoning models to power the new brain



To make all these advanced features work, the iPhone maker partnered directly with Google. The new system runs on the Gemini family of foundation models to handle complex requests and broad world knowledge.



This means the digital helper can easily answer difficult questions from the web and generate helpful responses. As the landscape of AI grows, the company is using a mix of on-device processing and Private Cloud Compute to keep user data completely private while still delivering top performance. You can read a complete breakdown of how Apple calls its new assistant Siri AI to understand the partnership details.



By completely rebuilding its digital helper from the ground up, the company is finally delivering the smart conversational partner it promised years ago. The days of rigid commands and web search errors are ending. With the power of Gemini inside, the assistant is ready to help you manage your digital life with genuine ease.]]></content:encoded>
</item>
<item>
<title><![CDATA[Jeff Bezos Is Funding a Wild Hunt for the Brain's 'Core Algorithm']]></title>
<description><![CDATA[Jeff Bezos is backing Flourish, a new "neuro AI" startup with $500 million in funding and a reported $2.5 billion valuation, that aims to reinvent AI by studying the brain's architecture and building systems that learn continuously while using far less power than today's large language models. Th...]]></description>
<link>https://tsecurity.de/de/3581843/it-security-nachrichten/jeff-bezos-is-funding-a-wild-hunt-for-the-brains-core-algorithm/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3581843/it-security-nachrichten/jeff-bezos-is-funding-a-wild-hunt-for-the-brains-core-algorithm/</guid>
<pubDate>Mon, 08 Jun 2026 17:07:13 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Jeff Bezos is backing Flourish, a new "neuro AI" startup with $500 million in funding and a reported $2.5 billion valuation, that aims to reinvent AI by studying the brain's architecture and building systems that learn continuously while using far less power than today's large language models. The company's long-term bet is that neuroscientists and AI researchers working together can uncover the brain's "core algorithm" and eventually create brain-inspired AI that runs on a tiny fraction of current compute. Wired reports: Rob Williams knows how to pitch Jeff Bezos: You write a press release as if your product has already been built. Bezos reads it and gives a thumbs up or down. Williams went through this process a lot as an executive on Amazon's "S-team," in charge of software products such as Alexa, until his departure last fall. But the pitch he made a few weeks later -- in December 2025 -- was different. Now he was collaborating with Thomas Reardon, a neuroscientist and repeat startup founder, and approaching Bezos as a funder, not a boss. Here's what Bezos, sitting on his yacht somewhere, read while Williams anxiously watched on Zoom: "Flourish is a neuro AI company that is solving the two most difficult problems facing AI today: power efficiency and continuous learning. We are building Cortex AI, the first synthetic intelligence system designed to match the computational capacity, learning efficiency, and power budget of the human brain."
 
A month later, I'm lunching with Reardon and Williams in the Flatiron neighborhood in New York City. Reardon gets right to the point. AI has dug itself into a hole, he says. Though increasingly powerful, large language models are greedy consumers of computer power and data. Though the inspiration for LLMs was rooted in biology, current frontier models have little in common with the human brain. A person uses about 20 watts of energy to process information; a single chip in an AI training cluster uses more than 30 times that amount. The hyperscalers require thousands of chips and gigawatts of energy, enough to power small cities. And those models need to suck up virtually all of what humans have written. Each new model requires more, more, more. For all of that, the models don't learn. Once you train them, they're stuck. The goal, Reardon tells me, is to build "a synthetic artificial intelligence brain that runs on 50 watts or less." It should adapt to its conditions, be as nimble as a human mind, and burn a tiny fraction of an LLM's compute power and energy. The proof of concept is thriving inside our skulls. "There's something fundamentally wrong with saying, "I need to basically read every book ever written 20 times over in order to learn English,'" Reardon says. "A human baby does it with a couple hundred thousand utterances."
 
Reardon and Williams haven't figured out yet how to build systems that match the magic of a human brain. What they have is a belief that an expert, well-resourced team -- of AI researchers and neuroscientists working essentially side by side -- can find the answer. The neuroscientists will conduct original wet lab experiments with some of the most advanced lab equipment available, to hunt for usable intel on the brain's architecture. They plan to release the models they're currently developing as near-term products on the path to a full reinvention of AI. The fuzziness of the proposal didn't bother Jeff Bezos. After reading Williams' two-pager, he chipped in $50 million. Other funding came from Lux Capital, Google Ventures, and Catalio, among others. Bezos then almost doubled his initial stake and told Reardon he'd have given more if they'd asked. Now with a war chest of $500 million and a reported valuation of $2.5 billion, Flourish just needs to invent a new way to do AI.<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=Jeff+Bezos+Is+Funding+a+Wild+Hunt+for+the+Brain's+'Core+Algorithm'%3A+https%3A%2F%2Fscience.slashdot.org%2Fstory%2F26%2F06%2F08%2F0418226%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fscience.slashdot.org%2Fstory%2F26%2F06%2F08%2F0418226%2Fjeff-bezos-is-funding-a-wild-hunt-for-the-brains-core-algorithm%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://science.slashdot.org/story/26/06/08/0418226/jeff-bezos-is-funding-a-wild-hunt-for-the-brains-core-algorithm?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Windows user for years, decided to try Linux(CachyOS) for the first time, mixed feelings.]]></title>
<description><![CDATA[I work in IT support. I've configured over 400 computers running Windows across different environments. My honest take on Windows: if you have three functioning brain cells and can install drivers, it just works. I've had minimal issues. I'm not a Windows fanboy, I'm just someone who values thing...]]></description>
<link>https://tsecurity.de/de/3577022/linux-tipps/windows-user-for-years-decided-to-try-linuxcachyos-for-the-first-time-mixed-feelings/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3577022/linux-tipps/windows-user-for-years-decided-to-try-linuxcachyos-for-the-first-time-mixed-feelings/</guid>
<pubDate>Sat, 06 Jun 2026 05:37:59 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>I work in IT support. I've configured over 400 computers running Windows across different environments. My honest take on Windows: if you have three functioning brain cells and can install drivers, it just works. I've had minimal issues. I'm not a Windows fanboy, I'm just someone who values things that work without friction.</p> <p>That said, I wanted to give Linux a real shot. I picked CachyOS because of the performance focus and KDE. Here's what happened.</p> <p>The bad (and it's real)...</p> <p>Getting it to boot was a nightmare. BalenaEtcher bricked my USB on first try, switched to Rufus. Then CachyOS flat out refused to boot on my Acer 515-54 (backup device). Tried disabling Secure Boot, changing partition tables, enabling AHCI mode, nothing. Eventually found a niche forum post with a specific command that fixed it. It worked, but that should NOT be the onboarding experience.</p> <p>Bluetooth audio is painful. My Anker headphones sound genuinely bad on Linux. I understand it's a codec issue with HiRes audio, but features like ANC and HiFi mode are just broken. On Windows they work out of the box. This alone is a dealbreaker for daily use or any noob user.</p> <p>Now...</p> <p>I support piracy. </p> <p>Stremio with Real-Debrid was a headache. Add-ons wouldn't install via the desktop app at all, had to use the web version. And then Stremio refused to play audio entirely. Took a good chunk of terminal commands to fix it.</p> <p>On Windows: installed it, opened it, it worked.</p> <p>Gaming is where it really falls apart for me. Soulframe, Ride 5/6, significantly worse than on Windows and also tried star wars fallen order an it didn't open at all. Some other games require setting up Bottles with what feels like a PhD's worth of parameters, just for the game to crash 15 minutes in. The frustrating part? When everything runs, the performance gap is actually small, like 4-5 FPS difference. That's fine. But the setup tax is not.</p> <p>Also, can we stop pretending Windows 11 is unusable? A simple debloat script from GitHub and it runs beautifully lean. My secondary laptop has a GTX 1650 and it handles plenty of games without breaking a sweat. The "Windows is bloated" argument feels outdated if you actually know what you're doing with it.</p> <p>The community in other subreddits was rough. I asked how to install Office 365 on Linux and got buried in responses telling me to use LibreOffice/only office and that I should "ditch Microslop" I just needed Office. For advanced data analysis and complex spreadsheets, the open source alternatives genuinely fall short, that's not an opinion, that's a workflow reality. Same story with the Adobe suite. I wasn't asking for a philosophy debate or a 5 hour guide to get my adobe to work. </p> <p>The good (and it's actually good!)</p> <p>The system feels cleaner and more fluid. Hard to quantify, but it's noticeable.</p> <p>Customization is genuinely excellent. I've always put effort into making Windows look good, but CachyOS/KDE let me go much further in a very satisfying way.</p> <p>Battery life doubled. Not a slight improvement, doubled. That alone is remarkable.</p> <p>Performance doesn't tank when unplugged. On Windows I need to stay plugged in for stable performance. On CachyOS, battery mode barely changed anything. That's impressive.</p> <p>More granular system control. I can tweak things at a level Windows doesn't expose, and it feels good to have that kind of access.</p> <p>Final verdict</p> <p>I'll probably keep Linux on this backup device for indie gaming and on the side for specific use cases, the battery life and unplugged performance are too good to ignore entirely.</p> <p>No hate. Just an honest assessment from someone who actually tried.</p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/Honest_Tart1071"> /u/Honest_Tart1071 </a> <br> <span><a href="https://www.reddit.com/r/linux/comments/1ty6446/windows_user_for_years_decided_to_try/">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/1ty6446/windows_user_for_years_decided_to_try/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[We’re forgetting the most critical system in the AI loop: the human brain]]></title>
<description><![CDATA[The question I am asked most frequently today is no longer “which AI tools should we deploy?” but “why are our people not performing at the level our technology investment should be enabling?”



The numbers tell a story that should concern every C-suite leader and CIO investing in artificial int...]]></description>
<link>https://tsecurity.de/de/3574991/it-security-nachrichten/were-forgetting-the-most-critical-system-in-the-ai-loop-the-human-brain/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3574991/it-security-nachrichten/were-forgetting-the-most-critical-system-in-the-ai-loop-the-human-brain/</guid>
<pubDate>Fri, 05 Jun 2026 12:08:19 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>The question I am asked most frequently today is no longer “which AI tools should we deploy?” but “why are our people not performing at the level our technology investment should be enabling?”</p>



<p>The numbers tell a story that should concern every C-suite leader and CIO investing in artificial intelligence right now. According to a<a href="https://thefinancialbrand.com/news/artificial-intelligence-banking/why-95-of-enterprises-are-getting-zero-return-on-ai-investment-191950" rel="nofollow"> </a><a href="https://thefinancialbrand.com/news/artificial-intelligence-banking/why-95-of-enterprises-are-getting-zero-return-on-ai-investment-191950" rel="nofollow">2025 MIT study</a>, 95% of enterprise AI pilot programs are failing to deliver measurable financial returns.<a href="https://www.bcg.com/press/24october2024-ai-adoption-in-2024-74-of-companies-struggle-to-achieve-and-scale-value" rel="nofollow"> </a><a href="https://www.bcg.com/press/24october2024-ai-adoption-in-2024-74-of-companies-struggle-to-achieve-and-scale-value" rel="nofollow">BCG research</a> puts it plainly: 74% of companies struggle to achieve and scale value from AI. And yet, as an<a href="https://www.itpro.com/business/business-strategy/ai-adoption-projects-keep-failing-but-enterprise-fomo-means-investment-is-still-rising" rel="nofollow"> </a><a href="https://www.itpro.com/business/business-strategy/ai-adoption-projects-keep-failing-but-enterprise-fomo-means-investment-is-still-rising" rel="nofollow">Orgvue analysis from 2026</a> reveals, 57% of organizations deploying AI are doing so primarily because their competitors are, not because they have a strategy.</p>



<p>Read that again. More than half of the organizations racing to deploy AI are running a technology adoption program without a clear reason for it. That is not transformation. That is theater.</p>



<p>Investment is accelerating regardless.<a href="https://www.deloitte.com/nl/en/issues/generative-ai/ai-roi-the-paradox-of-rising-investment-and-elusive-returns.html" rel="nofollow"> </a><a href="https://www.deloitte.com/nl/en/issues/generative-ai/ai-roi-the-paradox-of-rising-investment-and-elusive-returns.html" rel="nofollow">Deloitte’s 2025 survey</a> of over 1,800 senior executives found that 85% of organizations increased AI investment in the past year, and 91% plan to increase it again. Meanwhile, only 6% of those organizations qualify as genuine high performers, those seeing a 5% or more impact on earnings. The gap between what organizations is spending and what they are getting back is not a technology problem. It never was.</p>



<h2 class="wp-block-heading">The real reason AI initiatives are underperforming</h2>



<p>The most forward-thinking technology leaders I’ve encountered have already made this shift. They understand that the most significant risk to their technology investment is not a system failure. It’s a human one. AI amplifies what already exists in an organization. If the underlying human system is undisciplined, reactive or misaligned, AI will accelerate those same weaknesses.</p>



<p>I’ve seen this pattern repeat consistently. Companies make significant capital investments into AI infrastructure, but invest almost nothing in redesigning how people work, make decisions or learn from failure. The result is sophisticated capabilities layered on top of outdated operating models, broken decision-making cultures and teams that have never been taught to think critically about outputs.</p>



<p>Three human behaviors, in particular, derail good technology more than any other.</p>



<p>The first is confirmation bias. People use AI to validate what they already believe rather than to genuinely challenge their assumptions. The model becomes a sophisticated mirror rather than a thinking partner.</p>



<p>The second is risk aversion disguised as due diligence. Organizations create endless review cycles and approval layers that slow execution to the point where the insight the AI generated is no longer relevant by the time a decision is made.</p>



<p>The third, and perhaps the most damaging, is the absence of a failure-forward learning culture. AI systems improve through iteration and feedback. But many organizations still treat failure as something to be managed politically rather than mined for intelligence. When people are incentivized to hide errors rather than learn from them, the feedback loop that makes both humans and AI systems smarter simply breaks down.</p>



<h2 class="wp-block-heading">What does good human infrastructure look like?</h2>



<p>Here is the question I find most important, and most consistently ignored at the leadership level. AI systems require clean data, disciplined governance and structured feedback loops. What is the human equivalent of that infrastructure?</p>



<p>Clean data in a human system is the <strong>quality of thinking</strong> people bring to their roles. Their ability to observe accurately, reason clearly and separate signal from noise. Most organizations invest nothing in this.</p>



<p>Governance on the human side is <strong>behavioral discipline. </strong>The standards, habits and decision-making frameworks that determine how people operate under pressure, not just in ideal conditions.</p>



<p>And the feedback loop equivalent is what I call <strong>failure-forward learning</strong>. The organizational capacity to extract structured insight from what goes wrong and feed it back into how people and teams operate.</p>



<p>When these three elements are absent, you do not have a human operating model. You have a group of individuals hoping that good intentions and expensive software will be enough. Newsflash, they won’t be.</p>



<p>The organizations seeing the strongest returns from AI are not necessarily those with the most advanced models. They’re the ones who invested in the human infrastructure around the technology first.</p>



<h2 class="wp-block-heading">Five actions leaders must take now</h2>



<p><strong>1. Stop treating AI adoption as a technology deployment.</strong> AI is a business transformation that happens to involve technology. The moment a leader frames it as an IT initiative, they have constrained its potential before it has even begun. Framing determines resourcing, sponsorship and accountability. Get it wrong, and everything that follows is compromised.</p>



<p><strong>2. Build structured reflection into the operating rhythm. </strong>High-performing teams use short, focused weekly review cycles, rather than lengthy retrospectives. They ask the right questions. What did we learn? What did we assume that proved incorrect? What do we need to adjust? Without this, people repeat the same cognitive errors at increasing speed.</p>



<p><strong>3. Establish decision hygiene.</strong> Teams need explicit frameworks for how decisions are made. Make it clear who holds accountability, what information is required and how outcomes are tracked against the reasoning that produced them. AI surfaces decisions faster than ever before. Without decision hygiene, that acceleration becomes a liability.</p>



<p><strong>4. Measure outcomes, not inputs.</strong> Too many leadership teams celebrate the number of tools deployed, licenses purchased or training hours completed. None of that is operational value. Operational value is measured in decision quality, execution speed, cost efficiency and competitive differentiation. Hold yourself and your organization to outcome metrics from day one.</p>



<p><strong>5. Model the behaviors you want to see.</strong> Intellectual curiosity, comfort with iteration and the willingness to be publicly wrong and publicly learning are not soft cultural aspirations. They are hard operational requirements. A team operating in cognitive overload or fear will corrupt even the most sophisticated AI initiative from the inside.</p>



<h2 class="wp-block-heading">The most critical system in the AI loop</h2>



<p>In the next three to five years, AI itself will be largely commoditized. The competitive advantage won’t come from simply having the technology, but from the quality of the human system wrapped around it.</p>



<p>Every serious organization investing in AI today has people responsible for model performance: Tracking what the system gets wrong, retraining on new data, auditing outputs continuously. That rigor is appropriate. However, in most organizations, the same level of discipline is almost entirely absent when it comes to evaluating and improving the ‘human system’ surrounding the technology.</p>



<p>When did you last audit the quality of thinking in your senior team with the same discipline you audit your data? When did you last build a genuine feedback loop around human performance, not an annual review, but a real mechanism for learning and adjusting? For most leaders, the honest answer is rarely, or never.</p>



<p>The organizations that will define excellent AI-augmented performance will be those whose leaders understood, at a foundational level, that they were always running two systems simultaneously, and that the performance of one was always a ceiling on the performance of the other. AI will continue to advance at a pace that is difficult to overstate. But the human brain, its capacity for judgment, creativity, ethical reasoning and genuine connection, will remain the most critical system in the loop.</p>



<p>Treat it accordingly.</p>



<p><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><strong><a href="https://www.cio.com/expert-contributor-network/">Want to join?</a></strong></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Siri's Google Brain: What to Expect at WWDC 2026 video]]></title>
<description><![CDATA[Apple's Worldwide Developers Conference is days away. Here's what the iPhone Ultra rumors, Apple's track record and Siri's new Google powers tell us about what to expect.]]></description>
<link>https://tsecurity.de/de/3573328/it-nachrichten/siris-google-brain-what-to-expect-at-wwdc-2026-video/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3573328/it-nachrichten/siris-google-brain-what-to-expect-at-wwdc-2026-video/</guid>
<pubDate>Thu, 04 Jun 2026 18:32:46 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Apple's Worldwide Developers Conference is days away. Here's what the iPhone Ultra rumors, Apple's track record and Siri's new Google powers tell us about what to expect.]]></content:encoded>
</item>
<item>
<title><![CDATA[Pokémon Champions Launches June 17]]></title>
<description><![CDATA[We are pleased to report that Pokémon Champions will launch in less than two weeks on Wednesday, June 17. Champions brings a serious Pokémon Stadium vibe, which my millennial brain is very much on board with. In the game, you choose Pokémon, then they fight. You will play against other humans, co...]]></description>
<link>https://tsecurity.de/de/3572921/it-nachrichten/pokmon-champions-launches-june-17/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3572921/it-nachrichten/pokmon-champions-launches-june-17/</guid>
<pubDate>Thu, 04 Jun 2026 16:32:49 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>We are pleased to report that Pokémon Champions will launch in less than two weeks on Wednesday, June 17. Champions brings a serious Pokémon Stadium vibe, which my millennial brain is very much on board with. In the game, you choose Pokémon, then they fight. You will play against other humans, collect different Pokémon, and...</p>
<p>Read the original post: <a href="https://www.droid-life.com/2026/06/04/pokemon-champions-launches-june-17/">Pokémon Champions Launches June 17</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Jeff Bezos Is Funding a Wild Hunt for the Brain’s ‘Core Algorithm’]]></title>
<description><![CDATA[With $500 million in funding and a reported $2.5 billion valuation, Flourish wants to reinvent AI by putting real neurons under the microscope.]]></description>
<link>https://tsecurity.de/de/3572206/ai-nachrichten/jeff-bezos-is-funding-a-wild-hunt-for-the-brains-core-algorithm/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3572206/ai-nachrichten/jeff-bezos-is-funding-a-wild-hunt-for-the-brains-core-algorithm/</guid>
<pubDate>Thu, 04 Jun 2026 12:32:57 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[With $500 million in funding and a reported $2.5 billion valuation, Flourish wants to reinvent AI by putting real neurons under the microscope.]]></content:encoded>
</item>
<item>
<title><![CDATA[The Humanoid Robot of the Future Is a 6-Foot-Tall Beefcake With a Chinese Body and an American Brain]]></title>
<description><![CDATA[Spencer Huang, Nvidia’s robotics lead, tells WIRED that the new bot combines the best of both worlds.]]></description>
<link>https://tsecurity.de/de/3570465/it-nachrichten/the-humanoid-robot-of-the-future-is-a-6-foot-tall-beefcake-with-a-chinese-body-and-an-american-brain/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3570465/it-nachrichten/the-humanoid-robot-of-the-future-is-a-6-foot-tall-beefcake-with-a-chinese-body-and-an-american-brain/</guid>
<pubDate>Wed, 03 Jun 2026 20:01:41 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Spencer Huang, Nvidia’s robotics lead, tells WIRED that the new bot combines the best of both worlds.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2024-7071 | Brain Information Technologies Brain Low-Code up to 2.0.x sql injection]]></title>
<description><![CDATA[A vulnerability categorized as critical has been discovered in Brain Information Technologies Brain Low-Code up to 2.0.x. This affects an unknown part. Such manipulation leads to sql injection.

This vulnerability is listed as CVE-2024-7071. The attack may be performed from remote. There is no av...]]></description>
<link>https://tsecurity.de/de/3569980/sicherheitsluecken/cve-2024-7071-brain-information-technologies-brain-low-code-up-to-20x-sql-injection/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3569980/sicherheitsluecken/cve-2024-7071-brain-information-technologies-brain-low-code-up-to-20x-sql-injection/</guid>
<pubDate>Wed, 03 Jun 2026 16:39:19 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability categorized as <a href="https://vuldb.com/kb/risk">critical</a> has been discovered in <a href="https://vuldb.com/product/brain_information_technologies:brain_low-code">Brain Information Technologies Brain Low-Code up to 2.0.x</a>. This affects an unknown part. Such manipulation leads to sql injection.

This vulnerability is listed as <a href="https://vuldb.com/cve/CVE-2024-7071">CVE-2024-7071</a>. The attack may be performed from remote. There is no available exploit.

It is advisable to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[Qualcomm Reacts to NVIDIA RTX Spark: “Welcome to the Family”]]></title>
<description><![CDATA[Qualcomm has welcomed NVIDIA’s entry into the Windows on Arm market following the announcement of the new RTX Spark processor, a move that adds another…
The post Qualcomm Reacts to NVIDIA RTX Spark: “Welcome to the Family” appeared first on OnMSFT.]]></description>
<link>https://tsecurity.de/de/3568187/windows-tipps/qualcomm-reacts-to-nvidia-rtx-spark-welcome-to-the-family/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3568187/windows-tipps/qualcomm-reacts-to-nvidia-rtx-spark-welcome-to-the-family/</guid>
<pubDate>Wed, 03 Jun 2026 06:09:17 +0200</pubDate>
<category>🪟 Windows Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Qualcomm has welcomed NVIDIA’s entry into the Windows on Arm market following the announcement of the new RTX Spark processor, a move that adds another…</p>
<p>The post <a href="https://onmsft.com/news/qualcomm-reacts-to-nvidia-rtx-spark-welcome-to-the-family/">Qualcomm Reacts to NVIDIA RTX Spark: “Welcome to the Family”</a> appeared first on <a href="https://onmsft.com/">OnMSFT</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[The Agentic Reckoning: Enterprise AI organizations have a runtime problem, not a model problem — and most are building the wrong solution]]></title>
<description><![CDATA[In Q1 2026, VentureBeat's Pulse Research surfaced the “Governance Mirage”: the gap between the governance org charts enterprises had drawn and the control layers they had actually built. Forty-three percent said a central team owned AI governance; 23% couldn't agree on who owned it at all; and 31...]]></description>
<link>https://tsecurity.de/de/3567536/it-nachrichten/the-agentic-reckoning-enterprise-ai-organizations-have-a-runtime-problem-not-a-model-problem-and-most-are-building-the-wrong-solution/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3567536/it-nachrichten/the-agentic-reckoning-enterprise-ai-organizations-have-a-runtime-problem-not-a-model-problem-and-most-are-building-the-wrong-solution/</guid>
<pubDate>Tue, 02 Jun 2026 22:17:10 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>In Q1 2026, VentureBeat's Pulse Research surfaced the <a href="https://venturebeat.com/orchestration/the-ai-governance-mirage-why-72-of-enterprises-dont-have-the-control-and-security-they-think-they-do">“Governance Mirage”</a>: the gap between the governance org charts enterprises had drawn and the control layers they had actually built. Forty-three percent said a central team owned AI governance; 23% couldn't agree on who owned it at all; and 31% named vendor opacity as the single biggest obstacle.</p><p>This new wave of research asks the next question: Once you've admitted the governance problem, what breaks first when you try to fix it? The answer from our respondents is unambiguous. The failure point is not the model. It's the runtime.</p><p>Enterprises are discovering that AI agents built on stateless infrastructure — Python scripts, LangChain chains, ad hoc orchestration — cannot survive the operational realities of production. Container restarts erase context. Token costs breach business cases. Hallucinations in Step 3 compound into catastrophic failures by Step 12. And the majority of engineering teams are spending more time managing this "plumbing" than building the intelligence that was supposed to justify the investment.</p><p>What emerges from this survey is a picture of an industry at a critical fork. The organizations that survive the Agentic Reckoning will be those that treat runtime durability as a first-class engineering concern — not an afterthought to be patched with retries and prompting. The ones that don't will find themselves back where RPA left enterprises a decade ago: a graveyard of clever pilots that couldn't survive Day Two.</p><h2>Methodology</h2><p>VentureBeat conducted this survey in May 2026 as part of its ongoing Pulse Research series on agentic AI adoption in the enterprise. Respondents were filtered to organizations with 100 or more employees. The final qualified sample consists of 132 <b>verified, highly qualified technology leaders</b> at the forefront of enterprise AI agent deployment. </p><p>They span:</p><table><tbody><tr><td><p>Directors of AI/Analytics (8%)</p></td><td><p>Directors of Engineering/IT (16%)</p></td></tr><tr><td><p>VP of Data/AI/Analytics (5%)</p></td><td><p>VP of Engineering/IT (5%)</p></td></tr><tr><td><p>CIOs/CTOs/CISOs (15%) </p></td><td><p>Product and Program Managers (13%) </p></td></tr><tr><td><p>Consultants (9%) </p></td><td><p>Software and ML Engineers (9%) </p></td></tr><tr><td><p>Enterprise Architects (8%) </p></td><td><p>Other (12%)</p></td></tr></tbody></table><p>Industries represented include Technology/Software (42%), Financial Services (20%), Professional Services (8%), Healthcare/Life Sciences (7%), Retail/Consumer (6%), Education (4%), and others.</p><p>Given our strict filtering criteria, this cohort provides a robust and authoritative look at emerging agentic infrastructure trends.</p><p><b>Respondent demographics by company size:</b></p><ul><li><p><b>Large enterprise (10,000+ employees):</b> 35% of the sample</p></li><li><p><b>Mid-to-large enterprise (500–9,999 employees):</b> 48% of the sample</p></li><li><p><b>Growth enterprise (100–499 employees):</b> 17% of the sample</p></li></ul><p>These quantitative findings capture a critical moment in infrastructure evolution and are best synthesized alongside VentureBeat’s Q1 2026 governance reports and our deep-dive practitioner conversations conducted throughout the quarter.</p><h2>Finding 1: The runtime is the problem</h2><p><b>The "spine vs. brain" debate is over</b></p><p>The foundational question of enterprise AI in 2026 is whether agent failures trace back to the model's reasoning capability — the Brain — or to the runtime infrastructure's inability to manage state, survive failures, and coordinate execution — the Spine. We asked our respondents directly. </p><p>Integration/governance challenges were the biggest problem. But Spine issues were close behind.</p><div></div><p>However, 17% still say the Brain is the primary failure mode. That’s not a rounding error — it’s a signal. The organizations in this cohort are not disputing the infrastructure problem; they are telling us that the models themselves are not yet reliable enough for the edge cases their workflows are generating. The model-versus-runtime debate is genuinely three-sided. Read together, these three answers are not fully in conflict. The Spine and Gap camps are struggling with infrastructure and governance respectively. The Brain cohort is struggling with something upstream: reasoning reliability at scale. </p><p>This is a significant finding. The frontier model wars — GPT-5 vs. Claude 4.7 vs. Grok — are consuming enormous mindshare in the enterprise technology press. Our respondents are telling us that war is, for now, beside the point. The models are smart enough, but the infrastructure around them is not.</p><blockquote><p>"The models are smart enough, but our stateless infrastructure is too fragile to manage long-running, multi-step agentic processes." 

<i>— Director of Engineering / IT, Financial Services, 10,000–49,999 employees</i></p></blockquote><h2>Finding 2: The DIY tax is eating teams alive</h2><p><b>Engineering capacity is being consumed by plumbing, not intelligence</b></p><p>If the Spine is a primary failure mode, what does that cost in practice? We asked respondents what percentage of their team's weekly engineering capacity is consumed by building and maintaining custom "plumbing" — manual retries, state-persistence, checkpointing — rather than actual agentic logic.</p><p>The results reveal a market in two distinct camps, with a dangerous middle.</p><div></div><p>The arithmetic is stark. Seventy-seven percent of respondents are spending meaningful engineering time on infrastructure overhead. Just 23% — those whose frameworks are handling reliability — have escaped the tax. The distribution is notably flat: the Crisis and Efficiency poles are the same sizes as the middle categories (Trap and Maintenance Tax). This is the signature of a market that has partially addressed the worst failures but has not yet escaped the structural overhead.</p><p>The Efficiency Zone respondents are not necessarily in a more sophisticated position. In many cases, they may be on managed platforms that abstract away the durability problem — or they may simply not yet have hit the scale at which stateless architectures begin to fail. The Complexity Trap is often where the Efficiency Zone ends.</p><p>There’s a direct business consequence for organizations in the Crisis zone. Every engineering hour spent writing retry logic or debugging a "ghost failure" — a silent API timeout that leaves an agent hanging without a traceback — is an hour not spent on the differentiated logic that was supposed to justify the AI investment in the first place.</p><h2>Finding 3: State amnesia is the production killer</h2><p><b>The No. 1 technical obstacle has shifted: Cost and hallucination now lead state failures</b></p><p>When AI agents fail to reach production or scale, what is the primary technical obstacle? We named five candidates, ranging from model hallucination to cost overruns to latency failures.</p><div></div><p>Hallucination Propagation at 24% compounds silently — reasoning errors in early steps become catastrophic by Step 10. Ghost Failures at 20% are invisible by definition, which means their real prevalence is likely higher than this number suggests.</p><h2>Finding 4: The observability tax falls heaviest on Microsoft</h2><p><b>Platform visibility costs are not equally distributed</b></p><p>Our Q1 2026 research identified vendor opacity as the single biggest obstacle to AI governance — ahead of talent gaps, tooling, and budget. That finding pointed to this question: Which vendor ecosystem, in practice, imposes the highest cost to achieve basic production visibility?</p><p>We asked respondents which platform requires the most custom telemetry, manual instrumentation, and "logging glue" to achieve visibility into agentic failures.</p><div></div><p>Microsoft's position at the top of this ranking is not noise. It is a structural characteristic of the Microsoft agentic ecosystem — the same Azure/Copilot stack that dominates enterprise AI adoption requires the most instrumentation overhead to see inside.</p><p>It also reinforces the warning that Brian Gracely, Senior Director at Red Hat, made at VentureBeat’s Boston event in March: that building your control system entirely inside one cloud provider's toolset means "renting a cage." The organizations paying the highest observability tax are precisely those most locked into provider-native tooling.</p><p>The implication for teams currently evaluating orchestration architecture is direct: observability cost is a real budget item that should appear in any build-vs-buy analysis. A platform that appears cheaper at the API layer may impose substantially higher engineering costs at the telemetry layer.</p><h2>Finding 5: The hype-reality gap belongs to OpenAI and Microsoft</h2><p><b>Agentic coding marketing is significantly ahead of production reliability. </b></p><p>We asked respondents a pointed question: Which major platform's Agentic Coding marketing is the most disconnected from the actual technical reliability and fault-tolerance of their product? Thirty-two percent said they didn't know — a figure that has held roughly constant across all three waves, suggesting persistent uncertainty is structural, not a sample artifact. Cursor also registered 6% in this wave. Among those with enough production experience to have a view.</p><div></div><p>Microsoft leads at 45%; OpenAI is second at 22%. The gap is too large to attribute solely to deployment footprint. It suggests that GitHub Copilot Workspaces and AutoGen are generating a specific category of disappointment — probably around the reliability of multi-agent orchestration in production — that accumulates with use. A platform that fewer enterprises are running in production will accumulate fewer credible disappointed practitioners.</p><p>The more significant observation is what this gap means for decision-makers evaluating new agentic tooling. The marketing around all major platforms describes agentic autonomy and reliability at a level that production deployments are not yet delivering. The organizations in our survey who have moved beyond pilots are encountering the difference firsthand.</p><h2>Finding 6: The security mesh is being built from first principles</h2><p><b>Enterprises are not waiting for vendors to solve agent security</b></p><p>How are enterprises protecting proprietary research data from AI leakage and prompt-driven exfiltration? The security architecture question is one of the most consequential in agentic AI, because agents — unlike static models — can actively call APIs, traverse file systems, and execute code. The blast radius of a security failure is qualitatively different.</p><p>Policy-as-Code is a leading security mechanism, but not by much. </p><div></div><p>The NHI and Policy-as-Code approaches are meaningfully different in their security philosophy. NHI is identity-centric: The question it answers is "who is this agent and what is it allowed to touch?" Policy-as-Code is rule-centric: The question it answers is "regardless of what the model decides to do, what hard stops exist at the infrastructure level?"</p><p>Rough parity across all four mechanisms is the headline finding. This is what market convergence looks like in early motion: No dominant pattern has emerged. Notably, though, Egress-Locked Sandboxing is a relatively new trend in agentic AI deployments, yet it’s already at 22%. As more agents gain terminal-level access to enterprise systems, the cost-benefit of sandboxing is improving. This is notable given the maturity of the identity management and policy-as-code disciplines in traditional IT security. The AI security layer is, for now, being built largely from scratch.</p><p>The Egress-Locked Sandboxing number deserves attention despite its smaller share. Sandboxing untrusted code execution is the most technically intensive of the four approaches, but it is also the most direct defense against prompt injection attacks that try to execute malicious code through agent tooling. As agentic systems gain more terminal-level access — a trend our survey confirms is accelerating — this approach may prove more important than its current adoption rate suggests.</p><blockquote><p>"How do we audit agentic tools that have terminal-level access to our proprietary repos?"</p><p><i>— Composite concern expressed by multiple respondents</i></p></blockquote><h2>Finding 7: The complexity cliff is real, and most are climbing it</h2><p><b>The migration away from stateless architectures is underway — but fragmented</b></p><p>The central thesis of the Agentic Reckoning is that stateless Python/LangChain architectures cannot survive the complexity cliff — the point at which multi-step, long-running agent workflows begin failing at rates that make production deployment untenable. We asked respondents directly: are you migrating toward durable execution frameworks to solve for state loss?</p><p>The answers reveal a market in transition, with meaningful disagreement about the right destination.</p><div></div><p>The 20% committed to stateless architectures — attempting to solve a structural durability problem through better prompting — are the cohort most likely to encounter State Amnesia and Ghost Failures as their workloads scale. It’s essentially the same trap that RPA teams fell into a decade ago, when brittle process automations were patched with increasingly elaborate rule sets rather than re-architected on more resilient foundations.</p><p>The Stateless Commitment cohort deserves a reinterpretation. These teams are not all naive: some are building on managed platforms that genuinely abstract state management. But a portion is patching structural fragility with prompting improvements, and the Ghost Failures data in Finding 3 suggests this approach may be encountering its ceiling.</p><p>The combined 59% who are either in Active Migration or in Governance-First Evaluation represent the market's leading edge — organizations that have recognized the architectural problem and are investing to solve it structurally.</p><h2>Finding 8: The “polyglot orchestration” lead is narrow — the field is fragmented</h2><p><b>Architectural conviction is spread across multiple bets</b></p><p>What is the longterm architectural philosophy winning enterprises' strategic investment? We offered four options representing the major bets available in the current market.</p><div></div><p>The Polyglot Bet's lead suggests that enterprises are seeing advantages of using a flexible approach: Using model-driven architectures where non-deterministic reasoning works well, but using deterministic structures and pipelines where accuracy and mission-critical execution is at stake.</p><p>This has direct competitive implications for the frontier labs and cloud providers. The cohort saying the use a Cloud-Native Managed Stack is significant. This likely reflects the enterprise reality that Azure OpenAI Service and AWS Bedrock deployments come with built-in organizational gravity — procurement relationships, security approvals, and existing data pipelines. The Independent Durable Runtime bet at 16% signals that a cohort of teams have rejected both cloud lock-in and frontier lab dependency in favor of full architectural sovereignty.</p><p>The Polyglot result also helps explain why the observability and governance problems described in this survey are so persistent. When your architecture deliberately spans multiple orchestration layers and multiple providers, no single vendor's telemetry gives you the full picture. The "Dynatrace for AI" — <a href="https://venturebeat.com/orchestration/how-massmutual-and-mass-general-brigham-turned-ai-pilot-sprawl-into">the unified observability platform</a> called for by Mass General Brigham's CTO Nallan Sriraman at the VentureBeat Boston event — becomes not just desirable but structurally necessary.</p><blockquote><p>"Enterprises trust no single provider enough to give them full control, yet they lack the engineering capacity to build entirely from scratch." </p><p><i>— Survey respondent</i></p></blockquote><h2>Finding 9: User acceptance rate is the emerging production standard</h2><p><b>The market is settling on a human-trust metric as its primary A-SLA</b></p><p>What metrics are enterprises actually using to determine whether an AI agent is ready for production? We asked respondents to identify their primary Agentic SLA (A-SLA) indicator — the number that, above all others, tells them whether an agent can ship.</p><div></div><p>User Acceptance Rate as the dominant production metric is significant because it is a human-trust measure, not a technical performance measure. It does not ask whether the agent ran fast or maintained state. It asks whether a human who reviewed its output chose to accept it. This is, in effect, a field-level Turing test applied at the action level. </p><p>The persistence of UAR as the leading metric reflects the reality of where most enterprise agentic deployments still sit: in a human-in-the-loop posture, where agent actions require human review before execution. That is a rational response to the Hallucination Propagation and Ghost Failures described earlier in this survey. Organizations that have not yet solved runtime durability are, sensibly, keeping humans in the loop — and at 132 respondents, there is no evidence this is changing.</p><p>Context Fidelity's position at 30% is the most significant finding. It tracks directly with the Active Migration data in Finding 7: As more teams move into durable execution frameworks, the 48-hour+ memory problem becomes their primary production concern. Teams that have solved State Amnesia are now focused on whether their agent can remember what it was doing yesterday. Latency Jitter's collapse from 25% to 11% tells the complementary story: raw speed is no longer the primary anxiety. Correctness and durability have taken its place.</p><h2>The bottom line: The reckoning is runtime, not reasoning</h2><p>The data tells a consistent story: There’s a runtime deficit for agents. Enterprises are spending more time on infrastructure plumbing than on agent intelligence, and State Amnesia is still claiming production deployments. But fault lines are visible. The ROI Ceiling has overtaken State Amnesia as the leading production killer — which means the infrastructure problem is no longer purely a technical one. Token economics and orchestration overhead are now consuming enough business value that project sponsors are making the kill decision before engineering teams can solve the durability problem. Hallucination Propagation remains a big problem. The Brain vote in Finding 1 remains significant. And the Polyglot lead is fragile, with varied architectures well represented.</p><p>The models are, by most respondents' own assessment, smart enough — but 17% disagree. What is not yet smart enough is the infrastructure surrounding them: the state management, the fault-tolerance, the observability, the identity governance, and the deterministic execution layer that turns a model's judgment into something an enterprise can stake its operations on.</p><p>The 39% making the Polyglot Bet represent the current leading edge of enterprise architectural thinking. They are building systems where the model's intelligence is preserved and leveraged, but where the execution layer — the Spine — is deterministic, auditable, and durable by design. They are not waiting for a frontier lab to solve this for them. They are not betting that better prompting will patch infrastructure fragility. They are building the control plane.</p><p>The organizations still committed to stateless architectures — still trusting that manual retries and clever prompting can substitute for durable execution — are the ones most likely to contribute to the next wave of this data. Ghost Failures are a primary obstacle. The pattern is familiar: Early adopters diagnose the problem architecturally, migrate to durable runtimes, and escape the failure mode. Late movers inherit it. The Complexity Cliff is not theoretical. It is the wall that most current agentic architectures are already climbing toward.</p><p>The reckoning is runtime and economics, not reasoning.</p><hr><p><i>Based on survey responses from 132 qualified enterprise respondents (100+ employees). Sample size is small; data should be treated as directional. Respondents include Directors, VPs, CIOs, CTOs, and Enterprise Architects across Technology, Financial Services, Retail, Healthcare, and other sectors.</i></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Allen Institute’s big new bet: $400M effort aims to go from mapping the brain to treating disease]]></title>
<description><![CDATA[The Allen Institute is launching a $400 million initiative, the Brain Health Accelerator, to develop gene therapies for neurodegenerative diseases including Alzheimer's, Parkinson's, Huntington's, and ALS. It marks the first time the Seattle research organization, founded by Paul Allen in 2003, h...]]></description>
<link>https://tsecurity.de/de/3567128/it-nachrichten/allen-institutes-big-new-bet-400m-effort-aims-to-go-from-mapping-the-brain-to-treating-disease/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3567128/it-nachrichten/allen-institutes-big-new-bet-400m-effort-aims-to-go-from-mapping-the-brain-to-treating-disease/</guid>
<pubDate>Tue, 02 Jun 2026 19:47:37 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<img width="1260" height="840" src="https://cdn.geekwire.com/wp-content/uploads/2026/06/7RV04331-1-1260x840.jpg" class="webfeedsFeaturedVisual wp-post-image" alt="" decoding="async" loading="lazy" srcset="https://cdn.geekwire.com/wp-content/uploads/2026/06/7RV04331-1-1260x840.jpg 1260w, https://cdn.geekwire.com/wp-content/uploads/2026/06/7RV04331-1-768x512.jpg 768w, https://cdn.geekwire.com/wp-content/uploads/2026/06/7RV04331-1-1536x1024.jpg 1536w, https://cdn.geekwire.com/wp-content/uploads/2026/06/7RV04331-1.jpg 1620w" sizes="auto, (max-width: 1260px) 100vw, 1260px"><br>The Allen Institute is launching a $400 million initiative, the Brain Health Accelerator, to develop gene therapies for neurodegenerative diseases including Alzheimer's, Parkinson's, Huntington's, and ALS. It marks the first time the Seattle research organization, founded by Paul Allen in 2003, has made treating disease its goal. <a href="https://www.geekwire.com/2026/allen-institutes-big-new-bet-400m-initiative-aims-to-go-from-mapping-the-brain-to-treating-disease/">Read More</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Allen Institute’s big new bet: $200M effort aims to go from mapping the brain to treating disease]]></title>
<description><![CDATA[The Allen Institute is launching a $200 million initiative, the Brain Health Accelerator, to develop gene therapies for neurodegenerative diseases including Alzheimer's, Parkinson's, Huntington's, and ALS. It marks the first time the Seattle research organization, founded by Paul Allen in 2003, h...]]></description>
<link>https://tsecurity.de/de/3566481/it-nachrichten/allen-institutes-big-new-bet-200m-effort-aims-to-go-from-mapping-the-brain-to-treating-disease/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3566481/it-nachrichten/allen-institutes-big-new-bet-200m-effort-aims-to-go-from-mapping-the-brain-to-treating-disease/</guid>
<pubDate>Tue, 02 Jun 2026 16:32:26 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<img width="1260" height="840" src="https://cdn.geekwire.com/wp-content/uploads/2026/06/7RV04331-1-1260x840.jpg" class="webfeedsFeaturedVisual wp-post-image" alt="" decoding="async" fetchpriority="high" srcset="https://cdn.geekwire.com/wp-content/uploads/2026/06/7RV04331-1-1260x840.jpg 1260w, https://cdn.geekwire.com/wp-content/uploads/2026/06/7RV04331-1-768x512.jpg 768w, https://cdn.geekwire.com/wp-content/uploads/2026/06/7RV04331-1-1536x1024.jpg 1536w, https://cdn.geekwire.com/wp-content/uploads/2026/06/7RV04331-1.jpg 1620w" sizes="(max-width: 1260px) 100vw, 1260px"><br>The Allen Institute is launching a $200 million initiative, the Brain Health Accelerator, to develop gene therapies for neurodegenerative diseases including Alzheimer's, Parkinson's, Huntington's, and ALS. It marks the first time the Seattle research organization, founded by Paul Allen in 2003, has made treating disease its goal. <a href="https://www.geekwire.com/2026/allen-institutes-big-new-bet-200m-initiative-aims-to-go-from-mapping-the-brain-to-treating-disease/">Read More</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[NVIDIA Drops 3 New AI Upgrades CHANGING Robots (H2 PLUS HUMANOID)]]></title>
<description><![CDATA[Author: AI News - Bewertung: 3x - Views:41 NVIDIA just dropped 3 new AI upgrades changing robots forever, starting with the NVIDIA Isaac GR00T humanoid robot reference platform built for advanced physical AI research. This breakthrough open architecture features the Unitree H2 Plus humanoid robot...]]></description>
<link>https://tsecurity.de/de/3565584/it-security-video/nvidia-drops-3-new-ai-upgrades-changing-robots-h2-plus-humanoid/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3565584/it-security-video/nvidia-drops-3-new-ai-upgrades-changing-robots-h2-plus-humanoid/</guid>
<pubDate>Tue, 02 Jun 2026 11:47:20 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: AI News - Bewertung: 3x - Views:41 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/n7ZruRFTGB8?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>NVIDIA just dropped 3 new AI upgrades changing robots forever, starting with the NVIDIA Isaac GR00T humanoid robot reference platform built for advanced physical AI research. This breakthrough open architecture features the Unitree H2 Plus humanoid robot chassis integrated with dual Sharpa Wave tactile five-fingered hands, achieving 75 degrees of freedom. Powered by the onboard NVIDIA Jetson AGX Thor T5000 and Blackwell architecture GPU, the platform utilizes Isaac Sim, Isaac Lab, and Isaac ROS middleware to eliminate proprietary blackbox limitations. Additionally, NVIDIA announced Cosmos 3, a state-of-the-art family of open-weight omnimodal world foundation models, including Cosmos 3 Super and Cosmos 3 Nano, acting as an advanced robot brain for vision-language reasoning. Finally, Microsoft and NVIDIA unveiled the RTX Spark system-on-a-chip at Computex, featuring a 20-core ARM CPU co-designed with MediaTek and 128GB unified memory to run local AI agents offline via the NVIDIA OpenShell runtime.<br />
<br />
Discover the AI agent economy: https://8004agents.ai<br />
<br />
AI news:<br />
0:00 Nvidia GR00T<br />
1:49 SharpaWave<br />
2:43 Unitree H2 Plus<br />
4:21 Cosmos 3<br />
6:18 RTX Spark<br />
<br />
#nvidia #ai #news<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Der neue KI-Lock-In]]></title>
<description><![CDATA[KI beseitigt Lock-In-Tendenzen nicht, sondern setzt lediglich andere Schwerpunkte.Chizhevskaya Ekaterina | shutterstock.com



Die Wirtschaftsprüfer von PwC planen (in Kooperation mit Anthropic), rund 30.000 Mitarbeiter im Umgang mit Claude Code zu schulen und mit entsprechenden Zertifizierungen ...]]></description>
<link>https://tsecurity.de/de/3564738/it-security-nachrichten/der-neue-ki-lock-in/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3564738/it-security-nachrichten/der-neue-ki-lock-in/</guid>
<pubDate>Tue, 02 Jun 2026 04:07:47 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2025/01/Chizhevskaya-Ekaterina_shutterstock_2101608913_16z9_DEOnly.jpg?quality=50&amp;strip=all&amp;w=1024" alt="Brain w Padlock 16z9 DEOnly" class="wp-image-3809468" width="1024" height="576" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption">KI beseitigt Lock-In-Tendenzen nicht, sondern setzt lediglich andere Schwerpunkte.</figcaption></figure><p class="imageCredit">Chizhevskaya Ekaterina | shutterstock.com</p></div>



<p>Die Wirtschaftsprüfer von PwC <a href="https://www.anthropic.com/news/pwc-expanded-partnership" target="_blank" rel="noreferrer noopener">planen (in Kooperation mit Anthropic)</a>, rund 30.000 Mitarbeiter im Umgang mit Claude Code zu schulen und mit entsprechenden Zertifizierungen auszustatten. Daraus soll eine „Office of the CFO“-Business Group rund um die Technologie entstehen – für Kunden aus dem Banken-, Versicherungs- und Gesundheitswesen. Anthropic selbst hat in sein Partner-Netzwerk zudem kürzlich weitere rund 100 Millionen Dollar <a href="http://www.anthropic.com/news/claude-partner-network" target="_blank" rel="noreferrer noopener">bereitgestellt</a>.</p>



<p>Um nicht zurückzustehen, hat OpenAI seinerseits die OpenAI Deployment Company, auch bekannt als „DeployCo“, <a href="https://openai.com/index/openai-launches-the-deployment-company/" target="_blank" rel="noreferrer noopener">gegründet</a>. Das neue Unternehmen ist mit <a href="https://www.ciodive.com/news/openai-deployment-company-4-billion-ai-consulting-integration/819942/" target="_blank" rel="noreferrer noopener">mehr als 4 Milliarden Dollar Startkapital</a> ausgestattet und darauf ausgerichtet, GPT-Modelle vor Ort in die Workflows von Kunden zu integrieren.</p>



<p>Für Unternehmen, die millionenfach Token an den Mann bringen, kann diese Investition in professionelle Services, die nicht skalieren und mit niedrigen Margen einhergehen, auf den ersten Blick seltsam erscheinen. Ist es aber nicht: Auch wenn KI-Modelle immer leichter austauschbar sind, gilt das nicht für die damit verbundene Arbeit.</p>



<p>Entwickler wechseln schon heute zwischen Claude Code, Codex, Gemini und lokalen Modellen hin und her – mit weniger Aufwand, als den Anbietern lieb ist. Auch auf der API-Ebene wird der Austausch einfacher. Nicht mühe- oder kostenlos, aber immer noch simpel im Vergleich dazu, die Workflow-Infrastruktur rund um das Modell auszutauschen.</p>



<p>Diesen Aspekt unterschätzen Enterprise-Kunden möglicherweise. Offene Standards, bessere <a href="https://www.computerwoche.de/article/4004872/die-besten-apis-um-ki-zu-integrieren.html" target="_blank">APIs</a> und eine zunehmende Modellparität schwächen zwar die eine Lock-In-Form, stärken dafür aber eine andere hinsichtlich des umgebenden Workflows, der Governance und des Betriebsmodells.</p>



<h2 class="wp-block-heading">Lock-In-Verlagerung</h2>



<p><a href="https://www.linkedin.com/in/svgworld" target="_blank" rel="noreferrer noopener">Sanchit Vir Gogia</a>, Chefanalyst bei Greyhound Research, drückt es folgendermaßen aus: „Auf Orchestrierungsebene bleibt ein Austausch diffizil. Sobald Ihre Workflows, Kontrollen, Identitätsschichten und Governance-Strukturen um ein bestimmtes System herum aufgebaut sind, ist es kein leichter Task, dieses System zu verändern.“</p>



<p>Diese Diagnose liefert den deutlichsten Hinweis darauf, warum die KI-Anbieter Milliarden in die Workflow-Integration investieren: Neue KI-Technologie fügt sich nicht nahtlos genug in alte Enterprise-Workflows ein – und Menschen können das beheben. </p>



<p>Diverse Studien und Umfragen zeigen, dass die Kluft zwischen KI-Investition und <a href="https://www.computerwoche.de/article/4046876/5-wege-den-ki-roi-zu-maximieren.html" target="_blank">erzieltem Mehrwert</a> oft sehr groß ist. Die meisten KI-Fails hängen dabei auch nicht mit der Performanz des zugrundeliegenden Modells zusammen. Sondern mit der operativen Eignung. Oder ganz konkret: KI-Tools lernen den Workflow nicht, sind nicht in Approval-Prozesse eingebunden und verfügen nicht über die richtigen Berechtigungen. Mit anderen Worten: Sie bestehen den Praxistest mit realen, menschlichen Workflows nicht.</p>



<p>Das ist der einzige Grund, warum es Unternehmen wie DeployCo gibt. OpenAI hat sich nicht dazu entschieden, diesbezüglich die Palantir-Strategie zu kopieren, weil dem Unternehmen die Ideen ausgegangen sind. Vielmehr hat der KI-Pionier endlich verstanden, dass die Kunden nicht nach einem intelligenteren Modell streben. Sie haben vor allem Interesse daran, dass ein menschlicher Profi sie vor Ort besucht und die langweilige sowie kostenintensive Aufgabe übernimmt, das KI-Modell richtig in ihre Workflows einzubinden.</p>



<p>Aus dieser Perspektive ist die Verlagerung des Lock-In auch keine wirkliche Verlagerung: Sie fand immer schon eine (oder zwei) Ebenen höher statt. Der Hype um KI-Modelle hat das nur verschleiert.</p>



<h2 class="wp-block-heading">MCP ist nicht genug</h2>



<p>An dieser Stelle kommt das <a href="https://www.computerwoche.de/article/4031227/was-ist-model-context-protocol.html" target="_blank">Model Context Protocol</a> (MCP) ins Spiel. MCP ist tatsächlich nützlich und hält, was es verspricht: Es senkt die Kosten dafür, KI-Modelle mit Tools und Datenquellen zu verknüpfen. Wenn Sie schon einmal ein halbes Dutzend maßgeschneiderter Konnektoren für ServiceNow, Salesforce oder Jira gewartet haben, können Sie nachvollziehen, dass das ein wahrer Segen ist.</p>



<p>Allerdings ist ein Protokoll eben keine Plattform. MCP kann einen KI-Agenten dabei unterstützen, mit einem Tool zu kommunizieren. Es gibt jedoch keine Auskunft darüber,</p>



<ul class="wp-block-list">
<li>wer diesen Agenten genehmigt hat,</li>



<li>auf welche Daten dieser zugreifen darf,</li>



<li>wie seine Aktionen protokolliert werden oder</li>



<li>wie man ihn sicher deaktiviert.</li>
</ul>



<p>MCP sagt Ihnen auch nicht, wie die Compliance-Prüfung eines Vermögensverwalters tatsächlich abläuft, wie ein Underwriter über einen Grenzfall denkt oder was genau „done“ in Zusammenhang mit dem Monatsabschluss eines Finanzteams bedeutet. Diese Arbeit ist unveränderlich lokal – und menschlich.</p>



<p>Es verhält sich ganzähnlich wie bei <a href="https://www.computerwoche.de/article/4163026/die-kubernetes-dominanz-erodiert.html" target="_blank">Kubernetes</a>, das die Lock-In-Situation im Cloud-Bereich ebenfalls nicht eliminiert hat: Es standardisierte die Container-Ebene lediglich so weit, dass sich der nächste Kampf eine Ebene höher zu Managed Services, Identitätsmanagement, Netzwerken, Observability und Data Gravity verlagert hat. MCP macht quasi etwas Ähnliches für KI-Agenten: Eine Etage des Gebäudes wird portabel, die diffizileren Enterprise-Probleme sind eine Ebene höher angesiedelt und verbleiben dort. So senkt MCP zwar die Integrationskosten, aber nicht den Aufwand dafür, KI vertrauenswürdig zu betreiben.</p>



<h2 class="wp-block-heading">Wo der KI-Lock-In lauert</h2>



<p>Die wesentliche, strategische Frage bei agentenbasierter KI dreht sich darum, wem die Control Plane gehört. Hier zeichnet sich ein „Kampf“ an drei verschiedenen Schauplätzen ab.</p>



<ol class="wp-block-list">
<li><strong>Orchestrierungsebene:</strong> <a href="https://www.computerwoche.de/article/4164993/best-practices-um-agentic-ai-systeme-aufzubauen.html" target="_blank">Frameworks wie LangGraph</a> sind keine Lock-In-Fallen, sondern nützliche Tools. Aber: Orchestrierung sorgt für eine engere Kundenbindung, ob nun beabsichtigt oder nicht. Zu den Anwendern von LangGraph gehören etwa Klarna, Replit, Elastic und Ally. Wenn diese und andere Kunden ein Jahr damit verbracht haben, Agentenverhalten, Evaluierungen, Recovery-Logik und Observability-Traces innerhalb eines Frameworks zu orchestrieren, werden sie dieses nicht einfach über Bord werfen, nur weil ein Anbieter ein schnelleres oder billigeres KI-Modell auf den Markt bringt.</li>



<li><strong>Anbietergesteuerte Workflow-Oberflächen: </strong>Das baut Anthropic eigentlich gerade mit Claude Cowork auf. Durch die <a href="https://www.pymnts.com/artificial-intelligence-2/2026/anthropic-pushes-claude-beyond-chat-into-enterprise-workflows/" target="_blank" rel="noreferrer noopener">Erweiterung</a> hielten private Plug-in-Marktplätze, benutzerspezifische Bereitstellungen und vorgefertigte Agenten für verschiedene Geschäftsbereiche Einzug. Niemand im Enterprise-Umfeld dürfte Interesse daran haben, 400 generische Agenten einzusetzen, um sie dann an Vertragssysteme, HR-Daten und Kundendatensätze zu koppeln. Nicht die Agenten selbst sind das Produkt – sondern die administrative Oberfläche um sie herum.</li>



<li><strong>Service-Layer:</strong> Hier liegt die größte Ironie. Das deutlichste Zeichen dafür, dass sich der Wert der KI in Richtung Implementierung verlagert, hat nichts mit der Größe des Marktes zu tun. Vielmehr ist es die Tatsache, dass OpenAI, Anthropic, PwC, Accenture und Deloitte Heerscharen von Mitarbeitern ausbilden, um Workflows abzubilden, Systeme miteinander zu verknüpfen und Prozesse neu zu gestalten.</li>
</ol>



<h2 class="wp-block-heading">Was das für Anwender bedeutet</h2>



<p>Wenn Sie für die IT eines Unternehmens verantwortlich sind, ist diese Erkenntnis in gewisser Weise befreiend. Schließlich müssen Sie sich nicht mehr auf diese oder jene Punktlösung versteifen, sondern können stattdessen eine oder zwei Ebenen höher ansetzen. Die wichtigen strategischen Fragen lauten auf lange Sicht dabei wie folgt:</p>



<ul class="wp-block-list">
<li>In welches Orchestrierungs-Framework wird Ihr Code eingebunden?</li>



<li>In welcher Workflow-Oberfläche werden die Endbenutzer tatsächlich arbeiten?</li>



<li>Welcher Servicepartner ist tief genug in Ihre Betriebsabläufe eingebunden, um tatsächlich verbindliche Modellempfehlungen zu liefern?</li>
</ul>



<p>(fm)</p>



<p><strong>Dieser Artikel ist </strong><a href="https://www.infoworld.com/article/4171983/the-new-ai-lock-in.html" target="_blank"><strong>im Original</strong></a><strong> bei unserer Schwesterpublikation Infoworld.com erschienen.</strong></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Brain Mapping May Offer Promise in Treating Mental Health and Neurological Conditions]]></title>
<description><![CDATA[With a treatment known as brain mapping, practitioners say they can treat conditions like ADHD, depressive disorders, epilepsy, autism and more. In a fast-growing industry, brain mapping or neurofeedback is based on the idea that targeted brain exercises can rewire the brain to decrease the chall...]]></description>
<link>https://tsecurity.de/de/3564073/it-security-nachrichten/brain-mapping-may-offer-promise-in-treating-mental-health-and-neurological-conditions/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3564073/it-security-nachrichten/brain-mapping-may-offer-promise-in-treating-mental-health-and-neurological-conditions/</guid>
<pubDate>Mon, 01 Jun 2026 20:53:42 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>With a treatment known as brain mapping, practitioners say they can treat conditions like ADHD, depressive disorders, epilepsy, autism and more. In a fast-growing industry, brain mapping or neurofeedback is based on the idea that targeted brain exercises can rewire the brain to decrease the challenges presented by a broad range of mental impairments. Here’s </p>
<p>The post <a href="https://www.nashdisabilitylaw.com/brain-mapping-may-offer-promise-in-treating-mental-health-and-neurological-conditions/">Brain Mapping May Offer Promise in Treating Mental Health and Neurological Conditions</a> appeared first on <a href="https://www.nashdisabilitylaw.com/">Nash Disability Law</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Nvidia bets big on physical AI at GTC Taipei with a new world model, driving brain, and open humanoid robot]]></title>
<description><![CDATA[Nvidia used GTC Taipei to launch a series of models for robots, autonomous vehicles, and video systems. The centerpieces are the new world model Cosmos 3, a significantly scaled-up driving model called Alpamayo 2 Super, and an open reference platform for humanoid robots.
The article Nvidia bets b...]]></description>
<link>https://tsecurity.de/de/3563216/ai-nachrichten/nvidia-bets-big-on-physical-ai-at-gtc-taipei-with-a-new-world-model-driving-brain-and-open-humanoid-robot/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3563216/ai-nachrichten/nvidia-bets-big-on-physical-ai-at-gtc-taipei-with-a-new-world-model-driving-brain-and-open-humanoid-robot/</guid>
<pubDate>Mon, 01 Jun 2026 15:32:05 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1376" height="768" src="https://the-decoder.com/wp-content/uploads/2026/06/Nvidia-Physical-AI-Taipei.png" class="attachment-full size-full wp-post-image" alt="" decoding="async" fetchpriority="high"></p>
<p>        Nvidia used GTC Taipei to launch a series of models for robots, autonomous vehicles, and video systems. The centerpieces are the new world model Cosmos 3, a significantly scaled-up driving model called Alpamayo 2 Super, and an open reference platform for humanoid robots.</p>
<p>The article <a href="https://the-decoder.com/nvidia-bets-big-on-physical-ai-at-gtc-taipei-with-a-new-world-model-driving-brain-and-open-humanoid-robot/">Nvidia bets big on physical AI at GTC Taipei with a new world model, driving brain, and open humanoid robot</a> appeared first on <a href="https://the-decoder.com/">The Decoder</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[The Download: China’s brain implant ambitions]]></title>
<description><![CDATA[This is today’s edition of The Download, our weekday newsletter that provides a daily dose of what’s going on in the world of technology. China has approved the world’s first invasive brain-computer chip—here’s what’s next Sitting in the courtyard of his house in China’s Henan province last Octob...]]></description>
<link>https://tsecurity.de/de/3563028/ai-nachrichten/the-download-chinas-brain-implant-ambitions/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3563028/ai-nachrichten/the-download-chinas-brain-implant-ambitions/</guid>
<pubDate>Mon, 01 Jun 2026 14:33:05 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[This is today’s edition of The Download, our weekday newsletter that provides a daily dose of what’s going on in the world of technology. China has approved the world’s first invasive brain-computer chip—here’s what’s next Sitting in the courtyard of his house in China’s Henan province last October, Dong Hui decided to try holding a…]]></content:encoded>
</item>
<item>
<title><![CDATA[China has approved the world’s first invasive brain-computer chip—here’s what’s next]]></title>
<description><![CDATA[One day last October, sitting in the courtyard of his house in China’s Henan province, Dong Hui decided to see if he could hold a pen to write.  Dong, 39, had sustained spinal cord injuries in a car accident six years earlier that left him paralyzed from the neck down. Slowly but determinedly, he...]]></description>
<link>https://tsecurity.de/de/3562930/ai-nachrichten/china-has-approved-the-worlds-first-invasive-brain-computer-chip-heres-whats-next/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3562930/ai-nachrichten/china-has-approved-the-worlds-first-invasive-brain-computer-chip-heres-whats-next/</guid>
<pubDate>Mon, 01 Jun 2026 14:03:40 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[One day last October, sitting in the courtyard of his house in China’s Henan province, Dong Hui decided to see if he could hold a pen to write.  Dong, 39, had sustained spinal cord injuries in a car accident six years earlier that left him paralyzed from the neck down. Slowly but determinedly, he wrote…]]></content:encoded>
</item>
<item>
<title><![CDATA[The neocloud vendor trap: New infrastructure, same old risk]]></title>
<description><![CDATA[There is a governance gap at the center of enterprise AI infrastructure strategy. Most organizations cannot see it because they have not yet been forced to look. Neoclouds have moved from early-adopter experiments to mainstream enterprise deployments. The risk frameworks required to govern those ...]]></description>
<link>https://tsecurity.de/de/3562757/it-security-nachrichten/the-neocloud-vendor-trap-new-infrastructure-same-old-risk/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3562757/it-security-nachrichten/the-neocloud-vendor-trap-new-infrastructure-same-old-risk/</guid>
<pubDate>Mon, 01 Jun 2026 13:06:16 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>There is a governance gap at the center of enterprise AI infrastructure strategy. Most organizations cannot see it because they have not yet been forced to look. Neoclouds have moved from early-adopter experiments to mainstream enterprise deployments. The risk frameworks required to govern those deployments have not kept pace. The CIOs who close it first will define responsible AI infrastructure leadership for the next decade. No published framework combines a scored vendor evaluation tool, a contract gate, and a quantified governance ROI. This article does.</p>



<h2 class="wp-block-heading">The speed of adoption has outrun the risk community</h2>



<p>The enterprise cloud market is moving faster than enterprise risk frameworks can track it. Neoclouds, GPU native infrastructure platforms from providers such as CoreWeave, Lambda Labs, and Nebius, are capturing AI workloads at a pace that <a href="https://www.forrester.com/blogs/predictions-2026-cloud-outages-private-ai-on-private-clouds-and-the-rise-of-the-neoclouds/" rel="nofollow">Forrester projects will reach $20 billion in 2026</a>. The Barclays CIO Study, which surveyed 250 enterprise technology leaders, found that 86 percent plan to repatriate at least some public cloud workloads. IDC projects <a href="https://www.biztechreports.com/news-archive/2025/4/15/cloud-infrastructure-spending-continued-in-accelerated-mode-in-the-fourth-quarter-of-2024-as-ai-investment-path-surpasses-the-most-positive-expectations-idc" rel="nofollow">cloud infrastructure spending will exceed $200 billion in 2026</a>. Synergy Research Group reports  <a href="https://www.srgresearch.com/articles/neoclouds-currently-growing-by-over-200-per-year-will-reach-180-billion-in-revenues-by-2030" rel="nofollow">neocloud revenues exceeded $23 billion in 2025,</a> a 200% year-over-year increase. Gartner forecasts <a href="https://www.computerweekly.com/opinion/Gartner-Why-neoclouds-are-the-future-of-GPU-as-a-Service" rel="nofollow">neoclouds will capture 20 percent of the $267 billion AI cloud market by 2030</a>, and enterprise contracts signed in 2024 and 2025 come up for renewal in the second half of 2026, when evaluation criteria shift to production standards: sovereignty, resilience, and compliance. The frameworks built before that window closes determine who leads and who reacts.</p>



<h2 class="wp-block-heading">The operational maturity gap</h2>



<p><a href="https://www.computerweekly.com/feature/Weighing-up-the-enterprise-risks-of-neocloud-providers" rel="nofollow">The gap between neocloud capitalization and operational readiness is a fundamental capability failure</a>: Many have secured GPU capacity; few have demonstrated the incident response, SLA enforcement, and operational transparency enterprise clients require. <a href="https://www.gartner.com/en/newsroom/press-releases/2026-1-15-gartner-says-worldwide-ai-spending-will-total-2-point-5-trillion-dollars-in-2026" rel="nofollow">Gartner projects worldwide AI spending will reach $2.52 trillion in 2026</a>, committed to providers whose behavior under genuine stress is entirely unknown. <a href="https://www.deloitte.com/us/en/what-we-do/capabilities/applied-artificial-intelligence/content/state-of-ai-in-the-enterprise.html" rel="nofollow">Deloitte’s 2026 survey of 3,235 leaders found only 43 percent rate their technical infrastructure as highly prepared for AI</a>. Whether operational maturity has kept pace is the central CIO question.</p>



<p>Tracking 400+ incidents at <a href="https://whencloudsfail.opey.org/" rel="nofollow">whencloudsfail.opey.org</a> shows two patterns: disruption duration correlates with provider concentration, and organizations with exit provisions recover faster at materially lower cost. A Tier 2 European financial institution that committed 80 percent of its AI inference workload to a single neocloud provider faced a mandatory migration when that provider was acquired in early 2025. The enterprise had no portability clause. This institution, running $1.5 million annually in neocloud compute, incurred a $3 million remediation bill that appeared on no budget, plus an estimated $300,000 to $600,000 in revenue disruption above the migration cost itself. A peer organization that had tiered workloads across two providers and maintained contracts with exit provisions completed the same transition in 31 days at 12 percent of the cost. The difference was contractual: MECT Exit Architecture clauses requiring 30-day portability and 90-day migration support turned an unplanned crisis into a managed transition.</p>



<h2 class="wp-block-heading">The compute capacity trap</h2>



<p>The structural risk deepens as compute capacity dynamics evolve. GPU supply remains the most constrained commodity in enterprise technology, reinforced by <a href="https://nvidianews.nvidia.com/news/nvidia-and-coreweave-strengthen-collaboration-to-accelerate-buildout-of-ai-factories" rel="nofollow">NVIDIA’s $2 billion investment in CoreWeave</a> and the resulting capital expenditure race. McKinsey’s neocloud analysis identifies the central risk: Providers that secured GPU capacity before building enterprise-grade operations management are <a href="https://www.mckinsey.com/capabilities/tech-and-ai/our-insights/the-evolution-of-neoclouds-and-their-next-moves" rel="nofollow">structurally fragile, and consolidation will accelerate when demand softens</a>. Enterprises focused on failing providers will face migrations comparable to repatriation exercises that many are still completing. That is evidence that the risk community has not yet been forced to price it. McKinsey identifies the structural reason:  <a href="https://www.mckinsey.com/capabilities/tech-and-ai/our-insights/the-evolution-of-neoclouds-and-their-next-moves" rel="nofollow">BMaaS margins collapse to 14-16 percent after labor, power, and depreciation, and if utilization slips below 80 percent, returns flatline</a>. The financial distress signals are public: <a href="https://investors.coreweave.com/news/news-details/2026/CoreWeave-Reports-Strong-Fourth-Quarter-and-Fiscal-Year-2025-Results/default.aspx" rel="nofollow">CoreWeave’s Q4 2025 earnings set Q1 2026 guidance of $1.9 to $2 billion, below analyst consensus of $2.29 billion, with 2026 CapEx projected at $30 to $35 billion.</a> The company has an Altman Z-Score of 0.52, below the 1.8 distress threshold, and its top customer accounts for nearly 70 percent of revenue while building competing infrastructure.</p>



<p>The GPU assets collateralizing that debt have depreciated 60 to 75 percent from peak, compressing the collateral base as repayment obligations accelerate. Even a 10 percent consolidation scenario results in $2 billion of enterprise workloads being moved in unplanned migrations.</p>



<h2 class="wp-block-heading">The hyperscaler counter move</h2>



<p><a href="https://aws.eu/" rel="nofollow">AWS European Sovereign Cloud</a> and <a href="https://devblogs.microsoft.com/foundry/whats-new-in-microsoft-foundry-feb-2026/" rel="nofollow">Microsoft Foundry Local</a> represent deliberate moves into the territorial advantage that neoclouds built on sovereignty. Forrester has predicted <a href="https://www.forrester.com/blogs/predictions-2026-cloud-outages-private-ai-on-private-clouds-and-the-rise-of-the-neoclouds/" rel="nofollow">at least two major multiday hyperscaler outages in 2026, driven by AI infrastructure complexity</a>, sustaining pressure to rethink cloud concentration across all provider categories. For CIOs, this creates genuine optionality only for organizations that have built evaluation frameworks to exercise it. A second exposure: hyperscalers are subcontracting AI compute to neocloud providers, meaning an enterprise running workloads through a hyperscaler endpoint may be running on neocloud infrastructure with no MECT protections and no visibility into the underlying provider’s financial condition.</p>



<h2 class="wp-block-heading">The MECT framework: Maturity, Exit, Classification, Threshold</h2>



<p>Those frameworks have four components, and organizations executing well implement all of them before the first workload is placed.</p>



<h3 class="wp-block-heading">Component 1: Maturity scoring</h3>



<p>Before contract signature, require documented evidence of incident response procedures, historical availability data across the provider’s production enterprise workloads, SLA penalty structures that carry a minimum 15 percent service credit per breach, and references from enterprise clients who have lived through a significant production incident with that provider. Providers with Series C or later funding and more than two years of enterprise deployments represent the upper maturity tier; <a href="https://www.deloitte.com/us/en/what-we-do/capabilities/applied-artificial-intelligence/content/state-of-ai-in-the-enterprise.html" rel="nofollow">Deloitte confirms only 43 percent of organizations rate their AI infrastructure as highly prepared</a>. Any provider with fewer than 18 months of enterprise history scores zero on availability data by definition, setting the outcome band before the first reference call. The absence of an incident history is not a positive signal. It is a data gap that should trigger deeper diligence, not accelerated commitment.</p>



<h3 class="wp-block-heading">Component 2: Exit architecture</h3>



<p>Every neocloud engagement must be reviewed through an exit lens from day one. Contracts must require data portability standards with a 30-day full export window, prohibit proprietary API lock-in at the API layer, and specify a minimum 90-day obligation for migration assistance. If leaving is contractually expensive or technically complex, the organization has accepted an unpriced risk it has almost certainly not reported to its board.</p>



<h3 class="wp-block-heading">Component 3: Classification by criticality</h3>



<p>A practical tiering model distinguishes three classes: exploratory workloads that can tolerate interruptions, operational workloads where degradation is recoverable within 4 hours, and mission-critical inference, where failure carries immediate financial or regulatory consequences. The sovereignty risk is specific to this category: the majority of neocloud providers are US-headquartered, meaning <a href="https://blog.premai.io/ai-data-residency-requirements-by-region-the-complete-enterprise-compliance-guide/" rel="nofollow">CLOUD Act authority gives US law enforcement compelled access to all data they process, regardless of where the physical data center sits</a>. A CIO selecting a US-headquartered neocloud for EU sovereign AI has not achieved data sovereignty but has accepted a compliance liability that EU AI Act enforcement under Article 5 and Annex III high-risk system obligations <a href="https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai" rel="nofollow">can impose penalties of up to 7 percent of global annual turnover</a>. The EU Digital Operational Resilience Act requires documented vendor oversight and board accountability for critical third-party technology dependencies.</p>



<p>Mission-critical inference workloads with data residency or sovereignty requirements must run on infrastructure whose legal structure aligns with the governance promise made to regulators and boards. This category is the fastest growing: <a href="https://www.abiresearch.com/blog/neocloud-market-trends" rel="nofollow">ABI Research projects inference at 80 percent of neocloud GPUaaS demand by 2030</a>, making the highest risk tier the fastest scaling one.</p>



<h3 class="wp-block-heading">Component 4: Threshold monitoring</h3>



<p>The <a href="https://www.bis.org/publ/bcbs283.htm" rel="nofollow">Basel III framework caps single counterparty exposure at 25 percent of eligible capital</a>. Applied to AI infrastructure, no single neocloud provider should carry more than 25 to 30 percent of mission-critical AI inference capacity without a tested failover architecture. CIOs must report quarterly: provider share by workload class, recovery timeline for a multiday outage, and the rebalancing threshold that triggers action.</p>



<h4 class="wp-block-heading">MECT vendor readiness index: Score your provider before contract</h4>



<figure class="wp-block-table"><div class="overflow-table-wrapper"><table class="has-fixed-layout"><thead><tr><th><strong>Evaluation Criterion</strong></th><th class="has-text-align-center" data-align="center"><strong>0</strong></th><th class="has-text-align-center" data-align="center"><strong>1</strong></th><th class="has-text-align-center" data-align="center"><strong>2</strong></th><th><strong>Weight</strong></th></tr></thead><tbody><tr><td>Incident response runbook: provided, dated within 6 months</td><td class="has-text-align-center" data-align="center">__</td><td class="has-text-align-center" data-align="center">__</td><td class="has-text-align-center" data-align="center">__</td><td>Critical</td></tr><tr><td>Availability data: 24+ months production at enterprise scale</td><td class="has-text-align-center" data-align="center">__</td><td class="has-text-align-center" data-align="center">__</td><td class="has-text-align-center" data-align="center">__</td><td>Critical</td></tr><tr><td>Enterprise client references: 3+ with incident experience      </td><td class="has-text-align-center" data-align="center">__</td><td class="has-text-align-center" data-align="center">__</td><td class="has-text-align-center" data-align="center">__</td><td>Critical</td></tr><tr><td>SLA: minimum 15% credit per breach, penalties defined </td><td class="has-text-align-center" data-align="center">__</td><td class="has-text-align-center" data-align="center">__</td><td class="has-text-align-center" data-align="center">__</td><td>Standard</td></tr><tr><td>Portability: API-neutral export, 30-day transition clause</td><td class="has-text-align-center" data-align="center">__</td><td class="has-text-align-center" data-align="center">__</td><td class="has-text-align-center" data-align="center">__</td><td>Standard</td></tr><tr><td>Ownership: sovereign mandate or no acquisition cliff disclosed </td><td class="has-text-align-center" data-align="center">__</td><td class="has-text-align-center" data-align="center">__</td><td class="has-text-align-center" data-align="center">__</td><td>Standard</td></tr></tbody></table> </div></figure>



<p>SCORE BANDS:  0-4 = DO NOT PROCEED  |  5-8 = CONDITIONAL  |  9-12 = CLEARED<br><em>Score each criterion: 0 = not present, 1 = partially documented, 2 = fully verified. Total out of 12.</em></p>



<h4 class="wp-block-heading">MECT contract gate: Required clauses before signature</h4>



<figure class="wp-block-table"><div class="overflow-table-wrapper"><table class="has-fixed-layout"><thead><tr><th><strong>Component</strong></th><th><strong>Required contract clause</strong></th><th><strong>Status</strong></th></tr></thead><tbody><tr><td>Maturity</td><td>Min SLA: 15% credit per breach; 99.9% uptime floor</td><td>PASS / FAIL</td></tr><tr><td>Maturity</td><td>Right to audit: runbook and incident logs on demand</td><td>PASS / FAIL</td></tr><tr><td>Exit</td><td>Data portability: full export within 30 days </td><td>PASS / FAIL</td></tr><tr><td>Exit</td><td>Migration assistance: 90-day transition support</td><td>PASS / FAIL</td></tr><tr><td>Class.</td><td>Workload schedule: criticality tier per endpoint</td><td>PASS / FAIL</td></tr><tr><td>Class.</td><td>Jurisdiction: legal HQ and CLOUD Act exposure</td><td>PASS / FAIL</td></tr><tr><td>Threshold</td><td>Concentration cap: provider share ceiling in contract</td><td>PASS / FAIL</td></tr><tr><td>Threshold</td><td>Failover: tested alternate architecture within 60 days</td><td>PASS / FAIL</td></tr><tr><td>Class.</td><td>Subcontracting: all underlying compute providers disclosed</td><td>PASS / FAIL</td></tr></tbody></table> </div></figure>



<p>Any FAIL = contract not ready for signature. Escalate to General Counsel.</p>



<h2 class="wp-block-heading">The sovereignty intention gap</h2>



<p><a href="https://www.gartner.com/en/newsroom/press-releases/2026-02-09-gartner-says-worldwide-sovereign-cloud-iaas-spending-will-total-us-dollars-80-billion-in-2026" rel="nofollow">Gartner projects worldwide sovereign cloud IaaS spending will reach $80 billion in 2026</a>, driven by what Gartner terms geopatriation: the deliberate shift of workloads from global providers to local infrastructure for regulatory and geopolitical reasons. <a href="https://www.deloitte.com/us/en/what-we-do/capabilities/applied-artificial-intelligence/content/state-of-ai-in-the-enterprise.html" rel="nofollow">Deloitte’s 2026 State of AI survey of 3,235 leaders across 24 countries</a> found that 83 percent view sovereign AI as strategically important, 77 percent factor country of origin into vendor selection, and 66 percent are concerned about foreign-owned AI infrastructure. <a href="https://www.mckinsey.com/capabilities/mckinsey-digital/our-insights/sovereign-ai-ecosystems" rel="nofollow">McKinsey confirms the gap: Widespread interest, almost no executable action plans</a>. Organizations declaring sovereign AI as a board priority without completing workload classification are making commitments their infrastructure cannot honor. The MECT Framework closes that gap before a provider incident makes it a crisis response.</p>



<h2 class="wp-block-heading">The competitive consequence of waiting</h2>



<p>The financial case is in the incident record: the organization without exit provisions absorbed a $3 million remediation bill on a $1.5 million annual compute base, while the organization with MECT disciplines completed the same transition at 12 percent of that cost, a $2.64 million difference. Forrester documents <a href="https://www.forrester.com/blogs/predictions-2026-cloud-outages-private-ai-on-private-clouds-and-the-rise-of-the-neoclouds/" rel="nofollow">that enterprise deployments in this category are tripling year over year while governance frameworks remain at their starting point</a>. Organizations with a governance architecture in place compress decision cycles and capture the neocloud cost advantage: up to 66 percent savings versus hyperscaler GPU rates, without the unpriced risk that erodes those savings on the first unplanned migration. That combination of risk reduction and cost capture is the governance ROI the board has been waiting for a CIO to quantify.</p>



<p>The board conversation about AI infrastructure risk is coming for every organization. The only question is whether CIOs are leading it or responding to it.</p>



<p><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><strong><a href="https://www.cio.com/expert-contributor-network/">Want to join?</a></strong></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Xbox fan backlash to "PlayStation logos in the Showcase" isn't about gatekeeping — it's about distrust]]></title>
<description><![CDATA[Everybody with a brain knows it takes five seconds to go online and find out whether a game is multiplatform. Microsoft's logo "transparency" simply has users doubting whether it's truly behind Xbox's long-term success.]]></description>
<link>https://tsecurity.de/de/3562610/windows-tipps/xbox-fan-backlash-to-playstation-logos-in-the-showcase-isnt-about-gatekeeping-its-about-distrust/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3562610/windows-tipps/xbox-fan-backlash-to-playstation-logos-in-the-showcase-isnt-about-gatekeeping-its-about-distrust/</guid>
<pubDate>Mon, 01 Jun 2026 12:08:52 +0200</pubDate>
<category>🪟 Windows Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Everybody with a brain knows it takes five seconds to go online and find out whether a game is multiplatform. Microsoft's logo "transparency" simply has users doubting whether it's truly behind Xbox's long-term success.]]></content:encoded>
</item>
<item>
<title><![CDATA[Ozempic May Be Reshaping the Brain, Scientists Say]]></title>
<description><![CDATA[A research team found "extensive changes" on brain scans of 13 young women taking
GLP-1 drugs, reports the Washington Post:


Within only a few months, the brain connections in the salience network, which helps target attention, had multiplied... ["We didn't expect to see this effect, and we real...]]></description>
<link>https://tsecurity.de/de/3559383/it-security-nachrichten/ozempic-may-be-reshaping-the-brain-scientists-say/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3559383/it-security-nachrichten/ozempic-may-be-reshaping-the-brain-scientists-say/</guid>
<pubDate>Sat, 30 May 2026 18:49:36 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A research team found "extensive changes" on brain scans of 13 young women taking
GLP-1 drugs, reports the Washington Post:


Within only a few months, the brain connections in the salience network, which helps target attention, had multiplied... ["We didn't expect to see this effect, and we really don't know what it means," said an assistant professor assisting the research.] Ozempic and other GLP-1 drugs were initially understood as a metabolism breakthrough: medicines that act like hormones to control hunger, blood sugar and weight. But as researchers probe deeper into how the drugs work, early evidence suggests that GLP-1s may also be reshaping parts of the brain. 


Tens of millions of people are now taking the medications worldwide, turning what began as an obesity and diabetes treatment into what could be modern medicine's largest unplanned neuroscience experiments... Long before Oprah Winfrey and social media influencers helped popularize GLP-1 drugs, physician-scientist Lorenzo Leggio was studying them as a possible addiction treatment... Several major studies examining GLP-1 drugs on nicotine dependence, opioid- and cocaine-use disorders, gambling addiction and binge eating are also underway. "It's very exciting times, but we don't fully understand how it works," Leggio said... 

As evidence has grown that inflammation, metabolism and mental health may be far more connected than scientists once believed, researchers have become intrigued by patients who say GLP-1 drugs appear to ease anxiety, compulsive thinking and emotional distress. Daniel Drucker, a University of Toronto researcher and GLP-1 drug pioneer who receives funding from several drugmakers, said researchers are investigating the medications across a variety of psychiatric and neurological conditions, though none are approved for them. "We have so many anecdotal reports: They were treated for blood sugar and then they felt much happier. Or they took one dose of the drug and their brain fog cleared," he said. 

The article suggests social media complaints "raise deeper questions about what, exactly, these drugs are changing. 

"If GLP-1s alter the brain systems involved in reward, craving and motivation, researchers wonder, where is the line between quieting a person's destructive impulses and reshaping personality itself?"<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=Ozempic+May+Be+Reshaping+the+Brain%2C+Scientists+Say%3A+https%3A%2F%2Fscience.slashdot.org%2Fstory%2F26%2F05%2F30%2F0411212%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fscience.slashdot.org%2Fstory%2F26%2F05%2F30%2F0411212%2Fozempic-may-be-reshaping-the-brain-scientists-say%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://science.slashdot.org/story/26/05/30/0411212/ozempic-may-be-reshaping-the-brain-scientists-say?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[AI agents are entering their rebuild era as enterprises confront the reliability problem]]></title>
<description><![CDATA[As enterprise AI agents move into production, organizations are confronting a growing reliability problem. Many teams are discovering that LLM performance alone does not determine whether agents succeed in production. Long-running AI workflows must survive crashes, preserve state, recover from fa...]]></description>
<link>https://tsecurity.de/de/3557170/it-nachrichten/ai-agents-are-entering-their-rebuild-era-as-enterprises-confront-the-reliability-problem/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3557170/it-nachrichten/ai-agents-are-entering-their-rebuild-era-as-enterprises-confront-the-reliability-problem/</guid>
<pubDate>Fri, 29 May 2026 17:47:51 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>As enterprise AI agents move into production, organizations are confronting a growing reliability problem. Many teams are discovering that LLM performance alone does not determine whether agents succeed in production. Long-running AI workflows must survive crashes, preserve state, recover from failures, manage inference costs, and coordinate across APIs, tools, and enterprise systems.</p><p>After a first wave focused on rapid deployment, organizations now need to revisit those first-generation implementations, and redesign early agent architectures around workflow orchestration, observability, governance, and recovery, said Preeti Somal, Senior VP Engineering at Temporal Technologies, during the latest AI Impact Series event in New York. </p><p>“We do have a lot of customers that come to us where they’re building version 2.0 of the same agent,” Somal said. “They had to move really fast, but they didn’t take care of the plumbing. Things crash and burn, and then they’re back to rebuilding with the reliable foundation.”</p><p>For workflow orchestration company Temporal, whose infrastructure predates the current wave of agentic AI, the shift reflects a broader enterprise realization: production AI systems require durable execution, state management, visibility into workflows, and mechanisms to recover when models or downstream systems fail. </p><h2>Agentic AI has supercharged familiar engineering problems</h2><p>“These patterns aren’t necessarily new," Somal said. " AI just supercharges them."</p><p>Agentic systems introduce additional complexity because they often involve long-running, multi-step processes spanning multiple services, models, APIs, and tools. A single workflow might call several large language models, access retrieval systems, trigger external applications, and manage state over hours or days. The engineering questions, Somal said, often emerge only after deployment.</p><p>“People will write agents but haven’t thought about what happens if the agent crashes,” she said. “Am I going to need to run the entire agent flow again?” </p><p>For enterprises operating under cost constraints, the answer matters. Restarting workflows after failures can multiply inference expenses, increase latency, and create poor customer experiences.</p><p>Somal compared the current moment to an earlier period in enterprise cloud adoption when organizations went straight to migrating workloads before considering that they needed to redesign underlying architectures if they wanted these workloads to weather the long-term.</p><p>“This rush to do AI in a world where you haven’t even modernized your application reminds me a little bit of that lift-and-shift that happened in the cloud,” she said. “Everybody realized you’re spending more money on cloud and we haven’t gotten value there.” </p><h2>Why long-running agents force a new architecture</h2><p>Enterprise workflows increasingly involve agents executing over long windows, sometimes spanning many hours while interacting with tools and systems. Reliability challenges compound when workflows persist over time, and it impacts both state and memory, two ideas that are often treated interchangeably in AI conversations.</p><p>State concerns workflow execution. It includes where an agent is in a process, which actions have already completed, and where recovery should resume after failure. Memory or context captures information an agent carries forward across interactions or tasks.</p><p>“The state of the agent is around what step and what actions have been performed, and if something crashes, where do you want to recover from, versus the context and memory piece,” Somal explained. </p><p>That distinction becomes increasingly important when enterprises begin moving beyond simple chatbot interactions toward longer-running business processes. Somal pointed to a healthcare example involving customer Abridge, where workflows process physician visits through multiple stages, including audio processing, summarization, model calls, and after-visit generation.</p><p>“There’s not just one piece to that flow,” Somal said. “Taking videos and slicing that, taking summaries, calling the LLMs, generating the after-visit summary, all of that is being orchestrated.” </p><p>The implication for enterprises is that successful agents increasingly depend on systems that can survive interruptions, coordinate across services, and maintain continuity over time.</p><h2>The rise of the deterministic spine</h2><p>A useful framework for enterprise AI design is the deterministic spine, Somal said, which is how they think about Temporal's role. </p><p>“It is denoting the path you want to take," she said. "It is calling the brain, but if the brain doesn’t respond, it will call it again. If the brain responds but the next step is going to fail, it will pick up from where that failure happened.” </p><p>In this framing, the language model acts as a probabilistic system producing variable outputs, while orchestration software maintains execution reliability around it. And the concept matters because enterprise systems increasingly require consistency even when models remain non-deterministic. A procurement workflow, healthcare summary, customer support escalation, or compliance process cannot simply fail silently because a model call timed out or an external dependency crashed.</p><p>“What you care most about is making sure that you can recover and that you’re not paying the token tax if something goes wrong,” Somal said. </p><h2>Reliability, visibility, and the economics of token spend</h2><p>As enterprise leaders evaluate AI ROI, cost visibility has become a growing concern. Long-running agents frequently make multiple model calls across complex workflows, which can create opaque spending patterns. Somal described one operational advantage of orchestration as visibility into where costs accumulate. Because workflows are observable step-by-step, teams can see where tokens are being consumed across an agent process.</p><p>“You’ve got visibility into that entire flow in a single pane of glass,” she said. “You can now see where you’re spending the tokens in an agent that is multiple steps and calling multiple different systems.” </p><p>Workflow recovery also shapes cost efficiency. Without durable orchestration, a late-stage failure can force organizations to rerun an entire process from the beginning, including all prior model calls. Somal said systems designed around recovery can resume execution from the point of interruption.</p><p>“You pick up from where the crash happened,” she said. “We save you the cost of running the agent from step one again.” </p><h2>Enterprises need to build paved paths and enlist partner expertise</h2><p>Governance concerns are another emerging pattern as agentic AI takes hold. Rather than adopting fully managed agent systems wholesale, Somal said enterprises increasingly want standardized internal frameworks that provide guardrails while preserving flexibility, and implementing necessary features like governance controls, model selection policies, identity systems, cost management, and observability. </p><p>“The enterprises are looking at building these paved paths,” she said. “Taking something off the shelf is maybe not going to work because there are all of these other requirements.” </p><p>As organizations revisit first-generation deployments, challenges like this increasingly look less like a model problem and more like a systems engineering problem, and Temporal is positioned to help enterprises take this next step in part because for many organizations, it already existed as part of broader modernization programs before AI became a strategic priority.</p><p>“Temporal is already in the enterprise,” Somal said. “Taking that and extending that to AI and agent platforms feels very natural.” </p><p></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Investigating how hormones affect brain health]]></title>
<description><![CDATA[UL’s Prof George Barreto discusses his research and how it could help form new treatments for treating and protecting the brain.
Read more: Investigating how hormones affect brain health]]></description>
<link>https://tsecurity.de/de/3556953/it-nachrichten/investigating-how-hormones-affect-brain-health/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3556953/it-nachrichten/investigating-how-hormones-affect-brain-health/</guid>
<pubDate>Fri, 29 May 2026 15:02:25 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>UL’s Prof George Barreto discusses his research and how it could help form new treatments for treating and protecting the brain.</p>
<p>Read more: <a rel="nofollow" href="https://www.siliconrepublic.com/innovation/investigating-how-hormones-affect-brain-health">Investigating how hormones affect brain health</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[This Week In Rust: This Week in Rust 653]]></title>
<description><![CDATA[Hello and welcome to another issue of This Week in Rust!
Rust is a programming language empowering everyone to build reliable and efficient software.
This is a weekly summary of its progress and community.
Want something mentioned? Tag us at
@thisweekinrust.bsky.social on Bluesky or
@ThisWeekinRu...]]></description>
<link>https://tsecurity.de/de/3553405/tools/this-week-in-rust-this-week-in-rust-653/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3553405/tools/this-week-in-rust-this-week-in-rust-653/</guid>
<pubDate>Thu, 28 May 2026 10:25:02 +0200</pubDate>
<category>💾  Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Hello and welcome to another issue of <em>This Week in Rust</em>!
<a href="https://www.rust-lang.org/">Rust</a> is a programming language empowering everyone to build reliable and efficient software.
This is a weekly summary of its progress and community.
Want something mentioned? Tag us at
<a href="https://bsky.app/profile/thisweekinrust.bsky.social">@thisweekinrust.bsky.social</a> on Bluesky or
<a href="https://mastodon.social/@thisweekinrust">@ThisWeekinRust</a> on mastodon.social, or
<a href="https://github.com/rust-lang/this-week-in-rust">send us a pull request</a>.
Want to get involved? <a href="https://github.com/rust-lang/rust/blob/main/CONTRIBUTING.md">We love contributions</a>.</p>
<p><em>This Week in Rust</em> is openly developed <a href="https://github.com/rust-lang/this-week-in-rust">on GitHub</a> and archives can be viewed at <a href="https://this-week-in-rust.org/">this-week-in-rust.org</a>.
If you find any errors in this week's issue, <a href="https://github.com/rust-lang/this-week-in-rust/pulls">please submit a PR</a>.</p>
<p>Want TWIR in your inbox? <a href="https://this-week-in-rust.us11.list-manage.com/subscribe?u=fd84c1c757e02889a9b08d289&amp;id=0ed8b72485">Subscribe here</a>.</p>
<h4><a class="toclink" href="https://this-week-in-rust.org/atom.xml#updates-from-rust-community">Updates from Rust Community</a></h4>


<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#newsletters">Newsletters</a></h5>
<ul>
<li><a href="https://scientificcomputing.rs/monthly/2026-05">Scientific Computing in Rust #18 (May 2026)</a></li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#projecttooling-updates">Project/Tooling Updates</a></h5>
<ul>
<li><a href="https://github.com/GitoxideLabs/gitoxide/discussions/2621">gitoxide - May 26</a></li>
<li><a href="https://seanmonstar.com/blog/hyper-user-survey-2025-results/">hyper User Survey 2025 Results</a></li>
<li><a href="https://grpc.io/blog/grpc-welcomes-tonic/">Rust Update: gRPC Welcomes Tonic!</a></li>
<li><a href="https://github.com/ifsheldon/serde-const-default/releases/tag/v0.1">serde-const-default v0.1: Removes boilerplate when using const values as field defaults</a></li>
<li><a href="https://github.com/boquila/boquilahub/releases/tag/v0.5">BoquilaHUB 0.5: AIs for Nature. Now it includes SOTA AI bioacoustics models and embeddings models</a></li>
<li><a href="https://www.sextianbytes.fr/blog/imperfect-by-design/">splog: a log viewer TUI with automatic tag categorization</a></li>
<li><a href="https://dev.to/brevity1swos/building-a-regex-debugger-for-the-terminal-in-rust-977">rgx v0.12.3 — Building a regex debugger for the terminal in Rust</a></li>
<li><a href="https://davefx.com/en/2026/05/clipboardwire-construction-story/">UI tests are the guardrails an AI needs: the story of clipboardwire</a></li>
<li><a href="https://github.com/stevekwon211/slintcn/blob/main/docs/INTRODUCING_SLINTCN.md">slintcn 0.22: shadcn/ui-style copy-paste components for Slint native apps</a></li>
<li><a href="https://users.rust-lang.org/t/releasing-dtact-v0-2-2-and-rssn-advanced-v0-1-0/140278">Releasing dtact v0.2.2 and rssn-advanced v0.1.0: the next generation async concurrent engine and scientific computing engine</a></li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#observationsthoughts">Observations/Thoughts</a></h5>
<ul>
<li><a href="https://tritium.legal/blog/noroboto">Noroboto: Lying Fonts and Mitigation in Rust</a></li>
<li><a href="https://wolfgirl.dev/blog/2026-05-20-erasing-existentials/">Erasing Existentials</a></li>
<li><a href="https://yogthos.net/posts/2026-05-24-libwce.html">libwce: the entropy layer of a wavelet codec, on its own</a></li>
<li><a href="https://neugierig.org/software/blog/2026/05/theseus-wasm.html">Tech Notes: Theseus: translating win32 to wasm</a></li>
<li><a href="https://aibodh.com/posts/bevy-game-engine/">Bevy Game Engine Explained Visually</a></li>
<li><a href="https://verrchu.github.io/blog/3-the-reflex-of-deriving-serde-traits/">The reflex of deriving <code>serde</code> traits</a></li>
<li><a href="https://aimdb.dev/blog/typed-world-model">Physical AI Needs a Typed World Model, Not a Vector DB</a></li>
<li><a href="https://kerkour.com/rust-monorepos">Keep calm and use (Rust) monorepos</a></li>
<li>[audio] <a href="https://corrode.dev/podcast/s06e04-rust4linux/">Rust for Linux Live with Alice Ryhl and Greg Kroah-Hartman</a></li>
<li>[audio] <a href="https://netstack.fm/#episode-38">Netstack.FM episode 38 — Building and testing network stacks with Rama</a></li>
<li>[video] <a href="https://www.youtube.com/watch?v=RbmkNSqMvZY">Can a QR code be made of stars?</a></li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#rust-walkthroughs">Rust Walkthroughs</a></h5>
<ul>
<li><a href="https://microsoft.github.io/RustTraining/rust-patterns-book/">Rust Patterns &amp; Engineering How-Tos</a></li>
<li><a href="https://hemomorphic.alexblood.net/posts/laissez-faire-errors/">Laissez-Faire Errors</a></li>
<li><a href="https://blog.sheerluck.dev/posts/learn-hashmap-iterators-by-building-a-git-object-store-reader/">Learn Rust HashMap and Iterators by Building a Git Object Store Reader</a></li>
<li><a href="https://blog.sheerluck.dev/posts/learn-the-basics-of-bevy-by-building-and-deploying-pong-to-itch-io/">Learn the Basics of Bevy by Building and Deploying Pong to Itch.io</a></li>
<li><a href="https://cong-or.xyz/false-sharing-cache-lines.html">The Slowdown That Doesn't Show Up in Profiles</a></li>
<li><a href="https://blog.cat-girl.gay/3ds-async-part-one/">Building an AsyncIO executor for the 3DS</a></li>
<li>[video] <a href="https://www.youtube.com/watch?v=3IyKC5EtNkM">Nine Ways to do Inheritance in Rust, a Language without Inheritance</a></li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#miscellaneous">Miscellaneous</a></h5>
<ul>
<li><a href="https://kunobi.ninja/blog/what-kache-actually-caches">Content-addressed Rust builds (or, what kache actually caches)</a></li>
</ul>
<h4><a class="toclink" href="https://this-week-in-rust.org/atom.xml#crate-of-the-week">Crate of the Week</a></h4>
<p>This week's crate is <a href="https://docs.rs/inline_tweak">inline_tweak</a>, a crate to embed tweakable constants inside your Rust application without full recompilation.</p>
<p>Thanks to <a href="https://users.rust-lang.org/t/crate-of-the-week/2704/1607">Kill The Mule</a> for the suggestion!</p>
<p><a href="https://users.rust-lang.org/t/crate-of-the-week/2704">Please submit your suggestions and votes for next week</a>!</p>
<h4><a class="toclink" href="https://this-week-in-rust.org/atom.xml#calls-for-testing">Calls for Testing</a></h4>
<p>An important step for RFC implementation is for people to experiment with the
implementation and give feedback, especially before stabilization.</p>
<p>If you are a feature implementer and would like your RFC to appear in this list, add a
<code>call-for-testing</code> label to your RFC along with a comment providing testing instructions and/or
guidance on which aspect(s) of the feature need testing.</p>
<p><em>No calls for testing were issued this week by
<a href="https://github.com/rust-lang/rust/issues?q=state%3Aopen%20label%3Acall-for-testing%20state%3Aopen">Rust</a>,
<a href="https://github.com/rust-lang/cargo/issues?q=state%3Aopen%20label%3Acall-for-testing%20state%3Aopen">Cargo</a>,
<a href="https://github.com/rust-lang/rustup/issues?q=state%3Aopen%20label%3Acall-for-testing%20state%3Aopen">Rustup</a> or
<a href="https://github.com/rust-lang/rfcs/issues?q=label%3Acall-for-testing%20state%3Aopen">Rust language RFCs</a>.</em></p>
<p><a href="https://github.com/rust-lang/this-week-in-rust/issues">Let us know</a> if you would like your feature to be tracked as a part of this list.</p>
<h4><a class="toclink" href="https://this-week-in-rust.org/atom.xml#call-for-participation-projects-and-speakers">Call for Participation; projects and speakers</a></h4>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#cfp-projects">CFP - Projects</a></h5>
<p>Always wanted to contribute to open-source projects but did not know where to start?
Every week we highlight some tasks from the Rust community for you to pick and get started!</p>
<p>Some of these tasks may also have mentors available, visit the task page for more information.</p>
<ul>
<li><a href="https://github.com/rust-lang-nursery/rust-cookbook/issues/760">rust cookbook - Expand Command Line section with clap derive, subcommands, and env vars</a></li>
</ul>




<p>If you are a Rust project owner and are looking for contributors, please submit tasks <a href="https://github.com/rust-lang/this-week-in-rust?tab=readme-ov-file#call-for-participation-guidelines">here</a> or through a <a href="https://github.com/rust-lang/this-week-in-rust">PR to TWiR</a> or by reaching out on <a href="https://bsky.app/profile/thisweekinrust.bsky.social">Bluesky</a> or <a href="https://mastodon.social/@thisweekinrust">Mastodon</a>!</p>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#cfp-events">CFP - Events</a></h5>
<p>Are you a new or experienced speaker looking for a place to share something cool? This section highlights events that are being planned and are accepting submissions to join their event as a speaker.</p>


<ul>
<li><em>No Calls for papers or presentations were submitted this week.</em></li>
</ul>
<p>If you are an event organizer hoping to expand the reach of your event, please submit a link to the website through a <a href="https://github.com/rust-lang/this-week-in-rust">PR to TWiR</a> or by reaching out on <a href="https://bsky.app/profile/thisweekinrust.bsky.social">Bluesky</a> or <a href="https://mastodon.social/@thisweekinrust">Mastodon</a>!</p>
<h4><a class="toclink" href="https://this-week-in-rust.org/atom.xml#updates-from-the-rust-project">Updates from the Rust Project</a></h4>
<p>352 pull requests were <a href="https://github.com/search?q=is%3Apr+org%3Arust-lang+is%3Amerged+merged%3A2026-05-19..2026-05-26">merged in the last week</a></p>
<h6><a class="toclink" href="https://this-week-in-rust.org/atom.xml#compiler">Compiler</a></h6>
<ul>
<li><a href="https://github.com/rust-lang/rust/pull/156161"><code>rustc_on_unimplemented</code>: introduce format specifiers</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/156763">account for proc macro spans in <code>do_not_recommend</code> diagnostics</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/155598">implement fast path for <code>derive(PartialOrd)</code> when deriving <code>Ord</code></a></li>
<li><a href="https://github.com/rust-lang/rust/pull/153640">make bitset <code>would_modify_words</code> more vectorzer-friendly</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/156824">parse <code>mut</code> restrictions</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/156116">stop needing materialized places for most intrinsics</a></li>
</ul>
<h6><a class="toclink" href="https://this-week-in-rust.org/atom.xml#library">Library</a></h6>
<ul>
<li><a href="https://github.com/rust-lang/rust/pull/156828">add unstable Share trait</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/156594">stabilize <code>bool_to_result</code></a></li>
<li><a href="https://github.com/rust-lang/rust/pull/152112">use strongly typed wrapped indices in <code>VecDeque</code></a></li>
</ul>
<h6><a class="toclink" href="https://this-week-in-rust.org/atom.xml#cargo">Cargo</a></h6>
<ul>
<li><a href="https://github.com/rust-lang/cargo/pull/17006">compiler: forward verbose flag to rustc for local crates</a></li>
<li><a href="https://github.com/rust-lang/cargo/pull/17027">don't use the network for a publish dry-run test</a></li>
<li><a href="https://github.com/rust-lang/cargo/pull/17011">break out <code>RegistryConfig</code> and <code>crate_url</code> for interpreting <code>RegistryConfig::dl</code></a></li>
<li><a href="https://github.com/rust-lang/cargo/pull/17031">fix CVE-2026-5222 and CVE-2026-5223</a></li>
<li><a href="https://github.com/rust-lang/cargo/pull/17016">artifact: remove compat mode from artifacts</a></li>
</ul>
<h6><a class="toclink" href="https://this-week-in-rust.org/atom.xml#rustdoc">Rustdoc</a></h6>
<ul>
<li><a href="https://github.com/rust-lang/rust/pull/155307">stabilize <code>--remap-path-prefix</code> in rustdoc</a></li>
</ul>
<h6><a class="toclink" href="https://this-week-in-rust.org/atom.xml#clippy">Clippy</a></h6>
<ul>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17060"><code>useless_format</code>: fire on wrapped in a block-producing macro</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/16959"><code>return</code> can be removed from the last stmt of a block if it has an expr</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17025">add check for midpoint using multiplication by <code>0.5</code> and <code>&gt;&gt; 1</code></a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17057">avoid unnecessary <code>String</code> allocations in <code>MinifyingSugg</code> arithmetic ops</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/16767">extend <code>clippy::missing_safety_doc</code> to unsafe fields</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17065">fix <code>manual_range_contains</code> NAN handling</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17036">fix error message for <code>useless_borrows_in_formatting</code> for mutable borrows</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/16998">move <code>unnecessary_get_then_check</code> to <code>complexity</code></a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17055">simplify <code>is_some() &amp;&amp; …unwrap()</code> to <code>is_some_and</code> in <code>unit_arg</code></a></li>
</ul>
<h6><a class="toclink" href="https://this-week-in-rust.org/atom.xml#rust-analyzer">Rust-Analyzer</a></h6>
<ul>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22406"><code>diagnostics: mut_ref</code> binding feature diagnostic</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22342"><code>assists/add_reference_here: _modify_</code> the reference type when dealing with <code>&amp;T-&gt;&amp;mut T</code></a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22426"><code>cfg</code>: correct separator index in CfgDiff disable loop</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22430"><code>hir-ty</code>: saturate float-to-uint cast in const eval</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22427"><code>test-utils</code>: drain <code>inactive_regions</code> by <code>inactive_line_region</code></a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22411">add diagnostic for E0033</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22404">add diagnostic for E0608</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22416">completions imports exclude supports sub items</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22432">filter package-scoped features</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22437"><code>extract_module</code> missing import for macro calls</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22452">add <code>type_match</code> score for <code>struct_pat</code></a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22415">allow wildcard params in foreign fn declarations</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22449">analysis expected ty in <code>enum</code> variant</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22385">autoimport <code>enum</code> variants</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22392">do not autoref in method probe in path mode</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22408">do not complete semicolon in match-expr place</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22397">do not consider the path of the macro in a macro call to be inside a macro call</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22424">emit diagnostic for rest array patterns without fixed-length arrays</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/21566">fix <code>SyntaxContext::root</code>s technically overlapping valid interneds</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22451">flip <code>coerce_never type_mismatch</code> tys</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22383">have a specific error for unimplemented builtin macros</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22409">no suggest ref match when expected generic ref</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22369">no use sad pattern on happy arm with guard</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22425">normalize expected tuple <code>struct</code> pat field</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22252">refactor handling of generic params in <code>hir::Type</code></a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22396">support named consts in range pattern types</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22419">use grouped annotation for <code>add_label_to_loop</code></a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22322">provide better incrementality for modules</a></li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#rust-compiler-performance-triage">Rust Compiler Performance Triage</a></h5>
<p>This week was largely positive, with most of the improvements coming from algorithm change in visibility checking: <a href="https://github.com/rust-lang/rust/pull/156228">#156228</a>.</p>
<p>Triage done by <strong>@panstromek</strong>.
Revision range: <a href="https://perf.rust-lang.org/?start=281c97c3240a9abd984ca0c6a2cd7389115e80d5&amp;end=783eb8c8682ddde0807c60ed8293670ef523794f&amp;absolute=false&amp;stat=instructions%3Au">281c97c3..783eb8c8</a></p>
<p><strong>Summary</strong>:</p>
<table>
<thead>
<tr>
<th>(instructions:u)</th>
<th>mean</th>
<th>range</th>
<th>count</th>
</tr>
</thead>
<tbody>
<tr>
<td>Regressions ❌ <br> (primary)</td>
<td>0.4%</td>
<td>[0.1%, 0.7%]</td>
<td>5</td>
</tr>
<tr>
<td>Regressions ❌ <br> (secondary)</td>
<td>0.5%</td>
<td>[0.1%, 1.1%]</td>
<td>16</td>
</tr>
<tr>
<td>Improvements ✅ <br> (primary)</td>
<td>-0.9%</td>
<td>[-6.6%, -0.1%]</td>
<td>164</td>
</tr>
<tr>
<td>Improvements ✅ <br> (secondary)</td>
<td>-0.4%</td>
<td>[-1.3%, -0.1%]</td>
<td>51</td>
</tr>
<tr>
<td>All ❌✅ (primary)</td>
<td>-0.9%</td>
<td>[-6.6%, 0.7%]</td>
<td>169</td>
</tr>
</tbody>
</table>
<p>2 Regressions, 2 Improvements, 5 Mixed; 2 of them in rollups
34 artifact comparisons made in total</p>
<p><a href="https://github.com/rust-lang/rustc-perf/blob/4e9e90ee6ec008cadd1f351541185eff56319998/triage/2026/2026-05-25.md">Full report here</a></p>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#approved-rfcs"></a><a href="https://github.com/rust-lang/rfcs/commits/master">Approved RFCs</a></h5>
<p>Changes to Rust follow the Rust <a href="https://github.com/rust-lang/rfcs#rust-rfcs">RFC (request for comments) process</a>. These
are the RFCs that were approved for implementation this week:</p>
<ul>
<li><a href="https://github.com/rust-lang/rfcs/pull/3946">Propose the concept of a crates.io username for identity</a></li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#final-comment-period">Final Comment Period</a></h5>
<p>Every week, <a href="https://www.rust-lang.org/team.html">the team</a> announces the 'final comment period' for RFCs and key PRs
which are reaching a decision. Express your opinions now.</p>
<h6><a class="toclink" href="https://this-week-in-rust.org/atom.xml#tracking-issues-prs">Tracking Issues &amp; PRs</a></h6>
<a class="toclink" href="https://this-week-in-rust.org/atom.xml#compiler-team-mcps-only"></a><a href="https://github.com/rust-lang/compiler-team/issues?q=label%3Amajor-change%20label%3Afinal-comment-period%20state%3Aopen">Compiler Team</a> <a href="https://forge.rust-lang.org/compiler/mcp.html">(MCPs only)</a>
<ul>
<li><a href="https://github.com/rust-lang/compiler-team/issues/985">Promotes 5 Thumb-mode bare-metal Arm targets to Tier 2</a></li>
<li><a href="https://github.com/rust-lang/compiler-team/issues/976">Add -Z dead-fn-elimination to skip codegen of BFS-unreachable functions</a></li>
</ul>
<a class="toclink" href="https://this-week-in-rust.org/atom.xml#rust"></a><a href="https://github.com/rust-lang/rust/issues?q=is%3Aopen%20label%3Afinal-comment-period%20sort%3Aupdated-desc%20state%3Aopen">Rust</a>
<ul>
<li><a href="https://github.com/rust-lang/rust/pull/155989">Update <code>transmute_copy</code> to ub_checks and <code>?Sized</code></a></li>
<li><a href="https://github.com/rust-lang/rust/issues/117224">Tracking Issue for NEON dot product intrinsics</a></li>
<li><a href="https://github.com/rust-lang/rust/issues/152761">Never break between empty parens</a></li>
</ul>
<a class="toclink" href="https://this-week-in-rust.org/atom.xml#rust-rfcs"></a><a href="https://github.com/rust-lang/rfcs/issues?q=state%3Aopen%20label%3Afinal-comment-period%20state%3Aopen">Rust RFCs</a>
<ul>
<li><a href="https://github.com/rust-lang/rfcs/pull/3928">Avoid linting <code>unreachable_code</code> on <code>todo!()</code></a></li>
</ul>
<a class="toclink" href="https://this-week-in-rust.org/atom.xml#unsafe-code-guidelines"></a><a href="https://github.com/rust-lang/unsafe-code-guidelines/issues?q=is%3Aopen%20label%3Afinal-comment-period%20sort%3Aupdated-desc%20state%3Aopen">Unsafe Code Guidelines</a>
<ul>
<li><a href="https://github.com/rust-lang/unsafe-code-guidelines/issues/438">What are the values of a union type? (in particular, what is the validity invariant of a union)</a></li>
</ul>
<p><em>No Items entered Final Comment Period this week for
<a href="https://github.com/rust-lang/cargo/issues?q=is%3Aopen%20label%3Afinal-comment-period%20sort%3Aupdated-desc%20state%3Aopen">Cargo</a>,
<a href="https://github.com/rust-lang/lang-team/issues?q=is%3Aopen%20label%3Afinal-comment-period%20sort%3Aupdated-desc%20state%3Aopen">Language Team</a>,
<a href="https://github.com/rust-lang/reference/issues?q=is%3Aopen%20label%3Afinal-comment-period%20sort%3Aupdated-desc%20state%3Aopen">Language Reference</a> or
<a href="https://github.com/rust-lang/leadership-council/issues?q=state%3Aopen%20label%3Afinal-comment-period%20state%3Aopen">Leadership Council</a>.</em>
Let us know if you would like your PRs, Tracking Issues or RFCs to be tracked as a part of this list.</p>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#new-and-updated-rfcs"></a><a href="https://github.com/rust-lang/rfcs/pulls">New and Updated RFCs</a></h5>
<ul>
<li><em>No New or Updated RFCs were created this week.</em></li>
</ul>
<h4><a class="toclink" href="https://this-week-in-rust.org/atom.xml#upcoming-events">Upcoming Events</a></h4>
<p>Rusty Events between 2026-05-27 - 2026-06-24 🦀</p>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#virtual">Virtual</a></h5>
<ul>
<li>2026-05-27 | Virtual (Girona, ES) | <a href="https://lu.ma/rust-girona">Rust Girona</a><ul>
<li><a href="https://luma.com/9v7hv2g1"><strong>Weekly coding session</strong></a></li>
</ul>
</li>
<li>2026-06-02 | Virtual | <a href="https://luma.com/libp2p">libp2p Events</a><ul>
<li><a href="https://luma.com/ukfh0mcf"><strong>rust-libp2p Open Maintainers Call</strong></a></li>
</ul>
</li>
<li>2026-06-02 | Virtual (Tel Aviv-yafo, IL) | <a href="https://www.meetup.com/rust-tlv">Rust 🦀 TLV</a><ul>
<li><a href="https://www.meetup.com/rust-tlv/events/314871990/"><strong>‎שיחה חופשית ווירטואלית על ראסט</strong></a></li>
</ul>
</li>
<li>2026-06-03 | Virtual (Indianapolis, IN, US) | <a href="https://www.meetup.com/indyrs">Indy Rust</a><ul>
<li><a href="https://www.meetup.com/indyrs/events/314691782/"><strong>Indy.rs - with Social Distancing</strong></a></li>
</ul>
</li>
<li>2026-06-04 | Virtual (Berlin, DE) | <a href="https://www.meetup.com/rust-berlin">Rust Berlin</a><ul>
<li><a href="https://www.meetup.com/rust-berlin/events/308455930/"><strong>Rust Hack and Learn</strong></a></li>
</ul>
</li>
<li>2026-06-04 | Virtual (Nürnberg, DE) | <a href="https://www.meetup.com/rust-noris">Rust Nuremberg</a><ul>
<li><a href="https://www.meetup.com/rust-noris/events/313345241/"><strong>Rust Nürnberg online</strong></a></li>
</ul>
</li>
<li>2026-06-04 | Virtual (Tel Aviv-yafo, IL) | <a href="https://www.meetup.com/code-mavens/">Code Mavens 🦀 - 🐍 - 🐪</a><ul>
<li><a href="https://www.meetup.com/code-mavens/events/314979560/"><strong>Exploring FalkorDB - Learning to use a Graph Database in Rust</strong></a> </li>
</ul>
</li>
<li>2026-06-06 | Virtual (Kampala, UG) | <a href="https://www.eventbrite.com/e/rust-circle-meetup-tickets-628763176587">Rust Circle Meetup</a><ul>
<li><a href="https://www.eventbrite.com/e/rust-circle-meetup-tickets-628763176587"><strong>Rust Circle Meetup</strong></a></li>
</ul>
</li>
<li>2026-06-07 | Virtual (Dallas, TX, US) | <a href="https://www.meetup.com/dallasrust">Dallas Rust User Meetup</a><ul>
<li><a href="https://www.meetup.com/dallasrust/events/314095285/"><strong>Rust Deep Learning: First Sunday</strong></a></li>
</ul>
</li>
<li>2026-06-09 | Virtual (Dallas, TX, US) | <a href="https://www.meetup.com/dallasrust">Dallas Rust User Meetup</a><ul>
<li><a href="https://www.meetup.com/dallasrust/events/310254780/"><strong>Second Tuesday</strong></a></li>
</ul>
</li>
<li>2026-06-10 | Virtual (Girona, ES) | <a href="https://lu.ma/rust-girona">Rust Girona</a><ul>
<li><a href="https://luma.com/3bcnx1jb"><strong>Weekly coding session</strong></a></li>
</ul>
</li>
<li>2026-06-16 | Virtual (Washington, DC, US) | <a href="https://www.meetup.com/rustdc">Rust DC</a><ul>
<li><a href="https://www.meetup.com/rustdc/events/rdhhptyjcjbvb/"><strong>Mid-month Rustful</strong></a></li>
</ul>
</li>
<li>2026-06-17 | Hybrid (Vancouver, BC, CA) | <a href="https://www.meetup.com/vancouver-rust">Vancouver Rust</a><ul>
<li><a href="https://www.meetup.com/vancouver-rust/events/314000478/"><strong>Jiff</strong></a></li>
</ul>
</li>
<li>2026-06-17 | Virtual (Girona, ES) | <a href="https://lu.ma/rust-girona">Rust Girona</a><ul>
<li><a href="https://luma.com/ekws5nr4"><strong>Weekly coding session</strong></a></li>
</ul>
</li>
<li>2026-06-18 | Hybrid (Seattle, WA, US) | <a href="https://www.meetup.com/join-srug">Seattle Rust User Group</a><ul>
<li><a href="https://www.meetup.com/seattle-rust-user-group/events/314236370/"><strong>June, 2026 SRUG (Seattle Rust User Group) Meetup</strong></a></li>
</ul>
</li>
<li>2026-06-18 | Virtual (Berlin, DE) | <a href="https://www.meetup.com/rust-berlin">Rust Berlin</a><ul>
<li><a href="https://www.meetup.com/rust-berlin/events/308455931/"><strong>Rust Hack and Learn</strong></a></li>
</ul>
</li>
<li>2026-06-21 | Virtual (Dallas, TX, US) | <a href="https://www.meetup.com/dallasrust">Dallas Rust User Meetup</a><ul>
<li><a href="https://www.meetup.com/dallasrust/events/314329044/"><strong>Rust Deep Learning: Third Sunday</strong></a></li>
</ul>
</li>
<li>2026-06-23 | Virtual (Dallas, TX, US) | <a href="https://www.meetup.com/dallasrust">Dallas Rust User Meetup</a><ul>
<li><a href="https://www.meetup.com/dallasrust/events/310254779/"><strong>Fourth Tuesday</strong></a></li>
</ul>
</li>
<li>2026-06-23 | Virtual (London, UK) | <a href="https://www.meetup.com/women-in-rust">Women in Rust</a><ul>
<li><a href="https://www.meetup.com/women-in-rust/events/313767883/"><strong>Lunch &amp; Learn: What the heck are monads - and how do we fake them in Rust</strong></a></li>
</ul>
</li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#asia">Asia</a></h5>
<ul>
<li>2026-06-02 | Beijing, CN | <a href="https://www.meetup.com/wasm-rust-meetup/events/">Voice AI and Rust Meetup (Rust for AI, lowcoderust.com)</a><ul>
<li><a href="https://www.meetup.com/wasm-rust-meetup/events/314750465/"><strong>AI Agents and Open Source LLM (Call for Speakers)</strong></a></li>
</ul>
</li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#europe">Europe</a></h5>
<ul>
<li>2026-05-28 | Copenhagen, DK | <a href="https://www.meetup.com/copenhagen-rust-community">Copenhagen Rust Community</a><ul>
<li><a href="https://www.meetup.com/copenhagen-rust-community/events/314868448/"><strong>Rust meetup #68</strong></a></li>
</ul>
</li>
<li>2026-05-28 | London, UK | <a href="https://www.meetup.com/rust-london-user-group">Rust London User Group</a><ul>
<li><a href="https://www.meetup.com/rust-london-user-group/events/314846861/"><strong>LDN Talks May Community Showcase</strong></a></li>
</ul>
</li>
<li>2026-05-29 | Berlin, DE | <a href="https://www.meetup.com/rust-berlin">Rust Berlin</a><ul>
<li><a href="https://www.meetup.com/rust-berlin/events/314396588/"><strong>Rust Berlin Talks: The next generation</strong></a></li>
</ul>
</li>
<li>2026-05-30 | Stockholm, SE | <a href="https://www.meetup.com/stockholm-rust">Stockholm Rust</a><ul>
<li><a href="https://www.meetup.com/stockholm-rust/events/314926826/"><strong>Ferris' Fika Forum #26</strong></a></li>
</ul>
</li>
<li>2026-06-02 | Frankfurt, DE | <a href="https://www.meetup.com/rust-rhein-main">Rust Rhein-Main</a><ul>
<li><a href="https://www.meetup.com/rust-rhein-main/events/314051727/"><strong>gRPC with Rust and Tonic</strong></a></li>
</ul>
</li>
<li>2026-06-03 | Dublin, IE | <a href="https://www.meetup.com/rust-dublin">Rust Dublin</a><ul>
<li><a href="https://www.meetup.com/rust-dublin/events/314689875/"><strong>Join us live and INPERSON for Rust 261</strong></a></li>
</ul>
</li>
<li>2026-06-03 | Girona, ES | <a href="https://lu.ma/rust-girona">Rust Girona</a><ul>
<li><a href="https://luma.com/4bmlc7qd"><strong>Rust Girona Hack &amp; Learn 06 2026</strong></a></li>
</ul>
</li>
<li>2026-06-10 | München, DE | <a href="https://www.meetup.com/rust-munich">Rust Munich</a><ul>
<li><a href="https://www.meetup.com/rust-munich/events/313791798/"><strong>Rust Munich 2026 / 2 - Hacking Evening</strong></a></li>
</ul>
</li>
<li>2026-06-11 | Switzerland, CH | <a href="https://www.posttenebraslab.ch/wiki/events/start">PostTenebrasLab</a><ul>
<li><a href="https://www.posttenebraslab.ch/wiki/events/monthly_meeting/rust_meetup"><strong>Rust Meetup Geneva</strong></a></li>
</ul>
</li>
<li>2026-06-12 - 2026-06-14 | Kraków, PL | <a href="https://rustmeet.eu/">Rustmeet</a><ul>
<li><a href="https://rustmeet.eu/"><strong>Rustmeet</strong></a></li>
</ul>
</li>
<li>2026-06-16 | Leipzig, DE | <a href="https://www.meetup.com/rust-modern-systems-programming-in-leipzig">Rust - Modern Systems Programming in Leipzig</a><ul>
<li><a href="https://www.meetup.com/rust-modern-systems-programming-in-leipzig/events/313813937/"><strong>Interactive: Everything is Open Source</strong></a></li>
</ul>
</li>
<li>2026-06-16 | Milano, IT | <a href="https://www.meetup.com/rust-language-milano">Rust Language Milan</a><ul>
<li><a href="https://www.meetup.com/rust-language-milan/events/314766950/"><strong>Real-time planning in Rust: SolverForge &amp; SERIO</strong></a></li>
</ul>
</li>
<li>2026-06-18 | Aarhus, DK | <a href="https://www.meetup.com/rust-aarhus">Rust Aarhus</a><ul>
<li><a href="https://www.meetup.com/rust-aarhus/events/314965238/"><strong>Talk Night at Danske Commodities</strong></a></li>
</ul>
</li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#north-america">North America</a></h5>
<ul>
<li>2026-05-27 | Austin, TX, US | <a href="https://www.meetup.com/rust-atx">Rust ATX</a><ul>
<li><a href="https://www.meetup.com/rust-atx/events/314209662/"><strong>Rust Lunch - Fareground</strong></a></li>
</ul>
</li>
<li>2026-05-28 | Atlanta, GA, US | <a href="https://www.meetup.com/rust-atl">Rust Atlanta</a><ul>
<li><a href="https://www.meetup.com/rust-atl/events/313539319/"><strong>Rust-Atl</strong></a></li>
</ul>
</li>
<li>2026-05-28 | Los Angeles, CA, US | <a href="https://www.meetup.com/rust-los-angeles">Rust Los Angeles</a><ul>
<li><a href="https://www.meetup.com/rust-los-angeles/events/314218564/"><strong>Rust LA: Rust in Embedded &amp; Autonomous Systems at Parallel Systems in DTLA</strong></a></li>
</ul>
</li>
<li>2026-05-28 | Mountain View, CA, US | <a href="https://www.meetup.com/hackerdojo/events/">Hacker Dojo</a><ul>
<li><a href="https://www.meetup.com/hackerdojo/events/314716463/"><strong>RUST MEETUP at HACKER DOJO</strong></a></li>
</ul>
</li>
<li>2026-05-30 | Boston, MA, US | <a href="https://www.meetup.com/bostonrust">Boston Rust Meetup</a><ul>
<li><a href="https://www.meetup.com/bostonrust/events/314480537/"><strong>Central Cambridge Rust Lunch, May 30</strong></a></li>
</ul>
</li>
<li>2026-06-04 | Saint Louis, MO, US | <a href="https://www.meetup.com/stl-rust">STL Rust</a><ul>
<li><a href="https://www.meetup.com/stl-rust/events/314106244/"><strong>Testing, Coverage, Tracey &amp; Mutations</strong></a></li>
</ul>
</li>
<li>2026-06-06 | Boston, MA, US | <a href="https://www.meetup.com/bostonrust">Boston Rust Meetup</a><ul>
<li><a href="https://www.meetup.com/bostonrust/events/314480539/"><strong>Boston Common Rust Lunch, June 6</strong></a></li>
</ul>
</li>
<li>2026-06-11 | Lehi, UT, US | <a href="https://www.meetup.com/utah-rust">Utah Rust</a><ul>
<li><a href="https://www.meetup.com/utah-rust/events/314696643/"><strong>Utah Rust June Meetup</strong></a></li>
</ul>
</li>
<li>2026-06-11 | Mountain View, CA, US | <a href="https://www.meetup.com/hackerdojo/events/">Hacker Dojo</a><ul>
<li><a href="https://www.meetup.com/hackerdojo/events/314825006/"><strong>RUST MEETUP at HACKER DOJO</strong></a></li>
</ul>
</li>
<li>2026-06-11 | San Diego, CA, US | <a href="https://www.meetup.com/san-diego-rust">San Diego Rust</a><ul>
<li><a href="https://www.meetup.com/san-diego-rust/events/313721899/"><strong>San Diego Rust June Meetup - Back in person!</strong></a></li>
</ul>
</li>
<li>2026-06-16 | San Francisco, CA, US | <a href="https://www.meetup.com/san-francisco-rust-study-group">San Francisco Rust Study Group</a><ul>
<li><a href="https://www.meetup.com/san-francisco-rust-study-group/events/ghhwqtyjcjbvb/"><strong>Rust Hacking in Person</strong></a></li>
</ul>
</li>
<li>2026-06-17 | Hybrid (Vancouver, BC, CA) | <a href="https://www.meetup.com/vancouver-rust">Vancouver Rust</a><ul>
<li><a href="https://www.meetup.com/vancouver-rust/events/314000478/"><strong>Jiff</strong></a></li>
</ul>
</li>
<li>2026-06-18 | Hybrid (Seattle, WA, US) | <a href="https://www.meetup.com/join-srug">Seattle Rust User Group</a><ul>
<li><a href="https://www.meetup.com/seattle-rust-user-group/events/314236370/"><strong>June, 2026 SRUG (Seattle Rust User Group) Meetup</strong></a></li>
</ul>
</li>
<li>2026-06-24 | Austin, TX, US | <a href="https://www.meetup.com/rust-atx">Rust ATX</a><ul>
<li><a href="https://www.meetup.com/rust-atx/events/xvkdgtyjcjbgc/"><strong>Rust Lunch - Fareground</strong></a></li>
</ul>
</li>
<li>2026-06-24 | Los Angeles, CA, US | <a href="https://www.meetup.com/rust-los-angeles">Rust Los Angeles</a><ul>
<li><a href="https://www.meetup.com/rust-los-angeles/events/314386080/"><strong>Rust LA: Rust-Based Constraint Solvers in 2D Sketching with Zoo Technologies</strong></a></li>
</ul>
</li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#south-america">South America</a></h5>
<ul>
<li>2026-06-18 | Florianópolis, BR | <a href="https://luma.com/rust-sc">Rust SC</a><ul>
<li><a href="https://luma.com/acinctdf"><strong>Rust Floripa</strong></a></li>
</ul>
</li>
</ul>
<p>If you are running a Rust event please add it to the <a href="https://www.google.com/calendar/embed?src=apd9vmbc22egenmtu5l6c5jbfc%40group.calendar.google.com">calendar</a> to get
it mentioned here. Please remember to add a link to the event too.
Email the <a href="mailto:community-team@rust-lang.org">Rust Community Team</a> for access.</p>
<h4><a class="toclink" href="https://this-week-in-rust.org/atom.xml#jobs">Jobs</a></h4>
<p>Please see the latest <a href="https://www.reddit.com/r/rust/comments/1sobu1s/official_rrust_whos_hiring_thread_for_jobseekers/">Who's Hiring thread on r/rust</a></p>
<h3><a class="toclink" href="https://this-week-in-rust.org/atom.xml#quote-of-the-week">Quote of the Week</a></h3>
<blockquote>
<p>This overflows the trait solver today as well as my brain</p>
</blockquote>
<p>– <a href="https://nadrieril.github.io/blog/2026/05/14/when-can-traits-depend-on-themselves.html">Nadrieril on their blog</a></p>
<p>Thanks to <a href="https://users.rust-lang.org/t/twir-quote-of-the-week/328/1774">Theemathas</a> for the suggestion!</p>
<p><a href="https://users.rust-lang.org/t/twir-quote-of-the-week/328">Please submit quotes and vote for next week!</a></p>
<p>This Week in Rust is edited by:</p>
<ul>
<li><a href="https://github.com/nellshamrell">nellshamrell</a></li>
<li><a href="https://github.com/llogiq">llogiq</a></li>
<li><a href="https://github.com/ericseppanen">ericseppanen</a></li>
<li><a href="https://github.com/extrawurst">extrawurst</a></li>
<li><a href="https://github.com/U007D">U007D</a></li>
<li><a href="https://github.com/mariannegoldin">mariannegoldin</a></li>
<li><a href="https://github.com/bdillo">bdillo</a></li>
<li><a href="https://github.com/opeolluwa">opeolluwa</a></li>
<li><a href="https://github.com/bnchi">bnchi</a></li>
<li><a href="https://github.com/KannanPalani57">KannanPalani57</a></li>
<li><a href="https://github.com/tzilist">tzilist</a></li>
</ul>
<p><em>Email list hosting is sponsored by <a href="https://foundation.rust-lang.org/">The Rust Foundation</a></em></p>
<p><small><a href="https://www.reddit.com/r/rust/comments/1tptzbz/this_week_in_rust_653/">Discuss on r/rust</a></small></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Why machine-speed exploits demand autonomous defense]]></title>
<description><![CDATA[When Anthropic’s Mythos model unearthed a 27-year-old OpenBSD flaw in the time it takes to brew a coffee, the “AI Vulnerability Storm” stopped being a theoretical threat and became our new reality. For years, the security industry has debated when AI would truly disrupt the exploit market. That d...]]></description>
<link>https://tsecurity.de/de/3552555/it-nachrichten/why-machine-speed-exploits-demand-autonomous-defense/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3552555/it-nachrichten/why-machine-speed-exploits-demand-autonomous-defense/</guid>
<pubDate>Thu, 28 May 2026 00:32:25 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>When Anthropic’s Mythos model unearthed a 27-year-old OpenBSD flaw in the time it takes to brew a coffee, the “AI Vulnerability Storm” stopped being a theoretical threat and became our new reality. For years, the security industry has debated when AI would truly disrupt the exploit market. That debate is over. We are now defending against an adversary that doesn’t sleep, doesn’t get bored, and scans code at industrialised speeds.</p>



<p><strong>The death of the grace period</strong></p>



<p>We used to have the luxury of time, which is easy to say in hindsight. The traditional defensive playbook was a predictable rhythm: a CVE is released, you grab a coffee, raise some tickets, and your team spends the next few weeks “prioritising” the patch. I have worked in vulnerability management, and I know that is a huge oversimplification, but in comparison, that’s how it feels. You relied on the grace period between a vulnerability being announced and a reliable exploit hitting the wild.</p>



<p>Mythos just set that playbook on fire. </p>



<p>When a frontier model can scan your entire external attack surface and draft a working exploit in minutes, your 14-day or 30-day patching cycle isn’t a strategy, it’s a liability. The Australian Cyber Security Centre’s (ACSC) recent findings confirm this: while AI isn’t yet a “sentient hacker” capable of complex, end-to-end strategic takeovers, it is terrifyingly good at the “boring” parts of the tradecraft, such as reconnaissance, code analysis, and rapid prototyping.</p>



<p>Currently, the real threat isn’t an AI brain; the threat is the machine-speed collapse of the exploit window.</p>



<p><strong>System design is the real vulnerability</strong></p>



<p>I’ve realised a hard truth recently: If your entire security posture fails because of a single unpatched vulnerability, patching isn’t your problem. Your system design is.</p>



<p>Brittle systems rely on the absence of flaws. They are houses of cards waiting for the next CVE to blow them over. Resilient systems assume flaws are inevitable. We have to move past a defensive posture and start building a Modern Defensible Architecture (MDA).</p>



<p>This isn’t just my opinion. The Cloud Security Alliance (CSA) recently issued 11 Priority Actions for a “Mythos-ready” world, and they align perfectly with the ACSC’s direction on MDA. The message is clear: Security is no longer about fixing a bug. It is an architectural mandate to ensure that no single failure leads to a catastrophe.</p>



<p><strong>The counter-move: Turning speed against the machine</strong></p>



<p>If we can’t out-patch the machine, we have to out-architect it. A Modern Defensible Architecture relies on Zero Trust as the floor, but it uses Deception as the walls. This is where it gets interesting. Under CSA Priority Action #9, there is a clear push to move toward active defense (90-day clock in fact). In a traditional network, a compromised server is a foothold. In a defensible architecture, that server is surrounded by honeypots, tokens, and decoy pathways. </p>



<p>When an AI-driven tool like Mythos scans your environment, it doesn’t just see your assets; it sees a hall of mirrors. Because the AI moves at machine speed, it is actually more likely to trip a deception element than a human attacker would. </p>



<p>This creates what we call a “High-Fidelity Signal”. A touch on a decoy isn’t a “maybe” alert; it’s a definitive indicator of intent. This allows for Action #10: Automated Containment. When seconds count, you can’t wait for a human analyst to get to this in their queue and verify an alert. You need the architecture to recognise the threat and shut down the endpoint/segment automatically.</p>



<p><strong>The shift</strong></p>



<p>To move from reactive patching to a Modern Defensible Architecture, organisations must first focus on eradicating the external attack surface by moving applications behind a Zero Trust framework. By making internal assets invisible to the public internet and eliminating open “listeners,” you effectively deprive models like Mythos of the reconnaissance data they need to draft an exploit. This aligns with CSA Priority Actions #1 and #5, shifting the goal from “patching everything” to “hiding everything” so that a vulnerability cannot be reached in the first place.</p>



<p>Second, we must saturate the environment with active deception, deploying honeypots, tokens, and decoy pathways that turn an AI’s industrialised scanning speed into its own undoing. As outlined in CSA Action #9, a defensible architecture should function like a hall of mirrors. Because an AI probes at machine speed, it is statistically far more likely to interact with a decoy than a human attacker would. This creates the “High-Fidelity Signal” necessary to distinguish a legitimate system failure from a targeted, machine-led intrusion.</p>



<p>Finally, organisations must mandate automated containment to counter the total collapse of the exploit window. In a world where Mythos can weaponize a flaw in minutes, manual triage is a legacy process we can no longer afford. Following CSA Action #10, the architecture must be empowered to instantly isolate endpoints or revoke sessions the moment a high-confidence threat is detected. By moving from “Human-in-the-loop” to “Human-over-the-loop” for containment, we ensure that our defensive response finally matches the velocity of the adversary.</p>



<p><strong>The clock is ticking</strong></p>



<p>The Mythos era doesn’t require us to reinvent security, but it does require us to stop pretending that faster patching is a sustainable path forward. Nobody is saying patching doesn’t matter, but if it’s the foundation that the system is built on, you’re already behind.</p>



<p>Organisations need to get off the endless treadmill of CVE remediation and start building Modern Defensible Architectures. By combining Zero Trust with active Deception, we create systems that don’t just resist attacks, they defend against them autonomously.</p>



<p>The goal isn’t to build a ship that never leaks. The goal is to build a ship so well-compartmentalised that even when a hull plate fails, the mission continues. The CSA gave us the blueprint. Mythos gave us the deadline. It’s time to stop fighting the storm and start building better ships.</p>



<p>To learn more, visit us <a href="https://www.zscaler.com/?utm_source=google&amp;utm_medium=cpc&amp;utm_term=b-zscaler&amp;utm_campaign=194372733" target="_blank" rel="sponsored">here</a>.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Ribbit is the new Wordle, and I’m here to share it with you]]></title>
<description><![CDATA[A gentle daily puzzle is quietly becoming the most joyful part of my morning routine​ and reminds me that not every win needs to be epicThere’s been some pretty big news in the last couple of weeks in video game world: the long-running space shooter Destiny 2 is winding up after almost nine years...]]></description>
<link>https://tsecurity.de/de/3551508/it-nachrichten/ribbit-is-the-new-wordle-and-im-here-to-share-it-with-you/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3551508/it-nachrichten/ribbit-is-the-new-wordle-and-im-here-to-share-it-with-you/</guid>
<pubDate>Wed, 27 May 2026 16:47:42 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A gentle daily puzzle is quietly becoming the most joyful part of my morning routine​ and reminds me that not every win needs to be epic</p><p>There’s been some pretty big news in the last couple of weeks in video game world: the long-running space shooter Destiny 2 is <a href="https://www.bungie.net/7/en/News/Article/d2_may_21_2026">winding up</a> after almost nine years, PlayStation appears to have decided to <a href="https://www.videogameschronicle.com/news/playstation-boss-says-single-player-games-wont-come-to-pc-going-forward/">stop releasing</a> its flagship single-player games on PC, and Microsoft wants us to look like we’re shouting <a href="https://kotaku.com/the-internet-reacts-to-xbox-trying-to-rebrand-as-xbox-2000696758">every time we type XBOX</a>. But the biggest news for me is that I have found my new favourite word game. I am going to be so bold as to call it the new Wordle.</p><p>Ribbit is one of the varied suite of daily games on <a href="https://www.puzzmo.com/today">Puzzmo</a>, an online puzzle platform. It launched at the beginning of January, but I only recently discovered it because I have been unwell, bored, and spending too much time on my phone. Puzzmo’s daily hits include a satisfying shape-arranging game, variations on chess that make me feel extremely stupid, and pleasing word games, which are my favourites. Circuits has you making connections between the beginnings and ends of phrases (eg “stone cold &gt; cold medicine &gt; medicine cabinet”) as fast as you can. Bongo gives you a bunch of letter tiles and asks you to arrange them for a maximum score.</p> <a href="https://www.theguardian.com/games/2026/may/27/i-have-found-the-new-wordle-and-im-here-to-share-it-with-you">Continue reading...</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Why scaling AI requires both left-brain rigor and right-brain ingenuity]]></title>
<description><![CDATA[Neuroscience often describes the human brain as operating through two complementary modes of thinking, commonly referred to as the left and right brains. While modern neuroscience debates the strict division between these hemispheres, the metaphor remains useful and highly relevant, particularly ...]]></description>
<link>https://tsecurity.de/de/3547362/it-security-nachrichten/why-scaling-ai-requires-both-left-brain-rigor-and-right-brain-ingenuity/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3547362/it-security-nachrichten/why-scaling-ai-requires-both-left-brain-rigor-and-right-brain-ingenuity/</guid>
<pubDate>Tue, 26 May 2026 11:05:29 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Neuroscience often describes the human brain as operating through two complementary modes of thinking, commonly referred to as the left and right brains. While modern neuroscience debates the strict division between these hemispheres, the metaphor remains useful and highly relevant, particularly in an enterprise context, to illustrate two distinct cognitive approaches.</p>



<p>The left hemisphere is associated with logic, structure and analytical reasoning. The right hemisphere enables pattern recognition and creativity. Analytical thinking drives execution. Creative thinking enables adaptation.</p>



<p>This distinction is increasingly relevant in the age of AI. GenAI systems are inherently probabilistic, capable of producing a range of possible outputs based on patterns and context. They enable vivid exploration with increasing effectiveness but lack consistency and predictability in real-world execution. Deterministic systems, by contrast, provide the structure, control and repeatability required to translate those insights into outcomes.</p>



<p>This analogy draws on early neuroscience work by Nobel laureate Roger Sperry, who demonstrated that the brain’s hemispheres contribute differently to reasoning and perception. Human intelligence ultimately emerges from the interaction between these complementary capabilities.</p>



<p>Enterprises operate in a similar dual mode. The analytical side builds infrastructure, governance and discipline, forming the deterministic layer that ensures reliability and control. The creative side rethinks workflows, interprets signals and redesigns decision-making, where probabilistic intelligence plays a critical role. Organizations that scale AI successfully bring these capabilities together. Many, however, remain focused on infrastructure and models, limiting AI to incremental optimization rather than transformation.</p>



<p>While data platforms, governance frameworks and model performance are advancing, scaling remains uneven. According to the <a href="https://sloanreview.mit.edu/article/five-trends-in-ai-and-data-science-for-2026/" rel="nofollow">2026 AI and Data Leadership Executive Benchmark Survey</a> published in MIT Sloan Management Review, only 39 percent of companies have implemented AI in production at scale, despite years of investment in foundations and governance. <a href="https://www.deloitte.com/us/en/what-we-do/capabilities/applied-artificial-intelligence/content/state-of-ai-in-the-enterprise.html" rel="nofollow">Deloitte’s State of AI in the Enterprise 2026</a> reinforces the divide. Only 34 percent of organizations are using AI to deeply transform their business, while 37 percent remain at a surface level with little or no change to existing processes. This reflects a gap between technical readiness and workflow transformation.</p>



<h2 class="wp-block-heading">Enterprises have strengthened their analytical brain</h2>



<p>Over the past several years, CIOs have focused on building the analytical backbone required to deploy AI responsibly. Infrastructure has been modernized. Data platforms have matured. Governance and risk management frameworks are more robust. These capabilities are essential, particularly in regulated industries where reliability and compliance are non-negotiable. However, analytical strength alone does not create a competitive advantage.</p>



<p>Financial services illustrate this clearly. Most banks operate under similar regulatory frameworks and offer structurally comparable products. Their infrastructure and compliance models are largely consistent. Yet performance varies significantly between institutions. The difference lies in how leading banks activate the creative side of the enterprise.</p>



<p>Instead of relying solely on static models or predefined workflows, forward-looking institutions incorporate behavioral signals dynamically, continuously learning from customer interactions, transaction patterns and contextual data in real time. This is where the 3C framework connects directly to the left-brain, right-brain model. The “Core” provides the secure, governed and interoperable foundation that enables AI reliability, compliance and trust. “Context” gives AI access to enterprise data, processes, history and business rules, helping probabilistic intelligence interpret signals with domain awareness and traceability. “Coordination” then brings people, agents, applications and systems together through governed, process-driven workflows. Together, these three pillars allow deterministic systems and probabilistic intelligence to work as one, turning insights into consistent, auditable and adaptive actions.</p>



<p>This enables faster, more adaptive and intelligent decisions. Fraud detection becomes increasingly responsive by identifying emerging anomalies rather than relying only on known patterns. Customer onboarding becomes seamless through real-time identity validation and contextual risk assessment. Service interactions become more relevant. Over time, systems continuously improve.</p>



<p>This is where customer experience becomes a true differentiator. AI enables institutions to interpret customer needs continuously rather than episodically. The analytical foundation ensures reliability. Creative application enables differentiation.</p>



<h2 class="wp-block-heading">Technology alone won’t scale AI. Whole-brain teams will</h2>



<p>One of the most common reasons AI initiatives stall is not a technical limitation, but organizational design and change management. Many enterprises treat AI as a specialized capability within engineering or data science teams. While this ensures rigor in model development, it limits the ability to rethink how decisions and workflows should operate in an AI-native environment. As a result, AI is used to optimize existing processes rather than redesign them.</p>



<p>Scaling AI requires a shift in operating model. Business leaders, product teams, architects and engineers must work together to rethink workflows and decision structures. Technical teams ensure models are scalable and reliable. Business and product leaders ensure intelligence is applied to improve operational outcomes and customer experience. This convergence is not purely a technology effort. It is a change management exercise that requires redefining ownership and collaboration across functions.</p>



<p>This is where enterprises must move beyond isolated functional structures toward what can be described as a “purple team” model. Borrowed from cybersecurity, where purple teams integrate the defensive discipline of blue teams with the adversarial thinking of red teams, this model creates continuous collaboration between those who build systems and those who challenge assumptions. In enterprise AI, purple teams combine engineering precision with business context and operational insight, ensuring intelligence improves how the enterprise operates.</p>



<p>As this model takes hold, roles begin to evolve and overlap. Product managers, engineers and business leaders increasingly operate as unified teams responsible for end-to-end outcomes rather than isolated functions. These teams do not simply deploy AI into existing workflows. They redesign workflows to operate more intelligently and effectively.</p>



<h2 class="wp-block-heading">Redesign unlocks AI’s real value</h2>



<p>A healthcare diagnostics organization focused on early lung cancer detection illustrates how activating both analytical and creative capabilities can unlock meaningful impact. The organization applied machine learning to analyze diagnostic data and accelerate early detection. This reduced analysis time by nearly 70 percent while also improving detection performance and reducing false positives.</p>



<p>This demonstrates that AI delivers its greatest impact when applied to improve decision-making, not simply to speed up execution. The analytical foundation ensured reliability, safety and consistency. extended beyond the technology itself into how clinicians engaged with it.  By augmenting human judgment with AI-driven insights, practitioners were able to interpret signals more effectively, validate findings with greater confidence and make more informed decisions in critical moments. This human and machine interplay is where the true “creative” advantage emerges.</p>



<p>This pattern is increasingly visible across industries. While AI can automate workflows and improve efficiency, its strategic value lies in enabling organizations to rethink how decisions are structured and executed. Enterprises that apply AI only to optimize existing processes see incremental improvements. Those that redesign workflows to incorporate intelligence more natively achieve materially different levels of performance, responsiveness and business impact.</p>



<h2 class="wp-block-heading">CIOs must lead left-brain/right-brain transformation</h2>



<p>This shift marks a clear evolution in the CIO mandate. The first phase of enterprise AI focused on building analytical strength, modernizing infrastructure, establishing governance and creating scalable platforms. This laid the deterministic foundation for reliable execution.</p>



<p>The next phase is about redesign. CIOs must enable organizations to rethink workflows and decision-making to fully leverage AI. This requires closer alignment across business, product and engineering teams, integrating probabilistic intelligence with structured control.</p>



<p>AI now operates as an organizational capability, reshaping how decisions are made and how work gets done.</p>



<p>Enterprises now face a similar inflection point. Advantage will not come from execution alone, but from how effectively organizations combine creative, probabilistic intelligence with disciplined, deterministic systems to redesign how they operate.</p>



<p>Those who get this balance right will move beyond incremental gains to true transformation. The difference is no longer technology. It is the organizational intent.</p>



<p><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><strong><a href="https://www.cio.com/expert-contributor-network/">Want to join?</a></strong></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[A Step-by-Step Coding Tutorial to Implement GBrain: The Self-Wiring Memory Layer Built by Y Combinator’s Garry Tan for AI Agents]]></title>
<description><![CDATA[AI agents start every session from zero — no memory of meetings, notes, or decisions. GBrain, the open-source memory layer Y Combinator's Garry Tan built to power his own OpenClaw and Hermes deployments, fixes that with a markdown-first knowledge graph that wires itself through regex inference, n...]]></description>
<link>https://tsecurity.de/de/3540512/ai-nachrichten/a-step-by-step-coding-tutorial-to-implement-gbrain-the-self-wiring-memory-layer-built-by-y-combinators-garry-tan-for-ai-agents/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3540512/ai-nachrichten/a-step-by-step-coding-tutorial-to-implement-gbrain-the-self-wiring-memory-layer-built-by-y-combinators-garry-tan-for-ai-agents/</guid>
<pubDate>Fri, 22 May 2026 20:33:18 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>AI agents start every session from zero — no memory of meetings, notes, or decisions. GBrain, the open-source memory layer Y Combinator's Garry Tan built to power his own OpenClaw and Hermes deployments, fixes that with a markdown-first knowledge graph that wires itself through regex inference, not LLM calls. This step-by-step coding tutorial walks through installing GBrain v0.38.2.0, building a brain repo, running hybrid search, and connecting it to Claude Code via MCP — about 20 minutes, all terminal output captured live.</p>
<p>The post <a href="https://www.marktechpost.com/2026/05/22/a-step-by-step-coding-tutorial-to-implement-gbrain-the-self-wiring-memory-layer-built-by-y-combinators-garry-tan-for-ai-agents/">A Step-by-Step Coding Tutorial to Implement GBrain: The Self-Wiring Memory Layer Built by Y Combinator’s Garry Tan for AI Agents</a> appeared first on <a href="https://www.marktechpost.com/">MarkTechPost</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Steve Wozniak Tells Graduates They All Have 'AI': Actual Intelligence]]></title>
<description><![CDATA[While other commencement speeches have been met with boos for hyping up artificial intelligence, Apple cofounder Steve Wozniak reminded college graduates that they already posses "AI" of their own: "actual intelligence." He framed AI as an attempt to duplicate brain-like routines, and encouraged ...]]></description>
<link>https://tsecurity.de/de/3539258/it-security-nachrichten/steve-wozniak-tells-graduates-they-all-have-ai-actual-intelligence/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3539258/it-security-nachrichten/steve-wozniak-tells-graduates-they-all-have-ai-actual-intelligence/</guid>
<pubDate>Fri, 22 May 2026 13:08:13 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[While other commencement speeches have been met with boos for hyping up artificial intelligence, Apple cofounder Steve Wozniak reminded college graduates that they already posses "AI" of their own: "actual intelligence." He framed AI as an attempt to duplicate brain-like routines, and encouraged students to "think different" as they enter a workforce being reshaped by automation. Business Insider reports: Steve Wozniak did what other college graduation commencement speakers couldn't this year: earn applause when talking about AI. The Apple cofounder took the stage during Grand Valley State University's graduation ceremony earlier this month. During his speech, Wozniak offered reassurance to new graduates who are entering the workforce at the height of the AI revolution.
 
"It would take too long to go deeply into what I think about AI, but we've been trying to create a brain," Wozniak said. "Is there a way we can duplicate a routine a trillion times and have it work like a brain? AI is one of those attempts." [...]
 
During his commencement address, Wozniak reflected on working at Apple and offered students some advice as they begin their careers. "You should always try to think different," he said. "Don't follow the same steps as a million other people. Think, is there something I can do a little different?" You can watch the clip on YouTube.<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=Steve+Wozniak+Tells+Graduates+They+All+Have+'AI'%3A+Actual+Intelligence%3A+https%3A%2F%2Fnews.slashdot.org%2Fstory%2F26%2F05%2F22%2F0530218%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fnews.slashdot.org%2Fstory%2F26%2F05%2F22%2F0530218%2Fsteve-wozniak-tells-graduates-they-all-have-ai-actual-intelligence%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://news.slashdot.org/story/26/05/22/0530218/steve-wozniak-tells-graduates-they-all-have-ai-actual-intelligence?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Alibaba's proprietary Qwen3.7-Max can run for 35 hours autonomously and supports external harnesses like Anthropic's Claude Code]]></title>
<description><![CDATA[The AI industry has fully entered the "agent era," a paradigm where AI models do far more than generate text — they now actively plan, execute, and course-correct complex tasks over days rather than seconds. Thus, it's perhaps unsurprising to see Chinese e-commerce giant Alibaba's famed Qwen Team...]]></description>
<link>https://tsecurity.de/de/3538114/it-nachrichten/alibabas-proprietary-qwen37-max-can-run-for-35-hours-autonomously-and-supports-external-harnesses-like-anthropics-claude-code/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3538114/it-nachrichten/alibabas-proprietary-qwen37-max-can-run-for-35-hours-autonomously-and-supports-external-harnesses-like-anthropics-claude-code/</guid>
<pubDate>Fri, 22 May 2026 03:17:24 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>The AI industry has fully entered the "agent era," a paradigm where AI models do far more than generate text — they now actively plan, execute, and course-correct complex tasks over days rather than seconds. </p><p>Thus, it's perhaps unsurprising to see Chinese e-commerce giant Alibaba's famed Qwen Team of AI researchers release a model capable of performing autonomous agentic AI work over multiple days: that model has arrived in the form of Qwen3.7-Max which the<a href="https://qwen.ai/blog?id=qwen3.7"> company reports in a blog post</a> achieved "~35 hours of continuous autonomous execution" — albeit, in a proprietary, not open source format, as prior Qwen Team releases were.</p><p>This is also to be expected — it's what many analysts and industry experts feared in the <a href="https://venturebeat.com/technology/did-alibaba-just-kneecap-its-powerful-qwen-ai-team-key-figures-depart-in">wake of the departure of several key Qwen Team leaders earlier this year.</a> But it makes sense for Alibaba financially, at least in the short term: training AI models, especially ones as powerful as Qwen3.7-Max, is expensive, and giving them away essentially for free, as open source models are, does not immediately help recoup any costs. </p><p>In that sense, Alibaba is simply aligning its efforts with American AI giants like OpenAI and Google by offering the latest and greatest models only through paid APIs and subscription or paid web plan bundles, and slightly less performant ones through open source. </p><p>Still, the arrival of Qwen3.7-Max offers further optionality to enterprises and individual users, and more competition for American AI labs — rarely a bad thing for consumers at all budget levels. Yet, the fact that the model is only accessible from Chinese-based endpoints means it may be limited in its appeal to American and European enterprises seeking to maximize compliance and security posturing when fulfilling government contracts, or even just attempting to comply with all relevant state, local, and national data sovereignty regulations. </p><h2><b>The marathon AI era</b></h2><p>To understand why Qwen3.7-Max is a departure from previous models, one must look at how it was trained and how it operates in practice. </p><p>Language models typically degrade when forced to maintain a single train of thought over thousands of conversational turns; they forget instructions, hallucinate variables, or simply get stuck in logical loops. Qwen3.7-Max was specifically designed as a "versatile agent foundation" capable of "long-horizon reasoning" to overcome this exact bottleneck.</p><p>The starkest demonstration of this capability is an autonomous engineering task detailed by the Qwen team. The model was given access to an isolated server equipped with a T-Head ZW-M890 PPU—a hardware architecture the model had never encountered during its training. Its task was to optimize an attention kernel. </p><p>Over the course of 35 straight hours, Qwen3.7-Max operated entirely autonomously. It executed 1,158 distinct tool calls, performed 432 kernel evaluations, diagnosed compilation failures, and iteratively improved the code to achieve a 10.0x geometric mean speedup. </p><p>By comparison, Chinese competitor models like <a href="https://venturebeat.com/technology/ai-joins-the-8-hour-work-day-as-glm-ships-5-1-open-source-llm-beating-opus-4">z.ai's GLM-5.1</a> and  <a href="https://venturebeat.com/ai/kimi-k2-6-runs-agents-for-days-and-exposes-the-limits-of-enterprise-orchestration">Moonshot's Kimi K2.6</a> capped out at 7.3x and 5.0x speedups respectively, often voluntarily terminating their sessions when they failed to make progress. However, both are available open source. </p><p>This endurance is achieved through what Alibaba calls "environment scaling". Just as early LLMs grew smarter by ingesting more diverse text, Qwen3.7-Max was trained across a vast, scaled array of dynamic agentic environments. </p><p>It is capable of simulating a one-year lifecycle of a startup in the "YC-Bench" evaluation, navigating hundreds of decision-making rounds encompassing personnel management and contract screening. In this simulation, the model managed to generate $2.08 million in virtual revenue, nearly doubling the performance of the prior generation, Qwen3.6-Plus. </p><p>Furthermore, the model has built-in reward-hacking self-monitoring, autonomously detecting when it attempts to cheat a training environment and adding heuristic rules to correct its own behavior.</p><p><b>A brain for any scaffold</b></p><p>From a product perspective, Qwen3.7-Max is designed to be the cognitive engine for modern software development and enterprise automation. </p><p>The model offers a massive 1-million-token context window and a 64K maximum output limit, providing immense overhead for processing sprawling codebases or lengthy technical documents.</p><p>One of its most compelling features is<b> "cross-harness generalization". </b>Rather than being hardcoded to work best within a specific proprietary interface, Qwen3.7-Max is built to act as a drop-in intelligence layer for diverse agent frameworks. It <b>supports the Anthropic API protocol natively, </b>allowing developers to<b> plug it directly into existing tools like Claude Code or OpenClaw.</b></p><p>The benchmark data provided by Alibaba indicates that this generalized approach has paid massive dividends. </p><p>On the Apex Math Reasoning benchmark<b>, Qwen3.7-Max scored 44.5, eclipsing Claude Opus-4.6 Max's score of 34.5 </b>and <b>DeepSeek V4-Pro Max's 38.3.</b> It also posted <b>dominant scores on Humanity's Last Exam (41.4) and the realistic coding agent benchmark MCP-Atlas (76.4).</b></p><p>This translates into tangible utility for end-users. Through open source Model Context Protocol (MCP) integrations, the model can operate as an autonomous office assistant, capable of reading university formatting specs and automatically reformatting a messy Word document via command-line tools without human intervention.</p><p>Running this level of intelligence comes at a distinct cost. Developers accessing the API via Alibaba Cloud Model Studio will pay $2.50 per 1 million input tokens and $7.50 per 1 million output tokens. The platform also features explicit cache creation and read pricing, as well as a $10 fee per 1,000 calls for integrated web searches, though code interpreter tools remain free for a limited time.</p><p>Qwen3.7-Max occupies a strategic middle ground in the current API economy. While it demands a notable premium over aggressively priced domestic rivals—costing nearly double DeepSeek V4 Pro ($5.22) and Z.ai's GLM-5.1 ($5.80)—it drastically undercuts the Western frontier giants it routinely matches on benchmarks. </p><p>For context, running heavy agentic workflows through OpenAI's GPT-5.4 or Anthropic's Claude Opus 4.7 will run developers $17.50 and $30.00 per million tokens, respectively. See VentureBeat's pricing chart below:</p><h1>VentureBeat Frontier AI Model API Pricing Snapshot</h1><table><tbody><tr><td><p><b>Model</b></p></td><td><p><b>Input</b></p></td><td><p><b>Output</b></p></td><td><p><b>Total Cost</b></p></td><td><p><b>Source</b></p></td></tr><tr><td><p>MiMo-V2.5 Flash</p></td><td><p>$0.10</p></td><td><p>$0.30</p></td><td><p>$0.40</p></td><td><p><a href="https://platform.xiaomimimo.com/docs/en-US/pricing">Xiaomi MiMo</a></p></td></tr><tr><td><p>MiniMax M2.7</p></td><td><p>$0.30</p></td><td><p>$1.20</p></td><td><p>$1.50</p></td><td><p><a href="https://platform.minimax.io/docs/guides/models-intro">MiniMax</a></p></td></tr><tr><td><p>Gemini 3.1 Flash-Lite</p></td><td><p>$0.25</p></td><td><p>$1.50</p></td><td><p>$1.75</p></td><td><p><a href="https://ai.google.dev/gemini-api/docs/pricing">Google</a></p></td></tr><tr><td><p>MiMo-V2.5</p></td><td><p>$0.40</p></td><td><p>$2.00</p></td><td><p>$2.40</p></td><td><p><a href="https://platform.xiaomimimo.com/docs/en-US/pricing">Xiaomi MiMo</a></p></td></tr><tr><td><p>Kimi-K2.6</p></td><td><p>$0.95</p></td><td><p>$4.00</p></td><td><p>$4.95</p></td><td><p><a href="https://platform.kimi.ai/docs/pricing/chat-k26">Moonshot/Kimi</a></p></td></tr><tr><td><p>GLM-5</p></td><td><p>$1.00</p></td><td><p>$3.20</p></td><td><p>$4.20</p></td><td><p><a href="https://docs.z.ai/guides/overview/pricing">Z.ai</a></p></td></tr><tr><td><p>Grok 4.3 (low context)</p></td><td><p>$1.25</p></td><td><p>$2.50</p></td><td><p>$3.75</p></td><td><p><a href="https://docs.x.ai/developers/models/grok-4.3">xAI</a></p></td></tr><tr><td><p>DeepSeek V4 Pro</p></td><td><p>$1.74</p></td><td><p>$3.48</p></td><td><p>$5.22</p></td><td><p><a href="https://api-docs.deepseek.com/quick_start/pricing">DeepSeek</a></p></td></tr><tr><td><p>GLM-5.1</p></td><td><p>$1.40</p></td><td><p>$4.40</p></td><td><p>$5.80</p></td><td><p><a href="https://docs.z.ai/guides/overview/pricing">Z.ai</a></p></td></tr><tr><td><p>Claude Haiku 4.5</p></td><td><p>$1.00</p></td><td><p>$5.00</p></td><td><p>$6.00</p></td><td><p><a href="https://www.anthropic.com/pricing">Anthropic</a></p></td></tr><tr><td><p>Grok 4.3 (high context)</p></td><td><p>$2.50</p></td><td><p>$5.00</p></td><td><p>$7.50</p></td><td><p><a href="https://docs.x.ai/developers/models/grok-4.3">xAI</a></p></td></tr><tr><td><p><b>Qwen3.7-Max</b></p></td><td><p><b>$2.50</b></p></td><td><p><b>$7.50</b></p></td><td><p><b>$10.00</b></p></td><td><p><b></b><a href="https://modelstudio.console.alibabacloud.com/ap-southeast-1?spm=a2ty_o05.31384571.0.0.52649f6b7G0D55&amp;tab=doc#/doc/?type=model&amp;url=2840914_2&amp;modelId=qwen3.7-max&amp;serviceSite=international"><b>Alibaba Cloud</b></a></p></td></tr><tr><td><p>Gemini 3.5 Flash</p></td><td><p>$1.50</p></td><td><p>$9.00</p></td><td><p>$10.50</p></td><td><p><a href="https://ai.google.dev/gemini-api/docs/pricing">Google</a></p></td></tr><tr><td><p>Gemini 3.1 Pro Preview (≤200K)</p></td><td><p>$2.00</p></td><td><p>$12.00</p></td><td><p>$14.00</p></td><td><p><a href="https://ai.google.dev/gemini-api/docs/pricing">Google</a></p></td></tr><tr><td><p>GPT-5.4</p></td><td><p>$2.50</p></td><td><p>$15.00</p></td><td><p>$17.50</p></td><td><p><a href="https://openai.com/api/pricing/">OpenAI</a></p></td></tr><tr><td><p>Gemini 3.1 Pro Preview (&gt;200K)</p></td><td><p>$4.00</p></td><td><p>$18.00</p></td><td><p>$22.00</p></td><td><p><a href="https://ai.google.dev/gemini-api/docs/pricing">Google</a></p></td></tr><tr><td><p>Claude Opus 4.7</p></td><td><p>$5.00</p></td><td><p>$25.00</p></td><td><p>$30.00</p></td><td><p><a href="https://platform.claude.com/docs/en/about-claude/pricing">Anthropic</a></p></td></tr><tr><td><p>GPT-5.5</p></td><td><p>$5.00</p></td><td><p>$30.00</p></td><td><p>$35.00</p></td><td><p><a href="https://openai.com/api/pricing/">OpenAI</a></p></td></tr></tbody></table><p>By positioning Qwen3.7-Max just below Google's Gemini 3.5 Flash ($10.50) but well above budget-tier models, Alibaba is signaling that this isn't a commodity release; it’s a flagship reasoning engine priced to lure enterprise workloads away from Silicon Valley's most expensive offerings.</p><h2><b>Licensing remains proprietary for now</b></h2><p>For all its technical brilliance, the most controversial aspect of Qwen3.7-Max is how it is distributed. Qwen is billing the release as a "proprietary model". It is strictly API-only.</p><p>Historically,<a href="https://www.linkedin.com/pulse/open-source-summer-venturebeat-fkkge"> Alibaba’s Qwen has been a hero to the open-source</a> and local LLM communities. Previous iterations, like Qwen 2.5 and Qwen 3.6, released their weights publicly. Open weights allow developers, researchers, and enterprises to download the model, run it on their own hardware, and fine-tune it for highly specific or data-sensitive use cases without sending proprietary information to a third-party server.</p><p>By locking Qwen3.7-Max behind an API, Alibaba is pivoting to the standard commercial playbook utilized by OpenAI (with GPT-4) and Anthropic (with Claude). For enterprise users, this means utilizing Qwen3.7-Max requires trusting Alibaba Cloud with their data streams and relying entirely on internet connectivity to run their agentic workflows. For the open-source community, it means losing access to what is currently one of the most capable models on the planet.</p><h2><b>Community reactions split between awe and disappointment</b></h2><p>The reaction from the developer community has been swift, characterized by a mix of profound respect for the engineering achievement and frustration over the licensing model.</p><p>Prominent<a href="https://x.com/sudoingX/status/2057534264376471691?s=20"> AI commentator Sudo su (@sudoingX)</a> captured the prevailing sentiment on X (formerly Twitter). "qwen is unreal," they wrote. "they just dropped 3.7 max and it is beating opus 4.6 max on most of the benchmarks they ran".</p><p>The technical metrics, particularly the model's endurance, have left many in the field stunned. "the apex math number, 44.5 against opus 34.5, that is not a small gap," Sudo su noted. "the 35 hours straight on a kernel optimization task with 1000+ tool calls is the part i keep rereading. that is the agent era thing actually happening, not a slide".</p><p>The speed of Alibaba's iteration is also drawing notice. With Qwen 3.6 released just last month, the leap to 3.7-Max highlights a relentless development cadence. As Sudo su observed, "nobody else is moving like this".</p><p>Yet, the praise is heavily caveated by the shift to a closed ecosystem. The loss of the model weights is seen as a blow to the localized AI movement, which relies on state-of-the-art open models to push the boundaries of what can be done on consumer hardware or private enterprise clusters.</p><p>"one thing though, please open source this one too," Sudo su pleaded in their post. "3.6 dense made the entire local llm ecosystem better. the max tier going api only would close a door we have been keeping open. give us the weights eventually".</p><p>Qwen3.7-Max proves that the autonomous agent era is no longer a theoretical projection; it is a present reality capable of executing complex engineering feats while humans sleep. The only question now is whether this new frontier of AI will be a democratized resource you can download to your laptop, or an intelligence utility rented strictly from the cloud. For now, with Qwen3.7-Max, it is undeniably the latter.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Do Apple’s accessibility efforts point at its AI plans?]]></title>
<description><![CDATA[You can usually measure a society by the way it treats its most vulnerable populations, and technology often can help people live better, more autonomous lives. Apple firmly believes that, and this year’s raft of accessibility announcements introduced to mark Global Accessibility Awareness Day sh...]]></description>
<link>https://tsecurity.de/de/3537155/it-nachrichten/do-apples-accessibility-efforts-point-at-its-ai-plans/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3537155/it-nachrichten/do-apples-accessibility-efforts-point-at-its-ai-plans/</guid>
<pubDate>Thu, 21 May 2026 18:32:58 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>You can usually measure a society by the way it treats its most vulnerable populations, and technology often can help people live better, more autonomous lives. Apple firmly believes that, and this year’s raft of accessibility announcements introduced to mark <a href="https://accessibility.day/" target="_blank" rel="noreferrer noopener">Global Accessibility Awareness Day</a> shine a light on that belief. </p>



<p>The company has won a string of awards that recognize its work, including praise from the National Federation of the Blind, the American Foundation for the Blind, the Cerebral Palsy Foundation, and the National Association of the Deaf. These tools matter to everyone, of course; as we age and our faculties decline, the accessibility solutions Apple creates today promise better tomorrows.</p>



<h2 class="wp-block-heading"><strong>AI + Accessibility + Apple </strong></h2>



<p>With <a href="https://www.applemust.com/apple-announces-june-8-wwdc/" target="_blank" rel="noreferrer noopener">WWDC just weeks away</a>, Apple’s latest accessibility features promise powerful technologies for all. Most will arrive with the 27 series of Apple operating systems — and many of the most powerful tools lean deeply into AI and Apple Intelligence.</p>



<p>“The accessibility features our users rely on every day become even more powerful with Apple Intelligence,” said Sarah Herrlinger, Apple’s senior director of Global Accessibility Policy and Initiatives. “With these updates, we’re bringing new, intuitive options for input, exploration, and personalization, designed to protect users’ privacy at every step.”</p>



<p>They also give us a glimpse at what Apple has planned across its operating systems in terms of improved contextual intelligence in Siri. For example, a new tool called Image Explorer in VoiceOver lets you use Apple Intelligence to generate detailed descriptions of images held across your system, and those images can be documents, bills, receipts.</p>



<p>The idea is that you can hold up your iPhone, point your camera at the item and ask Apple Intelligence to describe what it is, read it to you, ask questions about what’s there, and even ask follow-up questions about what it sees. This will make a huge difference for disabled people who use voice to control their iPhone or iPad. (It remains unknown whether these services will also be available on Mac.)</p>



<p>All the same, the fact that these new accessibility improvements work on device mean you can use them in complete privacy, which makes them even more compelling.</p>



<h2 class="wp-block-heading"><strong>See it, say it, do it</strong></h2>



<p>While Apple hasn’t said anything specific, it’s hard to ignore that this feature could be of use in a more context-savvy Siri. If you think about it, what you see on your iPhone display is also an image; it seems plausible you’ll be able to use Siri to get things done on your device pretty soon.</p>



<p>That’s certainly true of a second accessibility improvement Apple introduced — Voice Control, which will let you navigate your device using natural speech. This is great for those of us who cannot easily use touch to navigate a device, and in combination with Image Explorer suggests deep use cases for all of us. After all, if Siri can open files with a voice command, why not with a text prompt? And if that file happens to be a workflow or agentic action, this could utterly transform the iPhone UI.</p>



<h2 class="wp-block-heading"><strong>AI that solves real problems</strong></h2>



<p>Apple is also putting more intelligence into Accessibility Reader, an invaluable tool for users with low vision or dyslexia that reads text to them. Now boosted by AI, this can handle far more complex source materials, including tables and multi-column layouts.</p>



<p>Accessibility Reader also takes a leap beyond just simply reading such material; thanks to AI, it can now generate on-demand summaries and even live translation of the text you choose to read. There’s intelligence in FaceTime conversations, too. Apple intends to introduce a new API for sign language interpretation app developers that lets users add human interpreters to ongoing calls.</p>



<p>AI is also available in video, meaning your device will automatically generate subtitles for spoken dialog for any content, including videos shared by family and friends. Apple’s on-device speech recognition means subtitles can be generated privately and appear automatically for uncaptioned videos on iPhone, iPad, Mac, Apple TV, and Apple Vision Pro.</p>



<h2 class="wp-block-heading"><strong>Mobility transformed with Vision Pro</strong></h2>



<p>Apple introduced a version of <a href="https://www.computerworld.com/article/1687259/the-story-behind-apples-wheelchair-activity-app.html">the Apple Watch Activity app for wheelchair users</a>  in 2016. This was a new first, as there had never been an accurate fitness tracker for wheelchair users before. The team building the solution had to create brand new algorithms and engage in massive tests to ensure it got this right.</p>



<p>Ten years later, and Apple has introduced something new: the capacity to control compatible power wheelchairs using the calibration-free eye-tracking capabilities of Apple Vision Pro. While this is interesting from a technical point of view, for some wheelchair users — particularly for those who cannot use a joystick to control their system — it’s a major benefit.</p>



<p>Pat Dolan is the founder of <a href="https://www.geoals.org/our-work" target="_blank" rel="noreferrer noopener">GeoALS</a>, which works to improve care, accelerate research, and advocate for the Amyotrophic lateral sclerosis (ALS) community. ALS is a progressive neurodegenerative disease that affects nerve cells in the brain and spinal cord. Dolan, who has lived with ALS for a decade said: “The option to control my power wheelchair on my own is gold to me; Apple is developing life-enhancing technology for the people who need it most.”</p>



<h2 class="wp-block-heading"><strong>For the many</strong></h2>



<p>In many ways, these features open up new opportunities for people who are customarily denied at least some of the chances many of us take for granted.</p>



<p>Apple CEO Tim Cook in 2018 <a href="https://www.computerworld.com/article/1690487/10-apple-accessibility-solutions-everyone-should-know.html">explained why Apple places so much focus on accessibility</a> within its platforms. “It’s a basic core value of Apple,” he said. “We don’t make products for a particular group of people; we make products for everybody. We feel very strongly that everyone deserves an equal opportunity and equal access.”</p>



<p>Ultimately, that’s the point with Apple’s approach to accessibility. The company builds all these features into its basic devices, which means people who need them aren’t forced into paying an accessibility tax in order to access the features they need. </p>



<p>“Apple’s approach to accessibility is unlike any other,” said Cook in a statement. “Now, with Apple Intelligence, we are bringing powerful new capabilities into our accessibility features while maintaining our foundational commitment to privacy by design.”</p>



<p><em>You can follow me on social media! Join me on </em><a href="https://bsky.app/profile/jonnyevanssays.bsky.social" target="_blank" rel="noreferrer noopener"><em>BlueSky</em></a><em>,  </em><a href="http://www.linkedin.com/in/jonnyevans" target="_blank" rel="noreferrer noopener"><em>LinkedIn</em></a><em>, and </em><a href="https://social.vivaldi.net/@jonnyevans" target="_blank" rel="noreferrer noopener"><em>Mastodon</em></a><em>.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Kore.ai launches Artemis AI agent platform, expands challenge to Microsoft and Salesforce]]></title>
<description><![CDATA[Kore.ai on Wednesday launched what amounts to a ground-up reinvention of its core technology: the Artemis edition of its Agent Platform, a system designed to let enterprises build, govern, and optimize AI agents using AI itself — compressing what has traditionally been months of engineering work ...]]></description>
<link>https://tsecurity.de/de/3536602/it-nachrichten/koreai-launches-artemis-ai-agent-platform-expands-challenge-to-microsoft-and-salesforce/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3536602/it-nachrichten/koreai-launches-artemis-ai-agent-platform-expands-challenge-to-microsoft-and-salesforce/</guid>
<pubDate>Thu, 21 May 2026 15:48:44 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><a href="http://kore.ai/">Kore.ai</a> on Wednesday launched what amounts to a ground-up reinvention of its core technology: the Artemis edition of its <a href="https://www.kore.ai/ai-agent-platform">Agent Platform</a>, a system designed to let enterprises build, govern, and optimize AI agents using AI itself — compressing what has traditionally been months of engineering work into days.</p><p>The platform arrives at a moment when every major technology vendor — from <a href="https://www.microsoft.com/en-us">Microsoft</a> and <a href="https://www.salesforce.com/">Salesforce</a> to <a href="https://www.google.com/">Google</a> and <a href="https://www.servicenow.com/">ServiceNow</a> — is racing to become the default infrastructure for enterprise AI agents. Kore.ai's answer to that crowded field is a bet on neutrality, a proprietary intermediary language for defining agents, and a philosophy that AI, not human developers, should do most of the heavy lifting.</p><p>"We're trying to change the paradigm about how people design, build, deploy and optimize agentic AI applications," Raj Koneru, the company's founder and CEO, told VentureBeat in an exclusive interview ahead of the launch. "The whole theme that we are now coming out with is you do AI with AI — you design with AI, you build with AI, you test with AI, you deploy with AI, manage with AI, and optimize with AI."</p><h2><b>A new YAML-based language aims to standardize how enterprises define and govern AI agents</b></h2><p>At the technical core of the Artemis platform sits <a href="https://docs.kore.ai/ai-for-service/app-settings/language-management/building-multi-language-bots">Agent Blueprint Language</a> (ABL), a compiled, declarative language built on YAML that standardizes how AI agents, workflows, and multi-agent systems are defined, validated, and governed. Kore.ai describes it as an intermediary layer that sits between the natural-language instructions a business user might provide and the production infrastructure where agents actually run.</p><p>ABL comes with its own parser, compiler, and runtime. It supports six built-in orchestration patterns — supervisor, delegation, handoff, fan-out, escalation, and agent-to-agent federation — that govern how multiple agents coordinate on complex tasks.</p><p>Koneru framed ABL as addressing a fundamental gap in the current AI landscape. "There's a lot of value in generating code, and that code is used by developers to build applications," he said. "What we saw is a gap between generating code and actually running it on infrastructure — with the deployment, version management, governance, and observability that production requires."</p><p>Because ABL artifacts are YAML-based, they can be stored in GitHub, version-controlled through CI/CD pipelines, and reviewed by both developers and business stakeholders — a design choice intended to bridge the divide between no-code platforms and traditional software engineering. "The final artifact is ABL, a YAML-based construct — you can put it in GitHub, you can version-control it," Koneru said. "It gives business people, developers, and IT a single standard to build on."</p><h2><b>Kore.ai's AI architect translates plain-language business goals into production-ready agent systems</b></h2><p>The second major innovation is <a href="https://docs.kore.ai/home">Arch</a>, an AI system that translates business requirements into production-ready ABL. Users provide specifications, data sources, and business rules in natural language. Arch then designs the multi-agent topology — selecting from the platform's six orchestration patterns — generates the ABL code, produces test data, deploys the application, and monitors it in production.</p><p>Critically, Arch also handles optimization. It observes whether deployed agents are meeting their goals, identifies where and why they fall short, and automatically regenerates and redeploys refined ABL to improve performance.</p><p>"Think of it this way," Koneru explained. "In the beginning, I wanted 50% automation for a particular use case. I'm getting 30%. Because of that cycle of optimization, it moves the needle to 50% by adjusting the application based on actual usage data."</p><p>This closed-loop approach — design, build, test, deploy, manage, optimize — is Kore.ai's bid to differentiate from both the no-code configuration platforms that dominated the previous era of chatbot development and the pro-code frameworks emerging from companies like <a href="https://www.anthropic.com/">Anthropic</a> and <a href="https://openai.com/">OpenAI</a>, which Koneru argues place too much burden on individual developers. "So that's a paradigm shift in the way AI agents have been built up until now," he said, "either with no code, configuration-based platforms — and we were one of them — or pro code capabilities that you get with Cloud code or a Codex or something else, which then puts the onus on the developer to build a platform for themselves."</p><h2><b>Why Kore.ai built a 'dual brain' to keep AI agents safe in banking, healthcare, and other regulated industries</b></h2><p>Perhaps the most architecturally significant element of the Artemis platform is what Kore.ai calls its Dual-Brain Architecture: two cognitive engines — one for agentic reasoning powered by large language models, the other for deterministic execution of business rules — operating in parallel through shared memory within a single runtime.</p><p>This design reflects a hard lesson Kore.ai has learned from more than a decade of deploying AI in banking, healthcare, insurance, and telecommunications. In those environments, leaving all decision-making to a language model is a non-starter.</p><p>"Enterprises are not going to completely relegate decision-making to a model," Koneru said. He drew a sharp contrast with newer AI-native startups: "A number of the AI-native companies that have emerged recently, especially in Silicon Valley, are essentially frameworks built as a wrapper around an LLM. That means much of the decision-making is left to the model — you're heavily reliant on it, and the model itself is the one implementing the guardrails."</p><p>Kore.ai's approach flips that. Guardrails — both input and output — are enforced at the platform layer, not by the model. Evaluations run inside the platform's governance engine. Business rules can execute deterministically when precision matters, while the LLM handles conversational responses and reasoning where appropriate. In a healthcare scenario where an AI agent is processing prescription refills for millions of consumers, or in a banking environment where an agent is advising clients on portfolio management, the consequences of a hallucinated response or an improperly executed workflow are severe. Kore.ai is positioning the Dual-Brain Architecture as the engineering answer to a trust problem that has slowed enterprise AI adoption across regulated sectors.</p><h2><b>Inside Kore.ai's deep partnership with Microsoft — and its pitch for vendor neutrality</b></h2><p><a href="https://www.kore.ai/">Artemis</a> launches initially on <a href="https://azure.microsoft.com/en-us">Microsoft Azure</a>, integrating natively with Microsoft Foundry, Microsoft Agent 365, Entra ID, and the Microsoft Graph API. Kore.ai is a launch partner for <a href="https://www.microsoft.com/en-us/microsoft-agent-365">Agent 365</a> and is working toward becoming a native Azure service within Azure Foundry.</p><p>The Microsoft partnership runs deep. Koneru described multiple co-build initiatives spanning the past year: agents built on Kore.ai's platform can run on <a href="https://azure.microsoft.com/en-us/products/ai-foundry">Azure Foundry</a> using its models and infrastructure; Kore.ai's AI for Work product integrates with Microsoft Copilot so that enterprise data and agentic workflows surface directly in the Copilot interface; and AI for Service integrates with Dynamics 365 as a joint go-to-market offering.</p><p>"There is a deep relationship," Koneru said. "In fact, I'm at their CEO Summit, and then for the next three days."</p><p>Stephen Boyle, CVP of Enterprise Partner Solutions at Microsoft, offered support for the partnership in the Artemis press release, noting that the platform "integrates with Microsoft Foundry and Microsoft Agent 365, giving customers a governed environment to build, deploy, and operate AI agents."</p><p>Yet Kore.ai simultaneously pitches itself as the vendor-neutral alternative to Microsoft and its peers — a tension the company addresses head-on. "All of the vendors or tech companies that you mentioned have a legacy that they're trying to protect," Koneru said when asked why a CIO should choose Kore.ai over an incumbent. "There's an inbuilt lock-in to their legacy, whether that's a Salesforce application, ServiceNow application, Microsoft Azure cloud, or whatever." The platform supports 175 different AI models — including those from OpenAI, Anthropic, and open-source providers — deploys across Azure, AWS, Google Cloud, and on-premises environments, connects to any data source via tool calling or MCP, and delivers across more than 40 voice and digital channels.</p><h2><b>How a pharmacy chain and a global investment bank deployed AI agents at massive scale</b></h2><p>Kore.ai's claims about enterprise readiness are backed by deployments that rank among the largest AI implementations in the world.</p><p>One of the largest pharmacy chains in the United States — which Koneru declined to name but described in enough detail to make identification straightforward — receives approximately 750 million calls from consumers annually. The chain signed with Kore.ai at the end of March 2025, deployed on its own infrastructure, had half of its 9,000 stores live within three months, and reached full deployment across all stores within six months.</p><p>"The speed at which they were able to build out very complex functionality — which requires understanding what the prescription is all about, being able to answer questions about them, then tying it to their backend systems to fill the prescription, refill it — all of those processes was done essentially," Koneru said.</p><p>A second example involves the world's second-largest investment bank, which deployed Kore.ai's AI for Work product to 135,000 employees and contractors. The bank uses the platform to give more than 30,000 financial advisors access to proprietary research and client portfolio data through a conversational interface, with agentic workflows handling routine tasks. The deployment went from initial users to global rollout within a year. A third customer — a major semiconductor manufacturer with 35,000 employees across multiple countries and languages — deployed AI for Work starting with HR use cases like onboarding, benefits management, and performance reviews, with backend integration to Workday, and has since expanded into IT, legal, and facilities management workflows.</p><h2><b>Kore.ai's analyst track record and funding history fuel its challenge to the hyperscalers</b></h2><p>The <a href="http://kore.ai/">Artemis</a> launch lands in one of the most fiercely contested markets in enterprise technology. Microsoft's Copilot Studio and Agent 365, Salesforce's Agentforce, Google's Vertex AI Agent Builder, and ServiceNow's AI Agents all target the same CIO budget. Meanwhile, a wave of well-funded startups — from established players like UiPath to AI-native entrants — is flooding the market with agent-building frameworks and platforms.</p><p>Kore.ai's competitive position rests on several pillars. The company has earned consistent recognition from major analyst firms: it has been named a Leader in the <a href="https://www.kore.ai/ai-research-reports/leader-gartner-magic-quadrant-conversational-ai-2025">Gartner Magic Quadrant for Enterprise Conversational AI Platforms</a> (positioned highest for Ability to Execute, according to the company), a <a href="https://www.kore.ai/ai-research-reports/kore-ai-leader-forrester-wave-cognitive-search-q4-2025">Leader in the Forrester Wave for Cognitive Search Platforms</a> with the highest ranking in the Strategy category, and an <a href="https://www.kore.ai/blog/kore-ai-positioned-as-an-emerging-leader-in-gartners-emqs-for-generative-ai-engineering-and-genai-applications">Emerging Leader in Gartner's Emerging Market Quadrants</a> for both Generative AI Engineering and GenAI Applications. Everest Group has also positioned Kore.ai as a Leader in its Agentic AI Products PEAK Matrix Assessment for 2026.</p><p>The company's financial trajectory adds further credibility. In January 2024, Kore.ai raised $150 million in a round led by <a href="https://ftvcapital.com/2024/kore-ai-secures-150-million-strategic-growth-investment-to-drive-ai-powered-customer-and-employee-experiences-for-global-brands/">FTV Capital</a> with participation from Nvidia, bringing total funding to approximately $223 million. TechCrunch reported at the time that the company's annual recurring revenue <a href="https://techcrunch.com/2024/01/30/kore-ai-a-startup-building-conversational-ai-for-enterprises-raises-150m/">exceeded $100 million</a>, with the platform automating 450 million interactions daily. In January 2026, the company secured an additional strategic growth investment led by AllianceBernstein Private Credit Investors, with continued backing from Vistara Growth, Beedie Capital, and Sweetwater Private Equity. The company now claims more than 500 Global 2000 customers and partners, with 75% of its customer base in regulated industries and support for over 300 enterprise integrations.</p><h2><b>What the Artemis launch means for the future of enterprise AI agent platforms</b></h2><p>The <a href="https://www.kore.ai/ai-agent-platform">Artemis platform</a> is available today at kore.ai, launching initially on Microsoft Azure with broader cloud availability to follow. Koneru said existing customers — many of whom built their current deployments on Kore.ai's previous no-code platform — are planning migrations to the new architecture, while all new customers are starting on Artemis.</p><p>The portability question remains partially unresolved. While ABL itself is a YAML-based artifact that customers can store and manage in their own systems, the runtime required to execute it is not yet available as a standalone component. Koneru said a lighter version of the runtime will be made available in the future for customers who want to run ABL outside the full Kore.ai platform, but acknowledged that the initial release prioritizes the integrated enterprise experience.</p><p>For CIOs navigating an increasingly crowded and fast-moving market for enterprise AI agents, the Artemis launch poses a clear choice: bet on a hyperscaler's native platform and accept the lock-in that comes with it, or adopt a neutral layer that promises to orchestrate and govern agents across any model, any cloud, and any vendor — but requires trust in a company that, for all its scale and analyst recognition, remains far smaller than the giants it competes against.</p><p>"If I'm going to go down the path of one hyperscaler or one SaaS company that provides an agentic platform, I'm getting locked in in some fashion or the other," Koneru said. "We need standardization. We need a central way to build and deploy. We need a central way to govern."</p><p>It is a bold claim from a company that has spent 12 years building the plumbing for enterprise AI while flashier names grabbed headlines. But if the next chapter of the AI revolution is defined not by which model is smartest but by which platform can be trusted to run agents safely at scale, then Kore.ai's long apprenticeship in the unglamorous trenches of compliance, governance, and regulated industry deployment may turn out to be exactly the right résumé for the job.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Industry Reacts to Verizon DBIR 2026 as Vulnerability Exploitation Takes Top Spot]]></title>
<description><![CDATA[The 2026 Verizon Data Breach Investigations Report (DBIR) has sparked widespread industry reaction, with security leaders warning that AI-enabled attacks, vulnerability exploitation, and third-party risk are reshaping the threat landscape faster than many organisations can respond. For the first ...]]></description>
<link>https://tsecurity.de/de/3536151/it-security-nachrichten/industry-reacts-to-verizon-dbir-2026-as-vulnerability-exploitation-takes-top-spot/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3536151/it-security-nachrichten/industry-reacts-to-verizon-dbir-2026-as-vulnerability-exploitation-takes-top-spot/</guid>
<pubDate>Thu, 21 May 2026 13:35:18 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>The 2026 Verizon Data Breach Investigations Report (DBIR) has sparked widespread industry reaction, with security leaders warning that AI-enabled attacks, vulnerability exploitation, and third-party risk are reshaping the threat landscape faster than many organisations can respond. For the first time…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/industry-reacts-to-verizon-dbir-2026-as-vulnerability-exploitation-takes-top-spot/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/industry-reacts-to-verizon-dbir-2026-as-vulnerability-exploitation-takes-top-spot/">Industry Reacts to Verizon DBIR 2026 as Vulnerability Exploitation Takes Top Spot</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Industry Reacts to Verizon DBIR 2026 as Vulnerability Exploitation Takes Top Spot]]></title>
<description><![CDATA[The 2026 Verizon Data Breach Investigations Report (DBIR) has sparked widespread industry reaction, with security leaders warning that AI-enabled attacks, vulnerability exploitation, and third-party risk are reshaping the threat landscape faster than many organisations can respond. For the first ...]]></description>
<link>https://tsecurity.de/de/3536111/it-security-nachrichten/industry-reacts-to-verizon-dbir-2026-as-vulnerability-exploitation-takes-top-spot/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3536111/it-security-nachrichten/industry-reacts-to-verizon-dbir-2026-as-vulnerability-exploitation-takes-top-spot/</guid>
<pubDate>Thu, 21 May 2026 13:22:36 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>The 2026 Verizon Data Breach Investigations Report (DBIR) has sparked widespread industry reaction, with security leaders warning that AI-enabled attacks, vulnerability exploitation, and third-party risk are reshaping the threat landscape faster than many organisations can respond. For the first time in the report’s history, vulnerability exploitation overtook stolen credentials as the leading initial access vector, […]</p>
<p>The post <a href="https://www.itsecurityguru.org/2026/05/21/industry-reacts-to-verizon-dbir-2026-as-vulnerability-exploitation-takes-top-spot/">Industry Reacts to Verizon DBIR 2026 as Vulnerability Exploitation Takes Top Spot</a> appeared first on <a href="https://www.itsecurityguru.org/">IT Security Guru</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Angular Signal Forms: From event pipelines to signal-driven state]]></title>
<description><![CDATA[Forms are often the most state-heavy part of a front-end application. They capture user input, run validation logic, track interaction states, and coordinate how changes propagate through the UI. As forms grow larger, with multi-step workflows, conditional fields, and asynchronous validation, the...]]></description>
<link>https://tsecurity.de/de/3535683/ai-nachrichten/angular-signal-forms-from-event-pipelines-to-signal-driven-state/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3535683/ai-nachrichten/angular-signal-forms-from-event-pipelines-to-signal-driven-state/</guid>
<pubDate>Thu, 21 May 2026 11:03:41 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Forms are often the most <a href="https://www.infoworld.com/article/4154060/rethinking-angular-forms-a-state-first-perspective.html" data-type="link" data-id="https://www.infoworld.com/article/4154060/rethinking-angular-forms-a-state-first-perspective.html">state-heavy part</a> of a front-end application. They capture user input, run validation logic, track interaction states, and coordinate how changes propagate through the UI. As forms grow larger, with multi-step workflows, conditional fields, and asynchronous validation, the amount of code required to keep everything synchronized increases quickly.</p>



<p>Angular has introduced several approaches to managing forms. Early applications relied on template-driven forms. Later, reactive forms provided a structured way to model validation and control state. Typed forms further improved the developer experience by bringing stronger type safety to the API.</p>



<p>Signal Forms represent the next step in that evolution.</p>



<p>Signal Forms reflect a broader shift toward what can be described as a state-first front-end architecture, where application state becomes the primary structure and UI behavior is derived from it. Instead of coordinating reactions to user events across multiple controls and validators, developers describe the form’s data structure and validation rules while Angular keeps the UI synchronized automatically.</p>



<p>This reflects a broader architectural trend across modern front-end frameworks.</p>



<p>Much of the complexity in modern forms comes from coordinating reactions to events rather than representing form state directly. Signal Forms explore what happens when the form state itself becomes the primary abstraction.</p>



<p>This shift becomes easier to understand when applied to a concrete problem. In a recent article, “<a href="https://www.infoworld.com/article/4145032/we-mistook-event-handling-for-architecture.html">We mistook event handling for architecture</a>,” I explored how front-end systems often become complex when built around chains of events rather than explicit state. Forms provide one of the clearest examples of this problem — and illustrate how a state-first model changes the way we structure front-end systems.</p>



<p>Modern front-end complexity is often not a result of scale, but of modeling systems around event flows instead of explicit state.</p>



<h2 class="wp-block-heading"><a></a>Why forms become complex</h2>



<p>Forms rarely consist of simple inputs. Even relatively small forms often include several layers of behavior:</p>



<ul class="wp-block-list">
<li>Validation rules</li>



<li>Error messages</li>



<li>Touched and dirty states</li>



<li>Conditional UI updates</li>



<li>Derived values</li>



<li>Asynchronous validation</li>
</ul>



<p>In traditional architectures, event flows frequently trigger these behaviors. When a user types into a field, the framework triggers validation, updates control state, and propagates status changes throughout the form.</p>



<p>While this approach works well, developers often end up coordinating many moving parts: validators, state flags, UI conditions, and control hierarchies. As forms become more dynamic, the coordination logic grows quickly.</p>



<p>Angular Signal Forms approach the same challenge from a different perspective: start with the state and derive everything else from it.</p>



<h2 class="wp-block-heading"><a></a>Modeling form data with signals</h2>



<p>Signal Forms begin with a model represented as a signal. Instead of constructing form controls first, developers define the data structure that represents the form.</p>



<pre class="wp-block-code"><code>import { signal } from '@angular/core';

interface LoginModel {
  email: string;
  password: string;
}

loginModel = signal<loginmodel>({
  email: '',
  password: '',
});
</loginmodel></code></pre>



<p>This signal represents the single source of truth for the form’s data. When users interact with form inputs, Angular updates this model automatically.</p>



<p>Because signals are reactive primitives, Angular can track how the UI depends on this state and update the interface whenever the model changes. In this approach, the form’s data model is at the center of the architecture.</p>



<h2 class="wp-block-heading"><a></a>Creating a Signal Form</h2>



<p>Once the model is defined, Angular’s Signal Forms API connects the model to form behavior.</p>



<pre class="wp-block-code"><code>import { form, required, email } from '@angular/forms/signals';

loginForm = form(this.loginModel, (schema) =&gt; {
  required(schema.email, { message: 'Email is required' });
  email(schema.email, { message: 'Enter a valid email address' });
  required(schema.password, { message: 'Password is required' });
});
</code></pre>



<p>The <code>form()</code> function links the signal model with form logic. The schema callback defines validation rules that apply to each field. Instead of attaching validators directly to control objects, validation becomes a declarative description of constraints on the form’s state.</p>



<p>This design keeps validation logic close to the data structure itself and allows Angular to compute field validity automatically.</p>



<h2 class="wp-block-heading"><a></a>Binding fields in the template</h2>



<p>Fields are bound to the form using the formField directive.</p>



<pre class="wp-block-code"><code>


</code></pre>



<p>Angular automatically synchronizes the form model with the UI.</p>



<p>Templates can also read the field’s current value directly:</p>



<pre class="wp-block-code"><code><p>Email value: {{ loginForm.email().value() }}</p>
</code></pre>



<p>Because the value is exposed through a signal, Angular automatically updates the UI whenever the underlying state changes. No manual subscriptions or explicit change detection are required.</p>



<h2 class="wp-block-heading"><a></a>Validation as reactive state</h2>



<p>Validation is one of the areas where Signal Forms highlight the benefits of a state-first model.</p>



<p>In traditional form architectures, validation often occurs as a chain of reactions. Input changes trigger validators, validators update control status, and UI elements react to those updates.</p>



<p>Signal Forms treat validation differently. With Signal Forms, validation rules describe constraints on the form’s state. Angular derives validity directly from the current model.</p>



<p>When validation becomes a function of form state rather than a chain of events, many synchronization problems disappear.</p>



<p>Developers define relationships between data and validity instead of orchestrating validation pipelines. Angular maintains those relationships automatically.</p>



<h2 class="wp-block-heading"><a></a>Reactive UI behavior</h2>



<p>Because the field state is reactive, templates can respond directly to validation results.</p>



<pre class="wp-block-code"><code>@if (loginForm.email().errors()) {
  <p>Please enter a valid email address.</p>
}
</code></pre>



<p>Whenever the field value changes or validation rules update the state, Angular automatically refreshes the UI. Developers do not need to manually subscribe to value changes or propagate state through component code.</p>



<h2 class="wp-block-heading"><a></a>A state-first mental model</h2>



<p>The most important aspect of Signal Forms is not just the new API but the mental model it encourages.</p>



<p>Traditional form systems are often organized around event flows: user input triggers validation, validation updates control state, and components respond to those changes.</p>



<p>Signal Forms shift the focus toward modeling state explicitly. The form model describes the current data. Validation rules describe constraints on that data. The UI reacts automatically.</p>



<p>Signal Forms move Angular form architecture away from event orchestration and toward explicit state modelling. This approach reduces the amount of manual synchronization required between validation logic, form state, and UI behavior.</p>



<p>For large forms, that simplification can make the application significantly easier to reason about.</p>



<h2 class="wp-block-heading"><a></a>Where Signal Forms fit today</h2>



<p>Signal Forms are currently an experimental feature in Angular and are intended primarily for applications that are already adopting Signals as their core reactive primitive.</p>



<p>Existing applications built around reactive forms can continue using reactive forms successfully. Reactive forms remain a stable and powerful solution for complex workflows. Furthermore, Angular’s Signal Forms API provides interoperability tools such as <code>compatForm</code> and <code>SignalFormControl</code> that allow existing <code>FormControl</code> or <code>FormGroup</code> instances to participate in signal-based forms. This makes it possible to adopt Signal Forms incrementally, for example, introducing signal-based state in new components while existing reactive forms continue powering legacy or highly customized workflows.</p>



<p>Signal Forms represent a new direction that aligns with Angular’s broader Signals-based architecture. They demonstrate how common UI patterns may evolve when state becomes the central abstraction.</p>



<h2 class="wp-block-heading"><a></a>Signals and the future of Angular forms</h2>



<p>Angular’s investment in Signals has already influenced several parts of the framework, including change detection and component/router inputs. Forms are another area where this approach has the potential to simplify application design.</p>



<p>By modeling form data as a reactive state, Angular can reduce the amount of coordination code that developers typically write when managing validation, UI updates, and derived values. As Signals mature in Angular, forms may become one of the clearest examples of the framework’s shift toward state-driven front-end architecture.</p>



<p>For many applications, forms are where complexity accumulates fastest. Signal Forms demonstrate how treating the state as the central abstraction can make that complexity easier to manage. And in modern front-end systems, clarity of state is often the key to building applications that remain understandable as they grow.</p>



<p>As this model evolves, it is likely that frameworks like Angular will move away from explicit event orchestration as a primary design tool, and instead center more of their architecture around state relationships and derived computation.</p>



<p>Forms are only one example. As Angular continues to expand its Signals-based APIs, similar patterns are emerging across component inputs, routing, and data fetching.</p>



<p>These developments point to a broader architectural shift where front-end systems are increasingly modeled around explicit state rather than chains of events — a direction that will shape how Angular applications are designed in the coming years.</p>
</div></div></div>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Why AI adoption may be lagging in Global South businesses]]></title>
<description><![CDATA[Brain drain and training languages continue to be major barriers for localized AI adoption]]></description>
<link>https://tsecurity.de/de/3535370/it-security-nachrichten/why-ai-adoption-may-be-lagging-in-global-south-businesses/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3535370/it-security-nachrichten/why-ai-adoption-may-be-lagging-in-global-south-businesses/</guid>
<pubDate>Thu, 21 May 2026 09:08:24 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Brain drain and training languages continue to be major barriers for localized AI adoption]]></content:encoded>
</item>
<item>
<title><![CDATA[NanoClaw's creators are turning the secure, open source AI agent harness into an enterprise 'second brain']]></title>
<description><![CDATA[The creators of NanoClaw — the hit open source, enterprise-friendly variant of autonomous AI agent harness OpenClaw — are moving towards commercializing their technology for enterprises at scale, aiming to provide them with secure AI agents, and an ever-updating library of workplace context, for ...]]></description>
<link>https://tsecurity.de/de/3533448/it-nachrichten/nanoclaws-creators-are-turning-the-secure-open-source-ai-agent-harness-into-an-enterprise-second-brain/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3533448/it-nachrichten/nanoclaws-creators-are-turning-the-secure-open-source-ai-agent-harness-into-an-enterprise-second-brain/</guid>
<pubDate>Wed, 20 May 2026 16:48:28 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>The creators of <a href="https://nanoclaw.dev/">NanoClaw</a> — the hit open source, enterprise-friendly variant of autonomous AI agent harness OpenClaw — are moving towards commercializing their technology for enterprises at scale, aiming to provide them with secure AI agents, and an ever-updating library of workplace context, for each human employee the enterprise has approved.</p><p>The duo, including former <a href="https://www.wix.com/">Wix.com</a> engineer Gavriel Cohen and his brother Lazer Cohen, also founder of tech public relations firm <a href="https://concrete.media/team/">Concrete Media</a>, shared with VentureBeat that their new startup, <a href="https://nanoco.ai/">NanoCo AI</a>, has received a $12 million oversubscribed seed round was led by Valley Capital Partners. </p><p>The round features a roster of strategic backers that reads like an enterprise infrastructure all-star team, including Docker, Vercel, monday.com, Factorial Capital, and Hugging Face CEO and founder Clem Delangue.</p><p>Buoyed by the seed round, NanoCo AI wants to move beyond basic automation to offer every enterprise worker a secure "professional assistant." Yet they are still committed to building out and maintaining NanoClaw as an MIT Licensed, enterprise-friendly, open source standard — just offering specialized commercial managed services integration atop it. </p><h2><b>The new killer use case: an informed, ever-updating personal assistant for each human worker</b></h2><p>Gavriel, now CEO of NanoCo AI, sees this personalized approach as the ultimate unlock for the modern worker. </p><p>“The killer use case is the the one to one we're calling it professional assistant,” Cohen explained in a recent exclusive interview with VentureBeat. "If you can give someone an agent and make them twice, three times as effective, then you probably want more people as well, right?" </p><p>He noted that as users forward emails, documents, and call notes to the agent, it systematically builds an "LLM wiki" — similar to the "LLM Knowledge Base" concept articulated by <a href="https://venturebeat.com/technology/andrej-karpathy-announces-hes-joining-anthropic">influential AI researcher Andrej Karpathy</a> — effectively creating a dynamic knowledge graph of the user's specific job and projects.</p><p>This persistent memory allows the agent to shift from simply answering questions to actively transforming information and executing first drafts that rival human output. </p><p>Cohen emphasized that NanoClaw acts as a massive productivity multiplier rather than a headcount replacement.</p><h2><b>One-to-one secure 'lobster' AI</b></h2><p>NanoCo’s core offering is a one-to-one professional AI assistant designed to shadow employees, draft contracts, review code, and manage accounts directly within tools like Slack and Microsoft Teams. </p><p>Rather than a generic chatbot, the assistant learns the employee's role and adapts to their specific working style through ordinary conversation.</p><p>How does NanoCo prevent this highly capable assistant from going rogue? By moving security away from fragile prompt engineering and embedding it directly into the infrastructure.</p><p>Unlike its predecessor and inspiration, the even popular open source AI assistant OpenClaw — which grew to a massive 400,000 lines of code — NanoClaw’s core logic was intentionally minimized to roughly 500 lines of TypeScript. This minimalism ensures the entire system can be audited by a human security team in about eight minutes.</p><p>Furthermore, every NanoClaw agent operates within a strictly isolated environment. Leveraging a <a href="https://venturebeat.com/infrastructure/nanoclaw-and-docker-partner-to-make-sandboxes-the-safest-way-for-enterprises">strategic partnership with Docker</a> announced in March, NanoCo AI runs these agents inside MicroVM-based Docker Sandboxes. </p><p>“In NanoClaw, the 'blast radius' of a potential prompt injection is strictly confined to the container and its specific communication channel,” Cohen previously explained.</p><p>To prevent unauthorized actions, raw API credentials never reach the agent itself. Instead, outbound requests pass through a secure OneCLI Rust Gateway that enforces company-defined policies. If an agent attempts a sensitive "write" action—like modifying a cloud environment or deleting an email—the gateway intercepts the request and pings the human user via a rich interactive card on Slack, Teams, or WhatsApp. </p><p>Only when the user explicitly taps "Approve" does the system inject the credential. It is the architectural equivalent of a highly capable junior employee drafting an important corporate communication, but being physically unable to click "send" without the manager turning a literal launch key.</p><h2><b>Continued commitment to open source, MIT License</b></h2><p>Despite its new enterprise push, NanoCo AI is maintaining its commitment to its open-source foundation. The core NanoClaw framework remains available under the permissive MIT License, meaning independent developers and companies can continue to fork, modify, and run the system locally.</p><p>In plain terms, the MIT License allows anyone to use the software commercially without paying NanoCo AI, provided they include the original copyright notice. </p><p>NanoCo AI's monetization strategy instead focuses on the vast majority of enterprises that lack the specialized engineering resources to build, maintain, and scale internal agent platforms. </p><p>While highly technical teams can choose to build their own infrastructure on top of the open-source code, NanoCo will sell managed, organization-wide deployments, taking on the burden of health checks, integrations, and ongoing security maintenance.</p><h2><b>Widespread global adoption</b></h2><p>The open-source adoption of NanoClaw has been staggering, crossing 250,000 downloads and nearing 29,000 GitHub stars since its debut. This ground-up momentum is entirely responsible for the surging enterprise demand.</p><p>“Countless enterprise executives have told us the same thing,” Cohen stated in the press release. “They're running NanoClaw personally, getting two and three times more done, and asking how to roll it out to their teams.”.</p><p>Perhaps the most high-profile validation came during the founders' recent trip to Singapore. The country’s Foreign Minister, Dr. Vivian Balakrishnan, invited the NanoCo team to his office after publicly posting about his personal use of NanoClaw. Balakrishnan described the agent as “getting smarter over time," referred to it as his "second brain," and stated he wouldn't "dare switch it off".</p><p>Cohen put the platform's security claims to the ultimate test during a live conference demonstration in Singapore. He invited a crowd of 300 people to chat simultaneously with his personal agent, which was actively connected to his real email and calendar. </p><p>Thanks to NanoClaw's zero-trust gateway architecture, the agent safely rejected malicious attempts to access his inbox or delete existing events, while successfully allowing 12 attendees to book legitimate coffee chats.</p><p>As AI shifts from a novelty tool that answers questions into a digital workforce that autonomously executes tasks, NanoCo AI is betting that verifiable security will be the defining metric of success. By combining a transparent open-source core with strict, infrastructure-level sandboxing, they aren’t just selling an assistant; they are selling the peace of mind required for enterprises to actually use one.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[OpenAI co-founder Andrej Karpathy announces he's joining Anthropic]]></title>
<description><![CDATA[Andrej Karpathy, the influential 39-year-old Slovak-Canadian AI researcher and one of the original 11 co-founders of OpenAI, and former head of Tesla's AI division, announced on Tuesday, May 19 that he's joining rival lab Anthropic.As Karpathy posted from his account on the social network X: "Per...]]></description>
<link>https://tsecurity.de/de/3530358/it-nachrichten/openai-co-founder-andrej-karpathy-announces-hes-joining-anthropic/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3530358/it-nachrichten/openai-co-founder-andrej-karpathy-announces-hes-joining-anthropic/</guid>
<pubDate>Tue, 19 May 2026 20:04:37 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Andrej Karpathy, the influential 39-year-old Slovak-Canadian AI researcher and one of the<a href="https://www.reddit.com/r/OpenAI/comments/1m80e9g/the_11_cofounders_of_openai_in_2025/"> original 11 co-founders of OpenAI</a>, and former head of Tesla's AI division, announced on Tuesday, May 19 that he's joining rival lab Anthropic.</p><p>As Karpathy <a href="https://venturebeat.com/technology/andrej-karpathy-announces-hes-joining-anthropic">posted from his account on the social network X</a>: <i>"Personal update: I've joined Anthropic. I think the next few years at the frontier of LLMs will be especially formative. I am very excited to join the team here and get back to R&amp;D. I remain deeply passionate about education and plan to resume my work on it in time."</i></p><p>Anthropic's current Head of Pretraining, Nicholas Joseph, also a former OpenAI alumnus, added more context to Karpathy's new role at Anthropic in <a href="https://x.com/nickevanjoseph/status/2056760504949842219">a post of his own on X,</a> writing: "<i>Excited to welcome Andrej to the Pretraining team! He'll be building a team focused on using Claude to accelerate pretraining research itself. I can’t think of anyone better suited to do it — looking forward to what we build together!"</i></p><p>An Anthropic spokesperson confirmed to VentureBeat via email that Karpathy will be starting a team focused on using Claude, Anthropic's own, increasingly popular AI model, to accelerate pretraining research. This would put Anthropic further toward the overarching AI research goal of many around the world to develop "<a href="https://www.forbes.com/sites/johnsviokla/2026/03/16/the-most-important-idea-in-ai-recursive-self-improvement-rsi/">recursive self-improvement,</a>" that is, AI that is capable of training its successors or upgrading itself with increasingly lesser, or ultimately no human intervention. </p><p>The announcement came on the same day as the start of rival AI-focused tech firm Google's annual I/O developer conference in its headquarters city of Mountain View, California, when many new releases and announcements were expected.</p><h2><b>Karpathy's storied history</b></h2><p>Karpathy is widely known for spanning three parts of the modern AI boom: academic research, big-company deployment and online education. </p><p>His <a href="https://karpathy.ai/">own website</a> describes him as an AI researcher and educator who was a founding member of OpenAI, later served as Director of AI at Tesla, and helped create Stanford’s first deep learning course, CS231n. </p><p>OpenAI’s December 2015 launch announcement also listed Karpathy among the group’s founding members.</p><p>At Tesla, where he worked from 2017 to 2022, Karpathy led the computer vision team for Autopilot and says his team handled in-house data labeling, neural network training and deployment on Tesla’s custom inference chip. </p><p>He then returned to OpenAI from 2023 to 2024, where his website says he built a team focused on midtraining and synthetic data generation — experience directly relevant to Anthropic’s reported pretraining role.</p><p>Karpathy’s academic work began at Stanford, where he earned his PhD under Fei-Fei Li and focused on neural networks for computer vision, natural language processing and the intersection of the two. </p><p>He also interned at Google Brain, Google Research and DeepMind, according to his website. His education includes an MSc from the University of British Columbia and a BSc from the University of Toronto, where he double-majored in computer science and physics.</p><h2><b>What will become of Karpathy's open source research and commitment to AI education?</b></h2><p>Since leaving OpenAI in 2024, Karpathy has become one of AI’s most visible public educators, publishing technical and general-audience videos on large language models and neural networks. </p><p>He also launched Eureka Labs in July 2024 as an “AI-native” school; its first product, <a href="https://x.com/karpathy/status/1813263734707790301">LLM101n</a>, is described as an undergraduate-level course guiding students through training their own AI system.</p><p>Acting on his own as a free agent over the last two years, Karpathy has also helped push open source AI research forward with products and standards including <a href="https://venturebeat.com/technology/andrej-karpathys-new-open-source-autoresearch-lets-you-run-hundreds-of-ai">autoresearch</a>, an LLM-driven automated researcher that can run multiple hypothesis and experiments simultaneously, and the <a href="https://venturebeat.com/data/karpathy-shares-llm-knowledge-base-architecture-that-bypasses-rag-with-an">LLM Knowledge Base</a>, an autonomous system of storing memory and context for AI agents in a kind of ever-growing library designed for them to access. </p><p>The big question is what becomes of these and Karpathy's open source AI efforts more generally as he joins Anthropic, a lab that has supported open source via the launch of its Model Context Protocol (MCP) technical standard, but which also famously has shipped primarily proprietary AI models and harnesses (such as Claude and Claude Code). </p><p>Based on the last statement in his announcement post on X — "<i>I remain deeply passionate about education and plan to resume my work on it in time" </i>— it appears that at least his contributions to the AI-native school effort will be paused as he digs in at Anthropic.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Android XR Updates for Unity, Unreal, and Godot]]></title>
<description><![CDATA[Posted by Luke Hopkins, Android Developer Relations Engineer for OpenXR & Ryan Bartley, Android XR Product ManagerToday, we are excited to announce that official support for Unreal Engine and Godot has arrived for Android XR. Alongside these engine expansions, we are also launching new tools desi...]]></description>
<link>https://tsecurity.de/de/3530266/android-tipps/android-xr-updates-for-unity-unreal-and-godot/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3530266/android-tipps/android-xr-updates-for-unity-unreal-and-godot/</guid>
<pubDate>Tue, 19 May 2026 19:56:27 +0200</pubDate>
<category>🤖 Android Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[
<img src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh9sRZp34Nz9OvtdjQgkUqBOCiB7snnY3tG2Q5zJUokTcmW8uY0lcpDP3oE23kXFlnxzLW2HkraebaXMENlUJ5s6-YabMq7_U7XT_hOhHbIfCJBuqD1SZm-l4Mi7lJ9sTSwa7httwdtvf1iYJHCIHwYV7UOZdiHME8DXGoCGZ3ocyx31WRtWPCtuA_rDdc/s2048/GoogleForDevelopers-AndroidCombo3-StrapiMetacard-2048x1323%20(1).png">


<div><div class="separator"><i>Posted by Luke Hopkins, Android Developer Relations Engineer for OpenXR &amp; Ryan Bartley, Android XR Product Manager</i></div></div><div class="separator"><a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhXNALkAWpqYWv2OThv_drVHbPQCX7f0fYfiMip7aRBL6ASb878EyoGtsZ7WZwuzdCYfHsPWuEqqQ6-3WI3XFFX41PByg4WgXZ7UrOGD6rE9eId6EN61X6NnlppLotFTDgPkX1uqYVoLrac9h4Zj06lNRLO4YRMK3vcO8h6-03MKIlc5pGZxfJ4UtbuWUA/s4209/GoogleForDevelopers-AndroidCombo3-Blogger-4209x1253.png"><img border="0" data-original-height="1253" data-original-width="4209" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhXNALkAWpqYWv2OThv_drVHbPQCX7f0fYfiMip7aRBL6ASb878EyoGtsZ7WZwuzdCYfHsPWuEqqQ6-3WI3XFFX41PByg4WgXZ7UrOGD6rE9eId6EN61X6NnlppLotFTDgPkX1uqYVoLrac9h4Zj06lNRLO4YRMK3vcO8h6-03MKIlc5pGZxfJ4UtbuWUA/s16000/GoogleForDevelopers-AndroidCombo3-Blogger-4209x1253.png"></a></div><br><p><br></p><p>Today, we are excited to announce that official support for <a href="https://www.unrealengine.com/">Unreal Engine</a> and <a href="https://godotengine.org/">Godot</a> has arrived for Android XR. Alongside these engine expansions, we are also launching new tools designed to boost your productivity and enable new XR capabilities: the <b>Android XR Engine Hub </b>and the <b>Android XR Interaction Framework</b>.</p>

  <h2>Android XR Engine Hub</h2>
  <p>The <a href="https://developer.android.com/xr/engine-hub">Android XR Engine Hub</a> is currently available for Windows and is your mission control for development. It unifies your workflow across Unity, Unreal Engine, and Godot by serving as a high-speed bridge that streams device-created perception data straight from your device into the engine of your choice.</p><div class="separator"><img border="0" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEivaoLNBD-WKlpnJ-r_cc-z0yaYWtr_CVmZfooRh9ebapUQU_WE0sHgjtzuaMODb185rZbCSJANKsd67XC9-2yTKh_hF-ET7DfDcmPb45NwNOCsOzTnYK1Mm_pyANcctuMgl8M6_6d8Mk0iRC9j0qQGr5KMzPOJ87FFrdLnyMT7oH38BcyjPuEwXOxLdEA/w640-h348/DirectPreview_Low.gif"></div>

  <h3>Real-Time Streaming via OpenXR</h3>
  <p>The Hub bridges the gap between desktop power and mobile sensor data. Instead of requiring a full build to see how your app reacts to the world, the Hub <b>streams OpenXR extensions</b> from the physical Android XR device directly to your Windows machine.</p>
  <p>This means you can iterate on complex interactions in "Play Mode" while receiving live, high-fidelity data from the headset’s sensors. Without this streaming capability, testing even a minor change to eye-tracking or spatial mapping would require a full APK export and installation.</p>
  <p>The Hub enables low-latency testing for the following streamed extensions:</p>
  
  <p><strong>Core &amp; Interaction Support</strong></p>
  <ul>
    <li><b>XR_EXT_hand_tracking &amp; hand_interaction</b>: Streams 26-point hand meshes and joint data for immediate interaction testing.</li>
    <li><b>XR_EXT_eye_gaze_interaction</b>: Virtualizes eye-gaze data to test UI and foveated logic on your PC.</li>
    <li><b>XR_EXT_palm_pose &amp; XR_EXT_uuid</b>: Real-time precision tracking and persistent object ID streaming.</li>
  </ul>

  <p><strong>Android XR Vendor Extensions</strong></p>
  <ul>
    <li><b>Eye &amp; Face Tracking</b> (<code>XR_ANDROID</code>): Stream expressive avatar data to your editor to refine social presence without building.</li>
    <li><b>Passthrough &amp; Trackables</b>: Access live environmental understanding—like plane detection and hit testing—directly within the engine's viewport.</li>
  </ul>
  
  <p>By virtualizing the device's hardware capabilities and streaming them over a low-latency desktop bridge, the Android XR Engine Hub allows for game engine developers to quickly iterate.</p>
  
  <p><strong>Download the Hub:</strong><br><a href="https://developer.android.com/xr/engine-hub">Get the Android XR Engine Hub for Windows</a><br><a href="https://developer.android.com/xr/direct-preview">Learn more about Direct Preview</a></p>

  <h2>Expanding Game Engine Support</h2>
  <p>Through our commitments to OpenXR standards, we are ensuring that whether you are a veteran studio or an indie developer, you have best-in-class tools to help bring your creative vision to life.</p>

  <h3>Unreal Engine</h3>
  <p>Unreal Engine support is now available in developer preview, targeting <a href="https://www.unrealengine.com/download"><b>version 5.6.1</b></a>. This integration is built directly on using OpenXR with the support for AndroidXR vendor specific API using the <b><a href="http://r-embodied-ai-review.git.corp.google.com/c/xr-persona-creator/+/1080">Android XR vendor plugin for Unreal</a></b>, you can access platform-specific extensions for advanced hand tracking, face tracking, and scene understanding (like plane detection and depth) whilst making use of Unreal blueprints or C++ support.</p><div class="separator"><a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgjyLLvLGZ-MHvGKsl5wdT0f_8YyLCQnZr9DbvQY98usskyY6yP8zE1aWh_1NtpFQNXVNu9k6ZymYRsfnuD2Kirp_CDa77T7NnQKQpFZ2dV-E7Llpe0UlhJ_H8_v1IiGruftqXseYBR2O9o9PHNGSgPZ-hcs5UTaKcxhmnIFcRoySbmMp_uPpjwphAWotk/s1124/ue5_1-02-ue-project-creation.png"><img border="0" data-original-height="748" data-original-width="1124" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgjyLLvLGZ-MHvGKsl5wdT0f_8YyLCQnZr9DbvQY98usskyY6yP8zE1aWh_1NtpFQNXVNu9k6ZymYRsfnuD2Kirp_CDa77T7NnQKQpFZ2dV-E7Llpe0UlhJ_H8_v1IiGruftqXseYBR2O9o9PHNGSgPZ-hcs5UTaKcxhmnIFcRoySbmMp_uPpjwphAWotk/s16000/ue5_1-02-ue-project-creation.png"></a></div><br><p><br></p>

  <p><strong>Get Started with Unreal:</strong><br></p><ul><li><a href="https://github.com/android-xr/android-xr-unreal-vendor-plugin">Download the Android XR Extension Plugin for Unreal</a></li><li><a href="https://www.unrealengine.com/">Official Unreal Engine Website</a></li><li><a href="https://developer.android.com/xr/unreal">View the Unreal Engine Development Guide</a></li></ul><p></p>

  <h3>Godot</h3>
  <p>In partnership with the <a href="https://godot.foundation/">Godot Foundation</a> and <a href="https://www.w4games.com/">W4 Games</a>, we are bringing official Godot support to Android XR for Godot 4.6.2 and higher.</p>
  <p>We are already seeing incredible momentum from W4 as they have ported experiences like <a href="https://play.google.com/store/apps/details?id=as.may.moat">MoAT</a> and <a href="https://play.google.com/store/apps/details?id=com.snopekgames.gwj81">Expedition to Blobotopia</a> that are already live on Google Play, proving that Godot is ready for production-grade spatial experiences today.</p>
  <p>To unlock the full potential of the platform, use the <b><a href="https://github.com/GodotVR/godot_openxr_vendors/tree/master/plugin">Godot OpenXR Vendors plugin 5.1</a></b>, which provides the necessary Android XR vendor extensions for features like <a href="https://github.com/GodotVR/godot_openxr_vendors/tree/c8f4c9fd38c10cec1b3dddc76229587fb2ed21c4/samples/androidxr-scenemeshing-sample">scene meshing</a>, <a href="https://github.com/GodotVR/godot_openxr_vendors/blob/c8f4c9fd38c10cec1b3dddc76229587fb2ed21c4/samples/androidxr-dynamic-resolution-sample/main.gd#L22">dynamic resolution</a>, <a href="https://github.com/GodotVR/godot_openxr_vendors/blob/c8f4c9fd38c10cec1b3dddc76229587fb2ed21c4/samples/androidxr-dynamic-resolution-sample/main.gd#L22">light estimation</a> and much more. We're collaborating with Godot to optimize the OpenXR implementation for the Android XR power profile and input standards.</p>

  <p><strong>Get Started with Godot:</strong><br></p><ul><li><a href="https://github.com/GodotVR/godot_openxr_vendors">Download the Godot OpenXR Vendors Plugin</a></li><li><a href="https://godotengine.org/">Official Godot Engine Website</a></li><li><a href="https://developer.android.com/xr/godot">View the Godot XR Setup Guide</a></li></ul><p></p>

  <h3>Unity</h3>
  <p>The Unity OpenXR: Android XR 1.13 package is now available for Unity 6.5 Beta. Unity has expanded Application SpaceWarp support to include both uGUI and TextMeshPro. Keep an eye out for the general release of Unity 6.5 and more platform enhancements arriving this summer.</p><p><b>Android XR Extensions v1.3.1 for Unity</b></p><p>Everything else you need for comprehensive platform integration is available in our latest <a href="https://github.com/android/android-xr-unity-package/releases/tag/v1.3.0">Android XR Extensions release</a>:</p>
  <ul>
    <li>Spatial API Support: You can now manage the <code>android.software.xr.api.SPATIAL</code> manifest tag directly through XRSessionFeature settings, making it easier than ever to define your app's Spatial API requirements and target levels.</li>
    <li>Fine Eye Face Tracking: A new Fine Eye Poses feature provides high-precision eye poses using the <code>TryGetFineEyePoses</code> extension method.</li>
    <li>Direct Preview Support: The Android XR Streaming feature enables Direct Preview support within Unity Editor's PlayMode (Windows only).</li>
  </ul>
<p>Note: <code>Android XR (Extensions): Hand Mesh</code> has been removed; you should now use the unified Hand Mesh Data within the <a href="https://docs.unity3d.com/Packages/com.unity.xr.androidxr-openxr@1.2/manual/features/hand-mesh-data.html">extensions package</a>.</p>

  <h2>Android XR Interaction Framework for Unity</h2>
  <p>The Android XR Interaction Framework (AXRIF) is now available in developer preview. AXRIF is an unstyled, opinionated input toolkit that abstracts the complex logic required to build interfaces that are consistent with Android XR system interactions.</p>
  <p>Instead of focusing on UI visuals, AXRIF prioritizes the underlying mechanics of the Android XR user experience. At its core is the same Transition Manager that powers the system's rich multimodal inputs, enabling state switching between 6DoF controllers, 3D mouse, hand tracking, and eye gaze. By leveraging this framework, developers can significantly reduce the implementation burden required to bring Android XR's full complement of robust interactions to their apps.</p>
  <p>At launch, the framework provides three core capabilities:</p>
  <ul>
    <li>Automated Multimodal Input Transitions: The framework manages the state machine for switching between input modalities. For example, it handles the transition logic when a user moves from gaze-targeting an object to directly touching it, simplifying simultaneous support for hands, controllers, and mice.</li>
    <li>Gaze-Assisted Gesture Interaction: AXRIF combines gaze vector targeting with hand gesture recognition (such as pinch-to-select) for precise distant interaction, matching the system's default behavior.</li>
    <li>Physics-Based 2D UI Interaction: The framework maps high-fidelity hand tracking to 2D plane interactions, enabling intuitive poke and swipe gestures on floating panels while respecting physical boundary constraints.</li>
  </ul>
  <p>By adopting AXRIF, your app inherits the platform's native interaction model, ensuring your app feels consistent with the rest of the OS.</p>
  
  <p><strong>Explore the Toolkit:</strong><br><a href="https://developer.android.com/xr/axrif">Interaction Framework Documentation</a><br><a href="http://github.com/android-xr/android-xr-interaction-framework-unity-package">Download the Unity Package</a> </p><p></p>

  <h2>Get Started Today:</h2>
  <p>There has never been a better time to dive into Android XR development. With support across Unity, Unreal, and Godot, the platform is ready for your creative vision, no matter which engine you call home. Explore our official engine partners to get started:</p>
  <ul>
    <li><a href="https://unity.com/">Unity Developer Portal</a></li>
    <li><a href="https://www.unrealengine.com/">Unreal Engine Developer Community</a></li>
    <li><a href="https://godotengine.org/">Official Godot Engine Website</a></li>
  </ul><div><br></div><div>Explore this announcement and all Google I/O 2026 updates on <span></span><a href="https://io.google/2026/?utm_source=blogpost&amp;utm_medium=pr&amp;utm_campaign=devblogs&amp;utm_content=" rel="noopener nofollow noreferrer" target="_blank">io.google<span></span></a>.</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[SecTor 2025 | When Hackers Meet Burglars]]></title>
<description><![CDATA[Author: Black Hat - Bewertung: 3x - Views:20 Smart buildings blur the line between IT and physical infrastructure, connecting HVAC, lighting, access control, elevators, cameras, and more under a single "brain" called a Building Automation System (BAS). Drawing on real engagements against Canadian...]]></description>
<link>https://tsecurity.de/de/3530095/it-security-video/sector-2025-when-hackers-meet-burglars/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3530095/it-security-video/sector-2025-when-hackers-meet-burglars/</guid>
<pubDate>Tue, 19 May 2026 19:18:31 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: Black Hat - Bewertung: 3x - Views:20 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/qNyJlfq-1RY?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>Smart buildings blur the line between IT and physical infrastructure, connecting HVAC, lighting, access control, elevators, cameras, and more under a single "brain" called a Building Automation System (BAS). Drawing on real engagements against Canadian smart building deployments, this talk guides you through a red teaming exercise that uncovers both digital and physical attack paths. You'll see how attackers gather intel, probe entry points, exploit insecure IoT protocols, and seize control of critical systems. We'll examine live scans, protocol abuse and real world video demos.<br />
<br />
Finally, we will flip to defense mode, offering a practical blue team playbook. Attendees will leave with an actionable framework rooted in Canadian field experience, for both offensive engagements and OT focused defenses.<br />
<br />
By: Amir Hosseinpour  |  Offensive Security Specialist, White Tuque<br />
<br />
https://blackhat.com/sector/2025/briefings/schedule/index.html#when-hackers-meet-burglars-red-teaming-the-smart-building-47597<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[‘Every keystroke scratches a very specific part of my brain’ — I reviewed the Epomaker P65 mechanical keyboard and it’s a typist’s dream with a wonderful sound profile]]></title>
<description><![CDATA[The Epomaker P65 is a 65% wireless mechanical keyboard that keeps it simple. It delivers stunning build quality and lovely acoustics, though a clunky app and a fixed typing angle hold it back from true greatness.]]></description>
<link>https://tsecurity.de/de/3529752/it-nachrichten/every-keystroke-scratches-a-very-specific-part-of-my-brain-i-reviewed-the-epomaker-p65-mechanical-keyboard-and-its-a-typists-dream-with-a-wonderful-sound-profile/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3529752/it-nachrichten/every-keystroke-scratches-a-very-specific-part-of-my-brain-i-reviewed-the-epomaker-p65-mechanical-keyboard-and-its-a-typists-dream-with-a-wonderful-sound-profile/</guid>
<pubDate>Tue, 19 May 2026 17:48:16 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The Epomaker P65 is a 65% wireless mechanical keyboard that keeps it simple. It delivers stunning build quality and lovely acoustics, though a clunky app and a fixed typing angle hold it back from true greatness.]]></content:encoded>
</item>
<item>
<title><![CDATA['The Mandalorian and Grogu' Review: Not the Star Wars Epic You're Looking For]]></title>
<description><![CDATA[Star Wars: The Mandalorian and Grogu is a fun popcorn flick, with little story and no purpose. Just shut off your brain and you'll be fine.]]></description>
<link>https://tsecurity.de/de/3529455/it-nachrichten/the-mandalorian-and-grogu-review-not-the-star-wars-epic-youre-looking-for/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3529455/it-nachrichten/the-mandalorian-and-grogu-review-not-the-star-wars-epic-youre-looking-for/</guid>
<pubDate>Tue, 19 May 2026 16:18:49 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Star Wars: The Mandalorian and Grogu is a fun popcorn flick, with little story and no purpose. Just shut off your brain and you'll be fine.]]></content:encoded>
</item>
<item>
<title><![CDATA[Open Source Security IT Platform: Threat Detection, Logging, Alerts, AI and SSO integration.]]></title>
<description><![CDATA[A real-world implementation with Wazuh, Graylog, MongoDB, Grafana, Nginx, OAuth2-Proxy, Redis, AI and SSO — no licenses, no vendor lock-in.Managing IT infrastructure security without commercial tools is entirely possible. This documenting the implementation of a complete open source security plat...]]></description>
<link>https://tsecurity.de/de/3528497/hacking/open-source-security-it-platform-threat-detection-logging-alerts-ai-and-sso-integration/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3528497/hacking/open-source-security-it-platform-threat-detection-logging-alerts-ai-and-sso-integration/</guid>
<pubDate>Tue, 19 May 2026 11:23:42 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><strong>A real-world implementation with Wazuh, Graylog, MongoDB, Grafana, Nginx, OAuth2-Proxy, Redis, AI and SSO — no licenses, no vendor lock-in.</strong></p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*UMOUaxSeMAE6VlSdtFrnJg.jpeg"></figure><p>Managing IT infrastructure security without commercial tools is entirely possible. This documenting the implementation of a complete open source security platform, deployed in production.</p><p>This is not a generic tutorial. It’s a guide based on real decisions, and an architecture that runs in production today.</p><h3>What problem does this platform solve?</h3><p>In any organization, visibility into what’s happening on servers tends to be fragmented: logs are scattered across different locations, alerts don’t arrive in real time, and each system has its own credentials. The result is an IT team that reacts instead of anticipating.</p><p>This platform centralizes three critical capabilities:</p><ul><li><strong>Threat detection</strong> — Wazuh monitors security events, file integrity, and system behavior in real time.</li><li><strong>Log management</strong> — Graylog receives, indexes, alerts, and allows querying all infrastructure logs from a single point.</li><li><strong>Operational visualization</strong> — Grafana delivers real-time dashboards.</li></ul><p>All of this is accessible through <strong>a single sign-on</strong> using the corporate account, thanks to OAuth2-Proxy.</p><h3>The architecture in brief</h3><p>The solution is built on five layers:</p><p><strong>Detection layer:</strong> Wazuh acts as the SIEM/XDR engine. It analyzes events, correlates alerts, and generates notifications. These events/alerts are sent to Graylog via Fluent Bit.</p><p><strong>Transport layer:</strong> Fluent Bit reads Wazuh events and forwards them to Graylog over RAW TCP. It’s lightweight, efficient, and highly configurable.</p><p><strong>Log management layer:</strong> Graylog parses the JSON data, indexes all events, enables natural language searches, and exposes an Bridge that we later integrate with Claude via MCP.</p><p><strong>Visualization layer:</strong> Grafana connects to Wazuh as a datasource and presents data in real-time operational dashboards.</p><p><strong>Access layer:</strong> Nginx acts as a reverse proxy with TLS ar HTTP header-based authentication. OAuth2-Proxy validates user identity against OIDC and propagates it to each application. Redis stores the sessions.</p><h3>Technology stack</h3><p>The entire stack is open source and runs on a single Linux server:</p><ul><li>Ubuntu 26.04 LTS</li><li>Wazuh v4.14.5</li><li>Graylog v7.1.0</li><li>MongoDB v7.0</li><li>Grafana v13.0.1</li><li>OAuth2-Proxy v7.15.2</li><li>Fluent Bit v5.0.5</li><li>Nginx v1.28.3</li><li>Redis v8.0.5</li></ul><p><strong>Hardware:</strong> Minimum 8 CPU cores, 16 GB RAM <br><strong>Storage:</strong> Dedicated LVM volumes (OS, data and logs separated)</p><h3>Why this design?</h3><p>Two architectural decisions deserve explanation:</p><p><strong>Separate LVM volumes.</strong> The operating system, application data, and logs live on independent partitions. If logs grow out of control, they don’t affect the OS or application data. Scaling log storage is as simple as expanding the corresponding volume.</p><p><strong>A single authentication point.</strong> Instead of managing users and passwords separately, OAuth2-Proxy delegates all authentication to IdP. The user logs in once and accesses all three systems. Local credentials are eliminated from the lifecycle.</p><h3>What’s coming in the next articles</h3><p>This series covers the complete implementation, component by component:</p><ol><li><strong>Introduction and architecture</strong> ← you are here</li><li><a href="https://infosecwriteups.com/open-source-security-platform-for-it-infrastructure-centralizing-threat-detection-logs-and-sso-c08d1b412f37#2776">Wazuh</a> — SIEM/XDR</li><li><a href="https://infosecwriteups.com/open-source-security-platform-for-it-infrastructure-centralizing-threat-detection-logs-and-sso-c08d1b412f37#8987">MongoDB</a> — Graylog’s DB</li><li><a href="https://infosecwriteups.com/open-source-security-platform-for-it-infrastructure-centralizing-threat-detection-logs-and-sso-c08d1b412f37#a640">Graylog</a> — Log management, data input, alerts</li><li><a href="https://infosecwriteups.com/open-source-security-platform-for-it-infrastructure-centralizing-threat-detection-logs-and-sso-c08d1b412f37#f229">Fluent Bit</a> — Log shipper</li><li><a href="https://infosecwriteups.com/open-source-security-platform-for-it-infrastructure-centralizing-threat-detection-logs-and-sso-c08d1b412f37#014b">Grafana</a> — Real-Time Operational Dashboards</li><li><a href="https://infosecwriteups.com/open-source-security-platform-for-it-infrastructure-centralizing-threat-detection-logs-and-sso-c08d1b412f37#4874">OAuth2-Proxy</a> — Single Sign-On with IdP (Identity Provider)</li><li><a href="https://infosecwriteups.com/open-source-security-platform-for-it-infrastructure-centralizing-threat-detection-logs-and-sso-c08d1b412f37#3b56">Redis</a> — Session Persistence and Storage</li><li><a href="https://infosecwriteups.com/open-source-security-platform-for-it-infrastructure-centralizing-threat-detection-logs-and-sso-c08d1b412f37#b390">Nginx</a> — Reverse Proxy with TLS and Header-Based Authentication</li><li><a href="https://infosecwriteups.com/open-source-security-platform-for-it-infrastructure-centralizing-threat-detection-logs-and-sso-c08d1b412f37#fcdf">Troubleshooting Guide</a></li><li><a href="https://infosecwriteups.com/open-source-security-platform-for-it-infrastructure-centralizing-threat-detection-logs-and-sso-c08d1b412f37#938b">Authentication </a>— Four steps: SSO and intregation Graylog with Wazuh</li><li><a href="https://infosecwriteups.com/open-source-security-platform-for-it-infrastructure-centralizing-threat-detection-logs-and-sso-c08d1b412f37#e3ed">Graylog Ingest</a> — Configuring Data Ingest from Fluent Bit</li><li><a href="https://infosecwriteups.com/open-source-security-platform-for-it-infrastructure-centralizing-threat-detection-logs-and-sso-c08d1b412f37#6a74">Graylog MCP + Claude</a> — Querying logs in natural language with AI</li><li><a href="https://infosecwriteups.com/open-source-security-platform-for-it-infrastructure-centralizing-threat-detection-logs-and-sso-c08d1b412f37#48e5">Final architecture, evidences, and conclusions</a></li></ol><p>Each article includes the exact commands used in production.</p><p>Recommendation: Create a working directory. In some sections, we jump to different directories cd; after each step, return to the directory.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/700/0*469jrtAPhs6EMetM.png"></figure><h3>Wazuh: SIEM/XDR</h3><p><strong><em>Part 2</em></strong></p><p>This article covers the foundation of the entire stack: the server where the platform lives, and the installation and configuration of Wazuh — the SIEM/XDR engine that detects and correlates security events in real time.</p><p><strong>The server platform<br></strong>Before installing any component, it’s worth explaining the storage decision. We use <strong>separate LVM volumes</strong> for the operating system, application data, and logs:</p><p>Volume Size Path Operating system 60 GB / Data 150 GB /data Logs 20 GB /log Swap 4 GB — estimate sizes based on own infrastructure.</p><p><strong>Why this separation?</strong> If logs grow out of control — and they will — they don’t affect the operating system or application data. Scaling log storage is as simple as expanding the /log volume without touching anything else. The same logic applies to application data in /data.</p><p><strong>Wazuh: the detection engine<br></strong>Wazuh is an open source SIEM (Security Information and Event Management) and XDR (Extended Detection and Response) platform. In practical terms, it continuously monitors system events, correlates alerts, detects file integrity issues, access anomalies, and much more.</p><p>In this implementation, Wazuh serves two roles:</p><ol><li><strong>Detection</strong> — analyzes operating system and service events.</li><li><strong>Export</strong> — generates alerts in JSON format that Fluent Bit forwards to Graylog.</li></ol><h3>Installation</h3><p>Wazuh’s installation is notable for its simplicity: a single script handles the entire stack (Wazuh Manager, Indexer, and Dashboard).</p><pre>curl -sO https://packages.wazuh.com/4.14/wazuh-install.sh &amp;&amp; bash ./wazuh-install.sh -a</pre><blockquote><strong><em>Info: </em></strong>Despite the compatibility information, it works without problems with Ubuntu 26.04.</blockquote><blockquote>“The recommended systems are: Red Hat Enterprise Linux 7, 8, 9; CentOS 7, 8; Amazon Linux 2; Amazon Linux 2023; Ubuntu 16.04, 18.04, 20.04, 22.04; Rocky Linux 9.4”</blockquote><blockquote><strong><em>Test environments:</em></strong><em> If the server doesn’t meet the minimum hardware requirements (4 GB RAM, 2 CPU cores), add the </em><em>-i argument to skip the validation.</em></blockquote><h3>Configuration</h3><p>The Wazuh installer places its data in default paths /var/lib/wazuh-indexer, /var/ossec/logs. We need to mount bind them to our LVM volumes while keeping the original paths functional.</p><pre># Stop services<br><br>systemctl stop wazuh-indexer wazuh-dashboard wazuh-manager filebeat</pre><p>Filebeat is included in the Wazuh installation but we’ll replace it with Fluent Bit, which is lighter and more flexible for forwarding events to Graylog.</p><pre># Disable Filebeat<br><br>systemctl disable filebeat</pre><pre># Create directory structure<br><br>mkdir -p /data/wazuh-indexer/lib /log/wazuh-indexer /data/wazuh/ossec/logs</pre><pre># Assign permissions to the service user and files<br><br>chown wazuh-indexer:wazuh-indexer /data/wazuh-indexer/lib /log/wazuh-indexer<br>chown wazuh:wazuh /data/wazuh/ossec/logs<br>chmod 770 /data/wazuh/ossec/logs </pre><pre># Move existing content<br><br>mv /var/lib/wazuh-indexer/* /data/wazuh-indexer/lib/<br>mv /var/ossec/logs/* /data/wazuh/ossec/logs/</pre><p><strong>Mount with bind — preserving original paths</strong></p><p>The key is using bind mounts: services continue using their default paths, but the actual storage is on the LVM volumes. This avoids modifying Wazuh’s internal configuration.</p><blockquote>Evaluate:<br>With “nofails” the server will start even if the mounts fail, but the services will fail. <br>Omitting “nofails” will start in emergency mode.</blockquote><pre>echo "/data/wazuh/ossec/logs /var/ossec/logs none defaults,bind,nofail 0 0" &gt;&gt; /etc/fstab<br>echo "/data/wazuh-indexer/lib /var/lib/wazuh-indexer none defaults,bind,nofail 0 0" &gt;&gt; /etc/fstab<br>echo "/log/wazuh-indexer /var/log/wazuh-indexer none defaults,bind,nofail 0 0" &gt;&gt; /etc/fstab<br>systemctl daemon-reload<br>mount -a</pre><p><strong>Compatibility adjustment for Graylog</strong></p><p>Wazuh Indexer uses OpenSearch with an option that, by default, forces another version for Filebeat compatibility.</p><pre># /etc/wazuh-indexer/opensearch.yml - Comment out<br><br>#compatibility.override_main_response_version: true</pre><blockquote><strong><em>About the Dashboard warning:</em></strong> When connecting Graylog, the Wazuh Dashboard may display a warning about <em>wazuh-alerts-*</em> index patterns. This is a cosmetic warning that does not affect functionality — it can be safely ignored.</blockquote><blockquote><strong><em>Expected scenario:</em></strong> Filebeat cannot send data to the indexer, and alerts will not appear in the Wazuh dashboard.</blockquote><figure><img alt="" src="https://cdn-images-1.medium.com/max/676/1*dpEcqSAQaH46kFkbqa7VoQ.jpeg"><figcaption>warning</figcaption></figure><h3>Adjusting the Dashboard for Nginx</h3><p>The Wazuh Dashboard will listen on 127.0.0.1:8080 instead of the default port, since Nginx will act as a reverse proxy with TLS on port 443.</p><pre># /etc/wazuh-dashboard/opensearch_dashboards.yml<br><br>server.host: 127.0.0.1<br>server.port: 8080</pre><p><strong>Credentials and backup<br></strong>After installation, Wazuh generates a wazuh-install-files.tar file containing certificates, the root CA, and passwords. It's critical to extract and back it up immediately.</p><pre>tar -xvf wazuh-install-files.tar</pre><p>The wazuh-passwords.txt file inside contains all automatically generated passwords. Protecting it is mandatory.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/700/0*469jrtAPhs6EMetM.png"></figure><h3>MongoDB: Graylog’s DB</h3><p><strong><em>Part 3</em></strong></p><p>MongoDB is the database Graylog uses to store its internal configuration: streams, alerts, dashboards, users, and metadata. It does not store the logs themselves — that’s handled by OpenSearch/ElasticSearch — but it’s an essential component for Graylog to function.</p><p><strong>An important warning before installing</strong></p><p>MongoDB version 8.0 has <strong>kernel incompatibilities with Ubuntu 26.04</strong>. The stable, tested version for this implementation is <strong>7.0</strong>. This is one of those cases where the latest version is not the best choice.</p><h3>Installation</h3><p>Add the official MongoDB 7.0 repository and install.</p><pre>curl -fsSL https://pgp.mongodb.com/server-7.0.asc | gpg -o /usr/share/keyrings/mongodb-server-7.0.gpg --dearmor<br>echo "deb [signed-by=/usr/share/keyrings/mongodb-server-7.0.gpg] https://repo.mongodb.org/apt/ubuntu jammy/mongodb-org/7.0 multiverse" | tee /etc/apt/sources.list.d/mongodb-org-7.0.list<br>apt update<br>apt install mongodb-org -y</pre><h3>Configuration</h3><p>We apply the same pattern as with Wazuh: move data to the /data volume and logs to the /log volume, using bind mounts to keep the original paths intact.</p><pre># Create directory structure<br><br>mkdir -p /data/mongodb/lib /log/mongodb</pre><pre># Assign permissions to the service user<br><br>chown mongodb:mongodb /data/mongodb/lib /log/mongodb</pre><pre># Bind mount<br><br>echo "/data/mongodb/lib /var/lib/mongodb none defaults,bind,nofail 0 0" &gt;&gt; /etc/fstab<br>echo "/log/mongodb /var/log/mongodb none defaults,bind,nofail 0 0" &gt;&gt; /etc/fstab<br>systemctl daemon-reload<br>mount -a</pre><p><strong>Why does this pattern repeat?</strong></p><p>We apply the same storage strategy to every component in the stack. The reason is simple: in a production environment, data must survive an OS reinstallation. If the OS lives on / (60 GB) and data on /data (150 GB), I can reinstall Ubuntu without losing any application data.</p><p>The /log volume (20 GB) is independent because logs have a different lifecycle — they rotate, compress, and get deleted — and we don't want their growth to affect either the OS or application data.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/700/0*MbvwpOS6jWqHHZiX.png"></figure><h3>Graylog: Centralized Log Management with TLS Integration to Wazuh Indexer</h3><p><strong><em>Part 4</em></strong></p><p>Graylog is the heart of log management in this platform. It receives security events from Fluent Bit, indexes them in OpenSearch (through Wazuh Indexer), enables real-time searches, and exposes an API that we later connect to Claude via MCP.</p><h3>Installation</h3><p>Graylog requires Java as a dependency. We install Java 17 and then the Graylog 7.1 server.</p><pre>apt install openjdk-17-jre-headless -y<br>wget https://packages.graylog2.org/repo/packages/graylog-7.1-repository_latest.deb<br>dpkg -i graylog-7.1-repository_latest.deb<br>apt-get update<br>apt install graylog-server -y</pre><h3>Configuration</h3><pre># Create directory structure<br><br>mkdir -p /data/graylog/lib/journal /data/graylog/jks /var/lib/graylog-server/journal /log/graylog</pre><pre># Assign permissions to the service user<br><br>chown -R graylog:graylog /data/graylog/lib /var/lib/graylog-server/journal /log/graylog</pre><pre># Bind mount<br><br>echo "/data/graylog/lib/journal /var/lib/graylog-server/journal none defaults,bind,nofail 0 0" &gt;&gt; /etc/fstab<br>echo "/log/graylog /var/log/graylog-server none defaults,bind,nofail 0 0" &gt;&gt; /etc/fstab<br>systemctl daemon-reload<br>mount -a</pre><p><strong>Credential configuration</strong></p><p>Graylog requires two key values in its main configuration file.</p><pre># password_secret - internal encryption key (64 characters)<br><br>cat /dev/urandom | tr -dc "a-zA-Z0-9" | fold -w 64 | head -n 1</pre><pre># root_password_sha2 - SHA256 hash of the administrator password<br><br>echo -n '&lt;password&gt;' | shasum -a 256 | cut -d' ' -f1</pre><pre># /etc/graylog/server/server.conf<br><br>password_secret = &lt;password_secret&gt;<br>root_password_sha2 = &lt;root_password&gt;</pre><p><strong>Integration with Wazuh Indexer<br></strong>This is one of the most important steps and the one most frequently omitted in generic guides. Graylog needs to connect to Wazuh Indexer (OpenSearch) over HTTPS, which requires it to trust Wazuh’s CA certificate.</p><p>The solution is to incorporate Wazuh’s CA into a <strong>Java Key Store (JKS)</strong> that Graylog can use.</p><pre># Copy the base Java keystore<br><br>cp /usr/share/graylog-server/jvm/lib/security/cacerts /data/graylog/jks/graylog.jks<br>cd /data/graylog/jks<br><br># Import the Wazuh CA certificate<br># When keytool asks "Trust this certificate? [no]:", answer: y<br># Set a custom or random password<br><br>keytool -importcert -keystore graylog.jks -storepass &lt;password&gt; -alias wazuh-ca -file /etc/wazuh-indexer/certs/root-ca.pem</pre><p>Then configure Graylog to use this keystore at startup.</p><pre># /etc/default/graylog-server - Enter the password defined in the previous step<br><br>GRAYLOG_SERVER_JAVA_OPTS="-Djavax.net.ssl.trustStore=/data/graylog/jks/graylog.jks -Djavax.net.ssl.trustStorePassword=&lt;password&gt;"</pre><pre># Assign permissions to the service user<br><br>chown -R graylog:graylog /data/graylog/jks</pre><p><strong>Why not just disable TLS verification?</strong></p><p>It’s a common temptation to use ssl_verify=false to skip this entire process. The problem is that in production this eliminates a real security layer: any server could present itself as Wazuh Indexer and Graylog would accept it without question. The JKS procedure takes ten extra minutes and guarantees secure communication between components.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/700/0*YX5kBfyd9o1QNtX5.png"></figure><h3>Fluent Bit: The Bridge Between Wazuh and Graylog</h3><p><strong><em>Part 5</em></strong></p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*whGladAjwDiDE2Ic5UvWlA.jpeg"></figure><p>Fluent Bit is the component that connects Wazuh with Graylog. Its function is simple but critical: read the JSON alerts file that Wazuh generates in real time and forward each event to Graylog over TCP. It’s lightweight, efficient, and consumes minimal resources even under high event load.</p><p><strong>Why Fluent Bit instead of Filebeat?</strong></p><p>Wazuh installs Filebeat by default to export data to ElasticSearch. Filebeat can be configured to send to Graylog (at the same time, Graylog’s data source is Wazuh), but Fluent Bit is significantly lighter, has better support for complex pipelines, and consumes less memory.</p><p>The decision is clear: we disable Filebeat (covered in the Wazuh article) and install Fluent Bit.</p><h3>Installation</h3><p>Ubuntu 26.04 (Resolute Raccoon) doesn’t yet have official Fluent Bit packages. The solution is to use the <strong>Noble</strong> (Ubuntu 24.04) packages, which are compatible.</p><pre>sh -c 'curl https://packages.fluentbit.io/fluentbit.key | gpg --dearmor &gt; /usr/share/keyrings/fluentbit-keyring.gpg'<br>echo "deb [signed-by=/usr/share/keyrings/fluentbit-keyring.gpg] https://packages.fluentbit.io/ubuntu/noble noble main" | tee /etc/apt/sources.list.d/fluent-bit.list<br>apt update<br>apt install fluent-bit -y</pre><h3>Configuration</h3><pre># Create directory structure<br><br>mkdir -p /log/fluent-bit /var/log/fluent-bit</pre><pre># Bind mount<br><br>echo "/log/fluent-bit /var/log/fluent-bit none defaults,bind,nofail 0 0" &gt;&gt; /etc/fstab<br>systemctl daemon-reload<br>mount -a</pre><p><strong>The main configuration file</strong></p><p>This is the core of Fluent Bit. It defines three sections: the global service, the data input (INPUT), and the output (OUTPUT).</p><blockquote><strong><em>Pay attention when copying:</em></strong><em> </em>The Fluent Bit configuration file is sensitive to indentation. Incorrect indentation will prevent the service from starting<em>.</em></blockquote><pre># /etc/fluent-bit/fluent-bit.conf<br><br>[SERVICE]<br>  flush 5<br>  daemon Off<br>  log_level info<br>  log_file /log/fluent-bit/td-agent-bit.log<br>  parsers_file parsers.conf<br>  plugins_file plugins.conf<br>  http_server Off<br>  storage.metrics on<br>  storage.path /tmp/storage<br>  storage.sync normal<br>  storage.checksum off<br>  storage.backlog.mem_limit 5M<br>[INPUT]<br>  name tail<br>  path /var/ossec/logs/alerts/alerts.json<br>  tag wazuh<br>  parser json<br>  Buffer_Max_Size 5MB<br>  Buffer_Chunk_Size 400k<br>  storage.type filesystem<br>  Mem_Buf_Limit 512MB<br>[OUTPUT]<br>  Name tcp<br>  Host localhost<br>  Port 5555<br>  net.keepalive off<br>  Match wazuh<br>  Format json_lines<br>  json_date_key true</pre><p><strong>How the pipeline works</strong></p><ol><li><strong>INPUT </strong><strong>tail</strong> — Reads the /var/ossec/logs/alerts/alerts.json file continuously, similar to tail -f. Every time Wazuh writes a new alert, Fluent Bit detects it.</li><li><strong>Tag </strong><strong>wazuh</strong> — Labels each event so the OUTPUT knows what to process.</li><li><strong>OUTPUT </strong><strong>tcp</strong> — Sends each event to port 5555 on localhost in JSON format, where Graylog will listen with a Raw HTTP input.</li></ol><p>The on-disk buffer storage.type filesystem ensures no events are lost if Graylog is momentarily unreachable. Events accumulate and are resent once the connection is re-established.</p><blockquote><em>Optional: </em>REST API — Monitor Fluent Bit data pipelines.<br><em>https://docs.fluentbit.io/manual/administration/monitoring</em></blockquote><figure><img alt="" src="https://cdn-images-1.medium.com/max/700/0*cbEm4ozA1npayvjy.png"></figure><h3>Grafana: Real-Time Operational Dashboards</h3><p><strong><em>Part 6</em></strong></p><p>Grafana is the visualization layer of the platform. It connects to Wazuh as a datasource and allows building operational dashboards that show in real time the state of the infrastructure: Wazuh alerts, log volume, access patterns, and any metric Graylog or Wazuh can provide.</p><p>In terms of base installation and configuration, Grafana is the simplest component in the stack. The complexity comes later when we integrate SSO authentication.</p><h3>Installation</h3><pre>wget -O /etc/apt/keyrings/grafana.asc https://apt.grafana.com/gpg-full.key<br>echo "deb [signed-by=/etc/apt/keyrings/grafana.asc] https://apt.grafana.com stable main" | tee -a /etc/apt/sources.list.d/grafana.list<br>apt update<br>apt install grafana -y</pre><h3>Configuration</h3><pre># Create directory structure<br><br>mkdir -p /data/grafana/lib /log/grafana</pre><pre># Assign permissions to the service user<br><br>chown grafana:grafana /data/grafana/lib /log/grafana</pre><pre># Bind mount<br><br>echo "/data/grafana/lib /var/lib/grafana none defaults,bind,nofail 0 0" &gt;&gt; /etc/fstab<br>echo "/log/grafana /var/log/grafana none defaults,bind,nofail 0 0" &gt;&gt; /etc/fstab<br>systemctl daemon-reload<br>mount -a</pre><p>The specific security dashboards — visualizing Wazuh alerts, Graylog logs, and service metrics — depend on the datasources we’ll configure once the entire platform is operational.</p><p><strong>A note on the visualization architecture:</strong></p><p>In many similar implementations, Wazuh already includes its own dashboard based on OpenSearch Dashboards (Kibana). So why add Grafana?</p><p>The reason is <strong>datasource flexibility</strong>. The Wazuh Dashboard can only visualize data from Wazuh Indexer. Grafana can simultaneously connect to Wazuh, Prometheus, InfluxDB, SQL databases, and dozens of other sources. A single dashboard can show Wazuh alerts alongside infrastructure metrics, application logs, and any other data source — all in real time, with its own alerting system.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/700/0*MNHDU6UurKLbz20v.png"></figure><h3>OAuth2-Proxy: Single Sign-On with IdP</h3><p><strong><em>Part 7</em></strong></p><p>OAuth2-Proxy is the component that eliminates the need to manage users and passwords in Wazuh, Graylog, and Grafana separately. Instead, it delegates all authentication to IdP. The user logs in once with their corporate account and accesses all three systems without entering credentials again.</p><p>This article covers the installation of OAuth2-Proxy and its base configuration. The integration with each application is completed in the <a href="https://infosecwriteups.com/open-source-security-platform-for-it-infrastructure-centralizing-threat-detection-logs-and-sso-c08d1b412f37#938b">Authentication article</a>.</p><p><strong>How the flow works:</strong></p><p>When a user accesses <a href="https://wazuh.domain.com/">https://site.domain.com</a></p><ol><li>Nginx receives the request and asks OAuth2-Proxy if the user is authenticated auth_request /oauth2/auth</li><li>If there’s no active session, OAuth2-Proxy redirects the user to IdP portal.</li><li>The user authenticates with their corporate account.</li><li>IdP returns an ID Token to OAuth2-Proxy.</li><li>OAuth2-Proxy validates the token and creates a session stored in Redis.</li><li>Nginx propagates the user’s identity in an HTTP header.</li><li>Each application receives the header and assigns permissions accordingly.</li></ol><blockquote><strong><em>OAuth2 Proxy uses several layers to confirm a token’s validity</em></strong></blockquote><blockquote><em>Signature Verification:</em> The proxy checks that the token’s cryptographic signature was created by the trusted Identity Provider. It typically retrieves public keys automatically from the IdP JWKS (JSON Web Key Set) endpoint, which is discovered via the OpenID Connect well-known configuration URL.</blockquote><blockquote><em>Claim Validation</em>: Once the signature is verified, it inspects specific fields (claims) within the token:</blockquote><blockquote><em>iss (Issuer): </em>Must match the configured provider URL.</blockquote><blockquote><em>aud (Audience)</em>: Must contain the <em>client_id</em> of the OAuth2 Proxy instance to ensure the token was intended for this specific application.</blockquote><blockquote><em>exp (Expiration)</em>: Ensures the token has not expired.</blockquote><p>The result: a single sign-on for the entire platform, with persistent sessions stored in Redis.</p><h3>Installation</h3><pre>wget https://github.com/oauth2-proxy/oauth2-proxy/releases/download/v7.15.2/oauth2-proxy-v7.15.2.linux-amd64.tar.gz<br>tar -xzvf oauth2-proxy-v7.15.2.linux-amd64.tar.gz<br>chown root:root oauth2-proxy-v7.15.2.linux-amd64/oauth2-proxy<br>mv oauth2-proxy-v7.15.2.linux-amd64/oauth2-proxy /usr/sbin/</pre><h3>Configuration</h3><pre># Create directory structure<br><br>mkdir -p /etc/oauth2-proxy /log/oauth2-proxy</pre><pre># Create service user<br><br>useradd -d /dev/null oauth2-proxy -s /usr/sbin/nologin</pre><pre># Create files<br><br>touch /etc/systemd/system/oauth2-proxy.service<br>touch /etc/oauth2-proxy/service.cfg</pre><pre># Assign permissions to the service user<br><br>chown oauth2-proxy:oauth2-proxy /log/oauth2-proxy</pre><pre># Generate the cookie secret (32 random characters)<br><br>cat /dev/urandom | tr -dc "a-zA-Z0-9" | fold -w 32 | head -n 1</pre><p><strong>Configuration file:</strong></p><blockquote>Case with IdP Microsoft Entra ID.</blockquote><blockquote>Enable debugs on errors.</blockquote><pre># /etc/oauth2-proxy/service.cfg<br><br>client_id = "&lt;app_id&gt;"<br>client_secret = "&lt;app_secret&gt;"<br>oidc_issuer_url = "https://login.microsoftonline.com/&lt;tenant_id&gt;/v2.0"<br>cookie_secret = "&lt;cookie_secret&gt;"<br>cookie_domains = "&lt;domain.com&gt;"<br>email_domains = "&lt;domain.com&gt;"<br>whitelist_domains = "*.&lt;domain.com&gt;"<br>cookie_expire = "24h"<br>cookie_httponly = true<br>cookie_refresh = "50m"<br>cookie_secure = true<br>logging_filename = "/log/oauth2-proxy/oauth2.log"<br>logging_max_size = 100<br>logging_max_age = 5<br>provider = "oidc"<br>provider_display_name = "OIDC"<br>redis_connection_url = "redis://127.0.0.1:6379"<br>scope = "openid offline_access"<br>session_store_type = "redis"<br>set_xauthrequest = true<br>silence_ping_logging = true<br>skip_provider_button = true<br>upstreams = [ "file:///dev/null" ]<br>#show_debug_on_error = true</pre><blockquote>More details: <a href="https://oauth2-proxy.github.io/oauth2-proxy/configuration/overview"><em>https://oauth2-proxy.github.io/oauth2-proxy/configuration/overview</em></a></blockquote><p><strong>Registering in Microsoft Entra ID</strong></p><blockquote><em>⚠</em><strong><em> Important</em></strong><em>: </em>The Authorization Code Flow is the primary method to authenticate users, an industry-standard. Both tokens — Access and ID — are not enabled for implicit or hybrid flows.</blockquote><blockquote>The variety of flows often leads to confusion. With Auth Code Flow and <em>openid</em> scope, we will always obtain an Identification Token👍</blockquote><p>For OAuth2-Proxy to work, you need to register an application in the Azure portal:</p><ol><li><strong>Azure Portal</strong> → Entra ID → App registrations → New registration</li><li>Application name, account type, and redirect URI: <a href="https://domain.com/oauth2/callback">https://system.&lt;domain.com&gt;/oauth2/callback</a></li><li>Obtain the <strong>Application Client ID</strong> and <strong>Tenant ID</strong>.</li><li>Create a <strong>Client Secret</strong> under “Certificates &amp; Secrets”</li><li>In “API permissions”, add openid and offline_access</li></ol><p>These values are used in client_id, client_secret, and oidc_issuer_url in the configuration file.</p><p><strong>Create service</strong></p><pre># /etc/systemd/system/oauth2-proxy.service<br><br>[Unit]<br>Description=OAuth2 Proxy Daemon<br>After=network.target<br>[Service]<br>User=oauth2-proxy<br>Group=oauth2-proxy<br>Type=simple<br>ExecStart=/usr/sbin/oauth2-proxy --config=/etc/oauth2-proxy/service.cfg<br>Restart=always<br>RestartSec=10<br>ProtectSystem=full<br>NoNewPrivileges=true<br>[Install]<br>WantedBy=multi-user.target</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/700/0*XMImQw4ixJ6WN3lV.png"></figure><h3>Redis: Session Persistence and Storage</h3><p><strong><em>Part 8</em></strong></p><p>Redis solves a real problem: OAuth2-Proxy session cookies can grow large (cookie bloat) and exceed size limits. Storing sessions in Redis instead of in the cookie keeps the size controlled and allows sessions to survive proxy restarts.</p><h3>Installation</h3><pre>apt install redis-server -y</pre><h3>Configuration</h3><pre># Create directory structure<br><br>mkdir -p /data/redis/lib /log/redis</pre><pre># Assign permissions to the service user<br><br>chown redis:redis /data/redis/lib /log/redis</pre><pre># Bind mount<br><br>echo "/data/redis/lib /var/lib/redis none defaults,bind,nofail 0 0" &gt;&gt; /etc/fstab<br>echo "/log/redis /var/log/redis none defaults,bind,nofail 0 0" &gt;&gt; /etc/fstab<br>systemctl daemon-reload<br>mount -a</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/700/0*469jrtAPhs6EMetM.png"></figure><h3>Nginx: Reverse Proxy with TLS and Header-Based Authentication</h3><p><strong><em>Part 9</em></strong></p><p>Nginx is the entry point to the entire platform. It acts as a reverse proxy with TLS, routes traffic to Wazuh, Graylog, MCP, and Grafana, and coordinates with OAuth2-Proxy (except with MCP) to validate user identity on every request.</p><h3>Installation</h3><pre>apt install nginx -y</pre><h3>Configuration</h3><pre># Create directory structure<br><br>mkdir -p /log/nginx /etc/nginx/TLS</pre><pre># Create files<br><br>touch /etc/nginx/sites-available/{wazuh,graylog,graylog-mcp,grafana}<br>touch /etc/nginx/snippets/{security-headers.conf,oauth2-proxy.conf}<br>touch /etc/nginx/TLS/{certificate.crt,private.key}</pre><pre># Delete default host<br><br>rm /etc/nginx/sites-enabled/default</pre><pre># Bind mount<br><br>echo "/log/nginx /var/log/nginx none defaults,bind,nofail 0 0" &gt;&gt; /etc/fstab<br>systemctl daemon-reload<br>mount -a</pre><p><strong>Main configuration: nginx.conf</strong></p><p>The <strong>most notable </strong>aspect of this configuration is the map block: it extracts the username from the email returned by OIDC, taking everything before the @. This allows receive the username instead of the full email address.</p><blockquote>To avoid excessive logging, the access log is set to off.</blockquote><pre># /etc/nginx/nginx.conf<br><br>user www-data;<br>worker_processes auto;<br>worker_cpu_affinity auto;<br>pid /run/nginx.pid;<br>include /etc/nginx/modules-enabled/*.conf;<br>                                     <br>events {<br><br>  worker_connections 1024;<br><br>}<br><br>http {<br><br>  map $upstream_http_x_auth_request_email $http_x_auth_user {<br>    "~^(?&lt;user&gt;[^@]+)@" $user;<br>  }<br><br>  include mime.types;<br>  default_type application/octet-stream;<br>  sendfile on;<br>  tcp_nopush on;<br>  tcp_nodelay on;<br>  keepalive_timeout 65;<br>  keepalive_requests 1000;<br>  types_hash_max_size 2048;<br>  server_tokens off;<br>  gzip on;<br>  gzip_vary on;<br>  gzip_min_length 256;<br>  gzip_proxied any;<br>  gzip_comp_level 6;<br>  gzip_buffers 16 8k;<br>  gzip_http_version 1.1;<br>  gzip_types text/plain text/css application/json application/javascript text/xml application/xml application/xml+rss text/javascript;<br>  ssl_protocols TLSv1.2 TLSv1.3;<br>  ssl_prefer_server_ciphers on;<br>  ssl_ciphers 'EECDH+AESGCM:EDH+AESGCM:AES256+EECDH:AES256+EDH:!aNULL:!MD5:!3DES:!CBC:!SHA1';<br>  ssl_session_cache shared:SSL:10m;<br>  ssl_session_timeout 15m;<br>  access_log /var/log/nginx/access.log combined buffer=512k flush=1m;<br>  error_log /var/log/nginx/error.log;<br>  include /etc/nginx/conf.d/*.conf;<br>  include /etc/nginx/sites-enabled/*;<br><br>}</pre><p><strong>Security Headers snippet</strong></p><p>Best practices that strengthen your website’s security against common attacks.</p><pre># /etc/nginx/snippets/security-headers.conf<br><br>add_header Strict-Transport-Security "max-age=31536000; includeSubDomains";<br>add_header X-Frame-Options "SAMEORIGIN";<br>add_header X-XSS-Protection "1; mode=block";<br>add_header X-Content-Type-Options nosniff;<br>add_header X-Download-Options "noopen";<br>add_header Permissions-Policy 'geolocation=(), microphone=(), camera=()';<br>add_header Referrer-Policy 'no-referrer';<br>add_header Content-Security-Policy 'upgrade-insecure-requests';</pre><p><strong>OAuth2-Proxy snippet</strong></p><p>This snippet is included in every virtual host that requires authentication. It defines two locations: one for the OAuth2 flow and one internal for validating sessions.</p><pre># /etc/nginx/snippets/oauth2-proxy.conf<br><br>location /oauth2/ {<br>  proxy_pass http://localhost:4180;<br>  proxy_set_header Host $host;<br>  proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;<br>  proxy_set_header Content-Length "";<br>  proxy_pass_request_body off;<br>  access_log off;<br>}<br><br>location = /oauth2/auth {<br>  internal;<br>  proxy_pass http://localhost:4180;<br>  proxy_set_header Host $host;<br>  proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;<br>  proxy_set_header Content-Length "";<br>  proxy_pass_request_body off;<br>}</pre><blockquote>The <em>Content-Length: ""</em> headers and <em>proxy_pass_request_body off</em> are critical. Without them, authentication requests to internal APIs fail. This configuration has been validated in production.</blockquote><p><strong>Virtual hosts: one per application</strong></p><p>Each application has its own configuration file. The pattern is consistent:</p><ul><li>Redirect HTTP to HTTPS (301).</li><li>TLS with Wildcard certificate.</li><li>Include security headers and OAuth2-Proxy snippet.</li><li>Proxy pass to each application’s local port.</li></ul><p><strong>Wazuh Host</strong></p><blockquote><em>⚠</em><strong><em> </em></strong>Firstly, proxy authentication in Wazuh does not require creating internal users.</blockquote><blockquote><em>⚠ </em>This configuration is intended for administration; therefore, it has the <em>"admin"</em> backend role hardcoded.</blockquote><blockquote><em>proxy_set_header x-proxy-roles "admin"</em></blockquote><blockquote>You can associate Security Groups or Nginx mappings with custom backend roles. See the <strong><em>Custom Backend Role</em>s </strong>references later in the authentication section.</blockquote><pre># /etc/nginx/sites-available/wazuh<br><br>server {<br>  listen 80;<br>  server_name wazuh.&lt;domain.com&gt;;<br>  access_log off;<br>  log_not_found off;<br>  return 301 https://wazuh.&lt;domain.com&gt;$request_uri;<br>}<br><br>server {<br>  listen 443 ssl;<br>  server_name wazuh.&lt;domain.com&gt;;<br>  ssl_certificate /etc/nginx/TLS/certificate.crt;<br>  ssl_certificate_key /etc/nginx/TLS/private.key;<br>  include /etc/nginx/snippets/security-headers.conf;<br>  include /etc/nginx/snippets/oauth2-proxy.conf;<br>  location / {<br>   #auth_request /oauth2/auth;<br>   error_page 401 = /oauth2/start;<br>   auth_request_set $user $http_x_auth_user;<br>   proxy_set_header x-proxy-user $user;<br>   proxy_set_header x-proxy-roles "admin";<br>   proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;<br>   proxy_set_header X-Real-IP $remote_addr;<br>   proxy_http_version 1.1;<br>   proxy_read_timeout 10s;<br>   proxy_set_header Upgrade $http_upgrade;<br>   proxy_set_header Connection 'upgrade';<br>   proxy_set_header Host $host;<br>   proxy_cache_bypass $http_upgrade;<br>   proxy_set_header X-Forwarded-Proto $scheme;<br>   proxy_pass https://localhost:8080;<br>   access_log off;<br>   log_not_found off;<br>  }<br>}</pre><p><strong>Graylog Host</strong></p><pre># /etc/nginx/sites-available/graylog<br><br>server {<br>  listen 80;<br>  server_name graylog.&lt;domain.com&gt;;<br>  access_log off;<br>  log_not_found off;<br>  return 301 https://graylog.&lt;domain.com&gt;$request_uri;<br>}<br><br>server {<br>  listen 443 ssl;<br>  server_name graylog.&lt;domain.com&gt;;<br>  ssl_certificate /etc/nginx/TLS/certificate.crt;<br>  ssl_certificate_key /etc/nginx/TLS/private.key;<br>  include /etc/nginx/snippets/security-headers.conf;<br>  include /etc/nginx/snippets/oauth2-proxy.conf;<br>  location / {<br>   #auth_request /oauth2/auth;<br>   error_page 401 = /oauth2/start;<br>   auth_request_set $user $http_x_auth_user;<br>   proxy_set_header x-proxy-user $user;<br>   proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;<br>   proxy_set_header X-Real-IP $remote_addr;<br>   proxy_http_version 1.1;<br>   proxy_read_timeout 10s;<br>   proxy_set_header Upgrade $http_upgrade;<br>   proxy_set_header Connection 'upgrade';<br>   proxy_set_header Host $host;<br>   proxy_cache_bypass $http_upgrade;<br>   proxy_set_header X-Forwarded-Proto $scheme;<br>   proxy_pass http://localhost:9000;<br>   proxy_set_header X-Graylog-Server-URL https://$server_name;<br>   access_log off;<br>   log_not_found off;<br>  }<br>}</pre><p><strong>Graylog MCP Host</strong></p><pre># /etc/nginx/sites-available/graylog-mcp<br><br>server {<br>  listen 443 ssl;<br>  server_name graylog-mcp.&lt;domain.com&gt;;<br>  ssl_certificate /etc/nginx/TLS/certificate.crt;<br>  ssl_certificate_key /etc/nginx/TLS/private.key;<br>  include /etc/nginx/snippets/security-headers.conf;<br>  location  / {<br>   proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;<br>   proxy_set_header X-Real-IP $remote_addr;<br>   proxy_http_version 1.1;<br>   proxy_read_timeout 10s;<br>   proxy_set_header Upgrade $http_upgrade;<br>   proxy_set_header Connection 'upgrade';<br>   proxy_set_header Host $host;<br>   proxy_cache_bypass $http_upgrade;<br>   proxy_set_header X-Forwarded-Proto $scheme;<br>   proxy_pass http://localhost:9000/api/;<br>   access_log off;<br>   log_not_found off;<br>  }<br>}</pre><p><strong>Grafana Host</strong></p><pre># /etc/nginx/sites-available/grafana<br><br>server {<br>  listen 80;<br>  server_name grafana.&lt;domain.com&gt;;<br>  access_log off;<br>  log_not_found off;<br>  return 301 https://grafana.&lt;domain.com&gt;$request_uri;<br> }<br><br>server {<br>  listen 443 ssl;<br>  server_name grafana.&lt;domain.com&gt;;<br>  ssl_certificate         /etc/nginx/TLS/certificate.crt;<br>  ssl_certificate_key     /etc/nginx/TLS/private.key;<br>  include /etc/nginx/snippets/security-headers.conf;<br>  include /etc/nginx/snippets/oauth2-proxy.conf;<br>  location  / {<br>   #auth_request /oauth2/auth;<br>   error_page 401 = /oauth2/start;<br>   auth_request_set $user $http_x_auth_user;<br>   proxy_set_header x-proxy-user $user;<br>   proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;<br>   proxy_set_header X-Real-IP $remote_addr;<br>   proxy_http_version 1.1;<br>   proxy_read_timeout 10s;<br>   proxy_set_header Upgrade $http_upgrade;<br>   proxy_set_header Connection 'upgrade';<br>   proxy_set_header Host $host;<br>   proxy_cache_bypass $http_upgrade;<br>   proxy_set_header X-Forwarded-Proto $scheme;<br>   proxy_pass http://localhost:3000;<br>   access_log off;<br>   log_not_found off;<br>  }<br>}</pre><p>The auth_request is intentionally commented during initial configuration — it's enabled in the Authentication article, once all roles and users are configured in each application.</p><p><strong>graylog-mcp</strong>: a special virtual host without OAuth2 so Claude can access the Graylog MCP Bridge directly with Basic authentication. Covered in the Graylog MCP article.</p><pre># Create links<br><br>cd /etc/nginx/sites-enabled<br>ln -s ../sites-available/wazuh<br>ln -s ../sites-available/graylog<br>ln -s ../sites-available/graylog-mcp<br>ln -s ../sites-available/grafana</pre><p><strong>Configure certificates</strong></p><p><strong>/etc/nginx/TLS/certificate.crt</strong> — Site and intermediate certificates.<br><strong>/etc/nginx/TLS/private.key</strong> — Private key.</p><p><strong>TLS and verification</strong></p><pre># Certificate with restrictive permissions<br><br>chmod 400 /etc/nginx/TLS/*</pre><pre># Verify configuration before starting<br><br>nginx -t</pre><p>Expected response:</p><pre>nginx: the configuration file /etc/nginx/nginx.conf syntax is ok<br>nginx: configuration file /etc/nginx/nginx.conf test is successful</pre><pre># Restart<br><br>systemctl restart nginx</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/700/0*BLX_WJBjJLfvTMg2.png"></figure><h3>Troubleshooting Guide</h3><h3>Log Paths and Common Issues in a Complex Security Stack</h3><p><strong><em>Part 10</em></strong></p><p>When something fails in a stack of this complexity — and something always does — knowing exactly where to look for information is the difference between resolving the problem in five minutes or an hour. This article documents the log paths for all components and the most common problems encountered during implementation.</p><p><strong>Real-time log monitoring</strong></p><p>To monitor any service in real time.</p><pre># Filtered error warn<br>journalctl -u &lt;service&gt; | grep -i -E "error|warn"<br><br># Limit the number of the last events shown<br>journalctl -u &lt;service&gt; -n &lt;number&gt;<br><br># Show only the most recent journal entries, and continuously print new entries<br>journalctl -fu &lt;service&gt;<br><br># Jump to the end and augment log lines with explanation texts from the message catalog<br>journalctl -xeu &lt;service&gt;</pre><p>Where &lt;service&gt; can be any of the following:</p><ul><li>wazuh-dashboard</li><li>wazuh-indexer</li><li>wazuh-manager</li><li>graylog-server</li><li>mongod</li><li>grafana-server</li><li>oauth2-proxy</li><li>fluent-bit</li><li>nginx</li><li>redis-server</li></ul><p><strong>Log file paths<br></strong>For direct access to log files:</p><pre>tail -f &lt;path&gt;</pre><ul><li>Wazuh-Indexer /log/wazuh-indexer/wazuh-cluster.log</li><li>Graylog /log/graylog/server.log</li><li>MongoDB /log/mongodb/mongod.log</li><li>Grafana /log/grafana/grafana.log</li><li>Fluent Bit /log/fluent-bit/td-agent-bit.log</li><li>OAuth2-Proxy /log/oauth2-proxy/oauth2.log</li><li>Nginx /log/nginx/error.log</li><li>Redis /log/redis/redis-server.log</li></ul><p><strong>Known issue: unexpected server restart</strong></p><p><strong>Symptom:</strong> Wazuh Manager fails to start after an unexpected server restart. The log shows:</p><pre>ERROR: Another instance is locking this process. If you are sure that<br>no other instance is running, please remove<br>/var/ossec/var/start-script-lock/</pre><p><strong>Cause:</strong> Wazuh creates a lock directory when starting and removes it on clean shutdown. If the server restarts abruptly (power cut, OOM killer, etc.), the directory remains and the next startup fails.</p><p><strong>Solution:</strong> Remove the lock directory manually and start service.</p><pre>rm -rf /var/ossec/var/start-script-lock/<br>systemctl start wazuh-manager</pre><p><strong>Recommended diagnostic approach</strong></p><p>When something isn’t working, the recommended review order is:</p><ol><li><strong>Is the service running?</strong> systemctl status &lt;service&gt;</li><li><strong>Any recent errors?</strong> journalctl -xeu &lt;service&gt; --since "10 minutes ago"</li><li><strong>Does the service’s own log file have more detail?</strong> tail -50 &lt;log_path&gt;</li><li><strong>For network issues between components:</strong> verify ports are listening<br>ss -tlnp | grep &lt;port&gt;</li><li><strong>For authentication issues:</strong> check the OAuth2-Proxy log and the headers Nginx is sending.</li></ol><p>The most frequent problems in this implementation were:</p><ul><li>Incorrect indentation in fluent-bit.conf (service starts without errors but doesn't process data).</li><li>Wazuh TLS certificate not included in Graylog’s JKS (connection silently rejected).</li><li>Service startup order: MongoDB must be running before Graylog.</li></ul><figure><img alt="" src="https://cdn-images-1.medium.com/max/700/0*Fx4TRiVvV9Z3fiR3.png"></figure><h3>Authentication: SSO and Integration Graylog with Wazuh</h3><p><strong><em>Part 11</em></strong></p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*wl3X9Hdfe8RZMX7lY0agwQ.jpeg"></figure><p>This is the most complex article in the series. Up to this point, all components are installed, but each has its own authentication system. The goal of this article is to configure the three solutions to accept the user identity propagated by OAuth2-Proxy via Nginx — completely eliminating local passwords from the daily login cycle.</p><blockquote><em>⚠</em><strong><em> Important</em></strong><em>:</em> Follow the order A-&gt;B-&gt;C-&gt;D. Configuring proxy authentication on a system before the user has been created will result in loss of access.</blockquote><blockquote>Verify the response of each curl command before proceeding.</blockquote><pre># Create random passwords for users<br><br>cat /dev/urandom | tr -dc "a-zA-Z0-9" | fold -w 16 | head -n 1</pre><p><strong>How Proxy Authentication Works</strong></p><p>The mechanism is as follows: Nginx validates the user’s identity with OAuth2-Proxy and then injects the username as an HTTP header x-proxy-user in each request to applications. Each application must be configured to trust this header and automatically assign roles.</p><p><strong>Continue with the following four steps:</strong></p><h4>11-A. Wazuh OAuth2</h4><pre># Reload systemctl and start services<br><br>systemctl daemon-reload<br>systemctl start oauth2-proxy wazuh-manager wazuh-indexer wazuh-dashboard</pre><blockquote>Startups may take some time. Check the logs for errors before continuing.</blockquote><p><strong>Creating Role Mapping</strong></p><p>Wazuh needs a role mapping that associates the username propagated by the proxy with the administrator role.</p><p><strong>Option A — Web<br></strong>https://wazuh.&lt;domain.com&gt;/app/security#/security?tab=roleMapping</p><blockquote>Use the “admin” credential from the “wazuh-passwords.txt” file.</blockquote><ul><li>Role mapping name: ProxyAuth</li><li>Roles: administrator</li><li>Custom rules → “Add new rule”</li><li>User field: user_name</li><li>Search operation: MATCH</li><li>Value: &lt;AD_user&gt;</li></ul><p><strong>Option B — API</strong></p><blockquote>Use the “wazuh-wui” credential from the “wazuh-passwords.txt” file.</blockquote><pre># Generate token<br><br>token=$(curl -u wazuh-wui:&lt;password&gt; -k -X POST "https://localhost:55000/security/user/authenticate?raw=true")</pre><pre># Create rule<br><br>curl -k -X POST "https://localhost:55000/security/rules" \<br>-H "Authorization: Bearer $token" \<br>-H "Content-Type: application/json" \<br>-d '{<br>  "name": "ProxyAuth",<br>  "rule": {<br>    "MATCH": {<br>      "user_name": "&lt;AD_user&gt;"<br>    }<br>  }<br>}'</pre><blockquote>Rule created with ID: 100</blockquote><pre># Assign the rule to the administrator role<br><br>curl -k -X POST "https://localhost:55000/security/roles/1/rules?rule_ids=&lt;id_rule&gt;" \<br>-H "Authorization: Bearer $token" \<br>-H "Content-Type: application/json"</pre><p>— — — end options</p><p><strong>Configure proxy authentication in OpenSearch</strong></p><pre># /etc/wazuh-dashboard/opensearch_dashboards.yml - Add and replace (part of the file)<br><br>opensearch_security.auth.type: "proxy"<br>opensearch_security.proxycache.user_header: "x-proxy-user"<br>opensearch_security.proxycache.roles_header: "x-proxy-roles"<br>opensearch_security.proxycache.proxy_header: "x-forwarded-for"<br>opensearch_security.proxycache.proxy_header_ip: "127.0.0.1"<br>opensearch.requestHeadersAllowlist: ["securitytenant","Authorization","x-proxy-user","x-proxy-roles","x-forwarded-for"]</pre><pre># /etc/wazuh-indexer/opensearch-security/config.yml — Enable xff and proxy auth (part of the file)<br><br>xff:<br>  enabled: true<br>  internalProxies: '127\.0\.0\.1'<br><br>proxy_auth_domain:<br>  description: "Authenticate via proxy"<br>  http_enabled: true</pre><pre># /etc/nginx/sites-enabled/wazuh - Enable<br><br>auth_request /oauth2/auth;</pre><pre># Apply changes<br><br>cd /etc/wazuh-indexer/opensearch-security/<br>/usr/share/wazuh-indexer/plugins/opensearch-security/tools/securityadmin.sh \<br>  -cacert /etc/wazuh-indexer/certs/root-ca.pem \<br>  -cert /etc/wazuh-indexer/certs/admin.pem \<br>  -key /etc/wazuh-indexer/certs/admin-key.pem \<br>  -h 127.0.0.1<br>systemctl restart wazuh-dashboard nginx</pre><blockquote>As of now, Wazuh uses OAuth2-Proxy for authentication.</blockquote><p><strong>Custom Backend Roles</strong></p><p>If your goal is to replace the backend role hardcoded with a Group 365:</p><ul><li>In the App Entra ID, add Security Group ID in Token optional Group Claims (Token configuration).</li><li>Next, obtain the Object ID of group 365.</li><li>Duplicate the “all_access” role at: https://wazuh.&lt;domain.com&gt;/app/security-dashboards-plugin#/roles/duplicate/all_access and name it "Group365" for reference.</li><li>Then, go to the mapping page: https://wazuh.&lt;domain.com&gt;/app/security-dashboards-plugin#/roles/edit/Group365/mapuser and paste the Object ID into the Backend roles field.</li><li>In /etc/wazuh-indexer/opensearch.yml, add "Group365" to the list defined under plugins.security.restapi.roles_enabled.</li><li>In Nginx Wazuh Host set auth_request_set $roles $upstream_http_x_auth_request_groups and proxy_set_header x-proxy-roles $roles.</li><li>Restart wazuh-indexer and nginx systemctl restart wazuh-indexer nginx</li></ul><p><strong>References</strong></p><pre># /etc/nginx/sites-enabled/wazuh</pre><pre>location / {<br>   auth_request /oauth2/auth;<br>   error_page 401 = /oauth2/start;<br>   auth_request_set $user $http_x_auth_user;<br>   proxy_set_header x-proxy-user $user;<br>   <strong>auth_request_set $roles $upstream_http_x_auth_request_groups</strong>;<br>   <strong>proxy_set_header x-proxy-roles $roles</strong>;<br>   proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;<br>   proxy_set_header X-Real-IP $remote_addr;<br>   proxy_http_version 1.1;<br>   proxy_read_timeout 10s;<br>   proxy_set_header Upgrade $http_upgrade;<br>   proxy_set_header Connection 'upgrade';<br>   proxy_set_header Host $host;<br>   proxy_cache_bypass $http_upgrade;<br>   proxy_set_header X-Forwarded-Proto $scheme;<br>   proxy_pass <a href="https://localhost/">https://localhost:8080;</a><br>   access_log off;<br>   log_not_found off;<br>  }</pre><pre># /etc/wazuh-indexer/opensearch.yml</pre><pre>plugins.security.restapi.roles_enabled:<br>- "all_access"<br>- "security_rest_api_access"<br>- "<strong>Group365</strong>"</pre><p><strong>Alernative Map Nginx</strong></p><pre># /etc/nginx/nginx.conf</pre><pre>http {<br>  map $upstream_http_x_auth_request_email $http_x_auth_user {<br>    "~^(?&lt;user&gt;[^@]+)@" $user;<br>  }</pre><pre><strong>map $http_x_auth_user $roles {<br>    "&lt;AD_user1&gt;" "&lt;group_object_id&gt;";<br>    "&lt;AD_user2&gt;" "readall";<br>  }</strong></pre><h4>11-B. Connect Graylog to Wazuh Indexer</h4><p><strong>Create user in Wazuh for Graylog</strong></p><blockquote>Graylog needs a user in Wazuh Indexer to be able to index logs.</blockquote><blockquote>Use the “admin” credential from the “wazuh-passwords.txt” file.</blockquote><blockquote>User defined “graylog” (or you can choose another name).</blockquote><p><strong>Option A — Web<br></strong>https://wazuh.&lt;domain.com&gt;/app/security-dashboards-plugin#/users</p><ul><li>Username: graylog</li><li>Password: &lt;password&gt;</li><li>Backend roles: admin</li></ul><p><strong>Option B — API</strong></p><pre># Create user<br><br>curl -k -X PUT "https://127.0.0.1:9200/_plugins/_security/api/internalusers/graylog" \<br>-H "Content-type: application/json" \<br>-u "admin:&lt;password&gt;" \<br>-d '{<br>  "password": "&lt;password&gt;",<br>  "backend_roles": ["admin"]<br>}'</pre><p>— — — end options</p><pre># /etc/graylog/server/server.conf - Enable ElasticSearch connection<br><br>elasticsearch_hosts = https://graylog:&lt;password&gt;@127.0.0.1:9200</pre><blockquote>Use “127.0.0.1” and not “localhost” — Wazuh’s TLS certificate requires the SAN (Subject Alternative Name) to match exactly.</blockquote><h4>11-C. Graylog OAuth2</h4><pre># Start services<br><br>systemctl start mongod graylog-server</pre><blockquote>Use the “admin” credential, <a href="https://infosecwriteups.com/open-source-security-platform-for-it-infrastructure-centralizing-threat-detection-logs-and-sso-c08d1b412f37#ce08">reference</a>.</blockquote><p><strong>Option A — Web</strong></p><p><strong>Enable header</strong><br>https://graylog.&lt;domain.com&gt;/system/authentication/authenticator/edit</p><ul><li>Enabled: ✓</li><li>Username header: x-proxy-user</li></ul><p><strong>Create user<br></strong>https://graylog.&lt;domain.com&gt;/system/users/new</p><ul><li>First Name: &lt;first_name&gt;</li><li>Last Name: &lt;last_name&gt;</li><li>Username: &lt;AD_user&gt;</li><li>E-Mail Address: &lt;email&gt;</li><li>Assign Roles: Admin</li><li>Password: &lt;password&gt;</li></ul><p><strong>Option B — API</strong></p><pre># Enable header<br><br>curl -X PUT "http://localhost:9000/api/system/authentication/http-header-auth-config" \<br>-H "Content-Type: application/json" \<br>-H "X-Requested-By: cli" \<br>-u "admin:&lt;password&gt;" \<br>-d '{<br>  "enabled": true,<br>  "username_header": "x-proxy-user"<br>}'</pre><pre># Create user<br><br>curl -X POST "http://localhost:9000/api/users" \<br>-H "Content-Type: application/json" \<br>-H "X-Requested-By: cli" \<br>-u "admin:&lt;password&gt;" \<br>-d '{<br>  "first_name": "&lt;first_name&gt;",<br>  "last_name": "&lt;last_name&gt;",<br>  "username": "&lt;AD_user&gt;",<br>  "email": "&lt;email&gt;",<br>  "password": "&lt;password&gt;",<br>  "roles": ["Admin"],<br>  "permissions": []<br>}'</pre><p>— — — end options</p><pre># /etc/graylog/server/server.conf -Enable and edit<br><br>trusted_proxies = 127.0.0.1/32</pre><pre># /etc/nginx/sites-enabled/graylog - Enable<br><br>auth_request /oauth2/auth;</pre><pre># Apply changes<br><br>systemctl restart graylog-server nginx</pre><h4>11-D. Grafana OAuth2</h4><pre># Start service<br><br>systemctl start grafana-server</pre><p><strong>Create user</strong></p><blockquote>Use the default “admin:admin” credential.</blockquote><p><strong>Option A — Web<br></strong>https://grafana.&lt;domain.com&gt;/admin/users/create</p><ul><li>Name: &lt;name&gt;</li><li>Email: &lt;email&gt;</li><li>Username: &lt;AD_user&gt;</li><li>Password: &lt;password&gt;</li></ul><p>Next screen:</p><ul><li>Enable "Grafana Admin” and change to "Admin" role.</li></ul><p><strong>Option B — API</strong></p><pre># Create user<br><br>curl -X POST "http://localhost:3000/api/admin/users" \<br>-H "Content-Type: application/json" \<br>-u "admin:&lt;password&gt;" \<br>-d ' {<br>  "name":"&lt;name&gt;",<br>  "email":"&lt;email&gt;",<br>  "login":"&lt;AD_user&gt;",<br>  "password":"&lt;password&gt;"<br>}'</pre><blockquote>Account created with ID: 2</blockquote><pre># Assign global admin<br><br>curl -X PUT "http://localhost:3000/api/admin/users/&lt;user_id&gt;/permissions" \<br>-H "Content-Type: application/json" \<br>-u "admin:&lt;password&gt;" \<br>-d '{<br>  "isGrafanaAdmin": true<br>}'</pre><pre># Assign organization administrator role<br><br>curl -X PATCH "http://localhost:3000/api/orgs/1/users/&lt;user_id&gt;" \<br>-H "Content-Type: application/json" \<br>-u "admin:&lt;password&gt;" \<br>-d '{<br>  "role":"Admin"<br>}'</pre><p>— — — end options</p><pre># /etc/grafana/grafana.ini - Enable and edit<br><br>[auth.proxy]<br>enabled = true<br>header_name = x-proxy-user<br>header_property = username<br>auto_sign_up = false<br>sync_ttl = 3600<br>whitelist = 127.0.0.1</pre><pre># /etc/nginx/sites-enabled/grafana - Enable<br><br>auth_request /oauth2/auth;</pre><pre># Apply changes<br><br>systemctl restart grafana-server nginx</pre><blockquote><em>⚠</em><strong><em> Important:</em></strong><em> </em>For security reasons, replace the default password for the user “admin”.</blockquote><figure><img alt="" src="https://cdn-images-1.medium.com/max/700/0*LlADIl-n2kYp6S5O.png"></figure><h3>Graylog Ingest: Configuring Data Ingest from Fluent Bit</h3><p><strong><em>Part 12</em></strong></p><p>With all components installed and SSO authentication configured, it’s time to connect the final wires: configure Graylog to receive the events that Fluent Bit sends from Wazuh, and activate all services so that the platform is fully operational.</p><p>Fluent Bit sends Wazuh events to “localhost:5555” in JSON format. Graylog needs an active input listening on that port to process them.</p><p><strong>Option A — Web interface:<br></strong>https://graylog.&lt;domain.com&gt;/system/inputs</p><ul><li>Select input type: Raw HTTP</li><li>Click “Launch new input”</li><li>Configure:<br><strong> </strong>Title<strong>:</strong> Wazuh<br><strong>Bind address:</strong> 127.0.0.1</li><li>Click “Launch Input”</li><li>Follow the wizard to start the input and verify your diagnosis.</li></ul><p><strong>Option B — API:</strong></p><pre># Create RAW HTTP input - Graylog admin credential<br><br>curl -X POST "http://localhost:9000/api/system/inputs" \<br>-H "Content-Type: application/json" \<br>-H "X-Requested-By: cli" \<br>-u "admin:&lt;password&gt;" \<br>-d '{<br>  "title": "Wazuh",<br>  "type": "org.graylog2.inputs.raw.http.RawHttpInput",<br>  "global": true,<br>  "configuration": {<br>    "bind_address": "127.0.0.1",<br>    "port": 5555,<br>    "recv_buffer_size": 1048576,<br>    "max_chunk_size": 65536<br>  }<br>}'</pre><blockquote>bind_address: 127.0.0.1 limits listening to the local interface — Fluent Bit runs on the same server, so there’s no need to expose the port externally.</blockquote><blockquote>Standard configuration uses the default stream.</blockquote><p>— — — end options</p><p>With the platform fully configured, we enable automatic service startup and start Fluent Bit to begin receiving events:</p><pre>systemctl enable fluent-bit mongod graylog-server grafana-server oauth2-proxy<br>systemctl start fluent-bit</pre><p>Order matters: MongoDB must be running before Graylog, and OAuth2-Proxy before Nginx. The “enable” command ensures that systemd respects dependencies on future server restarts.</p><p><strong>Verification: Is everything Working?</strong></p><p>Once all services are active, verify the complete flow:</p><ol><li><strong>Fluent Bit is reading Wazuh alerts</strong>:<br><em>tail -f /log/fluent-bit/td-agent-bit.log</em><br>You should see error-free processing lines.</li><li><strong>Graylog is receiving messages</strong>: In the web interface, navigate to Search and verify that messages with the source “wazuh” are arriving.</li><li><strong>SSO Authentication</strong>: Access <a href="https://site.domain.com/">https://site.domain.com</a> from your browser — it should redirect you to the IdP and then return authenticated.</li><li><strong>Grafana connected to Wazu</strong>h: In Grafana, configure a data source pointing to Wazuh and verify that it returns data.</li></ol><figure><img alt="" src="https://cdn-images-1.medium.com/max/700/0*_yPCjCev-1VHORsJ.png"></figure><h3>Graylog MCP + Claude: Querying Security Logs in Natural Language with AI</h3><p><strong><em>Part 13</em></strong></p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*zafoeeMeYUR77NUv3B4o3w.jpeg"></figure><p>This is the most groundbreaking article in the series. The platform is already operational: Wazuh detects threats, Fluent Bit transports events, Graylog indexes them, and Grafana visualizes them. But there’s an additional layer that completely changes how we interact with security data: <strong>integrating Claude as an AI client on the Graylog REST API — MCP is more than an API; it’s a Bridge</strong>.</p><p><strong>What is MCP and why does it matter?<br></strong>MCP (Model Context Protocol) is a protocol that allows language models like Claude to connect directly with external tools and data sources. In this case, Graylog exposes its API as an MCP server, and Claude acts as an intelligent client that can query, filter, and analyze security logs.</p><p><strong>The change this produces is significant</strong>:</p><ul><li>Instead of building queries in the Graylog interface, the analyst writes in natural language: “<strong>Were there any failed login attempts in the last 2 hours?</strong>”</li><li>Instead of reviewing hundreds of log lines, Claude summarizes the relevant patterns and presents them in context.</li><li>Non-technical users — operators without SIEM experience — can interact directly with the security data.</li><li>Every query is logged in Graylog like any other API interaction, maintaining complete traceability.</li></ul><p><strong>Architecture of integration</strong></p><figure><img alt="" src="https://cdn-images-1.medium.com/max/325/1*S0hueQdlC9DM7gMt2rQ4IA.jpeg"></figure><p>A specific virtual host was created in Nginx “graylog-mcp” without OAuth2-Proxy — Claude authenticates directly with Basic credentials encoded in base64.</p><h3>Installation</h3><p><strong>On the client:</strong></p><ol><li><strong>NodeJS:</strong> <a href="https://nodejs.org/en/download">https://nodejs.org/en/download</a></li><li><strong>Claude Desktop:</strong> <a href="https://claude.com/download">https://claude.com/download</a></li></ol><h3>Configuration in Graylog</h3><p><strong>Step 1: Enable MCP in Graylog</strong></p><p>https://graylog.&lt;domain.com&gt;/system/configurations/MCP</p><p><strong>Step 2: Create a user token</strong></p><p>Navigate to https://graylog.&lt;domain.com&gt;/system/users → Actions → More → Edit tokens.</p><ul><li>Token Name: &lt;name&gt;</li><li>Token TTL: &lt;time&gt;</li></ul><blockquote>TTL Syntax Examples: for 60 seconds: PT60S, for 60 minutes: PT60M, for 24 hours: PT24H, for 30 days: P30D</blockquote><p><strong>Step 3: Base64 Encoding of Credentials</strong></p><p>The format is "&lt;token&gt;:token” encoded in base64.</p><pre>echo -n "&lt;token&gt;:token" | base64</pre><h3>Claude Desktop Configuration</h3><p>Edit the “claude_desktop_config.json” file in Claude Desktop, usually located in "%APPDATA%\CLAUDE\".</p><pre>{<br>  "mcpServers": {<br>    "Graylog": {<br>      "command": "C:\\Program Files\\nodejs\\npx",<br>      "args": [<br>        "mcp-remote",<br>        "https://graylog-mcp.&lt;domain.com&gt;/mcp",<br>        "--header",<br>        "Authorization: Basic &lt;credential_b64&gt;"<br>      ]<br>    }<br>  }<br>}</pre><blockquote>Replace <em>&lt;domain.com&gt;</em> with your actual domain and <em>&lt;credential_b64&gt;</em> with the base64 value generated in the previous step.</blockquote><p>Restart Claude Desktop and check the connection status in: <br><strong>Settings → Developer</strong></p><blockquote>The state should be running or refer to the logs.</blockquote><figure><img alt="" src="https://cdn-images-1.medium.com/max/982/1*zf7ollrjFRmyHYCdc_h86w.jpeg"></figure><h3>Real-world use cases</h3><p>Once connected, Claude can answer questions such as:</p><ul><li>“How many critical alerts did Wazuh generate today?”</li><li>“Are there any IPs that repeatedly attempted to connect without success?”</li><li>“Summarize the events of the last 30 minutes”</li><li>“Which services experienced errors in the last 6 hours?”</li></ul><p>The response is not a list of raw logs — it’s a natural language analysis with relevant patterns identified and contextualized.</p><h3>Security considerations</h3><ul><li>Access to graylog-mcp is restricted to HTTPS with a valid certificate.</li><li>Base64-encoded credentials are NOT encrypted — they are only encoded. True security lies in TLS and ensuring the endpoint is only accessible from the corporate network.</li><li>Every request from Claude is logged in the Graylog access log, maintaining a complete audit trail.</li><li>Rotating the token periodically is a best practice.</li></ul><figure><img alt="" src="https://cdn-images-1.medium.com/max/700/0*7AWAjKALkSFXqCSq.png"></figure><h3>Final Architecture, evidences, and Conclusions: An Open Source Security Platform in Production</h3><p><strong><em>Part 14</em></strong></p><p>This is the final article in the series. After thirteen articles covering each component of the stack — from Wazuh to integration with Claude via MCP — it’s time to see the big picture and reflect on what worked, and what cost more than expected.</p><p><strong>Wazuh</strong></p><figure><img alt="" src="https://cdn-images-1.medium.com/max/969/1*G6ujNdCoZjnmY0KGutYgNA.jpeg"></figure><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*u3VN36Y05Vkaht3BXX6GEg.jpeg"></figure><p><strong>Graylog</strong></p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*2Nq4JG1ZvNYDUTqWPnv7Rg.jpeg"></figure><p><strong>Grafana</strong></p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*r6nrI73XCYVg_nZxowlhsQ.jpeg"></figure><p><strong>Claude</strong></p><figure><img alt="" src="https://cdn-images-1.medium.com/max/743/1*oUVy7cQSqs-d1XaWjqPVaw.jpeg"></figure><figure><img alt="" src="https://cdn-images-1.medium.com/max/743/1*gSsxbeKhCf35sRQ6aouAlg.jpeg"></figure><figure><img alt="" src="https://cdn-images-1.medium.com/max/740/1*xa9tIbOpgwLipnlUrvmV3g.jpeg"></figure><h3>The Complete Architecture</h3><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*vmW0rU3czxIzuIfjyuSisw.jpeg"></figure><p>The diagram shows two main flows that coexist on the platform:</p><h3>Data Flow</h3><figure><img alt="" src="https://cdn-images-1.medium.com/max/618/1*SLgK1QVdKfN8UV1mCvb1mA.jpeg"></figure><p>Wazuh detects events and writes them in JSON format. Fluent Bit continuously reads this file and forwards each event to Graylog via TCP. Graylog indexes the data to Wazuh Indexer (returns the connection to OpenSearch). Grafana connects to Wazuh as a data source for dashboards. Claude accesses the Graylog MCP Bridge for natural language queries.</p><h3>Authentication Flow</h3><figure><img alt="" src="https://cdn-images-1.medium.com/max/532/1*-0uEx_oWBnDzzvJ60tbKnw.jpeg"></figure><p>The user accesses any of the three systems with their corporate account. Nginx queries OAuth2-Proxy on each request. OAuth2-Proxy validates the session (stored in Redis) or redirects to IdP for authentication. Once authenticated, Nginx propagates the username as an HTTP header to the corresponding application.</p><h3>Lessons Learned</h3><p><strong>What worked well:</strong></p><ul><li><strong>Separate LVM volumes</strong> — the best implementation decision. On three occasions, logs grew larger than expected; none of these affected the operating system or application data.</li><li><strong>Single authentication point</strong> — after the initial (and complex) setup, the user experience is seamless. One login for three systems.</li><li><strong>Fluent Bit vs. Filebeat</strong> — Fluent Bit’s resource consumption is significantly lower. On a shared server, this matters.</li><li><strong>Graylog MCP + Claude</strong> — the most differentiating component. It completely changed how non-technical users interact with security data.</li></ul><p><strong>What cost more than expected</strong>:</p><ul><li><strong>TLS between Graylog and Wazuh Indexer</strong> — the JKS and CA certificate import is the step with the most incorrect documentation online. The guide in this article reflects what actually works.</li><li><strong>Order of operations in Authentication</strong> — configuring the authentication proxy before creating users results in loss of access. The order matters.</li></ul><h3>Is it worth it?</h3><p>For an organization that wants true visibility into its infrastructure without paying for commercial SIEM tool licenses (which can cost tens of thousands of dollars annually), the answer is yes.</p><p>The real cost is implementation time and technical expertise. This well-documented stack can be replicated in a single workday using this guide. The necessary technical knowledge includes Linux administration, basic TLS concepts, and reading the official documentation.</p><p>What you get in return is a security platform with features comparable to commercial solutions, complete control over your data, no vendor lock-in, and the ability to extend it with any component you need.</p><h3>About this series</h3><p>This implementation was carried out in production for the IT Infrastructure. All documentation reflects real decisions, real problems, and solutions that work in production.</p><p>If you have questions, found a bug, or want to share an improvement, the comments are open.</p><blockquote><strong><em>Your Turn — Operational Ownership</em></strong></blockquote><blockquote>From here, the real value comes from how you adapt it to your environment. As the operator or administrator, the next layer is yours to build:</blockquote><blockquote><strong><em>Graylog:</em></strong> Create dedicated indexes and streams per data source; build a JSON extractor for the message field to enable structured search.</blockquote><blockquote><strong><em>Vulnerability visibility:</em></strong><em> </em>A custom script can reindex Wazuh’s vulnerability summary index and inject it into Graylog via a new GELF HTTP input — all through the APIs — making vulnerability summaries available in Grafana dashboards .</blockquote><blockquote><strong><em>Alerting and reporting:</em></strong> Define alert conditions and scheduled reports based on what matters to your organization.</blockquote><blockquote><strong><em>Grafana dashboards:</em></strong> Design views tailored to what your team or clients actually need to see.</blockquote><blockquote><strong><em>API automation:</em></strong> Build scripts to automate recurring calls across the stack.</blockquote><blockquote><strong><em>Threat intelligence:</em></strong> Cross-reference events with NIST NVD and CISA KEV for deeper context and custom correlations.</blockquote><blockquote>If you have questions or need guidance on the operational side, feel free to reach out — happy to support within my availability.</blockquote><p><strong>Author:</strong><em> Antonio Valenzuela Serra </em><strong><em>— </em></strong><em>SysAdmin </em><strong><em>— </em></strong><em>Chile </em><strong><em>— </em></strong><em>May 2026\</em></p><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=c08d1b412f37" width="1" height="1" alt=""><hr><p><a href="https://infosecwriteups.com/open-source-security-platform-for-it-infrastructure-centralizing-threat-detection-logs-and-sso-c08d1b412f37">Open Source Security IT Platform: Threat Detection, Logging, Alerts, AI and SSO integration.</a> was originally published in <a href="https://infosecwriteups.com/">InfoSec Write-ups</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[4 cutting-edge tools for spec-driven development]]></title>
<description><![CDATA[In February 2025, AI developer Andrej Karpathy posted a tweet (or whatever they call them now on the site formerly known as Twitter) about what he called “vibe coding”:




There’s a new kind of coding I call “vibe coding”, where you fully give in to the vibes, embrace exponentials, and forget th...]]></description>
<link>https://tsecurity.de/de/3527447/ai-nachrichten/4-cutting-edge-tools-for-spec-driven-development/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3527447/ai-nachrichten/4-cutting-edge-tools-for-spec-driven-development/</guid>
<pubDate>Tue, 19 May 2026 00:47:11 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>In February 2025, AI developer <a href="https://x.com/karpathy">Andrej Karpathy</a> posted a tweet (or whatever they call them now on the site formerly known as Twitter) about what he called “<a href="https://x.com/karpathy/status/1886192184808149383?lang=en">vibe coding</a>”:</p>



<blockquote class="wp-block-quote is-layout-flow wp-block-quote-is-layout-flow">
<p>There’s a new kind of coding I call “vibe coding”, where you fully give in to the vibes, embrace exponentials, and forget that the code even exists. It’s possible because the LLMs (e.g. Cursor Composer w Sonnet) are getting too good. Also I just talk to Composer with SuperWhisper so I barely even touch the keyboard. I ask for the dumbest things like “decrease the padding on the sidebar by half” because I’m too lazy to find it. I “Accept All” always, I don’t read the diffs anymore. When I get error messages I just copy paste them in with no comment, usually that fixes it. The code grows beyond my usual comprehension, I’d have to really read through it for a while. Sometimes the LLMs can’t fix a bug so I just work around it or ask for random changes until it goes away. It’s not too bad for throwaway weekend projects, but still quite amusing. I’m building a project or webapp, but it’s not really coding — I just see stuff, say stuff, run stuff, and copy paste stuff, and it mostly works.</p>
</blockquote>



<p>Note that Karpathy was using <a href="https://www.infoworld.com/article/4078884/what-is-vibe-coding-ai-writes-the-code-so-developers-can-think-big.html" data-type="link" data-id="https://www.infoworld.com/article/4078884/what-is-vibe-coding-ai-writes-the-code-so-developers-can-think-big.html">vibe coding</a> for “throwaway weekend projects,” not his day job. He also deprecates the way he asks for “the dumbest things,” because he’s “too lazy to find it.” He says vibe coding is possible “because the LLMs (e.g. Cursor Composer w Sonnet) are getting too good.” He also says “it mostly works.”</p>



<p>“Mostly works” is not a glowing recommendation, and applying vibe coding to serious projects presents serious risks, including the creation of hidden bugs that will bite you later. It’s folly. It also inevitably creates technical debt.</p>



<p>If someone competent and experienced cleans up and refactors the code produced by the <a href="https://www.infoworld.com/article/2335213/large-language-models-the-foundations-of-generative-ai.html" data-type="link" data-id="https://www.infoworld.com/article/2335213/large-language-models-the-foundations-of-generative-ai.html">large language models</a>, you can avoid the worst outcomes and reduce the technical debt, but that often takes more time than just designing the architecture and writing the code by hand. AI slop followed by human cleanup leads to reduced programmer productivity, exactly the opposite of what you want to achieve by using LLMs to generate code.</p>



<h2 class="wp-block-heading">What is spec-driven development?</h2>



<p>Spec-driven development (SDD) is one way to avoid the chaos of vibe coding without completely returning to manual coding. It doesn’t involve waterfall planning or developing exhaustive requirements documents — it’s lighter-weight than those, and designed to be readable and concise.</p>



<p>In his <a href="https://github.blog/ai-and-ml/generative-ai/spec-driven-development-with-ai-get-started-with-a-new-open-source-toolkit/">introduction to Spec Kit</a>, <a></a><a>Den Delimarsky</a> at Microsoft calls a spec “version control for your thinking.” He goes on to say “This is a contract for how your code should behave and becomes the source of truth your tools and AI agents use to generate, test, and validate code. The result is less guesswork, fewer surprises, and higher-quality code.”</p>



<p>Birgitta Böckeler of Thoughtworks <a href="https://martinfowler.com/articles/exploring-gen-ai/sdd-3-tools.html">divides spec-driven development into three implementation levels</a>: spec-first, spec-anchored, and spec-as-source. Spec-first means that “a well-thought-out spec is written first, and then used in the AI-assisted development workflow for the task at hand.” Spec-anchored means that “the spec is kept even after the task is complete, to continue using it for evolution and maintenance of the respective feature.” <a>Spec-as-source </a>means that “the spec is the main source file over time, and only the spec is edited by the human, the human never touches the code.”</p>



<p>I’m not at all sure that any current tool implements spec-as-source. It’s a worthy aspiration, but we’re not there yet.</p>



<p>Let’s take a brief look at four tools and frameworks that currently support spec-driven development. </p>



<h2 class="wp-block-heading">Kiro</h2>



<p>AWS <a href="https://kiro.dev/blog/introducing-kiro-autonomous-agent/" data-type="link" data-id="https://kiro.dev/blog/introducing-kiro-autonomous-agent/">describes Kiro</a> as an autonomous agent that maintains context and learns over time while working on software development tasks independently. Kiro is available both as an IDE (based on Code OSS) and a CLI tool, and was developed by “a small, opinionated team within AWS.” <a href="https://kiro.dev/" data-type="link" data-id="https://kiro.dev/">Kiro IDE</a> explicitly supports both vibe coding and spec-driven development. <a href="https://kiro.dev/cli/" data-type="link" data-id="https://kiro.dev/cli/">Kiro CLI</a> doesn’t deal with specs at this point, although it does have a planner agent and agent steering.  </p>



<p>Kiro SDD generates three markdown files that together comprise the <a href="https://kiro.dev/docs/specs/">specification</a>.</p>



<ul class="wp-block-list">
<li>Requirements (requirements.md) – Captures user stories and acceptance criteria in structured EARS notation. </li>



<li>Design (design.md) – Documents technical architecture, sequence diagrams, and implementation considerations. </li>



<li>Tasks (tasks.md) – Provides a detailed implementation plan with discrete, trackable tasks.</li>
</ul>



<p>You can also <a href="https://kiro.dev/docs/specs/best-practices/#how-do-i-import-existing-designs-or-architecture" data-type="link" data-id="https://kiro.dev/docs/specs/best-practices/#how-do-i-import-existing-designs-or-architecture">import specs</a> from other systems and <a href="https://kiro.dev/docs/specs/best-practices/#how-do-i-iterate-on-my-feature-specs" data-type="link" data-id="https://kiro.dev/docs/specs/best-practices/#how-do-i-iterate-on-my-feature-specs">iterate on your specs</a>. You can even generate specs based on a vibe-coding session. Ideally, you would <a href="https://kiro.dev/docs/specs/best-practices/">create a spec for each project feature</a>.</p>



<p>EARS (Easy Approach to Requirements Syntax) notation captures user stories and follows the pattern:</p>



<p>WHEN [condition/event]<br>THE SYSTEM SHALL [expected behavior]</p>



<p>This format is clear and testable. Kiro can generate <a href="https://kiro.dev/docs/specs/correctness/">property-based tests</a> (PBT) based on your EARS-formatted requirements; these are more comprehensive than the usual unit tests.</p>



<p>In addition, Kiro can generate three markdown files that together define the steering for the agents. Steering gives Kiro persistent knowledge about your workspace and its conventions.</p>



<ul class="wp-block-list">
<li>Product overview (product.md) – Defines your product’s purpose, target users, key features, and business objectives. This helps Kiro understand the “why” behind technical decisions and suggest solutions aligned with your product goals.</li>



<li>Technology stack (tech.md) – Documents your chosen frameworks, libraries, development tools, and technical constraints. When Kiro suggests implementations, it will prefer your established stack over alternatives.</li>



<li>Project structure (structure.md) – Outlines file organization, naming conventions, import patterns, and architectural decisions. This ensures generated code fits seamlessly into your existing codebase.</li>
</ul>



<p>With my <a href="https://kiro.dev/pricing/">free plan</a>, Kiro IDE currently supports three Claude models, Sonnet 4.5, Sonnet 4, and Haiku 4.5. It can automatically select models if you wish. The documentation also mentions Opus 4.5, which I assume can be activated with a Pro ($20/month) or better plan.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/05/spec-driven-development-Kiro.png?w=1024" alt="spec-driven development - Kiro" class="wp-image-4171396" width="1024" height="649" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption"><p>Kiro IDE supports both vibe coding and spec-driven development workflows.</p>
</figcaption></figure><p class="imageCredit">Foundry</p></div>



<h2 class="wp-block-heading">Spec Kit</h2>



<p><a href="https://github.blog/ai-and-ml/generative-ai/spec-driven-development-with-ai-get-started-with-a-new-open-source-toolkit/">Spec Kit</a> is an <a href="https://github.com/github/spec-kit">open-source toolkit</a> for spec-driven development from Microsoft. It provides a four-phase, structured process to bring spec-driven development to coding agent workflows, and integrates with some 30 coding agents. </p>



<p>You start by installing the <code>specify</code> CLI, using <code>uv</code> for a persistent installation (recommended) or running it once with <code>uvx</code>. The <code>specify</code> command can initialize Spec Kit projects, optionally specify an AI agent, and check for installed tools. Once you have initialized a project your <a href="https://github.github.io/spec-kit/reference/integrations.html">AI coding agent</a> (e.g. GitHub Copilot or Claude Code) has access to several slash commands for structured development: </p>



<ul class="wp-block-list">
<li><code>/speckit.constitution</code> – Project governing principles</li>



<li><code>/speckit.specify</code> – Requirements and user stories </li>



<li><code>/speckit.clarify</code> – Clarify underspecified areas </li>



<li><code>/speckit.plan</code> – Technical implementation plans, including tech stack</li>



<li><code>/speckit.tasks</code> – Actionable task lists for implementation</li>



<li><code>/speckit.analyze</code> – Consistency and coverage analysis</li>



<li><code>/speckit.implement</code> – Execute all tasks</li>



<li><code>/speckit.checklist</code> – Checklists that validate requirements</li>
</ul>



<p>Spec Kit can generate a project from scratch (Greenfield), modernize legacy code (Brownfield), and explore diverse options in parallel. There’s been <a href="https://github.com/github/spec-kit/discussions/152">some discussion</a> about how Spec Kit is best used and whether Spec Kit is spec-anchored; there’s no general consensus, other than observing that Spec Kit as released prefers a small spec per feature rather than a giant spec for a whole project.</p>



<h2 class="wp-block-heading">Tessl</h2>



<p>The slogan is “Keep your agents on the rails with <a href="https://tessl.io/">Tessl</a>.” Tessl tries to do this with a framework and package registry, plus evaluations, all aided by a CLI. The Tessl CLI can scan your project for dependencies and configure Model Context Protocol (MCP) server settings for AI coding agents such as Claude Code, Codex, and Gemini. </p>



<p>The CLI can also search the package registry for “tiles” by name, PURL, or HTTP URL. Tiles contain skills (procedural workflows for the agent), documentation (for libraries and frameworks that agents can query on-demand), and rules (mandatory coding standards and conventions). You can use the existing registry and also create your own skills and tiles.</p>



<p>You can do <a href="https://docs.tessl.io/use/spec-driven-development-with-tessl">spec-driven development with Tessl</a> using the Tessl SDD tile. Once that is installed, simply include “use spec-driven development” in your prompt. Then the agent will ask questions and write specs before code. You can improve your results by also installing tiles that document the tools you use from the <a href="https://tessl.io/registry">Tessl skills registry</a>.</p>



<h2 class="wp-block-heading">Zenflow</h2>



<p><a href="https://zencoder.ai/zenflow">Zenflow</a> is a free platform that coordinates AI agents to build software. It features “spec-driven workflows, built-in verification, and multi-agent execution that actually works.” Another term for coordination is orchestration, and Zenflow is also described as an orchestration layer.</p>



<p>Developed by the <a href="https://zencoder.ai/">Zencoder</a> team, Zenflow works with the Zencoder plugins. (And features from Zenflow, such as guided workflows, have been added to Zencoder.) The CEO of Zencoder, Andrew Filev, told me that his team of experienced engineers has been using Zenflow for their own product development for over a year when I questioned whether it is ready for production code.</p>



<p>The high-level description of the relationship between Zencoder and Zenflow is that Zenflow is the workflow brain and Zencoder executes the work. You may have noticed some naming confusion: Zencoder is not only the name of the company and the name of its AI plug-in for IDEs, but it is also the name of the company’s in-house coding agent, which is one of four agent options for Zenflow (the others being Claude Code, Codex, and Gemini) and one of at least nine models available to the Zencoder plug-in.</p>



<p>When you start a Zenflow project, you’re offered a choice of standard workflows: Quick Change, Fix Bug, Spec and Build, or Full SDD Workflow, depending on scope. The wider the scope, the more structure you need in the workflow to keep the implementation from drifting away from the requirements. You can also define your own workflows, perhaps to conform to your shop’s standards.</p>



<p>Zenflow can run multiple tasks in parallel in isolated environments. The agents coordinate within workflows without corrupting your codebase.</p>



<p>Zenflow automates verification of its changes. Every workflow runs automated tests and cross-agent code review. Failed tests trigger automatic fixes. Your code ships only after passing all of the verification gates.</p>



<p>Zenflow projects are broken down into tasks, and those are divided into subtasks and chats. Each task runs inside its own isolated Git worktree. You can view the status of all tasks in Kanban boards or stacked list views.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/05/spec-driven-development-Zenflow.png?w=1024" alt="spec-driven development - Zenflow" class="wp-image-4171400" width="1024" height="685" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption"><p>Zenflow supports multiple workflows, from quick changes all the way up to full SDD. You can also define custom workflows.</p>
</figcaption></figure><p class="imageCredit">Foundry</p></div>



<h2 class="wp-block-heading">Feel the vibes?</h2>



<p>Where and when does spec-driven development make sense? In broad strokes, you can get away with doing AI-assisted coding without specs for personal projects, small features, and bug fixes. You need specifications to keep AI coding agents on the rails for large features, major refactoring, and enterprise-level projects.</p>



<p>Which spec-driven development tool should you use, if any? That depends entirely on your environment, your goals, and your personal and team preferences. Kiro, Spec Kit, Tessl, and Zenflow are all good places to start. </p>
</div></div></div>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[The real AI bottleneck isn’t what you think]]></title>
<description><![CDATA[At HumanX in San Francisco earlier this year, Andrew Ng made a point that reframed how many in the room were thinking about enterprise AI. Ng built the AI infrastructure at Google Brain and Baidu before founding DeepLearning.AI and Coursera, which now serves roughly 148 million learners globally....]]></description>
<link>https://tsecurity.de/de/3525532/it-security-nachrichten/the-real-ai-bottleneck-isnt-what-you-think/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3525532/it-security-nachrichten/the-real-ai-bottleneck-isnt-what-you-think/</guid>
<pubDate>Mon, 18 May 2026 12:08:43 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>At HumanX in San Francisco earlier this year, Andrew Ng made a point that reframed how many in the room were thinking about enterprise AI. Ng built the AI infrastructure at Google Brain and Baidu before founding DeepLearning.AI and<a href="https://www.coursera.org/" rel="nofollow"> </a><a href="https://www.coursera.org/" rel="nofollow">Coursera</a>, which now serves roughly 148 million learners globally. He is someone whose read on where AI creates organizational stress has earned its credibility.</p>



<p>His teams, he said, now expect two engineers to deliver in a month what previously required fifteen engineers over three. They are responding by hiring more engineers, not fewer, because the idea backlog has outrun the capacity to execute.</p>



<p>The implication is easy to miss. The bottleneck has moved. It is no longer in engineering capacity. It is decision-making speed. Engineers finish work and ask, “now what?” Product managers, not developers, have become the scarcest resource in the AI era. And the organizations pulling ahead are not the ones with the most AI tools. They are the ones that figured out how to make faster, better decisions about what to do with what AI produces.</p>



<p>This is more significant than it first appears. For three years, the dominant enterprise AI conversation has been about execution: Which tools to deploy, how to drive adoption, how to manage risk. Those are real questions. But they are not the binding constraint anymore. The binding constraint is judgment. How fast can the organization decide what to scale, what to fix and what to stop?</p>



<h2 class="wp-block-heading">The visibility problem is a decision problem</h2>



<p>What Lanai sees in customer data makes this concrete. One revenue operations team had 140 reps using AI across three regions. One rep had built a renewal outreach workflow that outperformed the team average by 110 times. Leadership had no idea it existed. There was no system to surface it, no way to connect it to the pipeline and no path to replicate it.</p>



<p>Once the workflow was visible, the team extracted it, deployed it as a governed agent and rolled it to all 140 reps across three regions in 72 hours. The result was 11.4 FTE of reclaimed capacity and $2.8 million in the affected pipeline. The technology was not the challenge. The decision was and that was only possible once someone could see what was actually happening.</p>



<p>The same pattern appears on the cost side. A customer in IT and security discovered 23 AI tools running across six departments. Nine were completely ungoverned, with customer PII flowing through personal accounts. Three enterprise licenses sat at under 8% utilization. The tools existed. The spend existed. What did not exist was a single place to see what was critical versus redundant and make a call. Once that visibility existed, they consolidated to 14 governed tools and cut $340,000 in shelfware. Not by deploying new technology. By making a decision they previously could not make because they lacked the information to make it confidently.</p>



<p><a href="https://www.coursera.org/business/resource/ai-skills-report" rel="nofollow">Coursera’s own retention data</a> points in the same direction from a different angle. Employees who completed AI training were retained at 50% higher rates than those who did not. The most valuable output was not task efficiency. It was that people who understood what AI could do started generating better ideas about what to do with it. The upside was clearer thinking about direction, not faster execution of the same tasks.</p>



<h2 class="wp-block-heading">The work itself is changing faster than the org chart</h2>



<p>There is a deeper structural issue underneath the visibility problem. The org chart and the income statement, the two systems enterprises use to understand who does the work and what it costs, were both designed in an era when the answer to “who does the work?” was so obvious nobody bothered to say it out loud: a human being.</p>



<p><a href="https://hbr.org/2014/09/the-chart-that-organized-the-20th-century?autocomplete=true" rel="nofollow">McCallum’s 1855 railroad org chart</a> mapped thousands of people across miles of track. Pacioli’s double-entry system evolved into the profit-and-loss account so merchants could see what was left after paying people, not processors. The industrial revolution added depreciation to admit that machines do work over time, but even that assumed workers were either people or large pieces of hardware. It never imagined a world where software itself is on the shop floor, doing the work as operating labor.</p>



<p>AI is operating labor in a software costume. And neither the org chart nor the P&amp;L was built to see it.</p>



<p>When an agent handles ten thousand support tickets, it appears on the P&amp;L as software expense. When a human did that work, it was labor. The substitution is real but registers nowhere official. Based on observed activity across Lanai B2B SaaS customers, here is where knowledge work actually sits today, and where customers predict it is going by 2028:</p>



<figure class="wp-block-table"><div class="overflow-table-wrapper"><table class="has-fixed-layout"><tbody><tr><td><strong>Level</strong></td><td><strong>Definition</strong></td><td><strong>Today</strong></td><td><strong>2028</strong></td></tr><tr><td>L1</td><td>Work only a human should own: accountability, trust, novel judgment</td><td>45%</td><td>20%</td></tr><tr><td>L2</td><td>Human does the work; AI assists and accelerates</td><td>35%</td><td>30%</td></tr><tr><td>L3</td><td>Agent executes; human reviews the output</td><td>15%</td><td>35%</td></tr><tr><td>L4</td><td>Agent runs end-to-end; no human required</td><td>5%</td><td>15%</td></tr></tbody></table> </div></figure>



<p><em>Source: </em><a href="https://www.withlanai.com/" rel="nofollow"><em>Lanai customer data</em></a><em>, 2026. Prediction: Lexi Reese, CEO Lanai.</em></p>



<p>The L2 peak-and-decline finding is the most counterintuitive and the most important. L2 does not decline because AI assistance gets worse. It declines because the best-adopted L2 workflows get promoted out of it. The question for any organization is not how to stay in L2. It is which L2 workflows are ready to move, and whether the organization has the data to make that call deliberately rather than accidentally.</p>



<p>By 2028, L3 will become the modal form of knowledge work. The most common configuration will be an agent executing a task while a human decides whether it was done right. That is a fundamentally different job description than what most knowledge worker roles were designed around. And it is arriving faster than most org designs are prepared for.</p>



<h2 class="wp-block-heading">The management problem nobody budgeted for</h2>



<p>Most enterprise AI dashboards are not built to surface any of this. They track adoption rates, active users and tasks completed. Those metrics measure activity. They do not measure whether the organization is converting AI activity into decisions, and decisions into results.</p>



<p>The gap shows up most visibly when the CFO asks what the company got for its AI spend. Token spend that was $5,000 a month eighteen months ago is $40,000 today in many organizations, with no clean story attached. The executives who survive that conversation are not the ones who spent less. They are the ones who built the translation layer between spend and outcome before anyone demanded it. Tokens to threads. Threads to tasks. Tasks to time saved. Time saved to business result. That chain exists in the data. Most organizations have not assembled it.</p>



<p>The CIOs who will have the clearest story for their boards in 2026 are the ones who treated AI deployment as a management problem from the start, built the systems to connect AI activity to the business outcomes they are already accountable for, and developed the organizational habit of acting on what they see.</p>



<p>Execution stops being the constraint. Judgment becomes the scarce resource. The organization that was slow because humans could not execute fast enough is now slow for a different reason: Not enough people who can make the right call under genuine uncertainty. Most org charts are designed to consume judgment, not develop it.</p>



<p>Leaders approved the tools. The ones pulling ahead are the ones who decided to own the outcomes.</p>



<p><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><strong><a href="https://www.cio.com/expert-contributor-network/">Want to join?</a></strong></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Thank You Linux Community!]]></title>
<description><![CDATA[I just want to thank the whole community for providing such a valuable, useful, revolutionary and in some ways sacred experience for free. I used Ubuntu over a decade ago for a few years but was gifted a macbook and kind of slowly stopped using my Linux computer. I recently decided enough was eno...]]></description>
<link>https://tsecurity.de/de/3521085/linux-tipps/thank-you-linux-community/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3521085/linux-tipps/thank-you-linux-community/</guid>
<pubDate>Sat, 16 May 2026 01:09:43 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>I just want to thank the whole community for providing such a valuable, useful, revolutionary and in some ways sacred experience for free. I used Ubuntu over a decade ago for a few years but was gifted a macbook and kind of slowly stopped using my Linux computer. I recently decided enough was enough and got back on the open source train. While I've been getting used to using linux again I have found so many helpful people and posts and videos all over the internet. I've also seen and heard many beautiful explanations of why human rights are something separate from political biases. I came for the kernel and software but I'm staying for the community values. Thank you Linux community for providing me with a safe harbor of like minded people during this strange and scary time. And for giving me the plans and materials to build an awesome boat (my computer). The one place I can always be assured that everything will make sense. That's a nice little reset for my brain at the end of each day. Things work the way they are supposed to for a brief change and that helps me get reoriented to take on whatever crazy stuff the world throws at us the next day.</p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/Slight-Commercial250"> /u/Slight-Commercial250 </a> <br> <span><a href="https://www.reddit.com/r/linux/comments/1tdt4p8/thank_you_linux_community/">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/1tdt4p8/thank_you_linux_community/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[How RecursiveMAS speeds up multi-agent inference by 2.4x and reduces token usage by 75%]]></title>
<description><![CDATA[One of the key challenges of current multi-agent AI systems is that they communicate by generating and sharing text sequences, which introduces latency, drives up token costs, and makes it difficult to train the entire system as a cohesive unit. To overcome this challenge, researchers at Universi...]]></description>
<link>https://tsecurity.de/de/3520880/it-nachrichten/how-recursivemas-speeds-up-multi-agent-inference-by-24x-and-reduces-token-usage-by-75/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3520880/it-nachrichten/how-recursivemas-speeds-up-multi-agent-inference-by-24x-and-reduces-token-usage-by-75/</guid>
<pubDate>Fri, 15 May 2026 23:47:15 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>One of the key challenges of current multi-agent AI systems is that they communicate by generating and sharing text sequences, which introduces latency, drives up token costs, and makes it difficult to train the entire system as a cohesive unit. </p><p>To overcome this challenge, researchers at University of Illinois Urbana-Champaign and Stanford University developed <a href="https://recursivemas.github.io/"><u>RecursiveMAS</u></a>, a framework that enables agents to collaborate and transmit information through embedding space instead of text. This change results in both efficiency and performance gains. </p><p>Experiments show that RecursiveMAS achieves accuracy improvement across complex domains like code generation, medical reasoning, and search, while also increasing inference speed and slashing token usage. </p><p>RecursiveMAS is significantly cheaper to train than standard full fine-tuning or LoRA methods, making it a scalable and cost-effective blueprint for custom multi-agent systems.</p><h2>The challenges of improving multi-agent systems</h2><p><a href="https://venturebeat.com/orchestration/research-shows-more-agents-isnt-a-reliable-path-to-better-enterprise-ai"><u>Multi-agent systems</u></a> can help tackle complex tasks that single-agent systems struggle to handle. When scaling multi-agent systems for real-world applications, a big challenge is enabling the system to evolve, improve, and adapt to different scenarios over time. </p><p>Prompt-based adaptation improves agent interactions by iteratively refining the shared context provided to the agents. By updating the prompts, the system acts as a director, guiding the agents to generate responses that are more aligned with the overarching goal. The fundamental limitation is that the capabilities of the models underlying each agent remain static. </p><p>A more sophisticated approach is to train the agents by updating the weights of the underlying models. Training an entire system of agents is difficult because updating all the parameters across multiple models is computationally non-trivial.</p><p>Even if an engineering team commits to training their models, the standard method of agents communicating via text-based interactions creates major bottlenecks. Because agents rely on sequential text generation, it causes latency as each model must wait for the previous one to finish generating its text before it can begin its own processing. </p><p>Forcing models to spell out their intermediate reasoning token-by-token just so the next model can read it is highly inefficient. It severely inflates token usage, drives up compute costs, and makes iterative learning across the whole system painfully slow to scale. </p><h2>How RecursiveMAS works</h2><p>Instead of trying to improve each agent as an isolated, standalone component, RecursiveMAS is designed to co-evolve and scale the entire multi-agent system as a single integrated whole. </p><p>The framework is inspired by <a href="https://venturebeat.com/ai/mits-new-recursive-framework-lets-llms-process-10-million-tokens-without"><u>recursive language models</u></a> (RLMs). In a standard language model, data flows linearly through a stack of distinct layers. In contrast, a recursive language model reuses a set of shared layers that processes the data and feeds it back to itself. By looping the computation, the model can deepen its reasoning without adding parameters.</p><p>RecursiveMAS extends this scaling principle from a single model to a multi-agent architecture that acts as a unified recursive system. In this setup, each agent functions like a layer in a recursive language model. Rather than generating text, the agents iteratively pass their continuous latent representations to the next agent in the sequence, creating a looped hidden stream of information flowing through the system. </p><p>This latent hand-off continues down the line through all the agents. When the final agent finishes its processing, its latent outputs are fed directly back to the very first agent, kicking off a new recursion round. </p><p>This structure allows the entire multi-agent system to interact, reflect, and refine its collective reasoning over multiple rounds entirely in the latent space, with only the very last agent producing a textual output in the final round. It is like the agents are communicating telepathically as a unified whole and the last agent provides the final response as text.</p><h2>The architecture of latent collaboration</h2><p>To make continuous latent space collaboration possible, the authors introduce a specialized architectural component called the RecursiveLink. This is a lightweight, two-layer module designed to transmit and refine a model's latent states rather than forcing it to decode text. </p><p>A language model's last-layer hidden states contain the rich, semantic representation of its reasoning process. The RecursiveLink is designed to preserve and transmit this high-dimensional information from one embedding space to another. </p><p>To avoid the cost of updating every parameter across multiple large language models, the framework keeps the models' parameters frozen. Instead, it optimizes the system by only training the parameters of the RecursiveLink modules.</p><p>To handle both internal reasoning and external communication, the system uses two variations of the module. The inner RecursiveLink operates inside an agent during its reasoning phase. It takes the model's newly generated embeddings and maps them directly back into its own input embedding space. This allows the agent to continuously generate a stream of latent thoughts without generating discrete text tokens. </p><p>The outer RecursiveLink serves as the bridge between agents. Because agents in a real-world system might use different model architectures and sizes, their internal embedding spaces have entirely different dimensions. The outer RecursiveLink includes an additional layer designed to match the embeddings from one agent's hidden dimension with the next agent's embedding space.</p><p>During training, first, the inner links are trained independently to warm up each agent's ability to think in continuous latent embeddings. Then, the system enters outer-loop training, where the diverse, frozen models are chained together in a loop, and the system is evaluated based on the final textual output of the last agent. </p><p>The only thing that gets updated in the training process is the RecursiveLink parameters and the original model weights remain unchanged, similar to <a href="https://venturebeat.com/ai/running-thousands-of-llms-on-one-gpu-is-now-possible-with-s-lora"><u>low-rank adaptation</u></a> (LoRA). Another advantage of this system comes into effect when you have multiple agents on top of the same backbone model. </p><p>If you have a multi-agent system where two agents are built on the exact same foundation model acting in different roles, you do not need to load two copies of the model into your GPU memory, nor do you train them separately. The agents will share the same backbone as the brain and use the RecursiveLink as the connective tissue.</p><h2>RecursiveMAS in action</h2><p>The researchers evaluated RecursiveMAS across nine benchmarks spanning mathematics, science and medicine, code generation, and search-based question answering. They created a multi-agent system using open-weights models including Qwen, Llama-3, Gemma3, and Mistral. These models were assigned roles to form different agent collaboration patterns such as sequential reasoning and mixture-of-experts collaboration. </p><p>RecursiveMAS was compared to baselines under identical training budgets, including standalone models enhanced with LoRA or full supervised fine-tuning, alternative multi-agent frameworks like Mixture-of-Agents and TextGrad, and recursive baselines like LoopLM. It was also compared to Recursive-TextMAS, which uses the same recursive loop structure as RecursiveMAS but forces the agents to explicitly communicate via text.</p><p>RecursiveMAS achieved an average accuracy improvement of 8.3% compared to the strongest baselines across the benchmarks. It excelled particularly on reasoning-heavy tasks, outperforming text-based optimization methods like TextGrad by 18.1% on AIME2025 and 13% on AIME2026. </p><p>Because it avoids generating text at every step, RecursiveMAS achieved 1.2x to 2.4x end-to-end inference speedup. RecursiveMAS is also much more token efficient than the alternative. Compared to the text-based Recursive-TextMAS, it reduces token usage by 34.6% in the first round of the recursion, and by round three, it achieves 75.6% token reduction. RecursiveMAS also proved remarkably cheap to train. Because it only updates the lightweight RecursiveLink modules, which consist of roughly 13 million parameters or about 0.31% of the trainable parameters of the frozen models, it requires the lowest peak GPU memory and cuts training costs by more than half compared to full fine-tuning.</p><h2>Enterprise adoption</h2><p>The efficiency gains — lower token consumption, reduced GPU memory requirements, and faster inference — are intended to make complex multi-step agent workflows viable in production environments without the compute overhead that limits enterprise agentic deployments. The researchers have released the <a href="https://github.com/RecursiveMAS/RecursiveMAS">code</a> and <a href="https://huggingface.co/RecursiveMAS">trained model weights</a> under the Apache 2.0 license.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Cisco patches another actively exploited SD-WAN zero-day (CVE-2026-20182)]]></title>
<description><![CDATA[Cisco has patched yet another Catalyst SD-WAN Controller authentication bypass vulnerability (CVE-2026-20182) that has been exploited as a zero-day by “a highly sophisticated cyber threat actor”. About CVE-2026-20182 CVE-2026-20182 – affecting both Cisco Catalyst SD-WAN Controller (the “brain” of...]]></description>
<link>https://tsecurity.de/de/3519774/it-security-nachrichten/cisco-patches-another-actively-exploited-sd-wan-zero-day-cve-2026-20182/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3519774/it-security-nachrichten/cisco-patches-another-actively-exploited-sd-wan-zero-day-cve-2026-20182/</guid>
<pubDate>Fri, 15 May 2026 15:08:08 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Cisco has patched yet another Catalyst SD-WAN Controller authentication bypass vulnerability (CVE-2026-20182) that has been exploited as a zero-day by “a highly sophisticated cyber threat actor”. About CVE-2026-20182 CVE-2026-20182 – affecting both Cisco Catalyst SD-WAN Controller (the “brain” of the…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/cisco-patches-another-actively-exploited-sd-wan-zero-day-cve-2026-20182/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/cisco-patches-another-actively-exploited-sd-wan-zero-day-cve-2026-20182/">Cisco patches another actively exploited SD-WAN zero-day (CVE-2026-20182)</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Cisco patches another actively exploited SD-WAN zero-day (CVE-2026-20182)]]></title>
<description><![CDATA[Cisco has patched yet another Catalyst SD-WAN Controller authentication bypass vulnerability (CVE-2026-20182) that has been exploited as a zero-day by “a highly sophisticated cyber threat actor”. About CVE-2026-20182 CVE-2026-20182 – affecting both Cisco Catalyst SD-WAN Controller (the “brain” of...]]></description>
<link>https://tsecurity.de/de/3519715/it-security-nachrichten/cisco-patches-another-actively-exploited-sd-wan-zero-day-cve-2026-20182/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3519715/it-security-nachrichten/cisco-patches-another-actively-exploited-sd-wan-zero-day-cve-2026-20182/</guid>
<pubDate>Fri, 15 May 2026 14:53:29 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Cisco has patched yet another Catalyst SD-WAN Controller authentication bypass vulnerability (CVE-2026-20182) that has been exploited as a zero-day by “a highly sophisticated cyber threat actor”. About CVE-2026-20182 CVE-2026-20182 – affecting both Cisco Catalyst SD-WAN Controller (the “brain” of the Cisco Catalyst SD-WAN solution) and Cisco Catalyst SD-WAN Manager (the management plane for the entire SD-WAN fabric) – stems from a flawed peering authentication mechanism. It affects both on-prem and cloud deployments. CVE-2026-20182 was reported … <a href="https://www.helpnetsecurity.com/2026/05/15/cisco-sd-wan-zero-day-cve-2026-20182/" rel="nofollow">More <span class="meta-nav">→</span></a></p>
<p>The post <a href="https://www.helpnetsecurity.com/2026/05/15/cisco-sd-wan-zero-day-cve-2026-20182/">Cisco patches another actively exploited SD-WAN zero-day (CVE-2026-20182)</a> appeared first on <a href="https://www.helpnetsecurity.com/">Help Net Security</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Four cutting-edge tools for spec-driven development]]></title>
<description><![CDATA[In February 2025, AI developer Andrej Karpathy posted a tweet (or whatever they call them now on the site formerly known as Twitter) about what he called “vibe coding”:




There’s a new kind of coding I call “vibe coding”, where you fully give in to the vibes, embrace exponentials, and forget th...]]></description>
<link>https://tsecurity.de/de/3519072/ai-nachrichten/four-cutting-edge-tools-for-spec-driven-development/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3519072/ai-nachrichten/four-cutting-edge-tools-for-spec-driven-development/</guid>
<pubDate>Fri, 15 May 2026 11:18:30 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>In February 2025, AI developer <a href="https://x.com/karpathy">Andrej Karpathy</a> posted a tweet (or whatever they call them now on the site formerly known as Twitter) about what he called “<a href="https://x.com/karpathy/status/1886192184808149383?lang=en">vibe coding</a>”:</p>



<blockquote class="wp-block-quote is-layout-flow wp-block-quote-is-layout-flow">
<p>There’s a new kind of coding I call “vibe coding”, where you fully give in to the vibes, embrace exponentials, and forget that the code even exists. It’s possible because the LLMs (e.g. Cursor Composer w Sonnet) are getting too good. Also I just talk to Composer with SuperWhisper so I barely even touch the keyboard. I ask for the dumbest things like “decrease the padding on the sidebar by half” because I’m too lazy to find it. I “Accept All” always, I don’t read the diffs anymore. When I get error messages I just copy paste them in with no comment, usually that fixes it. The code grows beyond my usual comprehension, I’d have to really read through it for a while. Sometimes the LLMs can’t fix a bug so I just work around it or ask for random changes until it goes away. It’s not too bad for throwaway weekend projects, but still quite amusing. I’m building a project or webapp, but it’s not really coding — I just see stuff, say stuff, run stuff, and copy paste stuff, and it mostly works.</p>
</blockquote>



<p>Note that Karpathy was using <a href="https://www.infoworld.com/article/4078884/what-is-vibe-coding-ai-writes-the-code-so-developers-can-think-big.html" data-type="link" data-id="https://www.infoworld.com/article/4078884/what-is-vibe-coding-ai-writes-the-code-so-developers-can-think-big.html">vibe coding</a> for “throwaway weekend projects,” not his day job. He also deprecates the way he asks for “the dumbest things,” because he’s “too lazy to find it.” He says vibe coding is possible “because the LLMs (e.g. Cursor Composer w Sonnet) are getting too good.” He also says “it mostly works.”</p>



<p>“Mostly works” is not a glowing recommendation, and applying vibe coding to serious projects presents serious risks, including the creation of hidden bugs that will bite you later. It’s folly. It also inevitably creates technical debt.</p>



<p>If someone competent and experienced cleans up and refactors the code produced by the <a href="https://www.infoworld.com/article/2335213/large-language-models-the-foundations-of-generative-ai.html" data-type="link" data-id="https://www.infoworld.com/article/2335213/large-language-models-the-foundations-of-generative-ai.html">large language models</a>, you can avoid the worst outcomes and reduce the technical debt, but that often takes more time than just designing the architecture and writing the code by hand. AI slop followed by human cleanup leads to reduced programmer productivity, exactly the opposite of what you want to achieve by using LLMs to generate code.</p>



<h2 class="wp-block-heading">What is spec-driven development?</h2>



<p>Spec-driven development (SDD) is one way to avoid the chaos of vibe coding without completely returning to manual coding. It doesn’t involve waterfall planning or developing exhaustive requirements documents — it’s lighter-weight than those, and designed to be readable and concise.</p>



<p>In his <a href="https://github.blog/ai-and-ml/generative-ai/spec-driven-development-with-ai-get-started-with-a-new-open-source-toolkit/">introduction to Spec Kit</a>, <a></a><a>Den Delimarsky</a> at Microsoft calls a spec “version control for your thinking.” He goes on to say “This is a contract for how your code should behave and becomes the source of truth your tools and AI agents use to generate, test, and validate code. The result is less guesswork, fewer surprises, and higher-quality code.”</p>



<p>Birgitta Böckeler of Thoughtworks <a href="https://martinfowler.com/articles/exploring-gen-ai/sdd-3-tools.html">divides spec-driven development into three implementation levels</a>: spec-first, spec-anchored, and spec-as-source. Spec-first means that “a well-thought-out spec is written first, and then used in the AI-assisted development workflow for the task at hand.” Spec-anchored means that “the spec is kept even after the task is complete, to continue using it for evolution and maintenance of the respective feature.” <a>Spec-as-source </a>means that “the spec is the main source file over time, and only the spec is edited by the human, the human never touches the code.”</p>



<p>I’m not at all sure that any current tool implements spec-as-source. It’s a worthy aspiration, but we’re not there yet.</p>



<p>Let’s take a brief look at four tools and frameworks that currently support spec-driven development. </p>



<h2 class="wp-block-heading">Kiro</h2>



<p>AWS <a href="https://kiro.dev/blog/introducing-kiro-autonomous-agent/" data-type="link" data-id="https://kiro.dev/blog/introducing-kiro-autonomous-agent/">describes Kiro</a> as an autonomous agent that maintains context and learns over time while working on software development tasks independently. Kiro is available both as an IDE (based on Code OSS) and a CLI tool, and was developed by “a small, opinionated team within AWS.” <a href="https://kiro.dev/" data-type="link" data-id="https://kiro.dev/">Kiro IDE</a> explicitly supports both vibe coding and spec-driven development. <a href="https://kiro.dev/cli/" data-type="link" data-id="https://kiro.dev/cli/">Kiro CLI</a> doesn’t deal with specs at this point, although it does have a planner agent and agent steering.  </p>



<p>Kiro SDD generates three markdown files that together comprise the <a href="https://kiro.dev/docs/specs/">specification</a>.</p>



<ul class="wp-block-list">
<li>Requirements (requirements.md) – Captures user stories and acceptance criteria in structured EARS notation. </li>



<li>Design (design.md) – Documents technical architecture, sequence diagrams, and implementation considerations. </li>



<li>Tasks (tasks.md) – Provides a detailed implementation plan with discrete, trackable tasks.</li>
</ul>



<p>You can also <a href="https://kiro.dev/docs/specs/best-practices/#how-do-i-import-existing-designs-or-architecture" data-type="link" data-id="https://kiro.dev/docs/specs/best-practices/#how-do-i-import-existing-designs-or-architecture">import specs</a> from other systems and <a href="https://kiro.dev/docs/specs/best-practices/#how-do-i-iterate-on-my-feature-specs" data-type="link" data-id="https://kiro.dev/docs/specs/best-practices/#how-do-i-iterate-on-my-feature-specs">iterate on your specs</a>. You can even generate specs based on a vibe-coding session. Ideally, you would <a href="https://kiro.dev/docs/specs/best-practices/">create a spec for each project feature</a>.</p>



<p>EARS (Easy Approach to Requirements Syntax) notation captures user stories and follows the pattern:</p>



<p>        WHEN [condition/event]<br>        THE SYSTEM SHALL [expected behavior]</p>



<p>This format is clear and testable. Kiro can generate <a href="https://kiro.dev/docs/specs/correctness/">property-based tests</a> (PBT) based on your EARS-formatted requirements; these are more comprehensive than the usual unit tests.</p>



<p>In addition, Kiro can generate three markdown files that together define the steering for the agents. Steering gives Kiro persistent knowledge about your workspace and its conventions.</p>



<ul class="wp-block-list">
<li>Product overview (product.md) – Defines your product’s purpose, target users, key features, and business objectives. This helps Kiro understand the “why” behind technical decisions and suggest solutions aligned with your product goals.</li>



<li>Technology stack (tech.md) – Documents your chosen frameworks, libraries, development tools, and technical constraints. When Kiro suggests implementations, it will prefer your established stack over alternatives.</li>



<li>Project structure (structure.md) – Outlines file organization, naming conventions, import patterns, and architectural decisions. This ensures generated code fits seamlessly into your existing codebase.</li>
</ul>



<p>With my <a href="https://kiro.dev/pricing/">free plan</a>, Kiro IDE currently supports three Claude models, Sonnet 4.5, Sonnet 4, and Haiku 4.5. It can automatically select models if you wish. The documentation also mentions Opus 4.5, which I assume can be activated with a Pro ($20/month) or better plan.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/05/spec-driven-development-Kiro.png?w=1024" alt="spec-driven development - Kiro" class="wp-image-4171396" width="1024" height="649" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption"><p>Kiro IDE supports both vibe coding and spec-driven development workflows.</p>
</figcaption></figure><p class="imageCredit">Foundry</p></div>



<h2 class="wp-block-heading">Spec Kit</h2>



<p><a href="https://github.blog/ai-and-ml/generative-ai/spec-driven-development-with-ai-get-started-with-a-new-open-source-toolkit/">Spec Kit</a> is an <a href="https://github.com/github/spec-kit">open-source toolkit</a> for spec-driven development from Microsoft. It provides a four-phase, structured process to bring spec-driven development to coding agent workflows, and integrates with some 30 coding agents. </p>



<p>You start by installing the <code>specify</code> CLI, using <code>uv</code> for a persistent installation (recommended) or running it once with <code>uvx</code>. The <code>specify</code> command can initialize Spec Kit projects, optionally specify an AI agent, and check for installed tools. Once you have initialized a project your <a href="https://github.github.io/spec-kit/reference/integrations.html">AI coding agent</a> (e.g. GitHub Copilot or Claude Code) has access to several slash commands for structured development: </p>



<ul class="wp-block-list">
<li><code>/speckit.constitution</code> – Project governing principles</li>



<li><code>/speckit.specify</code> – Requirements and user stories </li>



<li><code>/speckit.clarify</code> – Clarify underspecified areas </li>



<li><code>/speckit.plan</code> – Technical implementation plans, including tech stack</li>



<li><code>/speckit.tasks</code> – Actionable task lists for implementation</li>



<li><code>/speckit.analyze</code> – Consistency and coverage analysis</li>



<li><code>/speckit.implement</code> – Execute all tasks</li>



<li><code>/speckit.checklist</code> – Checklists that validate requirements</li>
</ul>



<p>Spec Kit can generate a project from scratch (Greenfield), modernize legacy code (Brownfield), and explore diverse options in parallel. There’s been <a href="https://github.com/github/spec-kit/discussions/152">some discussion</a> about how Spec Kit is best used and whether Spec Kit is spec-anchored; there’s no general consensus, other than observing that Spec Kit as released prefers a small spec per feature rather than a giant spec for a whole project.</p>



<h2 class="wp-block-heading">Tessl</h2>



<p>The slogan is “Keep your agents on the rails with <a href="https://tessl.io/">Tessl</a>.” Tessl tries to do this with a framework and package registry, plus evaluations, all aided by a CLI. The Tessl CLI can scan your project for dependencies and configure Model Context Protocol (MCP) server settings for AI coding agents such as Claude Code, Codex, and Gemini. </p>



<p>The CLI can also search the package registry for “tiles” by name, PURL, or HTTP URL. Tiles contain skills (procedural workflows for the agent), documentation (for libraries and frameworks that agents can query on-demand), and rules (mandatory coding standards and conventions). You can use the existing registry and also create your own skills and tiles.</p>



<p>You can do <a href="https://docs.tessl.io/use/spec-driven-development-with-tessl">spec-driven development with Tessl</a> using the Tessl SDD tile. Once that is installed, simply include “use spec-driven development” in your prompt. Then the agent will ask questions and write specs before code. You can improve your results by also installing tiles that document the tools you use from the <a href="https://tessl.io/registry">Tessl skills registry</a>.</p>



<h2 class="wp-block-heading">Zenflow</h2>



<p><a href="https://zencoder.ai/zenflow">Zenflow</a> is a free platform that coordinates AI agents to build software. It features “spec-driven workflows, built-in verification, and multi-agent execution that actually works.” Another term for coordination is orchestration, and Zenflow is also described as an orchestration layer.</p>



<p>Developed by the <a href="https://zencoder.ai/">Zencoder</a> team, Zenflow works with the Zencoder plugins. (And features from Zenflow, such as guided workflows, have been added to Zencoder.) The CEO of Zencoder, Andrew Filev, told me that his team of experienced engineers has been using Zenflow for their own product development for over a year when I questioned whether it is ready for production code.</p>



<p>The high-level description of the relationship between Zencoder and Zenflow is that Zenflow is the workflow brain and Zencoder executes the work. You may have noticed some naming confusion: Zencoder is not only the name of the company and the name of its AI plug-in for IDEs, but it is also the name of the company’s in-house coding agent, which is one of four agent options for Zenflow (the others being Claude Code, Codex, and Gemini) and one of at least nine models available to the Zencoder plug-in.</p>



<p>When you start a Zenflow project, you’re offered a choice of standard workflows: Quick Change, Fix Bug, Spec and Build, or Full SDD Workflow, depending on scope. The wider the scope, the more structure you need in the workflow to keep the implementation from drifting away from the requirements. You can also define your own workflows, perhaps to conform to your shop’s standards.</p>



<p>Zenflow can run multiple tasks in parallel in isolated environments. The agents coordinate within workflows without corrupting your codebase.</p>



<p>Zenflow automates verification of its changes. Every workflow runs automated tests and cross-agent code review. Failed tests trigger automatic fixes. Your code ships only after passing all of the verification gates.</p>



<p>Zenflow projects are broken down into tasks, and those are divided into subtasks and chats. Each task runs inside its own isolated Git worktree. You can view the status of all tasks in Kanban boards or stacked list views.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/05/spec-driven-development-Zenflow.png?w=1024" alt="spec-driven development - Zenflow" class="wp-image-4171400" width="1024" height="685" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption"><p>Zenflow supports multiple workflows, from quick changes all the way up to full SDD. You can also define custom workflows.</p>
</figcaption></figure><p class="imageCredit">Foundry</p></div>



<h2 class="wp-block-heading">Feel the vibes?</h2>



<p>Where and when does software-driven development make sense? In broad strokes, you can get away with doing AI-assisted coding without specs for personal projects, small features, and bug fixes. You need specifications to keep AI coding agents on the rails for large features, major refactoring, and enterprise-level projects.</p>



<p>Which spec-driven development tool should you use, if any? That depends entirely on your environment, your goals, and your personal and team preferences. Kiro, Spec Kit, Tessl, and Zenflow are all good places to start. </p>
</div></div></div>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Employees Report AI ‘Brain Fry’]]></title>
<description><![CDATA[Use of AI tools to boost worker productivity may backfire if used improperly, study finds, as staff report ‘brain fry’ This article has been indexed from Silicon UK Read the original article: Employees Report AI ‘Brain Fry’
Read more →
The post Employees Report AI ‘Brain Fry’ appeared first on IT...]]></description>
<link>https://tsecurity.de/de/3518687/it-security-nachrichten/employees-report-ai-brain-fry/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3518687/it-security-nachrichten/employees-report-ai-brain-fry/</guid>
<pubDate>Fri, 15 May 2026 09:08:16 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Use of AI tools to boost worker productivity may backfire if used improperly, study finds, as staff report ‘brain fry’ This article has been indexed from Silicon UK Read the original article: Employees Report AI ‘Brain Fry’</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/employees-report-ai-brain-fry/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/employees-report-ai-brain-fry/">Employees Report AI ‘Brain Fry’</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[IT Security News Hourly Summary 2026-05-15 09h : 10 posts]]></title>
<description><![CDATA[10 posts were published in the last hour 7:3 : [Guest Diary] New Malware Libraries means New Signatures, (Fri, May 15th) 7:2 : Employees Report AI ‘Brain Fry’ 7:2 : TeamPCP Hackers Exploit CI/CD Pipelines to Steal Cloud Credentials 7:2…
Read more →
The post IT Security News Hourly Summary 2026-05...]]></description>
<link>https://tsecurity.de/de/3518685/it-security-nachrichten/it-security-news-hourly-summary-2026-05-15-09h-10-posts/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3518685/it-security-nachrichten/it-security-news-hourly-summary-2026-05-15-09h-10-posts/</guid>
<pubDate>Fri, 15 May 2026 09:08:12 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>10 posts were published in the last hour 7:3 : [Guest Diary] New Malware Libraries means New Signatures, (Fri, May 15th) 7:2 : Employees Report AI ‘Brain Fry’ 7:2 : TeamPCP Hackers Exploit CI/CD Pipelines to Steal Cloud Credentials 7:2…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/it-security-news-hourly-summary-2026-05-15-09h-10-posts/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/it-security-news-hourly-summary-2026-05-15-09h-10-posts/">IT Security News Hourly Summary 2026-05-15 09h : 10 posts</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Innovator Spotlight: Radware]]></title>
<description><![CDATA[Radware’s Quiet Revolution In AI-Powered Defense If you have been around this industry long enough, Radware probably lives in a nostalgic corner of your brain. Load balancing. Application delivery controllers…. The post Innovator Spotlight: Radware appeared first on Cyber Defense…
Read more →
The...]]></description>
<link>https://tsecurity.de/de/3517932/it-security-nachrichten/innovator-spotlight-radware/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3517932/it-security-nachrichten/innovator-spotlight-radware/</guid>
<pubDate>Thu, 14 May 2026 23:36:31 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Radware’s Quiet Revolution In AI-Powered Defense If you have been around this industry long enough, Radware probably lives in a nostalgic corner of your brain. Load balancing. Application delivery controllers…. The post Innovator Spotlight: Radware appeared first on Cyber Defense…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/innovator-spotlight-radware/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/innovator-spotlight-radware/">Innovator Spotlight: Radware</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Innovator Spotlight: Radware]]></title>
<description><![CDATA[Radware’s Quiet Revolution In AI-Powered Defense If you have been around this industry long enough, Radware probably lives in a nostalgic corner of your brain. Load balancing. Application delivery controllers....
The post Innovator Spotlight: Radware appeared first on Cyber Defense Magazine.]]></description>
<link>https://tsecurity.de/de/3517910/it-security-nachrichten/innovator-spotlight-radware/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3517910/it-security-nachrichten/innovator-spotlight-radware/</guid>
<pubDate>Thu, 14 May 2026 23:22:29 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<img width="800" height="533" src="https://www.cyberdefensemagazine.com/wp-content/uploads/2026/05/radspot26.jpg" class="webfeedsFeaturedVisual wp-post-image" alt="" link_thumbnail="" decoding="async" fetchpriority="high" srcset="https://www.cyberdefensemagazine.com/wp-content/uploads/2026/05/radspot26.jpg 800w, https://www.cyberdefensemagazine.com/wp-content/uploads/2026/05/radspot26-768x512.jpg 768w" sizes="(max-width: 800px) 100vw, 800px"><p>Radware’s Quiet Revolution In AI-Powered Defense If you have been around this industry long enough, Radware probably lives in a nostalgic corner of your brain. Load balancing. Application delivery controllers....</p>
<p>The post <a href="https://www.cyberdefensemagazine.com/innovator-spotlight-radware/" data-wpel-link="internal">Innovator Spotlight: Radware</a> appeared first on <a href="https://www.cyberdefensemagazine.com/" data-wpel-link="internal">Cyber Defense Magazine</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[How Distressing Material Shapes Investigator Well-Being]]></title>
<description><![CDATA[Author: Forensic Focus: Digital Forensics & DFIR - Bewertung: 0x - Views:0 Dr. Fazeelat Duran, Assistant Professor in Psychology at the University of Birmingham, joins the Forensic Focus Podcast to talk about the psychological impact of working with distressing material in law enforcement roles. ...]]></description>
<link>https://tsecurity.de/de/3516358/it-security-video/how-distressing-material-shapes-investigator-well-being/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3516358/it-security-video/how-distressing-material-shapes-investigator-well-being/</guid>
<pubDate>Thu, 14 May 2026 12:17:07 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: Forensic Focus: Digital Forensics &amp; DFIR - Bewertung: 0x - Views:0 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/8OWw7Vw9i-A?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>Dr. Fazeelat Duran, Assistant Professor in Psychology at the University of Birmingham, joins the Forensic Focus Podcast to talk about the psychological impact of working with distressing material in law enforcement roles. Drawing on her recent longitudinal study — the first of its kind to follow newly recruited secondary investigators and analysts from day one through 18 months in role — Dr. Duran explains how repeated, indirect exposure to traumatic material shapes mental health over time. She walks through the trajectory her team observed at six, 12, and 18 months, the concept of "dosage of exposure," and why early warning signs often go hidden in the first six months when the novelty effect masks the emotional toll to come.<br />
<br />
The conversation then turns to coping strategies, the difference between adaptive and maladaptive responses (including the trap of thought suppression), and the idea of a psychological contract between staff and the organisation — and what happens when that contract is breached through unmanageable workloads, limited staffing, and a lack of allocated time for well-being resources. Dr. Duran and host Paul also discuss what organisations should be doing differently, why a one-size-fits-all approach to support fails this group, and the next phase of Dr. Duran's work, including brain imaging findings and a new study on neurodivergence in this workforce.<br />
<br />
#secondarytraumaticstress #mentalhealth  #lawenforcement  #wellbeing  #psychologicalcontract #digitalforensics  #dfir <br />
<br />
00:00 Introducing Dr Fazeelat Duran<br />
02:09 Secondary Trauma Explained<br />
03:42 Research Gap and Longitudinal Study Design<br />
11:17 Early Warning Signs<br />
12:51 Proactive Tailored Support<br />
18:02 Mixed Methods Evidence<br />
19:49 Dosage of Exposure<br />
22:59 Daily Volume and Attrition<br />
25:16 Coping Shifts Over Time<br />
26:45 Maladaptive Coping Patterns<br />
29:05 Isolation and Social Strain<br />
30:34 Workload and AI Pressure<br />
33:08 Psychological Contract Breach<br />
35:23 Building a Caring Culture<br />
37:25 Early Support and Preparation<br />
40:27 Signs, Symptoms and Self Care<br />
42:30 Neurodivergence Research<br />
44:51 Closing Reflections<br />
<br />
👉 Visit Forensic Focus: https://www.forensicfocus.com<br />
🎧 Video/Transcript: https://www.forensicfocus.com/podcast/how-distressing-material-shapes-investigator-well-being/<br />
<br />
📝 Show Notes <br />
Ongoing Exposure to Distressing Material is Associated with Worsening Mental Health in UK Law Enforcement Staff: a Longitudinal Interview Study – https://link.springer.com/article/10.1007/s11896-026-09809-2<br />
Dr Fazeelat Duran, University of Birmingham – https://www.birmingham.ac.uk/staff/profiles/psychology/duran-fazeelat<br />
National Police Chiefs' Council (NPCC) Academic Centres of Excellence – https://news.npcc.police.uk/releases/npcc-creating-nine-policing-academic-centres-of-excellence-p-aces<br />
<br />
👉 Follow Forensic Focus <br />
RSS | https://www.forensicfocus.com/feed <br />
YouTube | https://youtube.com/@ForensicFocus <br />
Podcast | https://forensicfocus.com/podcast <br />
LinkedIn Page | https://linkedin.com/company/forensicfocus <br />
LinkedIn Group | https://linkedin.com/groups/693917 <br />
X (Twitter) | https://x.com/ForensicFocus <br />
Facebook | https://facebook.com/forensicfocus <br />
Bluesky | https://bsky.app/profile/forensicfocus.bsky.social <br />
Instagram | https://instagram.com/forensicfocus <br />
TikTok | https://tiktok.com/@forensicfocus <br />
Mastodon | https://dfir.social/@forensicfocus<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[White-collar workers report growing feelings of ‘AI brain fry’]]></title>
<description><![CDATA[Workers are reporting feeling overwhelmed by the new technology]]></description>
<link>https://tsecurity.de/de/3514591/ai-nachrichten/white-collar-workers-report-growing-feelings-of-ai-brain-fry/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3514591/ai-nachrichten/white-collar-workers-report-growing-feelings-of-ai-brain-fry/</guid>
<pubDate>Wed, 13 May 2026 19:18:35 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Workers are reporting feeling overwhelmed by the new technology]]></content:encoded>
</item>
<item>
<title><![CDATA[Your “um” and pauses could reveal early dementia risk]]></title>
<description><![CDATA[The little pauses, “ums,” and moments when you struggle to find the right word may reveal far more about your brain than anyone realized. Researchers discovered that everyday speech patterns are closely tied to executive function — the mental system that powers memory, planning, focus, and flexib...]]></description>
<link>https://tsecurity.de/de/3514217/ai-nachrichten/your-um-and-pauses-could-reveal-early-dementia-risk/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3514217/ai-nachrichten/your-um-and-pauses-could-reveal-early-dementia-risk/</guid>
<pubDate>Wed, 13 May 2026 17:17:49 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The little pauses, “ums,” and moments when you struggle to find the right word may reveal far more about your brain than anyone realized. Researchers discovered that everyday speech patterns are closely tied to executive function — the mental system that powers memory, planning, focus, and flexible thinking. By using AI to analyze natural conversations, the team found they could predict cognitive performance with surprising accuracy, potentially opening the door to simple speech-based tools that could detect early signs of dementia long before traditional testing does.]]></content:encoded>
</item>
<item>
<title><![CDATA[First Real-Time Brain-Controlled Hearing Device]]></title>
<description><![CDATA[Researchers at Columbia demonstrated the first real-time brain-controlled hearing system that can identify which speaker a listener is focusing on in a noisy environment and automatically amplify that voice while suppressing others. "This breakthrough addresses the 'cocktail party effect,' a majo...]]></description>
<link>https://tsecurity.de/de/3510788/it-security-nachrichten/first-real-time-brain-controlled-hearing-device/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3510788/it-security-nachrichten/first-real-time-brain-controlled-hearing-device/</guid>
<pubDate>Tue, 12 May 2026 17:06:53 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Researchers at Columbia demonstrated the first real-time brain-controlled hearing system that can identify which speaker a listener is focusing on in a noisy environment and automatically amplify that voice while suppressing others. "This breakthrough addresses the 'cocktail party effect,' a major limitation of conventional hearing aids, which often struggle to distinguish between overlapping conversations in noisy settings," reports Neuroscience News. From the report: In the new study, Columbia researchers teamed up with surgeons and their epilepsy patients who were undergoing brain surgery to better pinpoint the sources of their seizures. The hospital patients, who volunteered to be part of this study, already had electrodes implanted in their brains. [senior author Nima Mesgarani's] system used the electrodes to measure the brain activity of the patients as they focused on one of two overlapping conversations played simultaneously. The system then automatically detected which conversation a patient was paying attention to and adjusted the volume in real time, turning up that conversation while quieting the other. For one volunteer, the experience of controlling the system with her brain was literally unbelievable. She accused the researchers of secretly adjusting the volumes. Others told stories about friends and family with hearing impairments who could benefit from such a technology. One person said: "It seems like science fiction."
 
[...] The scientists developed real-time machine-learning algorithms that could examine the brainwaves and identify which conversation the patients were paying attention to. Once deployed, their system could rapidly deduce which conversation each listener was paying attention to and make it easier for them to hear it. This happened both when the researchers guided the subjects toward a particular conversation, and when the subjects chose freely, as would be necessary in a real-world conversation. "For this to work in real time, the system has to be very fast, accurate and stable for the experience to feel pleasant for the listener," Dr. Mesgarani said. The scientists found their new system correctly identified which conversation the volunteers paid attention to. This dramatically improved the intelligibility of the speech the volunteers focused on, reduced listening effort, and was consistently preferred by the volunteers when compared to conversations the system did not provide assistance with. One volunteer recalled her uncle, who had hearing problems. "Can you imagine if this technology existed in a world [where] ... he could access it? He might actually live a much more peaceful... life." The research has been published in Nature Neuroscience.<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=First+Real-Time+Brain-Controlled+Hearing+Device%3A+https%3A%2F%2Fscience.slashdot.org%2Fstory%2F26%2F05%2F12%2F071255%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fscience.slashdot.org%2Fstory%2F26%2F05%2F12%2F071255%2Ffirst-real-time-brain-controlled-hearing-device%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://science.slashdot.org/story/26/05/12/071255/first-real-time-brain-controlled-hearing-device?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
</channel>
</rss>
<!-- Generated in 0,30ms -->